XPOSER.AI exists so that people can raise a concern safely. That promise is worth nothing if we are careless with the data those people entrust to us. This policy explains, in plain terms, what personal data we handle, why, who else ever sees it, how long we keep it, and what you can ask us to do about it. Where our answer differs depending on how you reach us — as a visitor to this website, or as someone using a reporting channel we host for an employer — we say so explicitly.
Who We Are & What This Covers
XPOSER.AI is a voice-first whistleblowing and compliance platform owned by AGITEKS. ("XPOSER.AI," "we," "us," "our"). In this policy, "personal data" means any information relating to an identified or identifiable natural person, and it carries the same meaning as "personal information" under the laws that use that term.
This policy applies to:
- This website (xposer.ai) and everything on it — browsing, demo requests, gated resource downloads, document requests and email correspondence.
- The XPOSER.AI platform — the voice and web intake channels, AI triage, case-management dashboards and follow-up messaging we host for enterprise customers.
It does not apply to the internal policies of the organisation that asked you to use a reporting channel, to third-party sites we link to, or to any product we do not operate. Our Terms & Conditions govern use of the platform itself; where a signed enterprise agreement or Data Processing Agreement exists, that agreement prevails over this policy for the data processed under it.
Controller Or Processor: The Two Roles We Play
This is the single most important distinction in this policy, because it determines who decides what happens to your data — and therefore who you should ask when you want something done about it.
- We are the controller for personal data we collect for our own purposes: visitors to this website, prospective and current customer contacts, people who request a demo or download a resource, applicants, and our own personnel. We decide why and how that data is processed, and this policy is the notice for it.
- We are a processor for personal data inside a customer's reporting channel — reports, voice recordings, transcripts, case files, follow-up messages and dashboard activity. The organisation that engaged us (typically an employer, in this policy the "Customer") is the controller. It decides what may be reported, who may read it, how long it is kept, and how requests from individuals are answered. We act only on that Customer's documented instructions.
What this means for you in practice. If you submitted a report through a channel your employer provided, we cannot grant you access to it, correct it, or delete it on our own initiative — doing so would breach both our contract and the confidentiality we owe to everyone else involved in that case. Send your request to the organisation that runs the channel. If you send it to us, we will pass it to them without undue delay and tell you that we have done so, unless doing so would itself risk revealing a reporter's identity.
Personal Data We Process
A. When you use this website (we are the controller).
- Contact and business details you give us — name, work email, phone number, organisation name, job context and anything you write into a message field when you request a demo, download a gated resource, ask us for a document, or email us.
- Your stated contact preference — whether you would rather we reach you by phone or by email.
- Technical data created by the request itself — IP address, user agent, and server log entries generated when your browser or our form endpoint is called. These are produced by the hosting infrastructure and used for security and abuse prevention.
We do not run advertising trackers, third-party analytics or social media pixels on this website. See Cookies & Local Storage for what we do use.
B. When you use a reporting channel we host (we are a processor).
- The content of the report — the audio you speak or the text you type, its transcript and translation, any file you attach, and the times and dates involved.
- Whatever identifying information you choose to give — your name, contact details, department or role. Where the Customer permits anonymous reporting, all of this is optional and may be left blank.
- Personal data about other people that a report necessarily contains — the person or people the report concerns, and any witnesses named. This may include allegations of criminal offences, and may touch on special-category data such as health, religion, political opinion, trade union membership or sexual orientation.
- Case-handling records — AI classification and severity scores with their supporting citations, assignments, comments, decisions, follow-up messages exchanged through the anonymous channel, and the immutable audit trail of who did what and when.
- Dashboard user accounts — the names, work emails, roles and sign-in and access logs of the Customer's case handlers and administrators.
Voice Recordings, Transcripts And AI Processing
Because our intake is voice-first, we are specific about what happens to a voice. When you speak a report, the audio is transcribed to text, translated where needed, and classified by AI models so that a human case handler receives a structured, prioritised case rather than a raw recording.
- We store no voiceprints and perform no voice matching. We do not generate a biometric template from your voice, and we do not attempt to identify a speaker by comparing audio against any other recording. We do not process voice as biometric data for the purpose of uniquely identifying you.
