Legal
Privacy Policy
1. Introduction and scope
This Privacy Policy explains how Xinference Holdings Pte. Ltd. (“Xinference”, “we”, “us” or “our”) collects, uses, discloses and protects personal data in connection with XAgent. XAgent is an agent platform for personal work, reusable team agents and enterprise AI systems. It can plan and execute multi-step tasks, use models and tools, work with files and knowledge bases, retain task context or memory, and interact with services that a user or customer connects.
This Policy applies to XAgent websites and cloud services that we operate, related sales and support activities, and personal data that we otherwise receive in connection with XAgent. It also explains the limited circumstances in which this Policy applies to self-hosted deployments.
When an organisation provides XAgent to its personnel or other end users, that organisation normally determines why and how Customer Content is processed. In that situation, the organisation is the controller or business and Xinference acts as its processor or service provider. The applicable customer agreement and Data Processing Agreement govern that processing and take precedence over this Policy to the extent of any conflict.
2. Deployment models and responsibility
2.1 XAgent Cloud
For a cloud or other managed deployment operated by us, we process the account, service, usage and Customer Content data necessary to provide the service, subject to the customer’s configuration and agreement with us.
2.2 Self-hosted XAgent
For a self-hosted deployment, the customer operates XAgent in infrastructure it selects. This Policy applies only to personal data that Xinference actually receives, such as account, licensing, support, security, update or optional telemetry information. We do not control data that remains solely within the customer’s environment. A customer may separately configure third-party models, tools and integrations, and those providers’ terms and policies apply to their processing.
3. Personal data we collect
3.1 Account, organisation and commercial information
We may collect names, usernames, work email addresses, telephone numbers, organisation names, roles, account preferences, subscription and order information, billing contacts, transaction records and communications with our sales, support and customer-success teams. Payment-card information may be collected directly by our payment provider rather than stored by Xinference.
3.2 Customer Content
Depending on how XAgent is configured and used, Customer Content may include:
- prompts, instructions, agent definitions, plans and configurations;
- files, documents, images, audio, datasets and other material uploaded or made available to an agent;
- knowledge bases, indexes, embeddings, retrieval results and agent memory or task state;
- model inputs and outputs, agent messages, tool calls, action results and generated artifacts;
- data read from, sent to, created in or changed within a connected service; and
- personal data about users or other individuals that a customer chooses to include in the service.
3.3 Connected services, credentials and permissions
When an authorised user connects a third-party account, API, MCP server, data source or other service, XAgent may receive account identifiers, authorisation scopes, access or refresh tokens, connection metadata and information returned by that service. XAgent uses those credentials and permissions to maintain the connection and perform the user-configured task or action. Users should grant only the permissions needed and can disconnect a service through the relevant account or integration settings.
3.4 Service, device and usage information
We may collect IP address, browser and device information, authentication events, workspace and user identifiers, dates and times of access, feature interactions, agent and task status, model and tool selections, token or credit consumption, latency, errors, diagnostic events, and security or audit information. The precise content of operational logs depends on the deployment, configuration and support context.
3.5 Website and cookie information
Our websites and cloud services may use cookies, local storage and similar technologies for authentication, security, preferences, service operation and analytics. Where required by law, we request consent before using non-essential technologies. Browser settings and any consent controls we provide can be used to manage these technologies.
3.6 Information from other sources
We may receive business contact information from a customer, partner or public professional source, and information from identity, payment, security and integration providers when a user chooses to use those services with XAgent.
4. Data from connected services and platforms
This section applies when a user or customer connects XAgent to an external platform, account, application, API, MCP server, database or other third-party service. Examples may include communications, social-media, productivity, storage, customer-support, sales, analytics and developer platforms.
4.1 Data received from connected services
The data XAgent receives depends on the service, the permissions granted, the user’s role and the customer’s configuration. It may include:
- user, organisation, workspace, channel, page, project or account identifiers and basic profile or account information;
- business resources, files, records, folders and configuration metadata;
- content and related metadata that the authorised account can access, such as documents, posts, media, comments, mentions, messages, conversations, tickets, leads, calendar items or webhook events;
- access tokens, granted permissions and connection status; and
- actions requested through XAgent and the status or result returned by the connected service.
XAgent does not receive every category listed above from every service. It receives only the fields made available for the permissions, features and resources that the authorised user or customer has enabled.
4.2 How we use connected-service data
We use connected-service data only to provide and secure the integration requested by the authorised user or customer. Depending on the enabled feature, this may include connecting and authenticating an account; displaying or synchronising authorised information; allowing an agent to retrieve, classify, search, summarise or draft content; carrying out an authorised creation, update, publishing, messaging, moderation or other action; recording action status; troubleshooting the integration; and complying with the connected service’s requirements and applicable law.
We do not sell connected-service data. We do not use it for unrelated advertising, data brokerage or surveillance, or to determine a person’s eligibility for employment, housing, credit, insurance or another high-impact service.
4.3 Connected-service data sharing and model processing
Connected-service data may be disclosed to service providers that process data for us, to a model or tool provider needed to perform the customer-configured task, to the connected service or an intended recipient to carry out the requested action, or as otherwise described in Section 7. The customer is responsible for selecting models and tools suitable for its use case and for obtaining any notices, consents or other authority required for the data it makes available.
4.4 Disconnecting a service and requesting deletion
An authorised user can stop new access by disconnecting the integration in XAgent, removing XAgent from the relevant third-party account settings, or revoking the applicable permissions. Disconnecting does not automatically erase data that was previously copied into XAgent, an agent memory, a knowledge base or an output.
