Privacy Notice

Last updated: 22nd December 2025 

Introduction 

XM.WORKS Ltd (“XM.WORKS”, “we, “us”, “our”), of Brightwell Grange, Britwell Road, Burnham, Buckinghamshire, England, SL1 8DF, a company registered in England and Wales, registration number 10987594, are committed to protecting the privacy and security of the Personal Data we collect about website visitors and end customers (“you”, “your”). 

The purpose of this privacy notice is to explain what Personal Data we collect about you when you visit our website or engage our services. When we do this, we are the Controller of the Personal Data we process, and are registered in the UK with the Information Commissioner’s Office (“ICO”) under registration number ZB937878. 

Please read this privacy notice carefully as it provides important information about how we handle your Personal Data and also includes information about your rights. If you have any questions about any aspect of this privacy notice, you can contact us using the information provided below in the ‘Contact us’ section. 

We update this privacy notice from time to time in response to changes in applicable laws and regulations, to our processing practices and to the products and services we offer. When changes are made, we will update the date at the top of this page. Please review this privacy notice periodically to check for updates. 

Who this notice applies to 

This notice applies if you: 

  • visit our website; 

  • visit our premises; 

  • subscribe to our communications; 

  • are a business associate (or a representative of a former, existing or potential client); 

  • purchase a service; or 

  • you contact us to enquire about our services. 

Please note that we have separate privacy information available for individuals who are looking to work with XM.WORKS. For more information, please read our Job Applicant privacy notice

What is Personal Data 

‘Personal Data’ means any information from which someone can be identified either directly or indirectly. For example, you can be identified by your name or an online identifier.  

 ‘Special Category Personal Data’ is more sensitive Personal Data including information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purposes of uniquely identifying someone, data concerning physical or mental health or data concerning someone’s sex life or sexual orientation.   

How we collect your Personal Data 

We collect most Personal Data directly from you in person, by telephone, email or via our website. However, we may also collect your Personal Data from third parties such as:  

  • through events and webinars; 

  • reputable companies who provide lead generation contact lists;  

  • others to whom you have provided consent; and 

  • publicly available sources such as social media platforms. 

Purposes for which we use Personal Data and the legal bases 

We may use your Personal Data for the following purposes and on the following lawful bases: 

Three Column Table
Purpose Personal Data Legal Bais for Processing
Responding to correspondence from you Name, business email address, phone number It is in our legitimate interest to respond to enquiries made via our website, by email, through our social channels or any other means.
Sending you information which may be of interest Name, email address If you are an existing customer or have expressed an interest in our products or services, we may rely on legitimate interests to contact you for marketing purposes. You may object to the processing for this purpose by emailing DPO@XM.Works.
If we have captured your consent for the purposes of marketing, that consent may be withdrawn at any time by emailing DPO@XM.Works.
Provision of our services Name, telephone number, email address, organisation details, communications Processing is necessary for performance of the contract between us.
Business management, forecasting and statistical purposes Your name (first & last name), organisation address, email address, phone number It is our legitimate interest to identify areas for managing current business relationships, developing new products and services, and managing our business.
Improving our website and portal and the overall user experience Technical data, Usage Information It is our legitimate interest to allow analytics and search engine providers to help improve and optimise our website.
Improving our websites and portal and the overall user experienceIP address, Location data, Device ID, Model and device type, Name and version of the operating system, Settings and language of the device We use cookies on our websites with your consent, unless they are strictly necessary cookies, in which case your consent is not required.
CCTV (which includes Ring Doorbells)CCTV Images Processing is necessary for our legitimate interest to protect the health, safety and security of employees and visitors to our premises.

Sharing your data 

We may also disclose your information to third parties in connection with other purposes set out in this policy. These third parties may include: 

  • business partners, suppliers and sub-contractors who may process information on our behalf; 

  • individuals and/or organisations who hold information related to your reference or application to work with us (e.g. current, past or prospective employers, educators and examining bodies and employment and recruitment agencies); 

  • advertisers, social media platforms, and advertising networks; 

  • analytics and search engine providers; 

  • IT service providers. 

Where we are under a legal or regulatory duty to do so, we may disclose your details to the police, regulatory bodies or legal advisors, and/or, where we consider necessary to protect the rights, property or safety of XM.WORKS, its personnel, users or others.  

We do not sell or share personal information to another business or third party for monetary or other valuable consideration. 

If XM.WORKS merges with or is acquired by another business or company in the future, (or is in meaningful discussions about such a possibility) we may share your personal data with the (prospective) new owners of the business or company. 

 

International Transfers 

Your Personal Data may be processed outside of the European Economic Area (EEA) as the organisations we use to provide our service to you may be based outside of the EU or UK (Client Relationship Management – Monday.com for example).  

