Legal Sheet
Xymeris Labs LLC, a company formed under the laws of the state and operating its systems design and applied research laboratory from the address 2599 Oak Forest Dr, Layton - 84040-7974, United States (US), publishes this Privacy Policy to describe how personal information is handled in connection with the website at the domain xina.autos and the consulting, prototyping, modeling and integration services described on this site. The developer name behind these works is Xymeris Labs. This policy explains what information is collected, why it is collected, how it is protected, and the choices available to every visitor and client of the service.
The document is written to be read by a person without legal training. Where a rule depends on a law, the relevant idea is stated plainly and the practical consequence is named in the same sentence. Questions about anything written here can be sent to the contact address given at the end of this sheet, and a named member of the laboratory staff will answer.
This Privacy Policy applies to each of the following channels that Xymeris Labs LLC controls. It covers the public website at xina.autos, including the homepage, the service proof sheets, the contact page and every legal sheet attached to the domain. It also covers written correspondence sent to the electronic mail address contact@xina.autos, telephone calls and recorded voicemail messages routed to the published number, and the enquiry contact information supplied through the site form.
The policy does not govern the practices of third parties whose services appear as links elsewhere on this site. Those parties publish their own notices, and a visitor should read them before handing over information. It also does not cover information handled internally by a client organisation after our laboratory delivers a prototype or a report, because those records belong to the client once the handover sheet is signed.
By browsing the site, sending an enquiry, or engaging the laboratory for work, a person accepts that this policy describes how their information is treated. If any single clause in this policy cannot be accepted, the clear remedy is to stop using the site and to avoid submitting personal information through any of the contact routes named here. There is no obligation on any person to provide information that they do not wish to provide.
Several words appear often in this sheet, and each is worth fixing in plain language before the detail begins. Personal information means any piece of data that can identify a living person, either on its own or when joined with other data we hold. A name, an electronic mail address, a telephone number and an account identifier are all personal information.
Processing is a very broad word. It covers collecting, recording, storing, organising, adapting, reading, retrieving, transmitting and deleting data. Every time this policy says the term information is processed, it means any one of those activities has happened.
The controller is the legal person who decides why personal information is processed and how. For this site and for the laboratory services, the controller is Xymeris Labs LLC at the Oak Forest Drive address. The term processor names a party that handles personal information only on the written instruction of the controller, such as a hosting provider or an invoicing helper. A recipient is anyone who receives the data after it has left the device of the person it describes.
Consent means a freely given, specific and informed agreement to process particular data, given through a clear affirmative act. Where this policy relies on consent, the person who gave it may withdraw that consent at any time with effect for the future, and the method for doing so is described under the section on rights.
Not every visit results in personal information being collected. Much of the browsing traffic to the site is processed in aggregated form without identifying individual people. The information that can be linked to a specific person falls into clear families, described below.
Information you give us directly. When a person completes the enquiry form on the contact page, we receive the personal name, the electronic mail address, an optional subject line and the free text of the message. When a person writes to contact@xina.autos directly, the correspondence carries the sender address and whatever is inside the thread. When a person calls the published number, we may keep the calling number and a summary of the conversation for the continuity of the engagement.
Information about the projects you ask us to assess. Once an engagement begins, the laboratory may receive technical materials that themselves carry personal data, such as configuration exports containing administrator identities or test data samples that resemble the details of real people. That information is treated with the same care as everything else on this sheet and is used only for the purpose of the agreed work.
Technical information collected automatically. The web servers record routine request logs that may include the internet protocol address of the requesting device, the browser type, the operating system, the referring page and the time of the request. We do not attempt to attach those logs to named individuals, and they are retained only as long as they are needed for security and for diagnosing faults.
Information we never ask for. The laboratory does not seek sensitive categories such as data revealing a racial origin, political opinion, religious belief, trade union membership or health condition. If such data arrives unsolicited inside a project file, it is handled only to the minimum needed to complete the task and is not used for any other purpose.
