Skip to content

Privacy notice · 31 July 2026

How XNLAB handlesenquiry data.

This notice describes the current website and enquiry flow in plain language. It records what the implementation does without claiming certification or completed legal review.

01

Who is responsible

Xnlab Studio is currently an independent, unincorporated studio. Pablo García Frade is the accountable operator. The public contact for data questions and requests is studio@xnlab.io.

A registered company, tax identity or public office address is not claimed on this site. The legal trading identity for a paid engagement must be confirmed in its private contract before work begins.

02

What the enquiry collects

The written brief can collect name, work email, organisation, website, sector, location, relevant surface, current pressure, timing, project scale, contact preference, relevant links, free-text context and a consent timestamp.

Delivery systems also record the submission time, accepted delivery channel and operational status needed to route the request, prevent rapid duplicate submissions and diagnose a failed delivery.

03

Why it is used

Enquiry data is used to assess fit, reply, prepare a requested commercial next step, maintain a reliable record of the exchange and protect the intake route from abuse.

XNLAB does not send form contents, contact details, supplied URLs, free text or commercial scale to website analytics.

04

Delivery and providers

The site is hosted by Vercel. Depending on the environment approved for launch, a brief may be delivered through Resend email, an authenticated private intake endpoint, or both. A configured CRM or webhook destination may receive the same brief only to operate the enquiry flow.

These providers may process data outside the visitor's country. Their contractual safeguards and the final production configuration require professional review before launch.

05

Analytics and cookies

The site uses Vercel Web Analytics for aggregate website and funnel measurement. Custom events contain only enumerated route, placement, language, public project and delivery-status groups. They contain no personal form values.

XNLAB does not add advertising pixels or behavioural profiles. Whether the final analytics configuration requires consent in each target jurisdiction remains a matter for professional review.

06

Retention and requests

No final retention period has been approved. Until a reviewed policy is adopted, enquiry data is kept only while needed to assess and answer the request, operate any resulting engagement, meet essential record obligations or resolve a security or delivery issue, then deleted or anonymised where practical.

To request access, correction, deletion, restriction or a copy of personal data, write to studio@xnlab.io from the address connected to the request. Identity may need to be verified before disclosure or deletion.

07

Security and review boundary

The implementation uses encrypted transport, server-side validation, bounded inputs, spam controls, scoped secrets and restricted analytics properties. No internet service can promise absolute security.

This notice is an operational disclosure, not legal advice or a claim of formal compliance. Data-controller details, retention, international transfers and the contract for a paid Business Leak Diagnostic require professional legal review.