Skip to main content

Privacy Policy

Effective Date: January 1, 2026
Parent Entity: XRTX Group (Operating XRTX Security, XRTX Labs, XRTX Systems, and associated initiatives)
Official Domain: xrtx.co.uk


1. Our Privacy Philosophy

At XRTX Group, privacy is not a compliance checkbox — it is a foundational architectural principle. Our development philosophy is defined by Security and Privacy by Design:

"Collect what is strictly necessary, protect what is collected with high-assurance cryptography, and eliminate unnecessary exposure of user information."

We do not sell, rent, or commoditize user data. We engineer systems with zero-knowledge paradigms, client-side encryption, and minimal telemetry.


2. Information We Collect

A. Information You Voluntarily Provide

When you communicate with us via our contact channels, email addresses, or consulting inquiries, we may receive:

  • Contact Information: Email address, name, or handle provided in correspondence.
  • Inquiry Details: Context regarding your security requirements or project scope.

B. Technical & Infrastructure Telemetry

When accessing our public web services, minimal non-identifying telemetry may be processed temporarily for network integrity, DDoS mitigation, and firewall protection:

  • Anonymized IP addresses and request timestamps.
  • User-agent and browser protocol version (for rendering optimization).
  • Server response metrics to maintain service availability.

We do not use invasive third-party cross-site trackers or behavioral advertising trackers.


3. Cryptographic Protection & Data Security

We implement rigorous physical, technical, and administrative safeguards designed to maintain confidentiality and prevent unauthorized access:

  • Encrypted Transports: All communications enforce modern TLS (Transport Layer Security) with strict cipher suites and HSTS.
  • End-to-End Cryptography: Where communication and storage tools are deployed, cryptographic keys remain isolated and under user or client control.
  • Principle of Least Privilege: Internal access to operational systems is restricted through zero-trust authentication boundaries.

4. Third-Party Services & Infrastructure

To provide resilient, high-speed global availability, we may utilize privacy-conscious infrastructure providers (such as Cloudflare for DDoS protection and DNS routing). These providers only process data necessary to route and protect network traffic in accordance with strict security standards.

We do not integrate with third-party data brokers or advertising exchanges.


5. Data Retention & Minimization

We retain correspondence and operational logs only for the minimum duration required to:

  • Fulfill the direct purpose for which it was provided.
  • Maintain infrastructure resilience, security auditing, and fraud prevention.
  • Comply with applicable statutory and regulatory requirements.

Once data is no longer necessary, it is securely purged or permanently anonymized.


6. Your Rights & Choices

Depending on your jurisdiction (including GDPR, UK Data Protection Act, and CCPA), you hold fundamental rights regarding your information:

  • Right of Access & Portability: Request confirmation of what minimal data we hold.
  • Right to Rectification: Request correction of inaccurate information.
  • Right to Erasure: Request immediate deletion of your correspondence or records where legally permissible.
  • Right to Object: Opt out of any non-essential communications at any time.

7. Contact Our Privacy & Security Team

For inquiries, verification requests, or data privacy concerns, contact our dedicated team:


Thank you for trusting XRTX Group with your security and privacy.