- Voice masking and transcript-only delivery are available where the Customer enables them. With transcript-only delivery, the underlying audio is not exposed to case handlers at all.
- A voice is still personal data. Even without a voiceprint, a recording can carry accent, language and speech patterns, and the words themselves may identify you. Treat what you say with the same care as what you would write.
- AI recommends; humans decide. Classification, severity and routing are decisions proposed by a model and reviewed by a person. We do not make decisions producing legal or similarly significant effects about you by automated means alone. Every classification carries the policy citations and reasoning behind it, and AI/human agreement is measured in periodic calibration reporting.
- We do not train models on one customer's data for the benefit of another. Report content is not used to train or fine-tune general-purpose models, and is not shared across tenants.
Why We Process Personal Data And Our Lawful Bases
Where we act as controller, we rely on the following bases under the EU and UK GDPR and, where applicable, the corresponding grounds under the Saudi Personal Data Protection Law (PDPL):
- To answer a demo request, deliver a resource or reply to you — performance of a contract or steps taken at your request, and our legitimate interest in responding to enquiries about our services.
- To send you occasional information about our services — your consent where it is required, or our legitimate interest in business-to-business communication. Every message carries an unsubscribe, and you can opt out at any time without affecting anything else.
- To keep the site and our systems secure and to prevent abuse — our legitimate interest in the integrity of the service, and compliance with legal obligations.
- To meet legal, tax, audit and regulatory obligations — compliance with a legal obligation.
Where we act as processor, the lawful basis is determined by the Customer, not by us. In a whistleblowing context a Customer will typically rely on its legal obligation to operate a reporting channel (for example under Directive (EU) 2019/1937, the Sarbanes-Oxley Act, or the SAMA Whistle Blowing Policy), on its legitimate interest in detecting and investigating misconduct, and — for the special-category data a report may contain — on the establishment, exercise or defence of legal claims or a substantial public interest ground. If you want to know the basis your organisation relies on, ask that organisation.
Anonymous Reporting And What We Deliberately Do Not Collect
Where a Customer enables anonymous reporting, the platform is built so that a report can be submitted, investigated and followed up on without anyone — including us — learning who sent it.
- Identity fields are optional and may be left empty.
- Two-way follow-up runs through a zero-knowledge channel keyed to a case credential held only by the reporter. XPOSER.AI administrators cannot link that channel to an identity.
- We do not require an account, and we do not fingerprint your device to re-identify you.
Anonymity has limits you should understand. Anonymity is not the same as untraceability. If you describe events only a handful of people witnessed, you may be identifiable from the content of the report no matter what the system does. If you report from a device or network your employer administers, that employer — not XPOSER.AI — may hold its own records of that activity. Where your Customer allows it, consider reporting from a personal device on a network outside your employer's control. Keep your case credential safe: if you lose it, the anonymous follow-up thread cannot be recovered, by design.
Confidentiality Of A Reporter's Identity
Where a reporter does identify themselves, that identity is treated as restricted data. It is disclosed only to the authorised people competent to receive and follow up on the report, and the same restriction covers any other information from which the reporter's identity could be directly or indirectly inferred — consistent with Article 16 of Directive (EU) 2019/1937.
We will not disclose a reporter's identity beyond that circle except where disclosure is a necessary and proportionate obligation imposed by law, for example in the context of an investigation by a national authority or judicial proceedings. Where the law permits us to do so and the Customer has not instructed otherwise, the reporter will be notified before any such disclosure, together with the reasons for it, unless that notification would jeopardise the related investigation or proceedings.
Rights Of Persons Named In A Report
If you are named in a report, you have data protection rights too — but they are exercised against the organisation running the channel, and they are balanced against the protection the law gives to the reporter.
- Your access request will not be used to unmask a reporter. Where responding in full would reveal, directly or indirectly, the identity of a person who made a report, that information may lawfully be withheld or redacted.
- Notification may be deferred. Informing a reported person while an investigation is live can allow evidence to be destroyed or a reporter to be retaliated against, so a Customer may lawfully delay that notification for as long as the risk persists.
- Everything else still applies. Subject to those limits, you retain the rights set out in Your Rights, including correction of inaccurate data and objection to processing.