Personal information reaches the laboratory through a small number of deliberate doors rather than through broad or silent sweeps. The first door is the enquiry form on this site, which passes only the fields the visitor chooses to complete. The second is direct correspondence, meaning an electronic mail message, a telephone conversation or a voicemail left on the published line. The third is the project intake itself, where technical evidence files supplied for an assessment happen to include personal data inside their contents.
The fourth channel is automated and happens without any keystrokes from the visitor. Browsers make requests to the site server, and each request naturally produces a line in the access log holding the internet protocol address and the characteristics of the requesting browser. Those logs are produced by the infrastructure that keeps the site reachable and secure, not by a hidden tracker, and they are not sold, rented or traded to any third party.
Cookies, described more fully later in this sheet, are treated as a form of collection only when they can be tied to a person. Statistically useful cookies are configured to avoid identifying individuals by name, and the small set of status cookies needed to make the contact page behave is described under the dedicated section.
Processing of personal information is justified by one of several lawful grounds, and it is useful to name the ground that applies to each family of data. When the laboratory processes information to decide whether to take on a piece of work or to carry out work already agreed, the ground is the formation and performance of a contract, backed by the legitimate interest of running a business without interruption.
When a message arrives outside any contract, such as an unsolicited enquiry from a visitor who simply wants to ask a question, the ground is the legitimate interest of Xymeris Labs LLC in answering enquiries from people who have approached it. The laboratory balances that interest against the privacy of the writer, and the weight stays small because the reply is confined to the writer and never published.
Where a visitor gives an express choice, consent is the ground for any processing that depends on that choice. Consent-driven processing is always optional, always reversible, and is never made a condition of receiving a contractual service. Security logs and fault diagnostics rest on the legitimate interest of keeping the site and the messages that pass through it safe from abuse.
Legal obligations form their own ground. If a tax authority, a court or a regulator lawfully demands records, the laboratory will provide only what the law compels and will say so plainly in its reply rather than inventing a wider disclosure than the request allows.
Every use of personal information at Xymeris Labs LLC is tied to an honest purpose, and none of those purposes is vague. Your information may be used to answer the enquiry you sent, to decide whether the laboratory can take on the described work, and to prepare the framing sheet and quotation for that work. Once an engagement is agreed, the information becomes part of the working file and is used to deliver the prototype, the model, the integration design or the opinion that was contracted.
The information is also used to send you the administrative messages an engagement requires. Those include acknowledgements of receipt, schedule confirmations, handover notes and final invoices, each of which is a functional part of doing business rather than a promotional mailing. We do not send newsletters as a routine, and if marketing correspondence ever begins it will do so only with explicit consent and a clear way to stop it.
Aggregated, de-identified statistical views of site use help the laboratory improve layout and readability. Because those summaries cannot be traced back to any named person, they fall outside most of the strict rules of this sheet, yet they are described here for the sake of a complete account. Support of the laboratory operation, including hosting, invoicing and record keeping, is also a purpose, but that support never entails selling the underlying personal information to an unrelated party.
Transparent disclosure of recipients is a core promise of this sheet. Xymeris Labs LLC does not sell, rent or barter personal information to data brokers, advertising networks or any unrelated commercial party. The laboratory is not in the business of trading the trust of its correspondents.
The recipients who may legitimately see personal information are kept to a short list. Hosting and infrastructure providers that operate the servers where the site and the mail service live will see the technical data needed to keep those systems running. Accounting and invoicing helpers may see the billing details required to issue a lawful invoice for an engagement, and legal or regulatory bodies may see information when a legal obligation demands it, and then only to the degree the obligation requires.
Each recipient is bound either by a written processor agreement that confines the use to what we instruct, or by a law that defines the limits of its own authority. When a trusted partner changes, this list is updated on the next publication of this policy. We will never make a silent gift of personal information to a party outside these described roles.
