Privacy Policy
Last reviewed & updated: September 2026
Last reviewed & updated: September 2026
About this Policy
This Privacy Policy explains how EXA Infrastructure ("EXA Infrastructure", "we", "us" or "our") handles personal data when acting as a controller. It applies to customers and prospective customers, suppliers and business partners, website and portal users, event attendees, and other people who interact with EXA Infrastructure in a business context.
"Personal data" means information relating to an identified or identifiable individual. "Applicable Data Protection Law" means the data protection and privacy laws applying to our processing, including, where relevant, the EU General Data Protection Regulation, the UK General Data Protection Regulation and the UK Data Protection Act 2018, as amended or replaced.
This Policy does not govern personal data processed by EXA Infrastructure solely on a customer's behalf as a processor. That processing is governed by the relevant customer agreement and data processing addendum. Separate notices may apply to employees, candidates or particular services and events.
Introduction & Company Profile
The controller is the EXA Infrastructure legal entity that determines why and how your personal data is processed, usually the entity with which you contract or interact.
Our principal privacy contact address is:
EXA Infrastructure
40 Strand
5th Floor
London WC2N 5RW
Email: legal@exainfra.net
Personal Data we collect
Depending on your relationship with EXA Infrastructure and how you use our websites, portals, products and services, we may collect:
- Identity and business contact data, including name, job title, employer, address, telephone number and email address
- Account and authentication data, including usernames, account identifiers, permissions and authentication information
- Commercial and service data, including enquiries, proposals, orders, contracts, service details, account history and customer-support communications
- Billing and transaction data, including billing contacts, invoices, payment status and payment or credit information where relevant
- Technical and usage data, including IP address, browser and device information, logs, referring pages, approximate location derived from IP address, timestamps and interactions with our websites or portals
- Marketing and preference data, including communication preferences, subscriptions, event attendance, campaign interactions and feedback
- Security and access data, including visitor records, building-access records, CCTV images where used, security logs and incident information
- Compliance and due-diligence data required for sanctions screening, anti-bribery checks, fraud prevention, conflict checks or regulatory compliance
- Other information you choose to provide when corresponding with us
- Site regulatory data that is required by in-country regulators and authorities that is part of our operating licence
We seek to avoid collecting special category personal data unless it is necessary and permitted by law. Where we process it, we apply appropriate safeguards.
How we collect personal data
- Directly from you when you contact us, request information, negotiate or enter into an agreement, create an account, use a service, attend an event, complete a survey or exercise a privacy right
- From your organisation, colleagues, advisers or others involved in the business relationship
- Automatically through websites, portals, network and security systems, cookies and similar technologies
- From EXA Infrastructure group companies and service providers supporting our operations
- From public sources and lawful third-party sources, including company websites, professional networks, corporate registers, marketing partners, credit-reference providers and compliance databases
Purposes and lawful bases
We process personal data only where we have a lawful basis. The applicable basis depends on the purpose and context.
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide and manage services | Account set-up, provisioning, support, billing, changes and termination. | Contract; legitimate interests |
| Manage business relationships | Enquiries, proposals, contracts, supplier and partner management. | Contract; legitimate interests |
| Operate and improve our business | Service quality, analytics, research, product development and reporting. | Legitimate interests |
| Protect systems, sites and services | Access control, monitoring, incident response, fraud prevention and continuity. | Legitimate interests; legal obligation |
| Comply with law and protect rights | Regulatory requests, screening, tax, accounting, disputes, audits and investigations. | Legal obligation; legitimate interests |
| Communicate and market | News, events, surveys and relevant product or service communications. | Consent where required; legitimate interests |
| Manage corporate transactions | Due diligence, reorganisation, financing, sale, merger or asset transfer. | Legitimate interests; legal obligation |
Cookies and similar technologies
Our websites and portals may use cookies and similar technologies to operate, secure and improve digital services and, where permitted, support analytics or marketing. Non-essential cookies are used only as permitted by applicable law.
See the EXA Infrastructure Cookie Policy.