Sharing, Subprocessors And Disclosure
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it only as follows:
- To the Customer whose reporting channel received the report — to the specific people that Customer has authorised as case handlers.
- To subprocessors who provide infrastructure under written contract: cloud hosting and storage, speech-to-text and classification models, and transactional email. Subprocessors act only on our instructions, are bound by confidentiality and security obligations no less protective than ours, and are engaged per hosting region. The current list is maintained on our Trust & Security page, and Customers under a Data Processing Agreement receive advance notice of changes with a right to object.
- To professional advisers — auditors, lawyers and insurers — where necessary and under a duty of confidence.
- To authorities where we are compelled by valid legal process. We assess every such demand, push back on those that are overbroad or defective, and where we are legally permitted we notify the affected Customer before responding so that it can seek to challenge the demand.
- In a corporate transaction — a merger, acquisition or asset sale — under confidentiality, with this policy continuing to apply to the transferred data until superseded by a notice at least as protective.
International Transfers And Data Residency
Regional hosting is available in Saudi Arabia, the United States, Canada and the European Union. Platform data resides in the region the Customer selects, and reports submitted into that tenant stay there in the ordinary course of the service.
Some processing is nevertheless cross-border: our own staff and certain subprocessors may access data from another country to provide support, security monitoring or maintenance. Where that happens, we rely on the transfer mechanisms the relevant law provides:
- From the EEA, the UK and Switzerland — an adequacy decision where one covers the destination, or otherwise the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where the UK GDPR applies), supported by a transfer impact assessment and technical measures including encryption in transit and at rest.
- From the Kingdom of Saudi Arabia — transfers outside the Kingdom are made only on a ground permitted by the PDPL and its Regulation on Personal Data Transfer Outside the Kingdom: an appropriate-level-of-protection determination, or approved safeguards such as standard contractual clauses or binding common rules, supported by a risk assessment where the transfer is continuous or involves sensitive data, and without prejudice to the vital interests of the Kingdom.
- Everywhere — a written contract imposing confidentiality, security and purpose limitation on the recipient.
A Customer with data residency requirements stricter than the above should raise them before onboarding so that they can be reflected in its Data Processing Agreement. You may request a copy of the relevant safeguards by writing to us at the address in Contact & Complaints.
Retention And Deletion
We keep personal data no longer than is necessary for the purpose it was collected for, and we do not keep report data "just in case."
- Report and case data — retained for the period the Customer configures. A report that does not proceed to investigation should be deleted promptly once that has been established; a report that does proceed is normally retained for the duration of the investigation and any resulting proceedings, plus the period required by the applicable whistleblowing or record-keeping law. At the end of the retention period, or on termination of the Customer's agreement, data is deleted or returned in accordance with that agreement.
- Voice audio — where transcript-only delivery is enabled, source audio is discarded once the transcript has been produced and quality-checked.
- Website enquiries and demo requests — retained for up to 24 months from our last substantive contact with you, then deleted, unless a contract or a legal obligation requires longer.
- Security and audit logs — retained for up to 12 months, except where an entry is relevant to an open investigation or legal hold.
- Backups — deletion propagates to backups on their normal rotation cycle rather than instantly; data awaiting rotation is isolated from active use.
How We Secure Personal Data
- Encryption — TLS 1.3 in transit, AES-256 at rest.
- Tenant isolation — every Customer's data is logically isolated; there are no shared report stores.
- Least privilege — access is role-based, granted on need, reviewed periodically and logged in an immutable audit trail.
- Independent assurance — a SOC 2 Type I audit is in progress, an ISO 27001 gap assessment is underway, and independent penetration testing is performed, with the executive summary available under NDA. Our Trust & Security page carries the current status.
- Breach response — we maintain an incident response process. Where we act as processor we notify the affected Customer without undue delay so that it can meet its own notification duties; where we act as controller we notify the competent supervisory authority, and affected individuals where the law requires, within the applicable deadline — 72 hours under the GDPR, and within the period the PDPL and its regulations prescribe.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please tell us at info@xposer.ai rather than disclosing it publicly, and we will work with you in good faith.
Your Rights And How To Exercise Them
Subject to the conditions and exceptions in the law that applies to you, you may have the right to:
- Be informed about how your personal data is processed — this policy is part of how we meet that.
