Privacy Policy
Effective: 17 August 2026 · for the Xirql website and platform
1. Controller
The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:
DataSquads UG (haftungsbeschränkt)Friedrichsgaber Weg 92c
22848 Norderstedt
Germany
Local Court of Kiel, HRB 21891 KI
Managing Director: Sebastian Kielmann
Privacy enquiries may be submitted by post to the address above or through the Support function in the Xirql application.
2. Roles and scope
This Privacy Policy explains processing for which Xirql is itself the controller, in particular operation of the website, registration and customer administration, billing, support, IT security and Xirql’s own usage analysis.
Where Customers use Xirql to research, assess, contact and follow up business contacts, the Customer generally determines the purposes and essential means of processing. The Customer is then the controller and Xirql processes personal data on its behalf under Article 28 GDPR. Details are governed by the Data Processing Agreement (“DPA”), which forms part of the contract where relevant functions are used.
Personal campaign, CRM, profile and communication data is not used for other customers or to train general cross-customer AI models. Product improvement, benchmarks and statistics use only data anonymised or aggregated so that it no longer relates to an identified or identifiable natural person.
3. Legal bases where Xirql is controller
Depending on the purpose, Xirql relies in particular on:
- Article 6(1)(b) GDPR for steps before entering into and performing a contract, including registration, account administration, service provision and billing.
- Article 6(1)(c) GDPR for legal obligations, including commercial and tax documentation and retention duties.
- Article 6(1)(f) GDPR for legitimate interests, including IT security, fraud and abuse prevention, service stability, support improvement and legally permitted B2B communication. Xirql performs a balancing assessment where required.
- Article 6(1)(a) GDPR where consent is required, including certain analytics or marketing technologies.
Article 28 GDPR governs commissioned processing but is not itself a legal basis for processing.
4. Processing on the website and platform
4.1 Registration and customer accounts
Xirql processes names, business email addresses, company details, roles, account data and, where supplied, business telephone numbers to establish and perform the contract under Article 6(1)(b) GDPR. Passwords are stored only in hashed form.
4.2 Contract, billing and administration
Required master, contract, billing and transaction data is processed for contract administration, payment, invoicing, accounting and tax records under Article 6(1)(b) and (c) GDPR. Payment information may also be processed by Stripe under its applicable terms and privacy information.
4.3 Support and communication
When Customers or prospects contact Xirql, contact details, request content, uploaded images and relevant technical information are processed to respond and manage the business relationship. The legal basis is Article 6(1)(b) or (f) GDPR depending on context.
4.4 ICP reports and website analysis
Where a Customer submits a website URL, Xirql analyses publicly available content to create an Ideal Customer Profile report. This generally concerns company information. Any personal data processed as part of a Customer analysis is handled on the Customer’s instructions under the DPA and is not used for Xirql’s own or cross-customer purposes.
4.5 Connected LinkedIn, email and other accounts
When a Customer connects a third-party account, Xirql processes the technical authorisation data and Customer-initiated profile, contact and communication data required for enabled functions. This generally occurs on the Customer’s behalf. The Customer remains responsible for the legality of its campaigns, legal basis and transparency duties towards recipients; Xirql remains responsible for its processor obligations.
4.6 CRM imports and lead data
Imported CRM data, lead lists and comparable records are processed solely to run Customer-defined campaigns and Customer-specific matching, scoring, prioritisation and contact management under Article 28 GDPR.
4.7 AI-assisted processing
External AI and language-model providers may be used for ICP analysis, lead scoring, message personalisation, summaries and assistant features. Data is minimised to what the selected function requires. Providers processing Customer personal data are contractually integrated as subprocessors. Personal Customer Data is not used by Xirql to train general cross-customer models.
4.8 Technical logs and IT security
Technical logs may include IP address, timestamp, browser and device details, login events and security events. They are used for secure delivery, troubleshooting and detection of abuse or attacks under Article 6(1)(f) GDPR.
4.9 Product analytics and anonymised benchmarks
Usage metrics and campaign outcomes may be evaluated to improve features and create benchmarks. Personal campaign or communication data is not used across customers. Cross-customer analysis is limited to anonymised or sufficiently aggregated information. Where non-essential analytics access a user device, consent is obtained as required.
5. Recipients and service providers
Xirql uses selected providers for platform and business operations. Depending on their role, they act as Xirql’s processors, as subprocessors under the Customer DPA or as independent controllers. Current technical integrations include:
- Hosting, database and infrastructure providers for application hosting, storage, databases, queues, backups and delivery.
- Google Gemini for enabled AI-assisted analysis and generation functions.
- Unipile for enabled connections to LinkedIn and other Customer-connected accounts.
- Icypeas for enabled business contact and company research or enrichment.
- Mailgun for transactional email delivery.
- PostHog for enabled product analytics.
- Stripe for payment processing and billing.
- Professional advisers and public authorities where required by law.
The subprocessors relevant to commissioned Customer processing are described in Appendix 2 to the DPA. Which provider receives data depends on the features selected by the Customer.
6. Transfers outside the EU/EEA
Where personal data is processed outside the European Union or European Economic Area, Xirql follows Articles 44 et seq. GDPR. Depending on the recipient, transfers may rely on an adequacy decision, the EU–US Data Privacy Framework for participating US organisations, or European Commission Standard Contractual Clauses. Xirql assesses supplementary safeguards and the specific transfer where required.
7. Retention and deletion
Personal data is retained only for as long as the relevant purpose requires or legal duties require further retention. Contract and communication data is generally retained for the business relationship and afterwards only for applicable evidence, limitation and retention periods.
German commercial and tax retention periods depend on the document type and include ten years for specified accounting records, eight years for booking documents and six years for business correspondence and other required records.
Personal data processed on a Customer’s behalf is deleted or returned after the commissioned processing ends in accordance with the DPA, unless retention is legally required.
8. Data-subject rights
Subject to statutory requirements, data subjects have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21). Consent can be withdrawn at any time with future effect.
Where Xirql processes data solely for a Customer, that Customer is generally the contact for requests. Xirql forwards received requests to the controller and supports it under the DPA.
Data subjects may lodge a complaint with a supervisory authority, in particular the authority responsible for their residence, workplace or the place of an alleged infringement. For Xirql’s establishment, the competent authority is the Independent State Centre for Data Protection Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany, www.datenschutzzentrum.de.
9. Cookies and access to user devices
Xirql observes section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) when storing information on, or accessing information from, a user’s device. Strictly necessary storage or access may occur without consent where statutory conditions are met. Consent is requested in advance for non-essential analytics, marketing or comparable technologies; subsequent personal-data processing is additionally governed by the GDPR.
10. Security
Xirql applies technical and organisational measures appropriate to risk under Article 32 GDPR, including encrypted transmission, role-based access following least-privilege principles, protected administrative access, security logging, backups, recovery measures and logical Customer separation. Measures are reviewed as risks and technology develop.
11. Changes
This Privacy Policy is updated when processing, providers or legal requirements change. The published version applies.
12. Contact
Privacy enquiries may be sent by post to DataSquads UG (haftungsbeschränkt) at the address in section 1 or submitted through the Support function in the Xirql application.
← Back to sign in