Sharing personal data
Where necessary and lawful, we may share personal data with:
- EXA Infrastructure group companies involved in providing services, operating shared systems or supporting corporate functions
- Service providers and subcontractors supporting hosting, cloud, communications, security, professional services, billing, support, marketing, analytics or events
- Banks, payment providers, credit-reference or debt-recovery organisations, where relevant
- Professional advisers, auditors and insurers
- Regulators, courts, law-enforcement agencies, tax authorities and other public bodies where disclosure is required or permitted by law
- Actual or prospective purchasers, investors, lenders or advisers in connection with a corporate transaction, subject to appropriate confidentiality protections
- Other parties where you request disclosure or give valid consent
We require service providers processing personal data for us to protect it and use it only for agreed purposes and comply with applicable contractual and legal requirements.
International Transfers
EXA Infrastructure operates internationally and may transfer personal data outside the country in which it was collected. Where Applicable Data Protection Law restricts a transfer, we use an approved mechanism, such as an adequacy decision, approved standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, or another lawful safeguard. We assess and apply supplementary measures where required.
You may request further information about the applicable safeguard by contacting us. Any copy provided may be redacted to protect confidential or commercially sensitive information.
Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide services, meet legal, tax, accounting and regulatory requirements, establish or defend legal claims, resolve disputes and enforce agreements. When data is no longer required, we delete or anonymise it. Where immediate deletion from backup systems is not practicable, we securely isolate it from further use until deletion through the normal backup cycle.
Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Data protection and cyber controls include:
- All laptops and devices are maintained with FDE (Full disk encryption)
- Classified data is encrypted in transit
- Data on media is erased or destroyed using secure disposal methods
- Data classification is deployed to ensure protection is provided safeguard information from unauthorised usage or transport
To ensure the protection of sensitive data encryption technologies are applied as necessary:
Strong encryption mechanisms are used for external access to the network systems which includes VPN access.
- AES256 with SHA-256
- RSA and Diffie-Hellman for key exchange
Further encryption protocols will be used only on internal networks, as necessary to ensure appropriate security controls based on technologies deployed or architecture deployments. EXA Infrastructure's policy is not to use bespoke non-repudiation encryption but only standard industry encryption standards.
However, no method of transmission or storage is completely secure. If you believe your interaction with EXA Infrastructure or your account is no longer secure, please contact us promptly.
Your rights
Depending on the law that applies and subject to legal conditions and exemptions, you may have the right to:
- be informed about how your personal data is used
- request access to your personal data and obtain a copy
- request correction of inaccurate or incomplete personal data
- request deletion or restriction of processing
- object to processing, including direct marketing and certain processing based on legitimate interests
- receive eligible personal data in a structured, commonly used and machine-readable format and transmit it to another controller
- withdraw consent at any time where processing is based on consent, without affecting prior lawful processing
- not be subject to certain decisions based solely on automated processing; and
- complain to a competent data protection supervisory authority
To exercise a right, email legal@exainfra.net. Please describe your request and relationship with EXA Infrastructure. We may request information reasonably necessary to verify identity and authority. We will respond within the period required by applicable law and explain if an exemption or extension applies.
Marketing choices
You can opt out of electronic marketing using the unsubscribe link in a marketing message or by contacting us. We may still send non-marketing communications needed to administer an account, provide contracted services, communicate important service or security information, or comply with legal obligations.
Children's data
EXA's business services and websites are not directed at children. We do not knowingly seek to collect personal data from children through our general business websites. If you believe a child has provided personal data to EXA Infrastructure inappropriately, please contact us.
Complaints
Please contact our Legal and Compliance team first if you have a concern. We will investigate and respond in accordance with applicable law. You may also complain to the competent supervisory authority in your country.
For the UK - Information Commissioner's Office
For Europe - Our members | European Data Protection Board
Changes to this Policy
We may update this Policy to reflect changes in law, our activities or our processing practices. The current version is published on our website and is effective 15/09/26. Where appropriate, we will provide additional notice of material changes.
Contact us
Legal And Compliance Team
EXA Infrastructure
40 Strand
5th Floor
London WC2N 5RW
Email: legal@exainfra.net