Privacy Notice
Last updated: June 2026
1. Who we are
Xirtam ("we", "us") is a product operated by Eran Kolran ("the Seller"), acting as the data controller for personal data processed in connection with the Xirtam website and product. References to "you" mean the user of the website or product.
2. Personal data we collect
- Account data: name, email address, login credentials, language preference.
- Support data: messages, attachments, and any information you provide when contacting us.
- Usage and telemetry data: product feature usage, error reports, performance diagnostics.
- Device data: IP address, browser type, operating system, device identifiers.
- Order data: purchase records, license entitlements, plan history (payment instruments are collected and held by Paddle, not by us).
3. Purposes and legal basis
- Creating and managing your account and license — performance of contract.
- Providing, securing, and improving the Xirtam product — legitimate interests.
- Fraud prevention and protecting our service — legitimate interests.
- Customer support and responding to your requests — performance of contract.
- Sending service announcements and, where required, marketing — legitimate interests or consent.
- Complying with legal, tax, and accounting obligations — legal obligation.
4. Data sharing
We share personal data with:
- Paddle.com Market Ltd ("Paddle") — Merchant of Record. Paddle handles checkout, payments, subscription management, tax compliance, and invoicing on our behalf. Paddle's privacy notice is available at paddle.com/legal/privacy.
- Service providers / subprocessors — hosting, analytics, error monitoring, customer support tooling.
- Professional advisers — legal, accounting, and tax advisers, under confidentiality.
- Authorities — where we are required to do so by applicable law.
5. International transfers
Where personal data is transferred outside your jurisdiction (including outside the UK/EEA), we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions issued by the relevant authority.
6. Retention
We keep personal data only as long as necessary for the purposes set out above, to comply with legal obligations (e.g. tax retention), or to resolve disputes. When no longer needed, data is deleted or anonymised.
7. Your rights
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or port your personal data; to object to processing; and to withdraw consent at any time. UK/EEA users additionally have the right to lodge a complaint with their local supervisory authority. We aim to respond to verified requests within one month.
8. Security
We use appropriate technical and organisational measures — including encryption in transit, access controls, and least-privilege administration — to protect personal data against unauthorised access, loss, or alteration.
9. Cookies
The website uses strictly necessary cookies to operate the site and remember your preferences. We may use analytics cookies to understand aggregate usage. You can manage cookies through your browser settings.
10. Contact
For privacy questions or to exercise your rights, contact Eran Kolran via the contact options on this website.
