XIXOIO · LEGAL
Privacy notice
Version 1.8 · effective from 29 August 2026
Controller
XIXOIO LTD, company number 11013311, registered office 43 Owston Road, Doncaster, England, DN6 8DA. Contact: info@xixoio.com.
What is processed on an ordinary visit
When you visit the website, the hosting platform processes technical operating data — IP address, browser type, time and address of the request. This serves the operation and security of the website. The legal basis is the legitimate interest in keeping the website running and protected from abuse.
The website stores the necessary technical choices described in Cookies and browser storage. Optional statistical interaction events are created only after consent; they contain no form text and are not used for advertising profiles or cross-site tracking. Data processed on a purchase is described below in the Buying books and audiobooks section.
Retention
Operating logs are retained by the hosting platform provider under its own terms. The cookie choice is stored for up to six months. Necessary anti-abuse identifiers for the form and checkout remain until browser storage is cleared; the sharing signature remains only until the tab is closed.
We delete the database copy of a contact message and its technical events no later than 12 months after receipt. A record placed on legal hold because of a contractual relationship, legal claim or statutory duty is not automatically deleted until that reason ends. Follow-up correspondence in the email mailbox is governed by separate operational and legal retention duties.
We delete an unconfirmed newsletter request after 30 days; the confirmation link is valid for 24 hours. If the email provider cannot confirm a safe unsubscribe, we retain only the address and the error state that blocks sending for as long as necessary, and remove them after remediation. We retain an active email address, language, consent version and confirmation record until consent is withdrawn. We delete technical records of individual deliveries after 180 days and webhook records after 90 days. Short-lived pseudonymised anti-abuse limits are deleted no later than 24 hours after they expire. After unsubscribing, we keep the minimum record needed to evidence withdrawal and prevent further sending; a new request alone does not overwrite it, and activation resumes only after a new double opt-in and successful synchronisation.
The database periods above are enforced by a private authenticated maintenance command in bounded batches. Before the contact form and newsletter are activated in production, hosting operations must schedule it, repeat an unfinished batch and monitor successful completion; deploying the code alone does not create a scheduler.
Who receives the data
- The hosting and development platform on which the website runs — processor.
- The service from which the website’s images and files are loaded — processor.
- The service delivering the website typefaces — a recipient of ordinary technical connection data.
- The third-party video player — an independent controller, and only after you start the film yourself.
- For titles where secure checkout is active, the payment provider Stripe processes order details and the payment itself. Card details are entered directly with Stripe and are not stored by this website.
- Resend — provider of contact, confirmation, transactional and newsletter email; for a contact message it processes the name, address, topic and message text, and for a subscription the email address, language, subscription status and delivery data as our processor.
We do not sell or rent data. The contact message and the consent and subscription records are stored in the hosting platform database. Resend delivers the contact message to our mailbox; it receives a newsletter address when the confirmation email is sent and adds it to the updates list only after your confirmation.
Transfers outside the United Kingdom and the EEA
The suppliers named above may process data outside your country of residence, including in the United States. A transfer relies on an applicable adequacy decision or standard contractual clauses and the supplier’s data processing agreement.
Forms
The website contains a “Describe your use case” form, a contact form and a separate newsletter form. “Describe your use case” currently only prepares a message in your email application. The contact form and newsletter are submitted securely to the website server and use the database and email service described below.
Contact form and ordinary email
The contact form processes your name, reply email, topic, message, language, source page, time, the version of this notice and the technical sending and delivery status on the server. To limit abuse, we use a short-lived pseudonymised fingerprint of the network identifier; we do not store the raw IP address in the contact database. The required confirmation only records that you have read this notice; it is not consent as the legal basis. We use the details to handle the enquiry. The legal basis is our legitimate interest in handling the communication or, where applicable, steps taken at your request before entering into a contract.
Newsletter
After the newsletter form is submitted, we process the email address, selected language, source page, request time, consent version, and technical confirmation and delivery status. To limit abuse, we use a short-lived pseudonymised fingerprint of the network identifier; we do not store the raw IP address in the newsletter database. The legal basis for sending updates is your consent.