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Delete data where it is no longer necessary, where consent is withdrawn and no other basis applies, or where it has been processed unlawfully.
- Restrict or object to processing, including objecting to direct marketing at any time and without giving a reason.
- Portability — receive data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before you withdrew it.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see Voice, Transcripts & AI.
- Complain to a supervisory authority — see Contact & Complaints.
How to make a request. Where we are the controller, email info@xposer.ai with enough detail to locate your data. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. There is no fee unless a request is manifestly unfounded or excessive. We may ask for information to verify your identity — we ask for the minimum necessary, and we do not use it for anything else.
Requests about a report go to the organisation, not to us. Where we act as processor we have no lawful authority to release, amend or erase case data on our own initiative. Direct your request to the organisation that provided the reporting channel. If it reaches us instead, we will forward it promptly and confirm that we have — unless doing so would itself risk identifying a reporter.
Regional Disclosures
Kingdom of Saudi Arabia (PDPL).
- Where consent is our basis, it is freely given, specific and informed, and may be withdrawn at any time.
- You have the right to be informed, to access your data, to request a copy of it in a readable format, to request correction, and to request destruction where the data is no longer needed.
- We do not use personal data for marketing purposes without a lawful basis to do so, and we do not disclose personal data where disclosure would cause damage to the data subject or conflict with the Kingdom's interests.
- Cross-border transfers follow the rules in Transfers & Data Residency.
- Complaints may be made to the Saudi Data & Artificial Intelligence Authority (SDAIA) as the competent supervisory authority.
European Economic Area and United Kingdom (GDPR / UK GDPR).
- You may lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement; in the United Kingdom, with the Information Commissioner's Office.
- Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.
United States — California and other state privacy laws.
- We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, including with respect to minors under 16.
- For personal information processed on behalf of a Customer, we act as a service provider and process it only for the business purposes set out in our contract. We do not retain, use or disclose it for any other purpose, and we do not combine it with personal information from other sources.
- California, Colorado, Connecticut, Virginia, Utah and other state residents may exercise the rights in Your Rights, including the right to know, delete, correct, opt out of targeted advertising, profiling and sale or sharing, and to appeal a refused request. We will not discriminate against you for exercising any of them.
- Sensitive personal information is used only for the purposes permitted without a right to limit — performing the service, security, and legal compliance.
- An authorised agent may submit a request on your behalf with written proof of authorisation.
Cookies And Local Storage
This website runs no advertising cookies, no third-party analytics and no social media pixels. We use a small amount of your browser's local storage, which stays on your device and is never transmitted to us:
- Theme preference — remembers whether you chose light or dark mode.
- Resource download details — remembers the contact details you entered at a download form so you are not asked to retype them next time.
You can clear both at any time through your browser's "clear site data" controls, with no effect beyond being asked for those details again. The platform itself uses strictly necessary cookies for session security and abuse prevention; these cannot be switched off without breaking the service. If we ever introduce non-essential cookies, we will ask for your consent first.
Children
This website and the platform are intended for adults acting in a workplace or professional context. We do not knowingly collect personal data from anyone under 16, and we do not direct any part of the service to children. A report may nonetheless concern a child — for example a safeguarding allegation — and such data is handled with the heightened care its sensitivity demands. If you believe a child has given us personal data outside that context, contact us and we will delete it.
Changes To This Policy
We may update this policy as the service, our subprocessors or the law change. The "Last updated" date at the top always reflects the current version. For material changes — a new purpose, a new category of recipient, or a change that reduces your rights — we will give reasonable advance notice by posting a prominent notice on this site and, where we hold your contact details and the change affects you, by email. Continued use of the service after a change takes effect means you accept the updated policy; if you do not, the remedies in our Terms & Conditions apply. Previous versions are available on request.
Contact & Complaints
Questions about this policy, a request about your data, or a data protection concern — write to us. Our Data Protection Officer, where one is appointed, can be reached at the same address.
If you are not satisfied with our response, you may complain to your supervisory authority: SDAIA in the Kingdom of Saudi Arabia, your national data protection authority in the EEA, the Information Commissioner's Office in the United Kingdom, or your state Attorney General in the United States. We would rather you came to us first, and we will always try to resolve it directly.