Legal

Privacy Policy

How we collect, use and protect your information — written in plain language.

Last updated: 3 September 2026

This Privacy Policy explains how XORLabs LLC ("XORLabs", "we", "us") collects, uses, discloses and safeguards your information when you visit xorlabs.com or engage our services. We are committed to handling personal data in line with the California Consumer Privacy Act (CCPA/CPRA), the EU/UK GDPR, India's DPDP Act 2023, and other applicable U.S. and international laws, including anti-spam laws such as CAN-SPAM.

1. Who we are (Data Controller)

XORLabs LLC, 8690 East Villa Cassandra Dr., Scottsdale, AZ 85266, USA. For any privacy question or to exercise your rights, contact privacy@xorlabs.com.

2. Information we collect

  • Information you provide: name, work email, company, role, budget range and message when you submit our contact form or email us.
  • Usage data: IP address, browser type, pages viewed and referring URLs, collected via cookies and analytics.
  • Business contact data from third-party sources: for business-development outreach we may obtain your name, job title, company, industry, work email address and public professional-profile URL from B2B data providers (currently Apollo.io), public LinkedIn profiles, company websites and business directories. We collect work contact details only, never personal or consumer email addresses. See section 8 for how we use this data and how to opt out.
  • Email engagement data: if you receive our emails, whether and when a message was opened or a link clicked, plus device type and approximate (country/city) location, as described in section 8.4.
  • Cookies & similar technologies: see the Cookies section below.

3. How we use your information

  • To respond to your enquiry and provide the services you request.
  • To follow up on your enquiry. We use contact-form and email enquiries only to respond to you; we do not add enquirers to marketing lists unless you opt in.
  • To send business-development emails to business contacts we have identified through the sources described in section 8. You can opt out at any time, and we never sell or rent contact lists.
  • To operate, secure and improve our website.
  • To comply with legal, accounting and regulatory obligations.

Our legal bases are your consent, the performance of a contract (or steps to enter one), and our legitimate interests in running, promoting and protecting our business. Where we rely on legitimate interests for marketing, we limit the data we use to business contact details, target only professionals for whom our services are plausibly relevant, and make opting out easy.

4. AI & client data handling

When we build AI systems for clients, any data processed for those engagements is governed by a separate Data Processing Agreement (DPA). We do not use client or visitor data to train third-party foundation models, and we apply PII redaction, access controls and audit logging in line with SOC 2, HIPAA, ISO/IEC 42001 and EU AI Act-aligned practices where applicable.

5. Sharing your information

We do not sell your personal data. We share it only with trusted processors who help us operate (e.g. email delivery, hosting, analytics, CRM and B2B data providers — the ones we use for email outreach are named in section 8.5) under contract, or where required by law. Some providers may process data outside your country under appropriate safeguards (e.g. Standard Contractual Clauses).

6. Cookies

We use essential cookies to run the site and, with your consent, analytics cookies to understand usage. You can control cookies through your browser settings or our cookie banner where shown. Disabling cookies may affect some features. Tracking technologies used in our emails are described in section 8.4.

7. Data retention

We keep enquiry data for as long as needed to respond and for our legitimate business records, then delete or anonymise it. You can ask us to delete your data sooner (see your rights below). Retention periods for email-marketing data are set out in section 8.6.

8. Email marketing & prospect communications

This section explains how we run business-development email campaigns. It applies to business contacts we have identified through the sources in section 8.2 as professionals whose role suggests our services may be relevant to their organisation, and to people who have enquired about our services and opted in to hear more from us.

8.1 What we send and to whom

We send a small number of business-to-business emails introducing XORLabs, our services and relevant insights. We email work addresses of business decision-makers only; we do not send marketing to consumers or to personal email accounts. Our emails always identify XORLabs as the sender, include our physical address and contain a working unsubscribe option.

8.2 Where the data comes from

Prospect contact details come from the B2B data provider Apollo.io, from public LinkedIn profiles, and from company websites and public business directories — or from you directly, where you enquired with us and opted in to further communications. The data is limited to your name, job title, company, industry, work email address and public professional-profile URL. Where we did not obtain your details from you directly, our first email tells you where they came from and links to this policy.

