Xyreg Logo

    Privacy Policy

    Last Updated: July 2026

    This Privacy Policy explains how Xyreg collects, uses and protects personal data when you visit our website or use the Xyreg workspace.

    1. Data Controller

    The controller of your personal data is Xyreg SARL, a company incorporated under the laws of Luxembourg, having its registered address at House of BioHealth, 27 Rue Henri Koch, L-4354 Esch-sur-Alzette, Luxembourg. For any privacy request, use the contact form on this website. We reply from our Luxembourg office.

    2. Information We Collect

    We collect only what we need to run the service: • Contact data you submit through our forms (name, company, email, optional phone and message) • Account data for workspace users (name, email, role, organisation) • Content you upload into your workspace (documents, records, project and quality data) • Technical data (IP address, browser type, timestamps) and aggregated usage analytics

    3. How We Use Your Information

    We use personal data to: • Provide, operate and secure the Xyreg workspace • Respond to your enquiries and provide support • Manage subscriptions, trials, invoicing and account administration • Maintain audit trails required by quality-management regulations • Meet our legal obligations Legal bases: performance of a contract, our legitimate interest in operating and improving the service, your consent (optional analytics and product updates), and legal obligations.

    4. AI Processing (Xyreg Cortex AI)

    Xyreg Cortex AI assists with document drafting and analysis inside your workspace. • Your content is processed only to generate output for your own workspace. • Your content is not used to train foundation models and is not shared with other customers. • AI processing runs within our EU infrastructure and contracted EU-region model providers. • Human review remains mandatory: AI output is a draft, never an approved record.

    5. Where Your Data Is Hosted

    Production data is hosted in the European Union on OVHcloud infrastructure. Where a sub-processor requires a transfer outside the EEA, we rely on European Commission Standard Contractual Clauses and apply additional technical safeguards.

    6. Sharing and Sub-processors

    We never sell personal data. We share it only with: • Sub-processors that host, secure or support the workspace, under written data-processing agreements • Professional advisers bound by confidentiality • Public authorities where we are legally required to disclose A current list of sub-processors is available on request through the contact form.

    7. Data Security

    We apply security controls aligned with ISO/IEC 27001 practice: • Encryption in transit and at rest • Role-based access control, least privilege and audit logging • Segregated customer workspaces • Regular backups, vulnerability management and penetration testing • Documented incident response with notification without undue delay

    8. Data Retention

    • Contact form submissions: kept for up to 24 months, then deleted. • Customer workspace content: kept for the duration of the subscription and for 30 days after termination to allow export, unless a longer retention period is agreed in your contract or required by medical device record-keeping obligations. • Security and audit logs: kept for up to 12 months. • Invoicing records: kept for 10 years as required by Luxembourg law.

    9. Your Rights

    Under the GDPR you may request: • Access to your personal data • Rectification of inaccurate data • Erasure of your data • Restriction of, or objection to, processing • Portability of data you provided • Withdrawal of consent at any time We respond within one month. You also have the right to lodge a complaint with the Luxembourg supervisory authority, the Commission nationale pour la protection des données (CNPD).

    10. Cookies and Tracking

    We use essential cookies for site and workspace functionality, and optional analytics cookies to understand how the site is used. Optional cookies are set only with your consent, which you can withdraw at any time in your browser settings.

    11. Changes to This Policy

    We may update this policy. Material changes are announced in the workspace or by email at least 30 days before they take effect. The date at the top of this page always shows the current version.

    12. Contact Us

    For any privacy question or to exercise your rights, use the contact form on this website. Your message reaches our team directly and we reply by email.

    Questions about our privacy practices? Send us a message and we will reply by email.