This Privacy Policy explains how Xcevia Ltd (“Xcevia”, “we”, “our”, or “us”) collects, uses, and protects personal data when you visit xcevia.com or interact with our services. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable to data subjects in the European Economic Area, the EU General Data Protection Regulation (EU GDPR).
1. Who we are
Xcevia Ltd is a private limited company registered in England and Wales (company number 16737253). We are the data controller for personal data processed through our website and direct services.
Although we are based in the United Kingdom, we serve clients internationally. EU and UK residents' data is handled in accordance with the protections set out in this policy.
For all data protection enquiries, contact: privacy@xcevia.com
2. What personal data we collect
We collect personal data only when you actively provide it, or when it is technically necessary to operate the website. Specifically:
- Contact form submissions: name, email address, organisation (if provided), and the contents of your message.
- Direct correspondence: information you provide when you email us or engage with us on social media.
- Server access logs: IP address, browser user-agent, request timestamp, requested URL, and HTTP status code. These are generated automatically by our hosting provider for security and reliability purposes.
- Cookieless analytics: aggregated, non-identifying visit data collected via Vercel Web Analytics (see Section 4 below).
We do not run any advertising, behavioural tracking, fingerprinting, session-replay, or cross-site identification on this website.
3. How we use personal data
We process personal data for the following purposes and on the following lawful bases:
- To respond to your enquiries and provide the services you request (lawful basis: legitimate interest or, where you have engaged us, performance of a contract).
- To send service-related communications, such as replies to your contact form (lawful basis: legitimate interest).
- To detect, prevent, and investigate fraud, abuse, or security incidents using server logs (lawful basis: legitimate interest, and legal obligation where applicable).
- To comply with legal obligations under UK and EU law (lawful basis: legal obligation).
We do not use personal data for automated decision-making or profiling, and we do not sell personal data to anyone.
4. Cookies and analytics
This website does not set any cookies. No advertising cookies, no tracking cookies, no third-party cookies.
We use the browser's localStorageonly to remember your light or dark theme preference if you choose one. This information stays on your device, is not transmitted to us or any third party, and you can clear it at any time using your browser's settings.
Cookieless analytics. We use Vercel Web Analytics, a privacy-friendly, cookieless analytics service operated by our hosting provider. It collects aggregated, anonymised data about how the site is used (for example, which pages are viewed, approximate geography at country level, referrer, and device type) without setting cookies, without persistent identifiers, and without combining the data with any third party. Vercel Web Analytics does not track you across sites and does not build a personal profile.
Because no cookies or similar storage are used for analytics, this site does not require a cookie consent banner under the UK Privacy and Electronic Communications Regulations (PECR) or the EU ePrivacy Directive. If we introduce additional analytics or any cookie-based tracking in the future, we will update this policy and present a consent mechanism that complies with applicable law.
For more information about Vercel's privacy practices, see Vercel's Privacy Policy.
5. Who we share data with
We share personal data only with the limited set of service providers that are strictly necessary to run our website and services:
- Vercel Inc. (United States): website hosting, edge networking, server logs, and cookieless Web Analytics.
- Resend (United States): transactional email delivery (for example, contact form submissions and replies).
- Our domain registrar and DNS provider for routing.
Each provider is bound by data processing terms that include appropriate confidentiality and security obligations. We do not share personal data with any third party for marketing, profiling, or advertising purposes.
We may disclose personal data if required by law, court order, or to protect the rights, property, or safety of Xcevia, our clients, or others.
6. International data transfers
Some of our service providers are located in the United States. When your personal data is transferred outside the UK or EEA, we rely on one or more of the following safeguards:
- The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses.
- The EU Standard Contractual Clauses (SCCs) approved by the European Commission.
- The provider’s certification under the UK Extension to the EU–US Data Privacy Framework, where applicable.
You can request more details of these safeguards by contacting privacy@xcevia.com.
7. How long we keep data
- Contact enquiries: retained for up to 24 months after the last communication, then deleted or anonymised.
- Active client correspondence: retained for the duration of the engagement and for up to 6 years afterwards, to meet UK statutory limitation periods and tax record-keeping obligations.
- Server access logs: retained by our hosting provider for the period defined in their standard log retention policy (typically no more than 30 days).
8. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, access controls, and the principle of least privilege. Our infrastructure providers are independently audited against recognised standards (for example, ISO 27001 and SOC 2).
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) and, where required, affected individuals, without undue delay.
9. Your rights
Under the UK GDPR and EU GDPR, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request erasure of your personal data, in certain circumstances.
- Restrict or object to our processing of your personal data.
- Request portability of personal data you have provided to us.
- Withdraw any consent you have given, at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email privacy@xcevia.com. We will respond within one month of receiving a verifiable request.
10. How to complain
If you are unhappy with how we have handled your personal data, we encourage you to contact us first so we can try to resolve the issue. You also have the right to complain to a supervisory authority:
- In the United Kingdom: the Information Commissioner’s Office (ICO), https://ico.org.uk.
- In the European Economic Area: the data protection authority in your country of residence, place of work, or where the alleged infringement occurred.
11. Children
Our website and services are not directed at children under 13, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact privacy@xcevia.com and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page and, where appropriate, by a notice on the website.
13. Contact
Xcevia Ltd
Company number: 16737253
Registered in England and Wales
Email: privacy@xcevia.com