Back to Home
Privacy & ProtectionLast updated: August 17, 2026

Privacy Policy

This Privacy Policy explains how XPONITY LTD collects, uses, stores, and protects personal information when you visit our website, contact us, enquire about our services, become a client, or otherwise interact with us.

Our Core Commitment

We handle personal information fairly, transparently, and securely in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018. We do not sell personal information.

About This Privacy Policy

This Privacy Policy explains how XPONITY LTD (“Xponity”, “we”, “us” or “our”) collects, uses, stores and protects personal information when you visit our website, contact us, enquire about our services, become a client, or otherwise interact with us.

Data Controller: XPONITY LTD is the controller of the personal data covered by this Privacy Policy.

Company number: 17328550

Registered office: Madina Hall, 122 Withington Road, Manchester, M16 8FB

Email: hello@xponity.com

We aim to handle personal information fairly, transparently and securely in accordance with applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.

1. Information We Collect

We collect only information that is reasonably necessary for our business and the services we provide.

Information You Provide Directly

Depending on how you interact with us, this may include:

  • Full name
  • Email address
  • Telephone or other contact details
  • Business name and business information
  • Website or social media details
  • Project requirements, goals and specifications
  • Information provided through enquiries, consultations or communications
  • Billing and payment information necessary to process transactions

We do not need to collect or retain full payment card details where payment is processed directly through a third-party payment provider.

Information Obtained From Public Sources

As part of our business development activities, we may identify potential clients whose businesses may benefit from our services.

We may obtain professional or business contact information from publicly available sources, including business websites, professional social media profiles, Companies House and other publicly accessible business information.

This may include a person's name, professional role, business email address, business telephone number, website or social media profile.

We use this information for relevant business-to-business outreach and marketing relating to services we believe may be relevant to the individual or their business.

2. How We Use Personal Information

We may use personal information to:

  • Respond to enquiries and requests
  • Discuss potential projects and services
  • Provide and manage our services
  • Communicate with clients
  • Prepare proposals, agreements and project documentation
  • Process payments and maintain financial records
  • Provide customer support
  • Manage our business and maintain appropriate records
  • Improve our website, services and client experience
  • Conduct relevant business-to-business marketing and outreach
  • Comply with legal and regulatory obligations
  • Prevent fraud, misuse or security issues

We will not use personal information for purposes that are incompatible with the purpose for which it was collected without an appropriate lawful basis and, where required, providing further information.

3. Lawful Bases for Processing

We process personal information using an appropriate lawful basis under applicable UK data protection law.

Depending on the circumstances, these may include:

Contract

We may process information where it is necessary to enter into or perform a contract with you, such as delivering services, communicating about a project or processing payments.

Legitimate Interests

We may process personal information where necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.

This may include relevant business-to-business prospecting, marketing, maintaining business relationships, improving our services and protecting our business.

Consent

Where consent is required by law, we will ask for it before processing personal information for the relevant purpose.

You may withdraw consent at any time.

Legal Obligations

We may process information where necessary to comply with legal, accounting, regulatory or other obligations that apply to us.

Where we rely on legitimate interests, we consider whether the processing is necessary, proportionate and reasonably expected. Individuals have the right to object to processing based on legitimate interests, and the right to object to direct marketing is absolute.

4. Marketing and Business Outreach

We may contact coaches, educators, business owners and other professionals where we reasonably believe that our services may be relevant to their business.

Where personal information is obtained from publicly available sources, we will use it in accordance with applicable data protection and electronic communications laws.

The rules for business-to-business marketing can differ depending on whether we are contacting a corporate subscriber, sole trader or other type of business contact. We will comply with applicable requirements, including the Privacy and Electronic Communications Regulations (PECR).

If you do not wish to receive marketing communications from us, you can ask us to stop at any time.

You can also object to the use of your personal information for direct marketing at any time. We will respect such objections.

5. Where We Get Personal Information From

We may obtain personal information:

  • Directly from you
  • From your business or organisation
  • From publicly available sources
  • From professional or social media platforms
  • From Companies House and other public business records
  • From third-party service providers where appropriate

Where we obtain personal information from sources other than the individual, applicable privacy information will be provided in accordance with legal requirements.

6. Sharing Personal Information

We may share personal information with trusted third-party providers where reasonably necessary to operate our business or provide our services.

These may include providers of:

  • Website hosting and infrastructure
  • Email and communication services
  • Payment processing
  • Customer relationship management
  • Cloud storage
  • Project management
  • Business and automation software

Where third parties process personal information on our behalf, we take appropriate steps to ensure that the information is handled securely and in accordance with applicable data protection requirements.

We may also disclose information where required by law, legal proceedings, regulatory authorities or to protect our rights, property or security.

We do not sell personal information.

7. International Data Transfers

Some of the service providers we use may process or store information outside the United Kingdom.

Where a transfer of personal information is subject to UK international-transfer requirements, we will use an appropriate lawful transfer mechanism and safeguards as required by applicable law.

8. Data Security

We take reasonable technical and organisational measures to protect personal information against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include appropriate access controls, authentication, secure hosting and other security safeguards.

However, no method of electronic storage or transmission can be guaranteed to be completely secure.

9. How Long We Keep Personal Information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing services, maintaining appropriate business and financial records, resolving disputes and complying with legal obligations.

Retention periods may therefore vary depending on the type of information and the reason we hold it.

Where information is no longer required, we will take reasonable steps to securely delete or anonymise it.

10. Your Data Protection Rights

Depending on the circumstances and subject to applicable legal conditions and exemptions, you may have the right to:

  • Request access to your personal information
  • Request correction of inaccurate or incomplete information
  • Request deletion of your personal information
  • Request restriction of processing
  • Object to certain processing
  • Object to direct marketing
  • Request data portability where applicable
  • Withdraw consent where processing is based on consent

You can exercise your rights by contacting us at:

hello@xponity.com

We will respond to valid data protection requests without undue delay and generally within one month, subject to applicable law.

11. Complaints

If you have concerns about how we collect or use your personal information, please contact us first:

We will try to resolve your concern.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).

Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

Website: https://ico.org.uk/make-a-complaint/

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, technology, legal requirements or business practices.

The latest version will always be made available on our website, together with the date it was last updated.

We will take reasonable steps to bring significant changes to your attention where appropriate.