Section 01
Introduction
Exyllion ("Exyllion," "we," "our," or "us") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at exyllion.com, use any of our products or services — including Inictra, Aiphra, Onitee ID, Xiplio, and Venectra — or otherwise interact with us.
Please read this policy carefully. If you disagree with its terms, please discontinue use of our sites and services. By accessing or using any Exyllion product or platform, you acknowledge that you have read, understood, and agree to be bound by all terms of this Privacy Policy.
This Privacy Policy applies to all Exyllion properties and ventures unless a specific product provides a separate, supplementary privacy notice, in which case that notice governs for that product alongside this Policy.
Section 02
Who We Are
Exyllion is a product studio that conceives, designs, and builds digital products. Our portfolio currently includes Inictra (decision intelligence), Aiphra (AI agent marketplace), Onitee ID (digital identity verification), Xiplio (identity protection for iOS), and Venectra (cybersecurity). Each product may operate under its own brand while remaining a venture of Exyllion.
For the purposes of applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), Exyllion acts as the data controller for personal data collected through our corporate website and marketing channels. Individual products may act as separate or joint data controllers depending on the nature of the service. Where a product acts as a data processor on behalf of a business customer, the relevant data processing agreement governs that relationship.
You may contact our data protection contact at any time at privacy@exyllion.com.
Section 03
Scope of This Policy
This Privacy Policy applies to:
- The Exyllion corporate website (exyllion.com) and all subdomains
- All Exyllion venture websites (inictra.com, aiphra.com, oniteeid.com, and associated domains)
- Exyllion mobile applications, including Xiplio for iOS
- Any application, tool, or service operated by Exyllion or its ventures
- Communications you initiate with us by email, form, or other channel
This Policy does not apply to third-party websites, applications, or services that may be linked from our platforms. We encourage you to review the privacy policies of those third parties independently.
This Policy is incorporated by reference into our Terms of Service. Defined terms used but not defined here carry the meaning given in the Terms of Service.
Section 04
Information We Collect
We collect information in several categories depending on how you interact with us:
Information you provide directly:
- Account data: name, email address, username, password (hashed), profile photo, and account preferences when you register for any Exyllion product
- Identity verification data: for Onitee ID specifically, government-issued identification documents, biometric data processed for KYC verification, and selfie photographs submitted for liveness checks
- Payment information: billing name, billing address, and payment card details (processed by our payment processor; we do not store raw card data)
- Communications: content of emails, support tickets, feedback forms, and any other correspondence you send us
- Professional data: company name, job title, team size, and industry, where voluntarily provided
Information collected automatically:
- Usage data: pages visited, features used, actions taken within our products, session duration, and click patterns
- Device and technical data: IP address, browser type and version, operating system, device identifiers, screen resolution, and referring URLs
- Log data: server logs including access timestamps, error logs, and request metadata
- Location data: approximate geographic location derived from IP address; precise location only where you explicitly grant permission in a mobile application
Information from third parties:
- Social media profile information where you connect a social account to our services
- Identity verification results from third-party KYC providers
- Public records and open-source data used to surface impersonation findings within Xiplio
- Marketing and analytics data from advertising partners, subject to their own privacy policies
Section 05
How We Collect Information
We use a variety of methods to collect the information described in Section 4:
- Direct submission: forms, onboarding flows, settings pages, and support channels where you actively enter information
- Automated tracking: cookies, pixel tags, web beacons, and similar technologies embedded in our web pages and emails
- APIs and integrations: when you connect third-party services to our products, we receive data through those integrations as authorized by you and by the third party's terms
- Mobile SDK: our iOS applications collect device and usage data via our mobile SDK in accordance with Apple's App Tracking Transparency framework
- AI-driven scanning: Xiplio uses face-matching algorithms to scan publicly accessible social media content on your behalf; the data collected is processed solely to surface findings for your review
- Customer support systems: data you provide when contacting support is retained in our ticketing system
Section 06
How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: to create and manage your account, provide the features you have subscribed to, process transactions, and fulfill our contractual obligations to you
- Product improvement: to understand how our products are used, identify bugs, optimize performance, and develop new features
- Safety and security: to detect, investigate, and prevent fraudulent transactions, unauthorized access, abuse, and other security threats across all Exyllion products
- Identity verification: for Onitee ID specifically, to verify your identity against government-issued documents and establish a verified digital identity record
- Impersonation detection: for Xiplio specifically, to scan publicly available content for accounts that may be impersonating you and to deliver actionable Findings
- Communications: to send transactional messages (receipts, account alerts, security notifications) and, where you have consented, marketing communications about Exyllion products
- Legal compliance: to comply with applicable laws, respond to lawful requests from public authorities, and enforce our agreements
- Analytics and research: to conduct internal research, generate aggregate statistics, and improve our understanding of user needs — always using anonymized or pseudonymized data where possible
- Business operations: to manage our internal operations, perform audits, and carry out other legitimate business functions
We do not sell your personal information to third parties for their own marketing purposes. We do not use your data to train third-party AI models without your explicit consent.
