X-TENDS S.A.L. ("X-TENDS", "we", "us", or "our") respects your privacy and is committed to handling personal data responsibly, securely, and transparently.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit our website, contact us, request a demonstration, communicate with us, apply for a role, interact with a public product demonstration, or otherwise engage directly with X-TENDS.
It also explains the important distinction between data X-TENDS processes for its own website and business activities, and data processed through X-TENDS technology when our products are deployed by banks, financial institutions, or other enterprise customers.
1. Who We Are
X-TENDS is a technology company providing software, artificial intelligence solutions, consulting services, and digital platforms, including solutions designed for banks and financial institutions.
For personal data collected directly through the X-TENDS website or through direct business interactions with X-TENDS, X-TENDS will generally act as the data controller or equivalent responsible party under applicable privacy law.
Our registered details are:
- X-TENDS S.A.L.
- Registered address: [Insert registered address, Lebanon]
- Privacy contact: [privacy@x-tends.com]
- General contact: [info@x-tends.com]
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed by X-TENDS in connection with:
- the X-TENDS corporate website and its pages;
- contact, partnership, sales, and "Request a Demo" forms;
- business communications with prospects, customers, partners, and suppliers;
- public or pre-sales demonstrations made available directly by X-TENDS;
- events, newsletters, and marketing communications where used;
- recruitment and employment applications submitted to X-TENDS; and
- security, technical, and operational logs generated when you use our digital services.
This Policy does not replace the privacy notice of a bank, financial institution, or enterprise customer that provides an X-TENDS-powered product to its own users. Please see Section 8 for this distinction.
3. What Personal Data We May Collect
The personal data we collect depends on how you interact with us. It may include the following categories.
| Category | Examples |
|---|---|
| Contact and identity data | Name, business email, phone number, job title, company, country, and information you choose to provide. |
| Business inquiry data | Demo requests, product interests, project requirements, tender or partnership information, and correspondence with us. |
| Technical and usage data | IP address, browser type, device type, operating system, timestamps, page interactions, referral information, and security logs. |
| Cookie and analytics data | Cookie identifiers, session information, preferences, and website analytics where such tools are enabled. |
| AI interaction data | Prompts, messages, feedback, and related session information entered into a public or X-TENDS-operated demonstration. |
| Recruitment data | CV, employment history, education, contact information, interview notes, and information provided during a recruitment process. |
| Supplier and partner data | Business contact details, contractual communications, invoices, and relationship-management information. |
We aim to collect only personal data that is reasonably necessary for the relevant purpose.
4. Information You Should Not Submit Through General Website Forms
Our general website forms are not intended for highly sensitive banking or authentication information. Unless a specific secure workflow expressly requires it, please do not submit:
- passwords, PINs, OTP codes, security answers, or authentication secrets;
- full payment-card details;
- full bank account credentials or online-banking credentials;
- national identification numbers or copies of identity documents;
- confidential customer banking data belonging to you or another person; or
- confidential information belonging to a bank, employer, customer, or third party that you are not authorized to disclose.
If a public NOOR or other AI demonstration is available, use sample or non-sensitive information unless the interface clearly states that the environment has been approved for real data.
5. How We Collect Personal Data
We may collect personal data:
- directly from you when you submit a form, send an email, request a demo, attend a meeting, or communicate with us;
- automatically through website, device, security, and cookie technologies;
- from your employer or organization when it introduces you as a business contact;
- from partners, resellers, event organizers, or professional networks where permitted by law; and
- from publicly available professional sources where relevant to legitimate business development and permitted by applicable law.
6. How We Use Personal Data
We may use personal data for the following purposes:
- to operate, maintain, secure, and improve our website;
- to respond to inquiries and provide requested information;
- to arrange demonstrations, meetings, proposals, pilots, and commercial discussions;
- to manage customer, partner, supplier, and professional relationships;
- to provide technical support and investigate service or security issues;
- to operate public demonstrations and evaluate product quality and user feedback;
- to understand website usage and improve user experience;
- to send relevant business or marketing communications where permitted;
- to manage recruitment and evaluate candidates;
- to comply with legal, regulatory, audit, security, and contractual obligations; and
- to establish, exercise, or defend legal claims and protect X-TENDS, its customers, and users from misuse or fraud.
7. Legal Bases for Processing
Where applicable law requires us to identify a legal basis for processing, including under the EU General Data Protection Regulation (GDPR), we rely on one or more of the following:
- Consent - where you have clearly agreed to a specific use, such as certain optional cookies or marketing communications.
