Official Legal Policy • Data Governance

Privacy Policy

Last updated: 14 September 2026
"Business intelligence requires trust. Trust requires responsible handling of information."
Compliance Docs Prompts Guide

1. Introduction

INXA Partnership ("INXA", "we", "us", or "our") provides an AI-powered environment designed to facilitate trusted business relationships, partnership development, negotiation, agreement management and related business workflows.

This Privacy Policy explains how INXA collects, uses, stores, processes and protects information when you access or use the INXA Partnership service, including associated websites, applications, AI Agent functionality, partnership workspaces and related services.

INXA is designed around a simple principle: "Business intelligence requires trust. Trust requires responsible handling of information."

We therefore seek to collect only the information reasonably necessary to provide, secure and improve the service and to maintain the integrity of business relationships conducted through the platform.

2. Scope

This Privacy Policy applies to information processed through:

  • INXA Partnership and related web services
  • partnership workspaces
  • XCircle access mechanisms
  • INXA AI+ Agent interactions
  • business identity and VCard information used within the service
  • partnership proposals and negotiations
  • agreements and associated records
  • electronic-signature workflows
  • audit and integrity records
  • communications with INXA
  • related INXA services where this Privacy Policy is expressly referenced

This Policy does not automatically apply to third-party websites, applications or services that may be accessed through links or integrations from INXA.

3. Information We May Process

Depending on how you use INXA, we may process different categories of information.

3.1 Account and access information

This may include:

  • name
  • business role
  • company name
  • professional contact information
  • login or authentication information
  • XCircle Token or equivalent access credentials
  • technical identifiers
  • account preferences
  • access and security logs
Where technically possible, access credentials are designed to identify the relevant session or authorization without unnecessarily exposing personal information.

4. Business Identity and VCard Information

INXA may process business identity information supplied by users or made available through integrated trust services. This may include:

  • company information
  • professional identity
  • business contact details
  • role and authority
  • VCard information
  • Shartify Trust Rank or related trust indicators
  • business credentials or verification information
  • information concerning authorized representatives

The purpose is to help establish a trusted business context before parties engage in partnership or commercial activities.

INXA does not consider a Trust Rank to be a general-purpose assessment of a person's personal worth or character. Trust-related information is used in the context in which it is generated and for the purposes described by the applicable service.

5. Verification and KYC Information

Certain partnership activities may require verification of a business or authorized representative.

Where verification or KYC information is processed, the information may include business registration details, representative information and other documentation required by the applicable verification process.

Where such verification is performed by an independent third-party provider, that provider may process personal information under its own privacy terms.

INXA seeks to limit the information retained by the platform to what is reasonably necessary for verification, compliance, security, auditability and the operation of the service.

6. Partnership Information

When you create or participate in a partnership, INXA may process information such as:

  • partnership objectives
  • proposals
  • commercial terms
  • business requirements
  • counterparties
  • negotiation parameters
  • messages and communications
  • documents
  • milestones
  • deadlines
  • deliverables
  • approvals
  • amendments
  • partnership status
  • execution information

This information is necessary to provide the partnership-management functionality of INXA.

7. AI Agent Information

INXA AI+ Agents may process information provided by participating users or generated during the partnership lifecycle. This may include:

  • instructions provided to an Agent
  • business objectives
  • negotiation parameters
  • delegated authority
  • permitted actions
  • restrictions
  • approval thresholds
  • proposals and counter-proposals
  • relevant documents
  • partnership context
  • workflow information
  • outputs generated by the Agent

AI Agents are designed to operate within the authority and instructions established by the relevant participant.

Where an action requires human approval, the Agent may stop the workflow and request authorization rather than independently committing the participant.

8. Delegated Business Authority

INXA may process information defining what an AI Agent is authorized to do on behalf of a participant. This may include:

  • financial limits
  • negotiation boundaries
  • commercial conditions
  • permitted modifications
  • approval thresholds
  • restricted subjects
  • escalation requirements

This information is particularly important because it determines the operational boundaries within which an AI Agent may act. Authority information may therefore be retained as part of the partnership record and associated audit trail.