Section 07
Legal Basis for Processing
Where the GDPR or equivalent legislation applies, we rely on the following legal bases to process your personal data:
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to deliver the product or service you have signed up for, including account creation, feature delivery, and billing
- Legitimate interests (Art. 6(1)(f) GDPR): processing necessary for our legitimate business interests, including fraud prevention, product security, internal analytics, and improving our services — provided those interests are not overridden by your rights
- Legal obligation (Art. 6(1)(c) GDPR): processing required to comply with laws to which we are subject, including financial regulations, tax obligations, and court orders
- Consent (Art. 6(1)(a) GDPR): processing based on your freely given, informed, specific consent — including marketing emails and the use of non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing
- Vital interests (Art. 6(1)(d) GDPR): in exceptional circumstances where processing is necessary to protect someone's life
For special category data (including biometric data processed by Onitee ID), we rely on explicit consent under Art. 9(2)(a) GDPR or, where applicable, processing necessary for reasons of substantial public interest under Art. 9(2)(g).
Section 08
Cookies & Tracking Technologies
We use cookies and similar tracking technologies to operate our websites and products. A cookie is a small text file placed on your device when you visit a website.
Categories of cookies we use:
- Strictly necessary cookies: required for the website to function; they cannot be disabled. These include session management, authentication tokens, and security cookies
- Functional cookies: remember your preferences and settings (language, region, theme) to improve your experience
- Analytics cookies: help us understand how visitors interact with our site, including which pages are most visited and where users drop off. We use this data in aggregate only
- Marketing cookies: used to deliver advertising relevant to your interests and to measure campaign effectiveness. These are only set with your prior consent
You may manage your cookie preferences through our cookie consent banner at your first visit or through your browser settings. Note that disabling certain cookies may affect the functionality of our services.
We honor Do Not Track (DNT) signals and Global Privacy Control (GPC) signals where technically feasible. We do not use fingerprinting techniques to re-identify users who have opted out of tracking.
Section 09
Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We share your data only in the following circumstances:
- Service providers: we engage third-party vendors to perform services on our behalf, including cloud hosting, payment processing, email delivery, identity verification, and customer support tooling. These providers are contractually bound to process data only on our instructions and to maintain appropriate security
- Exyllion group companies: our ventures may share data with each other within the Exyllion group for the purposes of operating and improving our products, subject to this Policy
- Business transfers: in the event of a merger, acquisition, asset sale, or reorganization, your data may be transferred as part of that transaction. We will notify you via email or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy
- Legal requirements: we may disclose your information where required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- With your consent: we may share your information with third parties for any other purpose with your explicit prior consent
When we share data with service providers, we require them to execute data processing agreements that comply with applicable law, including standard contractual clauses where required for international transfers.
Section 10
International Data Transfers
Exyllion operates globally and your data may be transferred to, stored in, and processed in countries other than the one in which you reside. These countries may have data protection laws that differ from those in your jurisdiction.
