XERR commercial information
Privacy notice
This notice explains how XERR handles information when people visit this website, contact XERR, request a trial, purchase a licence or use an XERR software product.
1. Who controls the information
XERR is responsible for information used to operate this website, manage commercial contacts and enquiries, administer licences and secure product access. For project information placed into a client workspace, the licensed client organisation normally determines why that project information is used and XERR operates the service on its instructions.
2. Information we use
Depending on the service, this may include business contact details, organisation and project information, professional profile links, contact source, user roles, licence records, sign in and security records, correspondence, meeting and call notes, follow up tasks, audit events, evidence files submitted by authorised users, and transaction references returned by the payment provider. For controlled website demonstrations, XERR records the visitor's name, work email, organisation email domain, demonstration opened, first registration time, most recent access time and optional marketing choice. XERR does not collect raw card details on this website.
3. Why we use it
Information is used to answer enquiries, manage relevant business conversations, provide demonstrations, trials and licensed services, verify and secure access, isolate client workspaces, process authorised instructions, prevent misuse, maintain auditability, provide support and meet legal or accounting obligations. Relevant UK GDPR lawful bases may include performance of a contract, legitimate interests in operating and developing the business and protecting the service, compliance with legal obligations, and consent where required.
4. Business contacts and the XERR Client Studio
XERR may add a professional contact to its private Client Studio after an enquiry, controlled demo registration, referral, meeting, phone call, email or a relevant professional approach through a service such as LinkedIn. The record can include the source, business contact details, organisation, role, problem discussed, product interest, contact history, next action, email permission and a do not contact instruction. XERR uses these records to keep the conversation accurate and avoid unwanted or repeated approaches.
Information visible on a public professional profile is still personal information when it relates to an identifiable person. XERR will consider the context, relevance and reasonable expectations before using it and will provide privacy information when required. A person can object or ask XERR to stop direct marketing at any time. XERR retains the minimum suppression information needed to respect that request.
5. Marketing choice
Submitting an enquiry or registering for a demonstration does not automatically subscribe a visitor to marketing. Any marketing choice is separate, optional and unticked by default. XERR records the applicable permission or business contact basis before an official email is sent from the Client Studio. Marketing email is blocked in the system unless consent or a confirmed corporate business contact basis is recorded. Every XERR marketing email includes a clear way to stop future marketing. Sole traders and some partnerships are treated as individual subscribers where the electronic marketing rules require this.
6. Service providers
XERR may use carefully selected hosting, storage, authentication, email, analytics, transcription and payment providers where required to deliver the service. Providers receive only the information needed for their function and are expected to apply appropriate contractual and security safeguards. Card payments are completed on the payment provider's hosted checkout.
7. Retention and deletion
Commercial and accounting records are retained for the period required by law. Account, project and evidence records are retained for the licensed service period and any agreed retention window, then deleted or returned in accordance with the client agreement, subject to legal holds, backups and records that XERR must retain. Identifiable enquiries, demonstration registrations and prospective client records are reviewed and normally removed within 12 months after the last meaningful contact unless an active conversation, trial, service, suppression instruction or legal requirement justifies longer retention.
8. International processing
Where a service provider processes information outside the United Kingdom, XERR will use an applicable safeguard such as an adequacy regulation or approved contractual protection where required.
9. Your rights
Depending on the circumstances, individuals may have rights to access, correct, erase, restrict or object to processing, and to receive certain information in a portable form. Requests can be sent to support@xerr.co.uk. People may also complain to the UK Information Commissioner's Office.
10. Cookies, sessions and anonymous demand totals
XERR products use strictly necessary security and session storage to keep authorised users signed in and preserve controlled application functions. The limited demo and owner login cookies are required for access control.
For public website improvement, XERR records anonymous daily totals for page loads, links selected, downloads, contact selections and the product route involved. This first party measurement does not set an analytics cookie and does not create or store a visitor identifier, IP address, browser fingerprint, user agent or query string in the XERR analytics table. It cannot tell XERR who an anonymous visitor is or follow one person across visits. A visitor becomes identifiable to XERR only when they provide details through an enquiry, Finder review request, controlled demo registration or direct business conversation.
11. Website enquiries and Finder review requests
The website forms collect the name, email address, organisation, chosen product, enquiry type, message and relevant Finder result. They also record the source of the form, a reference number, handling status, internal follow up notes and email acknowledgement state. The information is stored in the private XERR enquiry inbox and Client Studio on the existing hosting service and is used to handle the request, not to enrol the person in marketing.
A short lived necessary form security cookie, signed form token and keyed hashes are used to resist spam and repeated submissions. Rate limit records expire and are cleared during normal use. Email acknowledgements and owner notifications use the XERR sending mailbox through Hostinger Email when configured. Acceptance by an email server does not guarantee inbox delivery.
Requests for correction, deletion or stopping direct marketing can be sent to support@xerr.co.uk. Do not send sensitive project files, passwords or payment details through the form.
12. Contact and changes
Questions can be sent to support@xerr.co.uk. This notice was updated on 12 September 2026 and may be updated as the XERR product family and its service providers develop.