To request deletion of connected-service data held by Xinference, email legal@xinference.co from the address associated with the XAgent account. Identify the relevant workspace, connection and data concerned. We may take reasonable steps to verify identity and authority before deletion. We will delete or de-identify data under our control unless retention is required by law, needed for security or dispute purposes, or governed by a customer’s instructions as controller. If a business customer controls the relevant workspace, we may direct the requester to that customer.
5. How we use personal data
We use personal data to:
- provide, operate, maintain and support XAgent and execute user-configured agents, tools and actions;
- create and administer accounts, workspaces, subscriptions, permissions and connected services;
- authenticate users and protect XAgent, customers and third parties from fraud, abuse and security threats;
- meter usage, administer plans and credits, process payments and maintain business records;
- monitor service health, troubleshoot faults and improve reliability, usability and performance;
- communicate about transactions, support, service changes, security and, where permitted, relevant products;
- enforce agreements and acceptable-use requirements; and
- comply with legal, regulatory, tax and accounting obligations and protect legal rights.
5.1 AI training and service improvement
Xinference does not use Customer Content to train or fine-tune foundation models unless the customer expressly agrees in writing. We may use service and usage information, feedback, and aggregated or de-identified information to secure, operate and improve XAgent. If a customer configures a third-party model or tool provider, that provider’s handling of data is governed by the customer’s configuration and the provider’s applicable terms and privacy policy.
6. Legal bases
Where a legal basis is required, we process personal data as necessary to perform a contract or take requested pre-contract steps; for legitimate interests such as operating, securing, supporting and improving XAgent and conducting business-to-business communications; to comply with legal obligations; and with consent where consent is required. Where Xinference acts as a processor or service provider, we process Customer Content on the customer’s documented instructions.
7. How we disclose personal data
We may disclose personal data to:
- cloud, hosting, database, authentication, payment, email, analytics, customer-support and security providers that process data for us;
- model, inference, search, tool and integration providers selected or enabled for the relevant deployment or task;
- connected services and intended recipients when an authorised agent performs a configured action;
- the customer that controls the relevant workspace and its authorised administrators;
- professional advisers, auditors and insurers under appropriate duties of confidentiality;
- law-enforcement authorities, regulators, courts or other parties where required by law or reasonably necessary to protect rights, safety, security or integrity; and
- an acquirer, investor or successor in connection with a financing, reorganisation, merger, acquisition or sale, subject to appropriate protections.
We do not sell personal data. A current list of subprocessors applicable to a contracted service may be provided through our contractual, trust or support channels. Customer-selected providers may act independently under their own terms.
8. International data transfers
Xinference and its service providers may process personal data in countries other than the country where it was collected. The locations involved depend on the deployment region, connected services, selected model and tool providers, and support arrangements. Where required, we use recognised transfer safeguards, such as contractual protections, and take supplementary measures appropriate to the circumstances.
9. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the service, preserve customer-configured agent state and records, comply with law, maintain security, resolve disputes and enforce agreements. Retention periods vary by data type, deployment, customer instruction and contractual requirement.
Customers and authorised users may be able to delete agents, files, knowledge bases, memory, outputs, integration data or accounts through XAgent. Account and workspace deletion requests may also be sent to legal@xinference.co. When Xinference is processing data for a business customer, deletion and access requests concerning Customer Content should ordinarily be directed to that customer. Data may remain for a limited period in backups or restricted records before being overwritten or deleted, and we may retain information that law requires us to keep.
10. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. Measures are selected according to the deployment and risk and may include access controls, authentication, encryption in transit, logging, monitoring, backups, personnel controls and vendor-management practices. No system is completely secure, and customers remain responsible for their deployment, user permissions, connected services, credentials, models, tools and agent configurations.
11. Your choices and rights
Depending on where you live and the role in which we process your data, you may have rights to request access, correction, deletion, restriction, portability or objection; withdraw consent; opt out of certain communications; and complain to a data-protection authority. These rights may be subject to legal exceptions.
Singapore residents may have rights under the Personal Data Protection Act 2012. Individuals in the European Economic Area or United Kingdom may have rights under the GDPR or UK GDPR. Individuals in other jurisdictions may have comparable rights under applicable law. To exercise a right relating to data controlled by Xinference, contact legal@xinference.co. If the data is controlled by an XAgent customer, please contact that customer first.
12. Automated processing and human oversight
XAgent can generate content and perform actions using AI models and connected tools. Outputs and actions may be inaccurate, incomplete or inappropriate. Unless a customer has implemented a legally compliant process for a particular use, XAgent should not be used as the sole basis for a decision that produces legal or similarly significant effects on an individual. Customers are responsible for appropriate human review, permissions, notices and safeguards.
13. Children
XAgent is intended for business and professional use and is not directed to children under 18. We do not knowingly collect personal data directly from children through XAgent accounts. If you believe a child has provided personal data to us, contact legal@xinference.co.
14. Third-party services
XAgent may link to or interact with third-party websites, models, tools, MCP servers and connected services. Those third parties control their own privacy practices. This Policy does not replace their terms or privacy notices, and Xinference is not responsible for processing performed independently by them.
15. Changes to this Policy
We may update this Policy as XAgent, our data practices or legal requirements change. We will update the effective date and provide additional notice where a change is material or applicable law requires it. Changes do not authorise us to use previously collected personal data in a materially incompatible way without any notice or consent required by law.
16. Contact us
Questions, privacy requests and complaints may be sent to legal@xinference.co.
Xinference Holdings Pte. Ltd.