9. Negotiation and Agreement Data

INXA may retain information generated during the negotiation process, including: original proposals, counter-proposals, accepted and rejected terms, versions of documents, negotiation events, approval events, timestamps, participant identities, and final agreed terms.

This information supports transparency, traceability and the ability to reconstruct the history of a partnership.

10. Electronic Signature and Agreement Execution

Where electronic-signature functionality is provided directly by INXA or through a third-party provider, INXA may process information necessary to facilitate the signature process, including signer identity, signature status, timestamps, agreement versions, authentication information, execution events, and technical evidence associated with the signing process.

Third-party electronic-signature providers may process information according to their own contractual and privacy terms.

11. Cryptographic Audit Records

INXA may create cryptographic records associated with partnership documents, versions and events. These records may include: cryptographic hashes, timestamps, document/version identifiers, event identifiers, and transaction or workflow references.

Cryptographic records are intended to support integrity and tamper-evidence. A cryptographic hash does not itself reveal the underlying document content.

Where cryptographic records are designed to remain part of an audit history, they may not be technically or operationally equivalent to ordinary editable account data and may therefore be subject to different deletion or modification constraints.

12. How We Use Information

We may process information to:

1 provide and operate INXA Partnership;
2 establish and maintain business identities;
3 facilitate trusted interactions between counterparties;
4 operate AI Agent workflows;
5 apply delegated authority rules;
6 facilitate proposals and negotiations;
7 manage partnership agreements;
8 facilitate electronic signing;
9 maintain audit and integrity records;
10 detect fraud, abuse and unauthorized activity;
11 maintain platform security;
12 comply with applicable legal obligations;
13 provide customer and technical support;
14 improve reliability and performance;
15 develop and improve INXA services, subject to applicable law and contractual restrictions.

INXA does not use personal information for purposes incompatible with the purposes for which it was collected.

13. AI Processing

INXA uses artificial intelligence as part of its service. Depending on the functionality used, information may be processed by AI systems to: understand business instructions, structure partnership requirements, draft documents, summarize information, identify relevant terms, generate proposals and counter-proposals, support negotiation, identify workflow events, and prepare suggested actions.

AI-generated content may contain errors and should be reviewed by an appropriately authorized human before consequential decisions are made.

INXA is designed to distinguish between AI-generated suggestions and authorized business decisions.

An AI Agent does not automatically receive unrestricted authority to commit a participant merely because information has been processed by an AI system.

14. AI Training

INXA does not sell personal information to AI providers or advertisers.

Personal or confidential business information processed through INXA is not automatically made publicly available for the purpose of training general-purpose AI models.

Where third-party AI infrastructure is used, applicable contractual and technical controls may govern how submitted information is processed.

Where INXA uses information for model improvement, analytics or service development, such processing will be subject to applicable law, contractual commitments and the configuration of the relevant service.

15. Legal Bases for Processing

Where applicable data-protection law requires a legal basis for processing personal information, INXA may rely on one or more of the following: performance of a contract; taking steps at the request of the user before entering into a contract; legitimate interests; compliance with legal obligations; and consent, where consent is required or appropriate.

The applicable legal basis may depend on the nature of the information and the specific activity.

16. Data Sharing

INXA may share information where reasonably necessary to operate the service. Recipients may include participating businesses and authorized counterparties; service providers supporting hosting and infrastructure; identity and verification providers; electronic-signature providers; AI infrastructure providers; security and fraud-prevention providers; professional advisers; and legal authorities where legally required.

INXA does not sell personal information as a commercial data product.

Information shared with a counterparty as part of a partnership is shared because the relevant business relationship requires it or because the participant has authorized the disclosure. Users should therefore avoid placing unnecessary personal or confidential information into fields intended for counterparties.

17. Business-to-Business Information

INXA is primarily designed for professional and business interactions. Users may encounter information relating to other companies, representatives, suppliers, customers or partners.

Users are responsible for ensuring that information they submit to INXA is lawfully collected and that they have an appropriate basis or authorization to provide it.