The subscription uses double opt-in. After the initial request we send a one-time link, but updates start only after you confirm it yourself. Every update contains an immediate unsubscribe link. You can also withdraw consent at info@xixoio.com; withdrawal does not affect the lawfulness of earlier processing. We do not use newsletter opens or clicks for advertising profiling.
The “Describe your use case” form
When you submit the form, we process the selected type of organisation, the answers about the case in question, the organisation name, country of operation, name, job title and work email. The organisation website and phone number are optional.
We use the data solely to assess whether the case matches the scope of Genesis One OS and for subsequent communication. The legal basis is the legitimate interest in handling a business enquiry and, where applicable, taking steps prior to concluding a contract at the user’s request.
The selected category only tailors the questions of the form; we do not use automated decision-making or profiling. We retain the data for no longer than 12 months from the last substantive communication, unless a contractual relationship arises or an obligation requires longer retention.
In the current email-based mode, the website does not receive these details. If server submission is activated later, they may be processed by the hosting and development platform and the transactional email provider; this notice will be updated before activation. We do not use them for marketing without separate consent.
Buying books and audiobooks
Payment can start only for a title whose final files and delivery system are verified by the website on each load. If that check is not successful, the purchase control remains locked and no payment can be created.
When you buy a book or audiobook, the data processed is your email address, the purchased title, the amount paid, the payment identifier and the data needed for an invoice. Card details are entered directly with the payment provider; the website itself does not have them.
The legal basis is the performance of the purchase contract, and for accounting and tax records the legal obligation of the seller.
After payment is confirmed, one secure access link to the private library containing the PDF, EPUB and MP3 is sent to the email address provided. The delivery database stores a one-way derived fingerprint of the address, the order identifier, title, amount, entitlement status and limited download records; it does not store the email address itself in the entitlement record.
Order and invoice records are kept for as long as required by accounting and tax rules.
What never to send us
Do not send us identity documents, seed phrases, private keys or sensitive materials relating to the ongoing proceedings. If we need them, we will request them through a secure channel.
Your rights
You have the right of access to your data, to rectification or erasure, to restriction of processing, to portability, to object to processing based on legitimate interest, and to withdraw newsletter consent at any time. You can exercise these rights at the contact address above. We respond without undue delay.
Changes
This document describes the website's actual behaviour, verified by measurement. Whenever a supplier or a feature changes, the measurement is repeated and this document is updated before the change goes live.
Genesis One OS is a concept and a target architecture. Individual parts exist and work; the whole is not in production. It is not presented as licensed or regulator-approved financial infrastructure. The content of this website is informational and does not constitute an investment offer, nor investment, legal, tax or financial advice.
Submitting an application, registering, expressing interest, starting a conversation, taking part in a demonstration, due diligence, a pilot or any other assessment, and any confirmation of receipt or preliminary approval thereof, do not create a contract, a binding promise or any legal entitlement to a licence, access, participation, continued negotiations or the establishment of a business relationship.
Every applicant may, to an extent proportionate to the nature of the intended relationship, be subject to assessment of identity and ownership structure, trustworthiness and integrity, source of funds, sanctions and regulatory status, and security, technical and risk profile, and may be asked to provide or update information.
The relevant legal person identified for the given module or service may, to the maximum extent permitted by law, refuse an application and may restrict, suspend or terminate access, registration, a pilot, a licence or any other participation that is not provided under an already concluded contract, based on its own legal, regulatory, sanctions, security, technical, capacity, integrity, reputational, strategic or operational assessment, including after preliminary approval. It need not state a reason unless required otherwise by law, by a decision of a competent authority or by an effective contract.
An automated confirmation, a status shown in an interface, or a statement or output of an AI or agent does not constitute an offer, an acceptance of an offer or a binding declaration on behalf of any legal person. Where a contractual relationship has already been concluded, the conditions and consequences of its restriction, suspension or termination are governed by the relevant contract and by binding law; the contract prevails over this notice. Rights and liabilities that cannot be excluded by law remain unaffected.