We have taken appropriate steps to ensure that any Personal Data processed outside the EEA has an essentially equivalent level of protection to that guaranteed in the EU or UK. We do this by ensuring that:  

  • Your Personal Data is only processed in a country which the Secretary of State has confirmed has an adequate level of protection (an adequacy regulation); 

  • We enter into an International Data Transfer Agreement (“IDTA”) with the receiving organization and adopt supplementary measures, where necessary. (A copy of the IDTA can be found here) or; 

  • We enter into Standard Contractual Clauses (“SCCs”) with the receiving organizations and adopt supplementary measures, where necessary. (A copy of the SCCs can be found here Standard Contractual Clauses (SCCs)). 

We may also utilise the services of providers who have chosen to certify themselves under the EU/US Data Privacy Framework (with UK extension).  

In terms of end user data (“Customer Data”), we can confirm that this information is only ever stored within our Microsoft 365 environment within the UK, with our back-ups also being hosted on UK servers.  

There may be times when we need to share Customer Data with colleagues/ workers who are located in other parts of the world. These individuals are an extension of our internal staff, working within our established security and data protection framework. Therefore, any transfer of Customer Data under these circumstances will not be considered as restricted under the data protection legislation. 

 

How long we keep your data 

We will retain your personal data for as long as is necessary to provide you with our services and for a reasonable period thereafter to enable us to meet our contractual and legal obligations and to deal with complaints and claims.  

At the end of the retention period, your personal data will be securely deleted or anonymised, for example by aggregation with other data, so that it can be used in a non-identifiable way for statistical analysis and business planning. 

 

How we protect your data 

We take every possible measure to ensure that your information is not compromised in any way. We implement appropriate technical and organisational measures to protect data that we process from unauthorised disclosure, use, alteration or destruction.  Our privacy promise is in place in respect of our website only. Other online services will be serviced by their own privacy policies. 

Some of the controls we have in place are: 

  • We ensure active SSL certification on all of our websites (using https:// rather than http://); 

  • We use technology controls for our information systems, such as firewalls, user verification, data encryption, and separation of roles, systems & data management; 

  • We use password encryption and password management tools; 

  • We enforce a “need to know” policy, for access to any data or systems. 

 In addition to the technical and organisational measures we have put in place, there are a number of simple things you can do to further protect your personal information;  

  • Never share a One Time Passcode (OTP). 

  • Never enter your details after clicking on a link in an email or text message. 

  • Always send confidential information by encrypted email where possible this reduces the risk of interception. 

  • If you are logged into any online service do not leave your computer unattended. 

  • Close your internet browser once you have logged off. 

  • Never download software or let anyone log on to your computer or devices remotely, during or after a cold call. 

 

Your data protection rights 

There are certain fundamental rights that you have in respect of your Personal Data: 

Two Column Table
Rights Description
Right to be informed Individuals have the right to be informed about the collection and use of their Personal Data
Right of access Individuals have the right to receive a copy of their Personal Data, and other supplementary information
Right to rectification Individuals have the right to have inaccurate Personal Data rectified or completed if it is incomplete
Right to erasure Individuals have the right to request their personal information to be erased, in certain circumstances
Right to restrict processing Individuals have the right to request the restriction or suppression of their Personal Data, in certain circumstances, in particular:
- if your data is not accurate;
- if your data has been used unlawfully but you do not want us to delete it;
- if your data is no longer needed, but you want us to keep it for use in legal claims; or
- if you have already asked us to stop using your data but you are waiting to receive confirmation from us as to whether we can comply with your request
Right to data portability Individuals have the right to obtain and reuse their Personal Data, in a machine-readable format, for their own purposes across different services, in certain circumstances
Right to object Individuals have the right to object to the processing of their Personal Data, in certain circumstances
Where we are using your Personal Data because it is in our legitimate interests to do so, you can object to us using it this way
Where we are using your Personal Data for direct marketing, including profiling for direct marketing purposes, you have an absolute right to ask us to stop doing so
Rights with respect to automated decision-making and profiling Individuals have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you

In addition to the above, you also have the following rights: 

Two Column Table
Rights Description
Right to withdraw consent Where we are using your Personal Data based on your consent, you can withdraw your consent at any time
Right to register a complaint with the Controller You have the right to register a complaint with the Controller if you feel we are not processing your Personal Data in accordance with this notice or data protection law
Right to lodge a complaint with a supervisory authority You have the right to raise a complaint about how we handle your personal information with a relevant supervisory authority

Exercising your data protection rights 

You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances. 

 

Contact us 

If you would like to exercise your statutory data protection rights, or if you have any concerns or questions about how we handle Personal Data, please complete the complaints form provided here

 

Raising a complaint with the Information Commissioner’s Office 

If you believe you have exhausted all possible avenues for resolving your data protection concerns, you may lodge a complaint with the ICO by calling their Helpline on 0303 123 1113. 

