Privacy Policy
XSY Agency is a project of SociiLabs LLC.
Effective Date: June 1, 2025
Last Updated: June 1, 2025
1. Who We Are
XSY Agency ("XSY", "we", "us", "our") is operated by SociiLabs LLC, a Wyoming limited liability company registered at:
30 N Gould St, Ste R
Sheridan, Wyoming 82801
United States
For all privacy-related inquiries, contact us at hey@xsy.agency.
2. Scope of This Policy
This Privacy Policy explains how SociiLabs LLC collects, uses, stores, shares, and protects personal information when you:
- Visit xsy.agency or any associated subdomains
- Subscribe to any XSY service plan
- Communicate with us via email, Slack, or any other channel
- Submit design requests or project briefs through our client portal
- Sign agreements or complete onboarding forms via Bonsai or any third-party tool we use
By using our website or services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use immediately.
3. Information We Collect
3.1 Information You Provide Directly
We collect personal information you voluntarily provide, including but not limited to:
- Identity information: Full name, company name, job title
- Contact information: Email address, phone number, physical address
- Billing information: Payment details processed via third-party payment processors (we do not store raw card data)
- Project information: Design briefs, brand assets, reference materials, product descriptions, and any other content you submit as part of onboarding or design requests
- Communications: Emails, Slack messages, Loom recordings, Figma comments, call notes, and any other correspondence
3.2 Information Collected Automatically
When you visit xsy.agency, we may automatically collect:
- Usage data: Pages visited, time spent, click patterns, referral URLs
- Device data: IP address, browser type and version, operating system, device identifiers
- Cookie data: Session cookies, preference cookies, and analytics cookies (see Section 9)
3.3 Information From Third Parties
We may receive information about you from third parties including:
- Bonsai (contract and billing platform): subscription status, payment history, agreement signatures
- Slack: communication history within your dedicated client channel
- Figma: design file access logs and comments
- Analytics providers: aggregated usage data
4. How We Use Your Information
We use collected information for the following purposes:
4.1 Service Delivery
- Providing, managing, and improving design services
- Processing and fulfilling design requests
- Communicating project status, revisions, and deliverables
- Scheduling and conducting strategy calls
4.2 Business Operations
- Processing subscription payments and invoicing
- Generating and executing service agreements and NDAs
- Maintaining client records and project history
- Managing client portal access and permissions
4.3 Legal and Compliance
- Complying with applicable laws and regulations
- Enforcing our Terms and Conditions
- Resolving disputes and investigating potential violations
- Responding to lawful requests from public authorities
4.4 Communications
- Sending service-related notices and updates
- Responding to inquiries and support requests
- Sending transactional emails related to your subscription
4.5 Improvement and Analytics
- Analyzing usage patterns to improve our website and services
- Conducting internal research and quality assurance
- Measuring service performance and client satisfaction
We will not use your information for unsolicited marketing without your explicit consent, and we will never sell your personal data to third parties.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal bases for processing your personal data are:
- Contract performance: Processing necessary to fulfill our service agreement with you
- Legitimate interests: Improving our services, preventing fraud, maintaining security
- Legal obligation: Compliance with applicable laws
- Consent: Where you have explicitly opted in (e.g., marketing communications)
You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. Confidentiality and NDAs
XSY takes client confidentiality seriously. We offer and honor Non-Disclosure Agreements (NDAs) at the commencement of any client engagement upon request.
Regardless of whether a formal NDA is in place, we treat all client-submitted materials — including design briefs, business information, product details, brand assets, and any proprietary content — as strictly confidential. We do not:
- Share your project materials with third parties outside our working team
- Use your brand assets, design work, or business information for any purpose other than delivering your requested services
- Disclose your identity or business details in case studies or portfolios without your explicit written consent
Our team members and any contractors engaged on your project are bound by confidentiality obligations.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share data in the following limited circumstances:
7.1 Service Providers
We share data with trusted third-party vendors who assist in delivering our services:
| Vendor | Purpose | Data Shared |
|---|---|---|
| Bonsai | Contracts, billing, client portal | Name, email, payment info |
| Slack | Client communication | Messages, files shared |
| Figma | Design delivery | Project files, comments |
| Loom | Design walkthroughs | Recorded video content |
| Calendly | Scheduling | Name, email, call time |
| Google Workspace | Email and internal ops | Email communications |
All service providers are contractually required to handle your data securely and only for the purposes we specify.
