Privacy Policy
XStack Technologies L.L.C. is committed to protecting your privacy and ensuring transparency in how we collect, process, secure, and manage personal and enterprise data across our platforms and services.
Our Core Privacy Commitments
Zero Unauthorized Data Training
Your private enterprise data, operational logs, and processed documents are never used to train public AI foundation models.
Enterprise Grade Encryption
All data in transit is encrypted using TLS 1.3 and stored at rest with military-grade AES-256 encryption.
Strict Tenant Isolation
Multi-tenant architectures with segregated schemas, zero cross-tenant access, and dedicated deployment options in UAE data centers.
UAE & Global Compliance
Engineered in alignment with UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL) and GDPR standards.
1. Overview & Who We Are
This Privacy Policy explains how XStack Technologies L.L.C. ("XStack", "we", "us", or "our"), registered in the Emirate of Dubai, United Arab Emirates (License No. and registered office at WO-RK Coworking Spaces, Burjuman Metro Station, Bur Dubai, Dubai, UAE), collects, uses, and safeguards information when you visit our website (xstack.ae), engage with our marketing channels, or use our enterprise software platforms and AI services.
We build mission-critical enterprise systems designed to transform operational efficiency. We hold data confidentiality, security, and regional legal compliance at the core of every architectural decision.
2. Data Controller vs. Data Processor Roles
Depending on how you interact with our services, XStack acts as either a Data Controller or a Data Processor:
When you browse our website, book a demo, fill out contact forms, or correspond directly with our sales and executive team. We determine the purposes and means of processing this personal data. The Data Controller mandates privacy and security requirements to the Data Processor.
When our enterprise clients deploy our platforms and solutions to ingest, process, scan, or analyze their business records, documents, operational logs, or customer communications. The client remains the Data Controller, and XStack acts strictly in accordance with client instructions.
3. Privacy by Design & Default Principles
XStack embeds the globally recognized Privacy by Design (PbD) framework (as codified in Article 25 of the GDPR and aligned with UAE Federal Decree-Law No. 45 of 2021) into the entire engineering lifecycle of all our software platforms, AI inference architectures, and cloud services:
Proactive not Reactive; Preventative not Remedial
We anticipate, identify, and mitigate privacy risks before any code reaches production. Our engineering lifecycle mandates Data Protection Impact Assessments (DPIAs), threat modeling, and continuous automated security scanning to eliminate vulnerabilities before data processing occurs.
Privacy as the Default Setting (Privacy by Default)
Our systems deliver maximum privacy protections automatically out-of-the-box, without requiring manual configuration by end users. Default configurations enforce strict data minimization, shortest viable retention cycles, least-privilege role access (RBAC), and opt-in settings for any supplementary analytics.
Privacy Embedded into Architecture & Engineering
Privacy is an essential architectural component of our software stack, not an ad-hoc add-on. Across all our enterprise systems and pipelines, data is isolated through dedicated database schemas, isolated container execution, ephemeral in-memory processing for OCR and LLM inference without unauthorized model caching, and segregated customer data streams.
Full Functionality — Positive-Sum, not Zero-Sum
We reject the false trade-off between privacy and innovation. Across all our solutions, our platforms achieve high-throughput operational intelligence, automated document OCR, and real-time conversational processing while upholding uncompromising confidentiality and sovereign compliance guarantees.
End-to-End Security — Full Lifecycle Protection
Security is maintained holistically across the entire lifecycle of all data assets. From the moment data is ingested via TLS 1.3 encrypted connections, stored under AES-256 encryption at rest, through to cryptographically secure deletion and sanitization upon retention window expiration.
Visibility and Transparency — Keep it Open
We operate with complete clarity. We provide verifiable audit logging, full visibility into sub-processor engagements, clear data processing agreements (DPAs), and unambiguous documentation ensuring that our operations are auditable by clients and regulatory authorities.
Respect for User Privacy — Keep it User-Centric
We design systems with user agency at the forefront. We empower clients and individuals with granular consent options, administrative permission tiers, prompt fulfillment of data subject requests, and frictionless data export/deletion mechanisms.
4. Information We Collect
We gather only the minimum data necessary to deliver high-quality technology solutions:
- Direct Inquiries & Contact Data: Name, business email, phone number, company name, job title, and details provided when booking a demo via Calendly or contacting sales.
- Platform Account & Auth Data: Usernames, work emails, employee badge IDs/PINs, single sign-on (SSO) credentials, role assignments, and authentication tokens.
- Technical & Usage Metadata: IP address, browser type, operating system, device identifiers, session timestamps, and error logs collected for system diagnostics and reliability.
5. AI & Machine Learning Processing Policy
As an AI-driven solutions provider, we uphold strict standards regarding how customer data interacts with Large Language Models (LLMs) and Machine Learning models:
- No Model Training on Client Data: We do not use your proprietary documents, conversational transcripts, or operational telemetry to train public AI foundation models.
- Enterprise API Agreements: We utilize dedicated, enterprise-tier AI model APIs governed by strict zero-data-retention (ZDR) and confidentiality agreements.
- Ephemeral Processing: In-flight data sent for OCR or NLP inference is processed in memory and immediately discarded by inference endpoints once the response is constructed.
6. How We Use Information
We process collected data exclusively for lawful purposes:
- Operating, maintaining, and enhancing our platform infrastructure and web applications.
- Delivering requested demonstrations, technical evaluations, and customer support.
- Executing client-instructed data processing and automated workflows.
- Detecting, preventing, and mitigating cybersecurity threats, fraud, and system outages.
- Complying with statutory obligations under UAE laws and applicable international regulations.
We never sell, rent, or monetize your personal information to advertisers or data brokers under any circumstances.
7. Third-Party Processors & Sharing
We share information only with vetted third-party service providers (sub-processors) bound by stringent confidentiality and Data Protection Agreements (DPAs):
| Sub-Processor Category | Purpose | Location / Safeguards |
|---|---|---|
| Cloud Infrastructure & Hosting | Hosting server nodes, databases, and container runtimes | UAE / Global data regions with ISO 27001 & SOC 2 certification |
| AI & Inference APIs | Document OCR parsing & natural language understanding | Enterprise zero-retention API endpoints |
| Communication & Scheduling | Calendly (demo booking) & messaging communication APIs | Encrypted message transport & TLS calendar sync |
| Analytics & Performance | Vercel Analytics for core web vitals and uptime metrics | Privacy-friendly, anonymized without cookie tracking |
8. Security, Hosting & Retention
We implement multi-layered technical, administrative, and physical security measures:
Retention: Enterprise client data is retained only for the term of our service agreement or as defined in the client's custom retention policy. When an agreement ends, all client data is securely sanitized or returned in accordance with our DPA.
9. Your Data Rights & Choices
Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), EU GDPR, and other applicable laws, you hold the following rights:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete records.
Request deletion of your data when processing is no longer required.
Object to processing or withdraw previously granted consent.
To exercise any of these rights, contact us at support@xstack.ae. We will respond within 30 days.
11. Contact Our Privacy Team
If you have questions, feedback, or concerns regarding this Privacy Policy or wish to enter into an Enterprise Data Processing Addendum (DPA), please reach out to our support team:
Bur Dubai, Dubai, United Arab Emirates