Information is kept only as long as the purpose that justified collecting it remains live, and no longer. Enquiry correspondence that never becomes a contract is reviewed on a schedule and removed when the enquiry has been answered or clearly abandoned, so that no stale note lingers without reason. For an accepted engagement, the working file, including any personal names carried inside delivered evidence, is kept for the period the law or the invoicing obligation reasonably requires, and is then confidentially erased.
Server access logs are typical of short lived technical records. They are held for a limited operational window used for diagnosing outages and spotting abuse, then cycled out of storage so that no permanent biography of a visitor accumulates in the machine room. Backups taken for disaster recovery follow a comparable cycle and are themselves erased when the record set they protect has passed its retention horizon.
When retention ends, deletion is performed in a way that removes the data from active service, and the deletion is logged so the erasure can be confirmed on request. Nothing in this paragraph guarantees the deletion of records that a regulator has lawfully required us to hold, because such records are retained for the duration of that requirement.
The laboratory treats the protection of information as part of good engineering rather than as an afterthought. Access to the systems that hold project files is limited to the named members of staff whose role actually requires it, and each access is governed by a distinct credential that can be reviewed and revoked. Files at rest are protected using accepted encryption practice when the sensitivity of the material justifies it, and traffic between a browser and the site travels over an encrypted channel.
Personnel are instructed in the discipline of least exposure: to pull only the data a task needs, to avoid extracting whole datasets when a subset will do, and to question any request for data that arrives without a purpose. Software hosting the site is kept current, and faults discovered by security review are fixed on a priority basis rather than being left for the next scheduled event.
No method of transmission or storage is perfectly free of risk, and this policy makes no promise of absolute safety. What the laboratory does promise is responsible care proportionate to the sensitivity of the information, honest disclosure when a breach is known to affect the data, and a record of the response so that lessons are never confined to the memory of a single engineer.
The services and the written material on this site are directed at grown professionals who commission systems design and research, and they are not aimed at children. Xymeris Labs LLC does not knowingly collect personal information from a child, and no child should submit an enquiry, a mailing address or any other personal detail through the contact routes on this domain.
If a parent or a legal guardian discovers that information belonging to a child under the age of consent has reached the laboratory, the parent should write to the contact address at the end of this sheet with enough evidence to identify the material. The laboratory will act promptly to remove the child information from active records and to confirm the removal in writing.
In the same spirit, the laboratory does not build profiles of children, does not run behaviourally targeted advertising against minors, and does not treat test data that merely resembles a minor as an invitation to reproduce it. Privacy for children is guarded not by a carve out but by the simple decision that minors are simply not part of this audience.
This site is deliberately light on external references, but the pages may occasionally point a reader toward a standards body, an open source project or a professional publication that is useful to the work. Following one of those links carries the visitor onto property the laboratory does not own, and responsibility for the handling of personal information then passes to the operator of that destination, not to Xymeris Labs LLC.
Third-party tools are admitted to the site only where they earn their place. If a helper such as a code repository, a schedule helper or a secure file transfer service is used as part of an engagement, the helper is chosen for its documented privacy behaviour and is bound by the processor limits described in the disclosure section. Free services that monetise their users through broad advertising are avoided precisely because they sit awkwardly with the commitments of this sheet.
When the site is updated and a previously unlisted helper is adopted, that helper is added to this section on the next policy revision. Visitors who want to know whether a particular tool is in active use should ask through the contact route, and the answer will be given plainly rather than in guarded language.
Xymeris Labs LLC operates from Layton in the United States, and the laboratory records, the site hosting and the mail service may rest on infrastructure located in the same country for most visitors. When a person outside the United States sends information, that transfer is a cross-border one, and this policy addresses it openly rather than pretending the geography does not exist.