7.2 Legal Requirements
We may disclose your information if required by law, court order, or government authority, or if we believe disclosure is necessary to:
- Comply with a legal obligation
- Protect the rights or safety of XSY, SociiLabs LLC, our clients, or the public
- Prevent or investigate fraud or security incidents
7.3 Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of SociiLabs LLC's assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our website prior to any such transfer.
7.4 SociiLabs LLC Internal Operations
As XSY is a project of SociiLabs LLC, your data may be accessed by SociiLabs LLC personnel involved in delivering or supporting XSY services. This access is governed by the same confidentiality standards described in this policy.
8. Data Retention
We retain your personal information for as long as necessary to:
- Maintain an active client relationship
- Comply with legal, accounting, and regulatory obligations
- Resolve disputes or enforce agreements
Specific retention periods:
| Data Type | Retention Period |
|---|---|
| Active client records | Duration of subscription + 3 years |
| Billing and payment records | 7 years (tax compliance) |
| Design files and project assets | 2 years post-engagement unless otherwise agreed |
| Email and Slack communications | 2 years post-engagement |
| NDA and contract records | 7 years post-execution |
| Website analytics | 26 months (rolling) |
Upon request, we will delete your personal data sooner where we are not legally required to retain it.
9. Cookies
xsy.agency uses cookies and similar tracking technologies:
- Essential cookies: Required for site functionality (session management, security)
- Analytics cookies: Help us understand how visitors use our site (e.g., Google Analytics or equivalent)
- Preference cookies: Remember your settings and preferences
You may control cookie settings through your browser settings. Disabling certain cookies may affect site functionality.
We do not use cookies for advertising or retargeting purposes.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction, including:
- Encrypted data transmission (HTTPS/TLS)
- Access controls limiting data access to authorized personnel only
- Secure password management and authentication practices
- Regular review of our data handling procedures
However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you transmit data at your own risk.
In the event of a data breach that affects your rights and freedoms, we will notify you and relevant authorities as required by applicable law within 72 hours of becoming aware of the breach.
11. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure:Request deletion of your personal data ("right to be forgotten")
- Restriction: Request that we limit processing of your data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdrawal of consent: Withdraw consent at any time where processing is consent-based
California residents (CCPA): You have the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale (we do not sell personal information).
EEA/UK residents (GDPR/UK GDPR): All rights listed above apply to you in full.
To exercise any of these rights, contact us at hey@xsy.agency. We will respond within 30 days. We may need to verify your identity before processing your request.
12. Children's Privacy
XSY services are intended for business use by adults aged 18 and over. We do not knowingly collect personal information from children under the age of 13. If we become aware that a child under 13 has provided personal information, we will delete it immediately. If you believe a child has submitted information to us, please contact us at hey@xsy.agency.
13. International Data Transfers
SociiLabs LLC is based in the United States. If you are accessing our services from outside the United States, your information may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
By using our services, you consent to such transfer. Where required by law (e.g., GDPR), we rely on appropriate transfer mechanisms such as Standard Contractual Clauses.
14. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies before submitting any personal information.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last Updated" date at the top of this page
- Notify active clients by email for material changes
Continued use of our services after changes are posted constitutes your acceptance of the updated policy. If you do not agree to the changes, you must discontinue use of our services.
16. Contact Us
For any questions, concerns, or requests related to this Privacy Policy:
XSY Agency (a project of SociiLabs LLC)
Email: hey@xsy.agency
Address: 30 N Gould St, Ste R, Sheridan, Wyoming 82801, United States
We aim to respond to all privacy inquiries within 5 business days.