Skip to content

Legal

Privacy

This notice explains what we do with the information you give us when you request access. It is short because we collect very little.

Last updated 26 August 2026

Who is responsible

Xamar AI Ltd, of 27 Huddersfield Road, Mirfield, United Kingdom, is the data controller for the information described in this notice. If you have a question about any of it, including any of the rights set out below, write to privacy@xamar.ai and a person will answer.

This notice covers this website and the access request form on it, and nothing else. It does not describe what the Xamar AI product does with data once you are a customer. That processing is different in kind and in scale, and it will be described separately, in the agreement that governs it and in a notice of its own.

What we collect, and why

We collect what the access form asks for, together with a few details recorded alongside it. There is nothing else. This site sets no cookies, runs no analytics, embeds no third party scripts, and stores nothing in your browser.

Work email

So that we can reply to you. It is also the address our reply goes to.

Name

So that we can address you properly.

Company

So that we understand who is asking.

Role

Lender, operator, or, if you choose Other, whatever you type in its place, so that we can point the right part of the product at the right person.

Facility scale

A range, so that we know whether we can help.

Message

Optional, and entirely yours. If you leave it empty, nothing is stored.

When you asked, and from where

The date and time of the request, and which page of this site it came from.

Browser user agent

The line your browser identifies itself with, recorded with the request and truncated. We use it only to diagnose a submission that failed.

A hash of your IP address

Explained in the two paragraphs below.

The record of your request does not contain your IP address. What it contains is a SHA-256 hash of that address combined with a secret salt, which is enough to notice five requests arriving from one source within an hour and refuse the sixth. We treat that hash as personal data, and we will not overstate what hashing achieves. There are only about four billion possible IPv4 addresses, so anyone holding the salt could work back from a hash to the address that produced it. We hold the salt. The protection is that we keep it secret and have no reason to use it that way, not that the arithmetic prevents it.

Separately from that record, the providers listed below keep the ordinary operational logs that every piece of internet infrastructure keeps, and those logs can contain the IP address of a request for a period each provider sets. We do not collect those logs, query them, or use them to identify anyone. We mention them because a notice that claimed your address was never written down anywhere would not be true.

Our lawful bases

Nearly all of this rests on Article 6(1)(f) of the UK GDPR and the EU GDPR, our legitimate interests. Those interests are three: replying to a business enquiry that was made to us, keeping a record of who has approached us and what they asked for, and keeping the form usable by limiting how often it can be submitted from one source. We have weighed them against your interests and rights and concluded that they do not override them. You gave us this information deliberately, in a professional capacity, precisely so that we would use it in this way, and we use it for nothing else. You may ask us for that assessment and we will send it to you.

Where you are yourself the person we would be contracting with, rather than someone enquiring on behalf of an employer, our reply is also covered by Article 6(1)(b), which is about steps taken at your request before entering into a contract. We do not lean on it for most requests, because the contract that might eventually follow would usually be with your company and not with you, and a basis that fits only some of the people who use a form is the wrong basis to build a notice on.

We do not ask for any special category data as defined in Article 9, and you should not send us any.

Who else sees it

Three processors handle it, each doing one thing. Each may in turn use its own subprocessors, and none of them is permitted to use your information for its own purposes.

  • Supabase, which provides the database that holds the record. Our project is hosted in the EU (eu-west-1).

  • Resend, which sends the single notification email to us. It does more than pass the message along. Your name, company, email address and whatever you wrote are held in Resend's systems, in the United States, while it delivers the message and for as long as it retains its own delivery logs.

  • Amazon Web Services, which hosts this site and serves the page you are reading, from the eu-west-1 region.

We do not sell your information, we do not share it with advertisers, and we do not add you to a mailing list. There is no mailing list.

Sending it outside the UK and the EEA

Some of this leaves the UK and the EEA, because the notification email is processed in the United States. Where the destination is a country the UK or the EU has formally found adequate, or a US organisation actively self certified to the UK Extension to the EU US Data Privacy Framework, the transfer is made on that basis and needs nothing further.

Where neither applies, the transfer is made under the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses, together with a transfer risk assessment and whatever supplementary measures it calls for. You are entitled to see the safeguards relied on for any of it. Ask at the address above and we will send you a copy, redacted only where it contains commercial terms that are not about your data.

How it is protected

The table holding your request has row level security enabled and no access policies at all, which means it cannot be read with the public key this site would use in a browser. It is reachable only by our server, using a key that never reaches your browser and is never included in anything we publish. Everything travels over TLS.

How long we keep it

We keep your request for 12 months from the day you make it, and delete it at the end of that period. We measure from the request itself rather than from our last conversation with you, because that is a date we can actually evidence. If it becomes clear sooner that we are not a fit, we delete it sooner. You can ask us to delete it at any point before then, and we will, without needing a reason.

Your rights

Under the UK GDPR and the EU GDPR you may ask us to do any of the following, free of charge. Write to privacy@xamar.ai and we will answer within one month.

  • See a copy of what we hold about you, and be told where it came from and who else has had it (Article 15).

  • Correct anything inaccurate, or complete anything incomplete (Article 16).

  • Delete it (Article 17).

  • Restrict what we do with it while a question about it is being resolved (Article 18).

  • Object to our processing it on legitimate interest grounds (Article 21).

  • Receive it in a portable, machine readable form (Article 20). This one is narrower than the others. It applies only where we process on the basis of your consent or a contract with you, which, as set out above, most of this is not. In practice Article 15 is what will get you a copy, and we will not hide behind the distinction if a copy is what you want.

An objection under Article 21 is not automatic, and we would rather say so than imply otherwise. When you object to processing based on legitimate interests, we must stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or that we need the data to establish or defend a legal claim. If we think we have such grounds, we will tell you what they are, in writing, rather than simply carrying on. We do not use any of this for direct marketing. If we ever did, an objection to that would be absolute and we would have to stop on being asked.

If you are unhappy with how we have handled it

Tell us, and tell us however suits you. Write to privacy@xamar.ai, or use the message box on the access form and say what the problem is, or simply reply to any email from us. We will treat it as a complaint however it arrives, and you do not have to use the word.

We will acknowledge it within 30 days of receiving it, look into it, and tell you the outcome without undue delay. If it is taking us a while, we will tell you where we have got to rather than leave you waiting. From 19 June 2026 this is what section 164A of the Data Protection Act 2018, inserted by the Data (Use and Access) Act 2025, requires of us. We would want to do it in any case.

You do not have to come to us first, and coming to us costs you nothing. You may complain to the Information Commissioner's Office (ICO) at any time, or to the supervisory authority of the EEA country where you live, where you work, or where you think the problem happened.

Decisions about you

Nothing on this site makes an automated decision about you, and we do not profile you. The figures shown in the product demonstration are illustrative, and they are not derived from anything you send us. A person reads every request.

Giving us the information

Providing it is entirely voluntary. There is no statutory or contractual requirement to do so, and nothing happens if you decline, except that a blank form leaves us no way to reply. The form is how we prefer to be approached, because it asks the few things that let us answer usefully. If you would rather not use it, privacy@xamar.ai reaches a person, though it is a mailbox for data protection questions rather than a general enquiry line.

Changes

This notice was last updated on 26 August 2026. If we change what we collect or why, we will change this page and the date on it before the change takes effect. Adding analytics, a cookie, or any third party script would be such a change.