Transfers into the United States from other regions are made on grounds the applicable law recognises, which include your affirmative request for an enquiry, the performance of a contract you have entered, or your explicit consent given after the fact of the transfer has been explained. The laboratory does not move information across a border for the sport of sitting data in a convenient country; it does so only because the delivery of the agreed work demands that particular route.
When a transfer occurs, the same protections named in the security section continue to apply, because moving data does not weaken the care owed to it. A visitor in a region that grants strong data protection rights retains those rights in full, and the sections on retention, security and rights are not diminished by the location of the server.
The rights that follow are described in plain terms, and each maps to a way a visitor or client can steer what happens to their own information. The right of access lets a person ask what personal information the laboratory holds about them and to receive a copy in a readable form. The right of rectification lets a person ask for an error in that information to be corrected without fuss.
The right of erasure lets a person ask that their information be deleted where no legal obligation requires it to be kept, and the laboratory will act when the request is made in good faith. The right to object lets a person stop processing that relies on the legitimate interest grounds described earlier, where stopping does not conflict with a duty we hold to a regulator or to another party.
The right of portability lets a person who provided their own data ask for it back in a structured, commonly used form where the processing rests on consent or on a contract. The right to withdraw consent lets a person revoke an earlier consent with effect for the future, at which point any processing that depended solely on that consent must stop.
To exercise any of these rights, a person should write to the contact address listed at the foot of this sheet and state the right they are invoking. The laboratory will verify the identity of the requester with a proportionate check before acting, will respond within the window the applicable law sets, and will explain in plain words if a request cannot be honoured and why.
Because Xymeris Labs LLC is a United States company, several American legal frameworks shape how personal information is treated. General obligations under federal trade law require truthful behaviour: the laboratory will not be reckless with data, will not mislead visitors about what it does with information, and will honour the commitments written into this policy.
Several states have enacted broader consumer privacy laws that grant residents additional steering power over their information. Where a state law gives a resident a right to know, to delete or to opt out of the sale of personal information, the laboratory honours that right to the extent the activity applies to it. Because this site does not set a data sale, the right to opt out of such a sale is evidently satisfied, yet the request route still exists for full candour.
Residents of any state with a specific privacy statute may write to the laboratory and identify themselves by state so that the most protective applicable rule can be applied. The laboratory answers such requests without treating the enquirer as a nuisance, because answering honestly is cheaper and better than the alternative of guessing.
This policy may be revised when the services grow, when a lawful obligation changes, or when the technical practices of the laboratory develop. Each revised version carries its own effective date at the top of the sheet, so a reader can always tell which edition they are being asked to accept.
Material changes that alter how personal information may be used are announced with reasonable prominence, including by updating this page and, where an engagement is live, by flagging the change in the next routine correspondence. A change that narrows how data is used is welcome and needs little ceremony; a change that broadens use will wait for fresh consent where the governing law so requires.
The history of revisions is not kept as a marketing story but as the working record the laboratory itself consults. Older editions are not silently rewritten; a revision is a new edition that replaces the old, and the old promises are superseded only by the new text that this page actually displays.
Questions, requests and complaints about privacy all travel to the same place, and they are answered by a named person rather than by an automated silence. Write to the electronic mail address contact@xina.autos, telephone the laboratory on +17754162244, or send physical mail to the company at 2599 Oak Forest Dr, Layton - 84040-7974, United States (US).
When a request concerns privacy, please mark the subject line so the mail lands with the staff member who handles information requests. Identify yourself in the body of the message far enough to allow a proportionate identity check, but never send passwords, card details or other secrets inside a first enquiry. The reply will confirm what information, if any, is held about you and the steps that have been taken in response.
If a complaint is not resolved to the satisfaction of the writer, the writer may also raise the matter with the supervisory or data protection authority that has jurisdiction over them. Xymeris Labs LLC will cooperate with any lawful investigation and will not penalise a person for choosing the formal route. The laboratory closes this sheet on the same note it opened: information travels only as far as the work requires, and every mark on the data proof is made in plain sight.