8.3 Legal basis

We rely on your consent where you have opted in, and otherwise on our legitimate interest in marketing our services to relevant business professionals, balanced against your interests through the safeguards described here: business contact data only, relevance targeting, short retention and a no-questions-asked opt-out. Where local law requires prior consent for the type of message we send, we obtain it first or do not email you.

8.4 Email tracking

Our emails may contain a small tracking pixel and tracked links that tell us whether a message was opened, which links were clicked, your device and email-client type, and an approximate (country/city) location derived from your IP address. We use this to measure whether our communications are useful and to improve their content and timing. We do not use tracking pixels for recipients in the EU/EEA or UK unless they have consented. You can block tracking in any email by disabling remote images in your mail client, and you can object to tracking entirely by contacting privacy@xorlabs.com.

8.5 Who processes the data

  • Google Workspace (Gmail) — email delivery and storage.
  • Apollo.io — prospect data sourcing, enrichment and email verification.
  • Our own tracking infrastructure — a XORLabs-operated server that records email open and click events. This is run by us, not a third party.

Third-party processors act under data processing agreements and, where data leaves your country, appropriate safeguards such as Standard Contractual Clauses. We never share or sell prospect data for anyone else's marketing.

8.6 How long we keep it

  • Prospect contact data: up to 90 days after our last outreach to you, unless you reply, engage with us or become a client, in which case it is kept as ordinary business-relationship data under section 7.
  • Email engagement data (opens, clicks, device, location): up to 30 days, then automatically deleted.
  • Opted-out addresses: when you unsubscribe we stop emailing you and delete your profile, but we retain your email address on a suppression list for as long as we run campaigns. This is used solely to make sure you are never re-imported and emailed again, and is required for us to honour your opt-out.

8.7 How to opt out

You can stop our emails at any time by clicking the unsubscribe link in any message, replying with “STOP” or “UNSUBSCRIBE”, or emailing privacy@xorlabs.com. Opt-outs are processed as soon as practicable and always within 10 business days; recipients in the EU/EEA and UK are removed without undue delay. Opting out does not require you to log in, pay anything or give a reason.

8.8 Region-specific commitments

  • United States (CAN-SPAM Act): our emails use accurate header and sender information and non-deceptive subject lines, are identified as commercial where required, include our physical postal address and a clear opt-out mechanism, and opt-outs are honoured within 10 business days. We do not sell or transfer opted-out addresses. California residents: the categories we collect are identifiers and professional information, from the sources in section 8.2, for the purposes in section 3. We do not sell personal information or share it for cross-context behavioural advertising.
  • EU/EEA and United Kingdom (GDPR, UK GDPR, ePrivacy/PECR): you may object to marketing at any time and we will stop immediately. We do not use tracking pixels without your consent. Where we obtained your data from a third-party source, we provide the information required by Article 14 in our first email. You may lodge a complaint with your supervisory authority.
  • India (Digital Personal Data Protection Act 2023 and IT Act 2000): we process your data only for the purposes described here, apply reasonable security safeguards, honour opt-outs within 10 days, and you may request access, correction or erasure or raise a grievance at privacy@xorlabs.com.
  • Canada (CASL): we send commercial emails only where the law permits — with your express consent, or where an existing business relationship exists or your business contact details are conspicuously published in a role relevant to our services — and every message identifies us and includes an unsubscribe mechanism honoured within 10 business days.

9. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction or portability of your data, and you may object to or withdraw consent for certain processing — including objecting to marketing emails and email tracking at any time (see section 8.7). To exercise any right, email privacy@xorlabs.com. You also have the right to complain to your data protection authority.

10. Security

We use technical and organisational measures — encryption in transit, access controls, least-privilege and monitoring — to protect personal data. No method of transmission is 100% secure, but we work to protect your information and review our controls regularly.

11. Children

Our site and services are intended for businesses and are not directed to children under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this policy from time to time. The "last updated" date above reflects the latest revision. Material changes will be highlighted on this page.

13. Contact

Questions? Email privacy@xorlabs.com or write to the address in section 1.