You can also send your postal correspondence to: The Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. 

Alternatively, you can contact them at https://ico.org.uk/make-a-complaint/

   

Cookie Policy

Last updated: 22nd December 2025 

1. Introduction 

XM.WORKS Ltd (“XM.WORKS”, “we”, “us”, “our”) use cookies on our website. This Cookies Notice explains more about cookies and why we use them. It also explains how you can control and opt out of receiving them. 

This policy should be read together with our Privacy Notice which sets out how and why we collect, store, use and share personal information generally, as well as your rights in relation to your personal information and details of how to contact us and the supervisory authorities if you have a complaint. 

We update this Cookies Notice from time to time in response to changes in applicable laws and regulations, changes to our processing practices and to the products and services we offer. When changes are made, we will update the ‘last updated’ date at the top of this notice. Please review this Cookies Notice periodically to check for updates. 

2. About Cookies  

A cookie is a small text file which may be downloaded to your device when you visit our website. We use cookies to allow our website to function correctly, remember your preferences and to track visitors to our website. 

The cookies we use on our website fall into the following categories: 

  • Strictly Necessary / Essential - Strictly necessary, or essential, cookies are vital for a website to perform its basic functions and provide a service explicitly requested by the user. Without them, the website would not work correctly. 

  • Statistics or Analytics Cookies - We use cookies to collect information about the use of our website by visitors, such as the pages they visit most often, how they arrived at our website and associated information. These do not collect any directly identifiable personal information about visitors.  We use these cookies to learn more about how our website is used to identify problems and areas for improvement. 

  • Functional Cookies - Functional cookies remember the choices you make when you visit our website. This includes, for example, your consent to the use of cookies on our website. 

  • Marketing or Targeting Cookies - These are cookies placed by third parties on our website which record your visit to our website, the pages you have visited and the links you have followed. They use this information for advertising purposes. 

  • Learn More About Cookies - For further information on our use of cookies, including a detailed list of your information which we and others may collect through cookies, please see details in the table below. For further information on cookies generally, including how to control and manage them, please visit www.aboutcookies.org or www.allaboutcookies.org.  

3. Cookies Used by XM.WORKS 

The cookies we use on our website and their purposes are as set out in the following table:  

Category Name Duration Description
Essential Crumb Session This cookie helps a website remember you as a visitor across different pages, preventing repeated security prompts, and it stops attackers from tricking your browser into performing unwanted actions (like changing passwords).
Essential _CFUVID Session This cookie prevents a single user from overwhelming a site with requests, even if they share an IP with others.
Essential _CF_BM 30 minutes This cookie is used to manage incoming traffic, identify bots, and provide security by preventing repeated challenges for legitimate users.
Functional SS_COOKIEALLOWED 1 year Its primary purpose is to record your consent choice regarding the placement of cookies on your browser.
Functional _HELP_CENTER_SESSION Session This cookie holds preferences and session settings for support management, and it will be deleted when the user closes the web browser.
Functional _GRECAPTCHA 6 months The _grecaptcha cookie is used for risk analysis and spam protection on website forms.
Analytics SS_MATTR 2 years The SS_MATTR cookie is used to identify a unique visitor to our website. It assigns a unique, anonymous ID to track user behaviour.
Analytics SS_MID 2 years The SS_MID cookie is used to identify unique visitors and tracks their session on our site.
Analytics SS_lastvisit 2 years The main purpose of the SS_lastvisit cookie is to help the site's analytics determine if a website visitor is a new or returning user.
Analytics SS_CID 2 years This cookie is used to calculate visitor, session, and campaign data for website analytics, such as traffic sources and popular pages.
Analytics SS_CPVISIT 2 years This cookie is used to identify unique visitors and tracks their session on our site.
Analytics SS_CVR 2 years This cookie works alongside other cookies to identify unique visitors and tracks their session on our site.
Analytics SS_CVT 30 minutes This cookie is used to identify unique visitors and track their session activity (like page views) on our website. This helps us to better understand user behaviour for site improvement.
Analytics USER_SEGMENT 1 year This cookie is used to anonymously group users into different categories or segments for internal analysis, website optimization, and more efficient advertisement.

4. Cookie Sharing with Third Parties 

We do not share the information collected by the cookies with third parties for the purposes of targeted advertising.  

 

5. Changing Your Cookies Preferences 

You can allow or block cookies by activating the setting on your browser that permits you to change the setting of all or some cookies. Please note that disabling cookies may affect the availability or functionality of our website. Most of the website will function normally, however, functions that rely on cookies may be disabled. 

If you would like more information on how to manage cookies on some popular browsers, please click on the links below. 

 

6. Contact Us 

Please contact us using the details set out in our Privacy Notice if you have any questions about this Cookies Notice or the information we hold about you.