- Contract or steps before a contract - where processing is necessary to respond to a request, provide a service, manage a commercial relationship, or take steps requested before entering into an agreement.
- Legitimate interests - where necessary for reasonable business purposes such as operating and securing our website, business-to-business communications, improving products, preventing misuse, and managing relationships, provided those interests are not overridden by your rights.
- Legal obligation - where processing is necessary to comply with applicable law, regulation, court order, audit, or other binding requirement.
- Other lawful bases - where a regional privacy law provides another valid basis for processing.
Where special-category, sensitive, financial, biometric, or other protected personal data is processed, we apply any additional legal conditions required by the applicable jurisdiction.
8. NOOR, Bank Deployments and Customer Banking Data
X-TENDS provides technology that may be deployed by banks and financial institutions. In those deployments, the bank or financial institution will normally determine why and how its customer data is processed and will typically act as the controller or equivalent responsible party. X-TENDS may act as a processor, service provider, technology provider, or other role defined by the applicable contract and law.
Certain X-TENDS deployments are designed to operate inside customer-controlled infrastructure, including on-premises environments. Depending on the agreed architecture and configuration, production banking data may remain within the customer's environment and X-TENDS may have limited or no routine access to that data.
The exact data flows, hosting model, retention rules, security controls, approved subprocessors, and responsibilities are determined by the relevant customer agreement and implementation.
If you are using NOOR or another X-TENDS-powered service through your bank, you should normally direct privacy requests concerning your banking data to that bank. We will support our enterprise customers with such requests where required by contract or law.
9. Artificial Intelligence Interactions
Some X-TENDS products and demonstrations use artificial intelligence to understand requests, generate responses, classify intents, retrieve information, produce insights, or support workflows.
When X-TENDS directly operates an AI demonstration, we may process the content you enter, associated session information, and feedback for purposes such as providing the demonstration, maintaining security, evaluating performance, troubleshooting, and improving the product, subject to applicable law and the configuration of that environment.
Do not enter real banking credentials or unnecessary sensitive personal data into a public demonstration. Where a demonstration is operated on behalf of a bank or another customer, that customer's privacy notice and contractual configuration may apply.
10. Automated Decision-Making and Profiling
The X-TENDS corporate website is not intended to make decisions about individuals that produce legal or similarly significant effects solely through automated processing.
X-TENDS products may generate automated classifications, financial insights, risk indicators, recommendations, or other decision-support outputs depending on the customer implementation. Such outputs are intended to support the relevant bank or enterprise workflow. Where applicable law grants rights relating to automated decision-making or profiling, those rights will be respected by the responsible controller.
A regulated financial decision, such as final credit approval or another legally significant determination, remains subject to the relevant financial institution's policies, controls, and legal obligations unless a different lawful arrangement is expressly established.
12. Marketing Communications
We may send business communications about X-TENDS products, services, events, or developments where we have a lawful basis to do so. Where consent is required, we will request it before sending such communications.
You may unsubscribe from marketing communications at any time using the unsubscribe option provided in the message or by contacting us. We may still send non-marketing messages that are necessary for an active business relationship, security matter, or service request.
14. International Transfers and Data Location
X-TENDS is established in Lebanon and may work with customers, partners, personnel, and service providers in multiple countries. Personal data may therefore be processed in a country different from the country in which it was originally collected, where permitted by applicable law.
Where European data protection law applies to a transfer outside the European Economic Area, we will use an available lawful transfer mechanism where required, such as an adequacy decision, appropriate contractual safeguards, or another legally recognized mechanism.
Where Middle Eastern jurisdictions impose data-localization or cross-border transfer requirements, we will apply the relevant requirements to the applicable processing activity and customer implementation.
For enterprise deployments, data location and cross-border processing are also governed by the relevant implementation architecture and customer contract.
15. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal, regulatory, contractual, accounting, security, and dispute-resolution requirements.
The retention period may vary depending on the type of data and relationship. We consider factors such as:
- whether the information is needed to provide or support an active service or business relationship;
- the sensitivity and volume of the data;
- security, fraud-prevention, and audit needs;
- applicable limitation periods and legal obligations; and
- whether the data can be safely anonymized instead of retained in identifiable form.
Enterprise customer data is retained in accordance with the applicable customer agreement, deployment configuration, and instructions of the responsible controller.
