Privacy Policy
Last updated: April 13, 2026
Important: This Privacy Policy explains how Xypheron collects, uses, stores, protects, and handles personal data when you access or use Xypheron and any associated websites, apps, dashboards, communication tools, APIs, and related services.
1. Who We Are
Xypheron is a secure communications and productivity platform operated by or on behalf of Xypheron / SMG.
In this Privacy Policy, “Xypheron”, “we”, “our”, or “us” refers to the platform owner/operator and its authorised affiliates, licensors, contractors, and service providers acting on its behalf.
2. Scope of This Policy
This Privacy Policy applies to personal data collected through Xypheron, including through:
- the website and web application;
- secure chat and secure mail features;
- phone book / contacts tools;
- calendar and reminder tools;
- projects, notes, logs, and collaboration areas;
- account registration, login, support, subscription, and billing features;
- related APIs, mobile views, and administrative systems.
3. Information We May Collect
Depending on how you use the platform, we may collect and process the following categories of data:
- account information, including username, display name, email address, alias address, password hashes, recovery details, and profile information;
- login and session information, including login timestamps, logout records, device sessions, IP addresses, browser type, operating system, and authentication events;
- communications data, including messages, message metadata, secure mail content, attachments, subject lines, recipients, sender information, timestamps, and related logs;
- contacts and phone book information, including names, emails, phone numbers, notes, and calendar-linked entries you choose to store;
- calendar and scheduling information, including event titles, dates, times, reminders, descriptions, and related notes;
- project and productivity data, including project names, descriptions, notes, task-related content, timestamps, logs, and user activity within project areas;
- billing and subscription data, including package type, payment status, billing references, invoice-related information, and subscription history;
- support and communications records, including enquiries, abuse reports, bug reports, and support tickets;
- technical and usage data, including system logs, diagnostic data, crash data, feature usage, access times, and security-related records;
- cookie and session data used for authentication, preference storage, security, and platform functionality.
4. Sensitive Content and Encrypted Content
Xypheron is designed to support privacy-focused communications. Some communications or stored content may be encrypted, including at rest or in transit, depending on the feature and configuration used.
However:
- not every feature is necessarily end-to-end encrypted;
- encryption strength and protection may depend on user configuration, device security, passwords, session handling, and operational behaviour;
- metadata such as timestamps, routing details, sender/recipient references, file properties, system events, and account activity may still be processed for operational, security, or administrative purposes.
5. How We Collect Information
We collect personal data when:
- you create an account;
- you log in, log out, or authenticate;
- you send messages, upload files, create contacts, create projects, save notes, or use platform features;
- you subscribe to a plan or make a payment;
- you contact us for support or submit a report;
- you use the website or platform and technical logs are generated automatically;
- cookies or similar technologies are used to keep sessions active or improve platform performance and security.
6. How We Use Personal Data
We may use personal data for the following purposes:
- to create and manage user accounts;
- to operate the platform and provide requested services;
- to deliver secure messaging, mail, calendar, phone book, project, and other productivity features;
- to authenticate users and maintain account security;
- to detect, investigate, and prevent fraud, abuse, misuse, unauthorised access, spam, and security incidents;
- to manage subscriptions, billing, package access, and payment-related administration;
- to provide support, respond to enquiries, and troubleshoot issues;
- to maintain logs, backups, recovery systems, and service continuity controls;
- to comply with legal obligations, lawful requests, court orders, or regulatory requirements;
- to improve platform functionality, infrastructure stability, performance, and security.
7. Lawful Bases for Processing
Where applicable data protection law requires a lawful basis for processing, we may rely on one or more of the following:
- performance of a contract with you;
- our legitimate interests in operating, securing, improving, and administering Xypheron;
- compliance with legal obligations;
- your consent, where consent is required by law;
- establishment, exercise, or defence of legal claims.
8. Sharing of Personal Data
We do not sell your personal data.
We may share personal data only where reasonably necessary with:
- hosting providers, infrastructure providers, and technical service providers supporting the platform;
- payment processors and billing providers for subscription and payment handling;
- email, notification, security, analytics, or support providers where relevant to service delivery;
- professional advisers, auditors, insurers, or legal representatives where reasonably necessary;
- law enforcement, courts, regulators, or competent authorities where required by law or where legally justified;
- affiliates or authorised service partners acting on behalf of Xypheron / SMG.
9. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including operational, contractual, legal, security, evidential, and support-related purposes.
Retention periods may vary depending on:
- account status and subscription type;
- user settings relating to deletion, archiving, or expiry;
- backup schedules and disaster recovery processes;
- security logging requirements;
- legal, compliance, tax, and dispute-related obligations.
Some data may remain in backups, logs, archives, or encrypted storage for a period even after deletion requests or account closure, where operationally necessary or legally permitted.
10. Message Deletion, Auto-Delete, and User-Controlled Removal
Xypheron may provide settings allowing deletion, expiry, archiving, or permanent removal of messages or other records.
You acknowledge that:
- deleted content may not be recoverable;
- copies may remain temporarily in logs, caches, backups, or security archives;
- we do not guarantee immediate or irreversible deletion from every technical layer at the exact time of request;
- you are responsible for retaining copies of important records where needed.
11. Cookies and Similar Technologies
We may use cookies, sessions, tokens, and similar technologies for purposes including:
- keeping users signed in;
- maintaining session security;
- remembering settings or preferences;
- preventing abuse or suspicious activity;
- helping the website and dashboards function correctly.
Some cookies are necessary for the service to operate. Disabling essential cookies may affect your ability to use parts of Xypheron.
12. Security Measures
We use technical and organisational measures intended to protect personal data, which may include encryption, access controls, authentication processes, security monitoring, limited permissions, logging, and infrastructure safeguards.
However, no online service can guarantee absolute security. You are also responsible for your own operational security, including securing your devices, credentials, recovery methods, and local environment.
13. International Transfers
Your data may be stored or processed in jurisdictions outside your country of residence depending on our hosting, infrastructure, support, or service provider arrangements.
Where required by law, we will take appropriate steps intended to protect personal data in connection with such transfers.
14. Children’s Privacy
Xypheron is not intended for children who are not legally able to enter into a binding agreement under applicable law unless expressly permitted and appropriately supervised in accordance with local legal requirements.
If we become aware that personal data has been provided in breach of applicable age-related rules, we may delete the account or data and restrict access.
15. Your Rights
Depending on your location and applicable law, you may have rights including the right to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request deletion of personal data in certain circumstances;
- request restriction of processing in certain circumstances;
- object to certain processing based on legitimate interests;
- request portability of certain data where applicable;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority if you believe your rights have been infringed.
These rights are not absolute and may be limited by law, security requirements, technical constraints, or our need to retain certain records for legitimate business or legal purposes.
16. Account Closure and Data Requests
If you wish to close your account, request deletion, or make a privacy-related request, you may contact us through the official Xypheron support or privacy channels.
We may require verification of identity and account ownership before acting on requests affecting personal data or account access.
17. Third-Party Services
Xypheron may link to or interoperate with third-party services such as payment processors, infrastructure providers, cloud hosts, security tools, analytics services, telecom services, or external sites.
We are not responsible for the privacy practices of third-party services, and your use of those services is subject to their own policies and terms.
18. Legal Disclosure and Protection of Rights
We may disclose personal data where reasonably necessary to:
- comply with legal obligations or lawful requests;
- respond to court orders, regulators, or law enforcement;
- protect the rights, safety, property, platform integrity, infrastructure, or users of Xypheron;
- investigate fraud, abuse, misuse, infringement, or security incidents;
- enforce our Terms, policies, or contractual rights.
19. Business Transfers
If Xypheron or its operating business undergoes a merger, acquisition, restructuring, financing, investment, sale of assets, or similar corporate transaction, personal data may be transferred as part of that transaction, subject to applicable law.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, platform features, operational practices, security requirements, or service arrangements.
Where appropriate, we may notify users through the website, platform, account area, or other reasonable means. The “Last updated” date at the top of this page will also be revised.
Your continued use of Xypheron after changes take effect constitutes acknowledgement of the updated Privacy Policy to the extent permitted by law.
21. Contact
If you have questions, concerns, or requests relating to this Privacy Policy or your personal data, you may contact Xypheron through the official support or privacy contact channels made available on the platform.