Who we are and how to reach us
XORVYNE LLC is a limited liability company registered in the State of Wyoming, United States, providing software development and technology services. For the purposes of the EU and UK General Data Protection Regulation, we act as the data controller for information collected through this website and our own business operations.
Where we build or operate software on behalf of a client and process personal data belonging to that client's users, we act as a data processor on the client's instructions, under a separate data processing agreement. That processing is governed by the agreement with that client and by their own privacy notice, not by this policy.
| Registered entity | XORVYNE LLC |
|---|---|
| Registered address | 30 N Gould St, Ste R, Sheridan, WY 82801, United States |
| Privacy contact | privacy@xorvyne.com |
| General contact | hello@xorvyne.com |
Information we collect
Information you give us directly
- Enquiry details submitted through our contact form or by email: your name, email address, company name, telephone number (optional), the service and budget range you select, your intended timeline, and the free-text description of your project.
- Engagement information if you become a client: billing contact details, business address, tax identifiers where legally required, purchase order references, and the contents of project communications.
- Recruitment information if you apply to work with us: your CV, portfolio links, and anything else you choose to send.
Information collected automatically
- Server logs. Our web host records the requesting IP address, timestamp, requested URL, HTTP status, referring page, and user-agent string for every request. These logs are generated by the hosting infrastructure for security and diagnostics.
- Essential cookies only. This website does not run advertising trackers, social media pixels, or third-party analytics that profile you across sites. See our Cookie Policy for the complete list.
Information we do not collect
We do not ask for, and ask that you do not send us, payment card numbers, government identification numbers, health information, or login credentials through the contact form or by email. We do not purchase marketing lists, and we do not build behavioural profiles of website visitors.
Why we use it, and our legal basis
Under the GDPR we must identify a lawful basis for each purpose. Ours are set out below.
| Purpose | Data used | Legal basis |
|---|---|---|
| Replying to your enquiry and preparing a proposal | Enquiry details | Steps taken at your request prior to entering a contract (Art. 6(1)(b)) |
| Delivering services under an engagement | Engagement information | Performance of a contract (Art. 6(1)(b)) |
| Issuing invoices and keeping accounting records | Billing details | Legal obligation (Art. 6(1)(c)) |
| Securing the website and preventing abuse | Server logs, form metadata | Legitimate interests in protecting our systems (Art. 6(1)(f)) |
| Defending or bringing legal claims | Relevant records | Legitimate interests in establishing and defending claims (Art. 6(1)(f)) |
| Occasional updates to existing clients | Name, email | Legitimate interests, with an unsubscribe link in every message (Art. 6(1)(f)) |
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not carry out profiling.
Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We share it only with the service providers we need to run the business, each of which is bound by contract to process it solely on our instructions:
| Provider category | Purpose | Data involved |
|---|---|---|
| Web hosting and email | Serving this website; sending and receiving mail | Server logs, enquiry and correspondence content |
| Cloud infrastructure | Development, staging, and production environments | Project data, as agreed in each engagement |
| Accounting and invoicing | Issuing invoices, bookkeeping, tax filing | Billing contact and transaction records |
| Payment processors | Collecting card payments where used | Handled directly by the processor; we never receive full card numbers |
| Project collaboration tools | Shared channels, issue tracking, code hosting | Names, work email addresses, project content |
We will also disclose information where we are legally required to do so — in response to a valid court order, subpoena, or lawful request from a public authority — and where necessary to protect our rights, safety, or property. Where the law permits it, we will tell you before we do.
If XORVYNE LLC is involved in a merger, acquisition, or sale of assets, personal information may transfer to the successor entity. You will be notified before your information becomes subject to a materially different privacy policy.
International transfers
XORVYNE LLC operates from the United States, and our service providers may process data in the United States and elsewhere. If you are located in the European Economic Area, the United Kingdom, or Switzerland, transferring your information to us means transferring it outside your home jurisdiction.
Where such a transfer takes place, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our agreements with providers, together with supplementary technical measures including encryption in transit and at rest, and access limited on a least-privilege basis. A copy of the relevant transfer mechanism is available on request at privacy@xorvyne.com.
How long we keep it
| Record type | Retention period |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact, then deleted |
| Client project records and correspondence | Duration of the engagement plus 6 years |
| Invoices and accounting records | 7 years, as required for tax purposes |
| Web server logs | Up to 12 months |
| Recruitment applications | 12 months, unless you ask us to keep them longer |
Client-owned data held in systems we build is deleted or returned according to the terms of the relevant engagement, normally within 30 days of a written request following handover.
How we protect it
We apply security measures proportionate to the risk, including:
- TLS encryption for all traffic to and from this website;
- encryption at rest for stored project data on cloud infrastructure;
- multi-factor authentication on every account that can reach client systems;
- least-privilege access, reviewed at each engagement milestone and revoked at handover;
- secrets held in a managed vault rather than in code, configuration files, or messages;
- dependency and vulnerability scanning on the code we ship.
No system is perfectly secure, and we do not claim otherwise. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high.
Your rights
If you are in the EEA, UK, or Switzerland
You have the right to: access the personal data we hold about you; have inaccurate data rectified; request erasure where we no longer have grounds to keep it; restrict processing while a dispute is resolved; receive your data in a portable format; object to processing based on our legitimate interests; and withdraw consent at any time where consent is the basis we rely on.
You may also lodge a complaint with your local supervisory authority. We would appreciate the chance to resolve the issue first.
If you are a California resident
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how it is used and disclosed; to request deletion; to request correction; and to be free from discrimination for exercising these rights.
We do not sell or share personal information as those terms are defined by the CPRA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes beyond those permitted under the CPRA, so no "Limit the Use of My Sensitive Personal Information" link is required.
Other US state privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other states with comprehensive privacy legislation have comparable rights of access, correction, deletion, and portability, and may appeal a refused request by writing to privacy@xorvyne.com with "Privacy appeal" in the subject line.
Making a request
Email privacy@xorvyne.com from the address you contacted us on, or tell us enough to locate your records. We respond within 30 days for GDPR requests and 45 days for US state law requests, and will tell you if we need an extension. There is no charge unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity, used only for that purpose. An authorised agent may act for you with written proof of authorisation.
Children
Our services are directed at businesses, and this website is not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@xorvyne.com and we will delete it promptly.
Third-party links
This website links to third-party sites we do not control, and our clients' products may do the same. This policy does not cover those sites. We encourage you to read the privacy notice of any site you visit from ours.
Changes to this policy
We update this policy when our practices change or the law requires it. The effective date at the top of the page always reflects the current version. If a change materially affects how we handle your information, we will notify active clients by email at least 30 days before it takes effect. Continuing to use the website or our services after a change takes effect indicates acceptance of the revised policy.
Contact
Privacy questions, requests, and complaints: privacy@xorvyne.com
Postal address: XORVYNE LLC, 30 N Gould St, Ste R, Sheridan, WY 82801, United States
We aim to acknowledge every privacy enquiry within one business day.
This document was last updated on September 2, 2026. XORVYNE LLC may revise it from time to time; the version published at xorvyne.com/privacy/ is always the version in force. Material changes affecting active engagements are notified by email at least 30 days before they take effect.
Questions about this document: legal@xorvyne.com