Legal and privacy

Privacy policy

This policy explains how personal data is processed when you visit xencra.com, submit a project request, contact Xencra or discuss a potential project with us.

Last updated: 15 July 2026

Controller and scope

The controller of personal data described in this policy is Lusfera OÜ. Xencra is a service brand operated by Lusfera OÜ.

This policy applies to xencra.com, the project request form and project-related communication initiated through the website or published contact details.

Personal data we process

We process only the information reasonably needed to respond to enquiries, assess projects, provide services, operate the website and meet legal obligations.

Please do not send special-category or otherwise sensitive personal data unless it is necessary for the project and has been agreed in advance.

  • Contact details such as your name, email address, telephone number, company and role.
  • Project information, selected project type and status, budget range, decision authority, business requirements, attachments and other content included in your project request or correspondence.
  • Communication history, including emails, meeting notes and decisions related to a potential or active project.
  • Contract, invoicing and transaction information if a commercial relationship begins.
  • Technical request data such as IP address, browser type, requested URL, timestamp, response status and security events.
  • For language suggestions, the server may derive a two-letter country code from the request IP address using a locally stored GeoLite2 Country database.
  • If analytics consent is granted, analytics data such as page path, permitted campaign parameters, referral source, selected language, browser and device category, approximate location, and events related to pricing views, case study views, project form progress, project brief downloads and successful project requests. Free-text form content, names, email addresses, company names, attachment names and request identifiers are not sent to Google Analytics.

Purposes and legal bases

We process personal data only where there is an appropriate legal basis.

  • To answer enquiries, evaluate project fit, prepare proposals and take steps requested before entering into a contract.
  • To perform contracts, deliver services, manage projects and communicate with clients.
  • To operate, maintain and secure the website and technical infrastructure based on our legitimate interests.
  • To suggest a suitable language version based on browser language and approximate country, based on our legitimate interest in improving website usability while preserving visitor choice.
  • To prevent misuse, investigate security incidents and establish, exercise or defend legal claims based on our legitimate interests.
  • To comply with accounting, tax, regulatory and other legal obligations.
  • On the basis of consent where consent is specifically requested. Consent may be withdrawn at any time.

Website and server logs

When you access the website, the web server or infrastructure provider may automatically record technical request information. This is standard operational data used to deliver the requested page, troubleshoot errors and protect the service.

Technical logs are not used by Xencra to build advertising profiles or to make automated decisions about visitors.

Language preference and approximate country

To suggest a suitable language version, Xencra may derive a two-letter country code from the request IP address using the MaxMind GeoLite2 Country database stored locally on our server. The visitor's IP address is not sent to MaxMind for this lookup.

The suggestion may also consider the browser language. The website does not automatically redirect the visitor, and the final language choice remains with the visitor.

An explicit language choice may be stored in local storage under xencra_locale_preference_v1 for up to 12 months. It is used only to remember the selected language and may be removed by clearing the website's browser data.

Cookies and analytics

Xencra uses Google Analytics only after the visitor gives analytics consent. Before consent or after rejection, the Google Analytics tag is not loaded and no analytics data is sent to Google.

Analytics is used to understand website traffic, acquisition sources, use of pricing and case study pages, project form progress, project brief downloads and successful project requests. The legal basis is consent.

After consent, Google Analytics may use first-party cookies named _ga and _ga_<container-id>, which have a default expiry of up to two years. Browser restrictions may shorten this period.

The analytics choice is stored in local storage under xencra_analytics_consent_v1 for up to 12 months so the website can remember the decision. This preference is used only to control analytics loading.

The visitor can reject analytics or withdraw consent at any time through Analytics settings in the website footer. Withdrawal prevents future analytics loading and the website attempts to remove existing Xencra analytics cookies.

Advertising storage, advertising user data, advertising personalisation and Google Signals are not enabled. Xencra does not send free-text fields, names, email addresses, company names, attachment names or request identifiers to Google Analytics.

For visitors in the European Economic Area, Switzerland or the United Kingdom, Google states that IP addresses are used only to derive approximate location before being discarded and are not logged or stored.

Language versions use separate localized URLs. The optional language preference is stored locally in the browser and is not used for advertising or cross-site tracking.

Recipients and service providers

Access to personal data is limited to people and service providers who need it for the purposes described in this policy.

We do not sell personal data.

  • Hosting, server and infrastructure providers.
  • Email and communication service providers.
  • Google Analytics, only after analytics consent, for website measurement and reporting.
  • Technical contractors or subcontractors involved in an agreed project.
  • Accounting, legal and professional advisers where necessary.
  • Public authorities where disclosure is required by law.

International data transfers

Where a service provider processes personal data outside the European Economic Area, we use an applicable adequacy decision, contractual safeguards or another lawful transfer mechanism where required.

Information about relevant safeguards can be requested by contacting info@xencra.com.

Retention

Project enquiries and submitted attachments that do not result in an engagement are generally deleted or anonymised within 24 months after the last meaningful contact, unless longer retention is necessary for legal claims, security investigation or another lawful reason.

Client, contract, project and financial records are retained for the duration of the relationship and afterwards for the periods required by applicable contract, accounting, tax and limitation rules.

Technical logs are retained only for as long as reasonably necessary for service operation, troubleshooting, security monitoring or incident investigation.

Google Analytics user-level and event-level data is configured for 14 months with reset on new activity disabled. Standard aggregated reports may remain available for longer under the Google Analytics reporting model.

Your data protection rights

Depending on the circumstances, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, data portability or object to processing based on legitimate interests.

Where processing is based on consent, you may withdraw that consent without affecting processing carried out before the withdrawal.

These rights are not absolute and may be limited where continued processing is required by law or is necessary for legal claims.

You may also lodge a complaint with the Estonian Data Protection Inspectorate.

Security

We use reasonable technical and organisational safeguards intended to protect personal data against unauthorised access, loss, alteration or disclosure.

No internet transmission or storage system can be guaranteed to be completely secure. If a relevant personal data breach occurs, we will assess and handle it in accordance with applicable law.

External links and policy changes

The website may link to third-party websites. Their privacy practices are controlled by those third parties and should be reviewed separately.

We may update this policy when our services, technology or legal obligations change. The latest version and its update date will be published on this page.

Privacy contact

Privacy and data requests

Email us to exercise your rights or ask how your personal data is processed.