16. Information Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction. Measures may include access controls, authentication, logging, encryption or secure transmission where appropriate, environment segregation, vulnerability management, backup controls, and security monitoring.
No system or transmission method can be guaranteed to be completely secure. Users are also responsible for protecting their own devices, accounts, credentials, and communications.
If you believe you have identified a security vulnerability, please contact [security@x-tends.com] and avoid publicly disclosing the issue until we have had a reasonable opportunity to investigate it.
17. Personal Data Breaches
If X-TENDS becomes aware of a personal data breach affecting data for which we are responsible, we will assess the incident, take reasonable containment and remediation steps, and make notifications to customers, authorities, or affected individuals where required by applicable law or contract.
Where X-TENDS processes data on behalf of an enterprise customer, we will handle breach notification and cooperation in accordance with the applicable data-processing agreement and legal requirements.
18. Your Privacy Rights
Depending on the law that applies to you and the circumstances of the processing, you may have rights such as:
- the right to receive information about how your personal data is processed;
- the right to request access to personal data held about you;
- the right to request correction of inaccurate or incomplete data;
- the right to request deletion or erasure in applicable circumstances;
- the right to request restriction or suspension of certain processing;
- the right to object to certain processing, including certain direct marketing;
- the right to withdraw consent where processing is based on consent;
- the right to receive or transfer certain personal data in a portable format where applicable;
- rights relating to certain automated decisions or profiling where applicable; and
- the right to complain to an appropriate data protection or supervisory authority.
These rights are not absolute and may be subject to legal exceptions, identity verification, and the specific law applicable to the processing.
19. Regional Privacy Frameworks
X-TENDS is based in Lebanon and may provide services across the Middle East and Europe. Depending on the relevant processing activity, applicable privacy frameworks may include, among others:
- Lebanon - Law No. 81/2018 concerning electronic transactions and personal data;
- European Union and European Economic Area - Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR);
- United Kingdom - the UK GDPR and Data Protection Act 2018, where applicable;
- Kingdom of Saudi Arabia - the Personal Data Protection Law and its implementing regulations, where applicable;
- United Arab Emirates - Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data, where applicable; and
- other national or sector-specific privacy, banking, cybersecurity, and data-residency laws that apply to a specific customer, user, or deployment.
This section is not intended to be an exhaustive list of every law that may apply. Mandatory local legal requirements prevail where they provide additional or different protections.
20. How to Exercise Your Rights
For personal data collected directly by X-TENDS through our website or business activities, you may submit a privacy request to [privacy@x-tends.com].
We may need to verify your identity before completing a request. We may also ask for information necessary to identify the relevant records and understand your request.
If your request relates to personal or banking data processed through a bank's deployment of NOOR or another X-TENDS product, please contact the bank or enterprise that provided the service. Where X-TENDS acts on behalf of that organization, we will assist it as required.
21. Children and Minors
The X-TENDS corporate website is primarily intended for business and professional audiences and is not directed to children.
We do not knowingly seek to collect personal data from children through general website forms. If a product deployment is intended to support minors or child-related banking products, the relevant bank or enterprise must implement the appropriate consent, authorization, age-verification, and safeguarding requirements under applicable law.
22. Recruitment
If you apply for a role with X-TENDS, we may process the information you provide to evaluate your application, communicate with you, conduct interviews and reference checks where appropriate, maintain recruitment records, and meet legal or compliance obligations.
We may retain recruitment information for a reasonable period after the process ends, taking into account applicable employment and privacy law and whether you have agreed to be considered for future roles.
23. Third-Party Websites and Services
Our website may contain links to third-party websites, social networks, technology providers, or other services. Their privacy practices are governed by their own notices and are not controlled by this Privacy Policy.
We encourage you to review the privacy information of any third-party service before providing personal data to it.
24. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our products, website, data practices, security requirements, or applicable law.
When we make a material update, we will revise the "Last Updated" date and provide any additional notice required by law. We encourage you to review this Policy periodically.
25. Contact and Complaints
Questions, requests, or complaints concerning this Privacy Policy or X-TENDS' handling of personal data may be directed to:
- X-TENDS S.A.L.
- Address: [Insert registered address, Lebanon]
- Privacy email: [privacy@x-tends.com]
- Security reports: [security@x-tends.com]
- Data Protection Officer, if appointed: [Name / contact]
- EU/EEA representative, if legally required: [Representative / contact]
You may also have the right to raise a complaint with the data protection, privacy, or supervisory authority responsible for your jurisdiction.