Where we transfer personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we rely on one or more of the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Agreement (IDTA) or addendum
- Binding Corporate Rules where applicable
- Your explicit consent, in cases where the transfer is necessary for the performance of a contract or for the establishment of legal claims
You may request a copy of the applicable transfer mechanism by contacting us at privacy@exyllion.com.
Section 11
Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Our general retention principles are:
- Account data: retained for the duration of your account and for a period of three (3) years following account closure, to enable dispute resolution and satisfy regulatory obligations
- Transaction records: retained for seven (7) years to comply with financial and tax regulations
- Identity verification records: retained for five (5) years following verification completion, or longer if required by applicable anti-money-laundering or KYC regulations
- Communication records: support tickets and email correspondence are retained for two (2) years following resolution
- Analytics and log data: aggregated analytics are retained indefinitely in anonymized form; raw log data is retained for ninety (90) days and then deleted or anonymized
- Marketing consent records: retained until consent is withdrawn, plus three (3) years thereafter to demonstrate compliance
At the end of the applicable retention period, data is securely deleted or anonymized so that it can no longer be attributed to you.
Section 12
Your Rights
Depending on your location, you may have the following rights with respect to your personal data. We honor these rights without discrimination:
- Right of access: to request a copy of the personal data we hold about you and information about how it is processed
- Right to rectification: to request correction of inaccurate or incomplete personal data
- Right to erasure ("right to be forgotten"): to request deletion of your personal data, subject to our legal retention obligations
- Right to restrict processing: to request that we limit how we use your data while a dispute is pending or while you verify its accuracy
- Right to data portability: to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller
- Right to object: to object to processing based on legitimate interests, including for direct marketing purposes
- Right to withdraw consent: to withdraw any consent you have given at any time, without affecting the lawfulness of prior processing
- Rights related to automated decision-making: to request human review of any automated decision that produces legal or similarly significant effects
To exercise any of these rights, please contact us at privacy@exyllion.com. We will respond within thirty (30) days of receiving a verifiable request. We may ask you to verify your identity before we fulfill your request. We will not charge a fee unless your request is manifestly unfounded or excessive.
Section 13
California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you specific rights regarding your personal information:
- Right to know: you may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources from which it was collected, the business purpose for collecting it, and the categories of third parties with whom we share it
- Right to delete: you may request deletion of personal information we have collected from you, subject to certain exceptions
- Right to correct: you may request correction of inaccurate personal information we maintain about you
- Right to opt out of sale or sharing: Exyllion does not sell personal information as defined under the CCPA, nor do we share personal information for cross-context behavioral advertising without your consent
- Right to limit use of sensitive personal information: you may direct us to limit our use of sensitive personal information to what is necessary to perform the services you have requested
- Right to non-discrimination: we will not discriminate against you for exercising any of your CCPA/CPRA rights
To submit a verifiable consumer request, contact us at privacy@exyllion.com or write to us at the address in Section 20. We will verify your identity before processing your request. You may designate an authorized agent to submit requests on your behalf, provided the agent presents written authorization and you verify the request directly with us.
Section 14
Children's Privacy
Exyllion's products and services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 16 without verifiable parental or guardian consent.
If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will take steps to delete that information as promptly as possible. If you believe we may have collected data from a child, please contact us immediately at privacy@exyllion.com.
For users between the ages of 16 and 18, we encourage parental involvement in any decision to use our services. Where a product requires age verification, we rely on the information provided by the user and accept no liability for misrepresentation of age.
Section 15
Security Measures
We implement technical, organizational, and administrative security measures designed to protect your personal data against unauthorized access, disclosure, alteration, and destruction. Our security program includes:
- Encryption of data in transit using TLS 1.2 or higher across all Exyllion properties
- Encryption of sensitive data at rest using AES-256 or equivalent standards
- Role-based access controls limiting data access to personnel with a legitimate need
- Multi-factor authentication required for all internal systems containing personal data
- Regular penetration testing and vulnerability assessments conducted by independent third parties
- Security incident response procedures with defined escalation paths and breach notification timelines
- Employee security training and background checks for personnel with access to personal data
- Vendor security assessments before engaging any third-party service provider
Despite these measures, no transmission over the internet and no electronic storage method can be guaranteed to be 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law, within 72 hours of becoming aware of the breach where required under GDPR.
