Privacy Policy for Xapi Platform

Effective Date: 26th November 2025

Welcome to Xapi’s Privacy Policy (the “Policy”). This Policy describes how X-venture Global Solutions Pvt Ltd (“Xapi,” “we,” or “us”) collects, uses, discloses, and protects your Personally Identifiable Information (PII) through our online services (the “Services”) and website (collectively, the “Site”).

We are committed to processing your PII in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the Personal Data Protection Act (PDPA) of Singapore, the Personal Data Protection Act (PDPA) of Sri Lanka, and in accordance with the security principles of ISO/IEC 27018:2019 for PII processors in the cloud.

1. Information Collection and PII Categories

We collect and process the following categories of PII, which are strictly necessary to provide and maintain the Xapi Services:

1.1.Information You Provide Directly (User Data)

We may collect the following types of information:

CategoryData Elements CollectedPurpose of Collection
Contact & IdentityUser Name, First Name, Last Name, Email (corporate email for paid version and personal email free version)To create and manage your account and identify you when you sign in.
Profile InformationProfile Picture/Bio, Website, Company, Country, TimeZoneTo customize your user experience and facilitate collaboration within the platform
Account AdministrationNames and email addresses for authorized users (if provided by a customer).To administer, manage, and update the Customer's Xapi account and access permissions.
Billing InformationBilling address, and transaction records.To process payments for paid services.

1.2.Information Collected Automatically (Usage and Technical Data)

CategoryData Elements CollectedPurpose of Collection
Usage DataInteractions with the Services, features used, time spent, and service configuration settings.To maintain and improve service performance, troubleshoot issues, and enhance user experience.
Log DataIP address, browser type, device information, access times, and referring website addresses.To monitor the stability and security of the Site and Services, prevent misuse, fraud, and security breaches

2. Legal Basis and Purpose of Processing

We rely on the following legal bases to process your PII:

Processing PurposeLegal Basis for ProcessingRationale
Service ProvisionPerformance of a ContractTo fulfill our obligations under the End User License Agreement (EULA) and deliver the core Xapi Services.
Account SecurityLegitimate InterestsTo prevent fraud, ensure network and information security, and protect the integrity of your account and our systems.
Marketing & AnalyticsConsentFor optional marketing communications or non-essential cookies. You have the full right to opt-in or opt-out.
Legal ComplianceLegal ObligationTo comply with mandatory legal or tax requirements.
We guarantee that granting consent for marketing or commercial use of your PII will never be a condition for receiving the contracted Xapi service.

3. Information Sharing, Sub-processors, and Transfers

3.1.Disclosure to Third Parties

Xapi does not sell your PII. We only share PII with third parties as described below or with your explicit consent

  • Service Providers (Sub-processors): We use third-party sub-processors (e.g., cloud hosting providers) to help us deliver the Services. These sub-processors are required to meet or exceed our security standards, including those mandated by our ISO 27018 compliance, and are strictly prohibited from using your PII for any purpose other than providing services to Xapi.
  • Legal Compliance: We may disclose PII if required by law, court order, or governmental regulation.

Note: The following third-party sub-processors are authorized by Xapi to store Personal data collected through the platform with respect to the profile management of the customer.

Sub-Processor EntityBrief DescriptionLocation of Data Center
MongoDB AtlasStoring of customer data (First Name, Last Name, Email) related to the customer profile.AWS / N. Virginia (us-east-1)
Office 365Storing information regarding the customers (If provided; Name, Email, and contact number).Standard Microsoft Office 365 Cloud
AWS - S3Storing of the customer profile pictureAWS / N. Virginia (us-east-1)

3.2. International Data Transfers

X-Venture is registered in Sri Lanka, and the PII collected from individuals located in the European Economic Area (EEA), the UK, or Singapore may be transferred to and stored in countries outside those jurisdictions.

When we transfer PII internationally, we take reasonable steps and implement appropriate safeguards to ensure the transferred PII receives a comparable level of protection, as required by the relevant data protection laws. These safeguards include Standard Contractual Clauses (SCCs) for data transfers between the originating country and third countries

3.3. Geographical Location

All User PII is primarily stored on servers located in data centers provided by our certified cloud hosting partner.

For a comprehensive list of the specific geographical locations where our sub-processors (third-party vendors) store or process data, please refer to the table in section 3.1.

4.Security

We are committed to protecting your PII. We implement and maintain reasonable and appropriate technical and organizational security measures to protect your PII against unauthorized access, alteration, disclosure, or destruction, as required by global and local privacy legislations.

Our security program is designed and managed in alignment with ISO/IEC 27001:2022 (Information Security Management System) and ISO/IEC 27018:2019 (PII Protection in the cloud).

In addition, we routinely validate our security posture through independent audits, including annual penetration testing of the Xapi platform.

5. Data Retention.

We retain your PII only for as long as necessary to fulfill the purposes for which it was collected, including for the purpose of satisfying any legal, accounting, or reporting requirements.

We determine the appropriate retention period based on:

  • Duration of Contract: Your PII is retained for the entire period your account is active.
  • Post-Termination: Following account closure, we securely delete your PII, unless retention is mandatory for legal defense or compliance with court orders.

6. Your Rights and Choices.

You have the following rights regarding the PII we hold about you. You can exercise these rights by contacting our Data Protection Officer as per section 08.

PII Principal RightDescription
Right to AccessObtain confirmation of whether your PII is being processed and, if so, access to the data.
Right to RectificationHave inaccurate or incomplete PII corrected without undue delay.
Right to ErasureRequest the deletion of your PII (Right to be Forgotten) under certain conditions.
Right to Restrict ProcessingRestrict the way we process your PII under certain conditions.
Right to Data PortabilityReceive your PII in a structured, commonly used, and machine-readable format.
Right to ObjectObject the processing of your PII, especially for direct marketing purposes.
Right to Withdraw ConsentWithdraw your consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.

7. Cookies and Similar Technologies.

Cookies are small data files stored on your browser. We use them for essential service functionality and non-essential analytics/performance tracking.

  • Management: We are currently working on letting you manage your preferences. For now, if you want to manage or have any concerns, please email to dpo@x-venture.io Once the feature is available, you can manage your preferences at any time via the cookie banner or by adjusting your browser settings to refuse or delete cookies.
  • Cookie Consent: For non-essential cookies, we plan to obtain your explicit consent via a cookie banner upon your first visit to the Site.
  • Cookie Policy: For a detailed list of cookies, their purpose, and their lifespan, please refer to our separate Cookie Policy atCookie Policy

8. Contact Us

For any questions, concerns, inquiries about this Privacy Policy, or to exercise any of your rights, please contact our dedicated Data Protection Officer at:

  • Email: dpo@x-venture.io
  • Address:
    X-venture Global Solutions Pvt Ltd (Attention: Data Protection Officer),
    No 1185/1/E, Vidyala Junction,
    Pannipitiya, Sri Lanka

9. Changes to this Policy.

We may update this Policy to reflect changes in our practices, services, or regulatory requirements. The updated Policy will be effective upon posting on our website. We will notify you of material changes via email or a prominent notice on the Site.

XAPI logo

The Xapi Community is a vibrant network of Xapi Platform users from around the globe: collaborating, innovating, and advancing together towards a more robust API design and governance ecosystem.

ISO logo

Copyright © 2025 X-Venture. All Rights Reserved.