Where a participant acts on behalf of a company, that participant is responsible for ensuring that they have the necessary authority to provide information and initiate a partnership.

18. International Data Transfers

INXA may operate through infrastructure and service providers located in different countries. As a result, information may be transferred across borders.

Where applicable law imposes requirements on international transfers, INXA will seek to use appropriate safeguards, which may include contractual safeguards, recognized transfer mechanisms, adequacy decisions, technical and organizational measures, or other legally recognized mechanisms.

The safeguards applied may depend on the countries involved and the nature of the processing.

19. Data Security

INXA applies technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, destruction, loss, or misuse.

Security measures may include access controls, authentication, encryption where appropriate, logging, infrastructure security and cryptographic integrity mechanisms.

No internet-based system can guarantee absolute security. Users are responsible for protecting their own credentials and for notifying INXA of suspected unauthorized access.

20. Data Retention

INXA retains information for as long as reasonably necessary for the purposes for which it was collected. Retention periods may depend on the nature of the information, partnership status, contractual requirements, legal obligations, accounting/compliance, dispute resolution, security, and audit requirements.

Agreement and audit records may need to be retained for longer periods than ordinary account information.

Where information is no longer required, INXA seeks to delete, anonymize or securely dispose of it, subject to applicable legal and technical constraints.

21. Your Rights

Depending on your jurisdiction, you may have rights concerning your personal information, including the right to access, rectify, delete, restrict processing, object to processing, request data portability, withdraw consent, or lodge a complaint with a competent data-protection authority.

Some rights are subject to legal exceptions. For example, information necessary to maintain legal records, comply with legal obligations, prevent fraud or preserve the integrity of a transaction may not be immediately deletable.

22. Automated Decision-Making

INXA may use automated systems and AI to support business workflows. Where automated processing produces legally significant effects concerning an individual, INXA will apply required safeguards.

INXA's Agentic architecture is designed around delegated authority and escalation rather than unrestricted autonomous decision-making. Where appropriate, users may be required to provide human authorization before consequential actions are completed.

23. Cookies and Technical Technologies

INXA may use cookies, local storage, session identifiers and similar technologies necessary to maintain sessions, authenticate users, protect the service, remember preferences, measure technical performance, detect abuse, and understand service usage.

Where non-essential cookies or similar technologies require consent under applicable law, the relevant consent mechanism will be provided.

24. Third-Party Services

INXA may integrate or interoperate with third-party services (authentication, verification, cloud infrastructure, AI, payments, electronic-signature, analytics and security).

Third-party services may have their own privacy policies and terms. INXA is not responsible for privacy practices outside its control.

25. Children's Privacy

INXA Partnership is designed for professional and business use. The service is not directed at children.

We do not knowingly seek to collect personal information from children where prohibited by applicable law. If you believe that a child has provided personal information to INXA improperly, please contact us.

26. Confidential Business Information

INXA may process commercially sensitive information. Users should consider carefully what information is necessary to provide to the platform and should use appropriate confidentiality arrangements when required.

The existence of a technical capability to process information does not mean that all information should be entered into an AI workflow.

Users remain responsible for determining whether particular information may legally or contractually be shared with INXA, an AI Agent or a counterparty.

27. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the service, technology, legal requirements, or our business practices.

The "Last updated" date at the top of this Policy indicates when it was most recently revised. Material changes may be communicated through the service or other appropriate means where required.

28. Contact

For questions concerning this Privacy Policy, privacy requests or data-protection matters, please contact:

INXA / INXA AI+

Privacy Contact

[email protected]

Where required by applicable law, additional information concerning the relevant data controller or representative will be provided.

29. Privacy by Design

INXA is being developed around the principle that trust should be part of the architecture rather than added after the product is built. Our approach includes:

Identity before interaction.
Authority before autonomous action.
Human approval for consequential decisions.
Integrity throughout the partnership lifecycle.
Controlled access to business information.
Traceability of relevant actions.
Security as an architectural requirement.

# TRUSTED AI FOR REAL BUSINESS.

INXA AI+ • Beyond the Prompt.

Trust. Authority. Intelligence. Partnership. Execution.