Section 16
Third-Party Links
Our websites and products may contain links to third-party websites, applications, and services that are not operated by Exyllion. When you click on a third-party link, you will be directed to that third party's site. We strongly encourage you to review the privacy policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy practices, or policies of any third-party sites or services. Our inclusion of a link does not imply endorsement of, or any affiliation with, the linked site or its operators.
If any of our products integrate with third-party platforms (such as social media platforms used by Xiplio for impersonation scanning), those platforms' own terms and privacy policies govern their data processing. We recommend reviewing their policies independently.
Section 17
AI & Automated Processing
Several Exyllion products use artificial intelligence and automated processing as core features:
- Xiplio uses face-matching AI to compare your submitted identity images against publicly accessible social media content to detect potential impersonators. This processing is carried out on your behalf and at your direction. Findings generated by AI are presented to you for your review and judgment — they are not automated decisions with legal effect
- Inictra may use AI-assisted features to help surface decision patterns and recommendations. These are advisory only and do not replace human judgment
- Aiphra may use automated moderation to screen listings for prohibited content. Appeals of automated moderation decisions are reviewed by a human
- Venectra uses AI-based threat detection models to analyze signals and identify security risks. Automated threat classifications may trigger alerts that are then reviewed by the user or their security team
Where automated processing produces a decision that has a legal or similarly significant effect on you, you have the right to request human review, to express your point of view, and to contest the decision. Please contact us at privacy@exyllion.com to exercise this right.
We do not use your personal data to train our AI models or those of third parties without your explicit, informed consent. Aggregated and anonymized data may be used for model improvement subject to appropriate safeguards.
Section 18
Product-Specific Notices
The following supplementary notices apply to specific Exyllion products and should be read alongside this Policy:
Onitee ID: Onitee ID processes biometric data (facial images and, where applicable, liveness data) for identity verification purposes. This constitutes special category data under GDPR. We process this data on the basis of your explicit consent, which you may withdraw at any time by deleting your Onitee ID account. Biometric data is processed by our KYC provider under strict contractual controls and is not retained beyond the period necessary for verification unless required by applicable anti-money-laundering regulations.
Xiplio (iOS): Xiplio accesses your device's camera and photo library solely for the purpose of capturing or importing your identity images. This data is transmitted securely to our servers for the purpose of running impersonation scans. It is not shared with Apple or any third party except our scanning infrastructure provider, which operates under a data processing agreement. You may revoke camera or library access at any time through your iOS settings.
Aiphra: Sellers on Aiphra may have visibility into transaction data and buyer interaction metrics relating to their listings. Buyers' identities are not shared with sellers beyond what is necessary to fulfill a transaction. Aiphra does not disclose user communications between buyers and sellers to either party's third parties.
Inictra: Decision data entered into Inictra is treated as confidential business information. Exyllion does not access, read, or use the content of your decisions for any purpose other than delivering the service. Where an organization subscribes to Inictra, the organization administrator may have access to team members' decision records within the platform as configured by the organization.
Section 19
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our products, or applicable law. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify registered users by email at the address associated with their account
- Display a prominent notice on our website or within the relevant product for a period of at least thirty (30) days
- Where required by law, obtain your renewed consent before the changes take effect
We encourage you to review this Policy periodically to stay informed about how we protect your information. Your continued use of our services after any changes become effective constitutes your acknowledgment of the updated Policy.
Prior versions of this Privacy Policy are available upon request by contacting us at privacy@exyllion.com.
Section 20
Contact & Complaints
If you have questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:
We will acknowledge your request within five (5) business days and aim to resolve all privacy inquiries within thirty (30) days. For complex requests, we will notify you if additional time is required.
If you are located in the European Economic Area and you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu. If you are located in the United Kingdom, you may contact the Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority and welcome you to contact us in the first instance.