Privacy Policy
Last updated: April 2026
Xirocco Limited is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website, contact us, request information, use our services, or otherwise interact with us. It also explains your rights and how to contact us if you have questions or concerns.
For the purposes of UK data protection law, the data controller is:
Xirocco Limited
71–75 Shelton Street
London WC2H 9JQ
United Kingdom
- Company registration number: 11054315
- ICO registration number: ZB178559
Scope
This Privacy Policy applies to personal data collected through:
- our website;
- email, phone, and other business communications;
- marketing enquiries, demo requests, and event sign-ups; and
- the provision of our SaaS services, to the extent we act as a controller.
Where Xirocco processes customer data within the SaaS platform on behalf of a customer, we generally act as a processor and the relevant customer is the controller. Details of that processing are governed by the applicable customer contract and data processing terms.
The personal data we collect
We may collect and use the following categories of personal data:
Information you provide directly
- name
- work email
- address
- phone number
- job title
- company name
- information you submit through forms, emails, support requests, or other correspondence
Information collected automatically when you use our website
- IP address
- browser type and version
- device type
- operating system
- referral source
- date and time of access
- marketing cookie and similar technology data, where consent has been provided
Information related to service delivery
If you use Xirocco’s online services, we may process account, access, and service administration data needed to provide, secure, and support the service.
Information from third parties
We may receive personal data from business partners, event partners, or publicly available sources where relevant to our business relationship with you.
How we use personal data
We use personal data for the following purposes:
To respond to enquiries and requests
For example, to answer questions, arrange demos, or provide information about Xirocco and its services.
To provide and support our services
Including account administration, onboarding, customer support, service communications, security monitoring, and operational management.
To manage our business relationship with you
Including contract management, record keeping, billing, and related administration.
To improve our website and services
Including understanding usage patterns, maintaining security, troubleshooting issues, and improving performance and user experience.
For marketing communications
To measure the effectiveness of our marketing activity, understand engagement with campaigns, and improve how we communicate with prospective customers, where permitted by law.
To meet legal, regulatory, and compliance obligations
Including fraud prevention, security, and responding to lawful requests.
Our lawful bases
Depending on the context, Xirocco relies on one or more of the following lawful bases:
Contract
Where processing is necessary to take steps at your request before entering into a contract, or to perform a contract with you or your organisation.
Legitimate interests
Where processing is necessary for our legitimate interests, such as operating our business, responding to enquiries, maintaining customer relationships, improving our services, protecting our systems, and preventing misuse, provided those interests are not overridden by your rights and freedoms.
Legal obligation
Where we need to process personal data to comply with applicable legal or regulatory requirements.
Consent
Where consent is required, including for marketing cookies, we will rely on consent and you may withdraw it at any time.
Cookies and similar technologies
Our website uses cookies solely for marketing purposes.
These cookies help us understand the effectiveness of our marketing activity and support relevant marketing communications and campaigns. They are not used for essential website functionality.
Where required by law, we will request your consent before placing marketing cookies on your device. You can manage your cookie preferences through our cookie settings or browser controls.
For more information about the cookies we use and how to manage your preferences, please see our Cookie Policy.
How we share personal data
We may share personal data where necessary with:
- group companies or affiliated entities, where relevant;
- cloud hosting, infrastructure, email, support, or other service providers acting on our behalf;
- professional advisers such as legal, audit, or insurance advisers;
- regulators, law enforcement, courts, or public authorities where required; and
- potential buyers, investors, or corporate advisers in connection with a merger, acquisition, financing, or business reorganisation, subject to appropriate confidentiality protections.
We require relevant service providers to handle personal data appropriately and only for authorised purposes.
International transfers
Xirocco does not transfer CRM data outside the UK. If we transfer any other personal data outside the UK, we will ensure appropriate safeguards are in place as required by applicable law.
Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, contractual, regulatory, accounting, or reporting requirements.
Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.
Xirocco’s wider security approach includes enterprise security controls, secure development practices, and operational safeguards.
AI and customer data
Xirocco does not use customer data to train general-purpose AI models.
Where AI capabilities are used within Xirocco services, they are intended to operate in support of the customer’s use of the service and subject to the applicable contractual and technical controls.
Your rights
Subject to applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing;
- request portability of data you have provided to us, where applicable; and
- withdraw consent at any time where consent is the lawful basis.
To exercise your rights, please contact us using the details below.
Complaints
You have the right to complain to the Information Commissioner’s Office if you believe your personal data has been handled unlawfully or unfairly.
We would, however, appreciate the opportunity to address your concerns first.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or business changes. We encourage you to review it periodically.
Contact us
If you have any questions about this Privacy Policy or how we handle personal data, please contact info@xirocco.io
Modern business leaders are asking whether the organisation is ready for what comes next, and what the exposure is if it is not.
Xirocco empowers IT leaders to respond confidently to the questions CEOs, CFOs, COOs and business leaders raise every day. It delivers clear, defensible answers to the organisation’s most strategic priorities, grounded in evidence - not in gut feel, intuition, or vendor opinions.
See it in action! Request a demo today.
You can also directly book a demo slot using our Calendly link.