Privacy Policy
Effective Date: January 1, 2026
Parent Entity: XRTX Group (Operating XRTX Security, XRTX Labs, XRTX Systems, and associated initiatives)
Official Domain: xrtx.co.uk
1. Our Privacy Philosophy
At XRTX Group, privacy is not a compliance checkbox — it is a foundational architectural principle. Our development philosophy is defined by Security and Privacy by Design:
"Collect what is strictly necessary, protect what is collected with high-assurance cryptography, and eliminate unnecessary exposure of user information."
We do not sell, rent, or commoditize user data. We engineer systems with zero-knowledge paradigms, client-side encryption, and minimal telemetry.
2. Information We Collect
A. Information You Voluntarily Provide
When you communicate with us via our contact channels, email addresses, or consulting inquiries, we may receive:
- Contact Information: Email address, name, or handle provided in correspondence.
- Inquiry Details: Context regarding your security requirements or project scope.
B. Technical & Infrastructure Telemetry
When accessing our public web services, minimal non-identifying telemetry may be processed temporarily for network integrity, DDoS mitigation, and firewall protection:
- Anonymized IP addresses and request timestamps.
- User-agent and browser protocol version (for rendering optimization).
- Server response metrics to maintain service availability.
We do not use invasive third-party cross-site trackers or behavioral advertising trackers.
3. Cryptographic Protection & Data Security
We implement rigorous physical, technical, and administrative safeguards designed to maintain confidentiality and prevent unauthorized access:
- Encrypted Transports: All communications enforce modern TLS (Transport Layer Security) with strict cipher suites and HSTS.
- End-to-End Cryptography: Where communication and storage tools are deployed, cryptographic keys remain isolated and under user or client control.
- Principle of Least Privilege: Internal access to operational systems is restricted through zero-trust authentication boundaries.
4. Third-Party Services & Infrastructure
To provide resilient, high-speed global availability, we may utilize privacy-conscious infrastructure providers (such as Cloudflare for DDoS protection and DNS routing). These providers only process data necessary to route and protect network traffic in accordance with strict security standards.
We do not integrate with third-party data brokers or advertising exchanges.
5. Data Retention & Minimization
We retain correspondence and operational logs only for the minimum duration required to:
- Fulfill the direct purpose for which it was provided.
- Maintain infrastructure resilience, security auditing, and fraud prevention.
- Comply with applicable statutory and regulatory requirements.
Once data is no longer necessary, it is securely purged or permanently anonymized.
6. Your Rights & Choices
Depending on your jurisdiction (including GDPR, UK Data Protection Act, and CCPA), you hold fundamental rights regarding your information:
- Right of Access & Portability: Request confirmation of what minimal data we hold.
- Right to Rectification: Request correction of inaccurate information.
- Right to Erasure: Request immediate deletion of your correspondence or records where legally permissible.
- Right to Object: Opt out of any non-essential communications at any time.
7. Contact Our Privacy & Security Team
For inquiries, verification requests, or data privacy concerns, contact our dedicated team:
- Official Inquiries & Privacy Operations: [email protected]
- Website: xrtx.co.uk
Thank you for trusting XRTX Group with your security and privacy.