Privacy Policy

Xono provides software that organisations use to receive and investigate reports of wrongdoing — often from people who would face real consequences if their identity became known. This policy explains what we do with personal information, and, just as importantly, which parts are our responsibility and which belong to the organisation you work for.

WHICH ORGANISATION IS RESPONSIBLE FOR YOUR INFORMATION

This is the most important section, because the answer differs depending on why you are here.

If you have made a report, or you handle reports, through your employer’s Xono account — your employer is responsible for that information. They decide what is collected, why, how long it is kept, and who inside their organisation can see it. We act on their instructions and provide the software. In data-protection terms, they are the controller and we are the processor.

If you want to exercise your rights over that information, or you have a complaint about how it is being handled, contact your own organisation first — they hold the decisions. You can contact us too, and we will help, but for most requests we will need to direct you to them.

If you are visiting our website, contacting us, or signing up as a customer — we are responsible. That is ordinary business information and this policy governs it directly.

WHAT INFORMATION IS INVOLVED

Through your employer’s Xono account:

  • Reports and the conversations about them — what was reported, any messages exchanged, files attached, and the record of how the case was handled.
  • Reporter details, which depend on the setting your organisation has chosen — see the next section.
  • Case-handler accounts — the names, email addresses and sign-in records of your organisation’s own staff who investigate reports.
  • Records of who did what — an audit trail showing actions taken on a case, which exists so that an investigation can be shown to have been handled properly.

Directly by us: the details you give us when you get in touch or become a customer — name, email address, phone number, organisation, and billing details.

ANONYMITY, AND WHAT IT ACTUALLY MEANS HERE

Your organisation chooses one of three settings, and it determines what we hold about you:

  • Anonymous — no link is created between a report and any account. We do not know who you are, and no one can look it up later.
  • You choose — you decide, per report, whether to identify yourself.
  • Identifiable — reports carry the reporter’s identity.

If you are unsure which applies to you, ask your organisation, or check what the app tells you before you submit.

Making an anonymous report and still being able to follow it up. When you report anonymously, you are given a one-time credential so you can check back and exchange messages without ever identifying yourself. We store only a scrambled form of it, never the credential itself, and it is shown to you exactly once. We cannot recover it for you — if it is lost, we have no way to reconnect you to that report. That is the necessary consequence of not knowing who you are.

COOKIES

Our website and dashboard set no cookies requiring your consent. We checked this directly rather than assuming it. Signing in uses your browser’s local storage rather than a session cookie, and our website analytics are self-hosted and record nothing on your device — which is why you will not see a cookie banner.

One page is different, and we would rather say so than let you find it. The sign-up page runs a bot check from Cloudflare, to stop automated abuse creating accounts. To do that, your IP address and some basic details about your browser reach Cloudflare, and Cloudflare may store something on your device for the check itself. It runs only on that one page, it is not analytics, and it is not used to track you anywhere else. We treat it as strictly necessary to offer sign-up safely, which is the category that does not require a consent banner.

WHAT THE MOBILE APP STORES ON YOUR DEVICE

The app keeps some information on your own phone, and one part of that is worth explaining because it exists specifically to protect you.

When you make an anonymous report, the app saves the reference for that report on your device. That is how you can come back and check on it later without us ever holding a record connecting you to it. If we kept that link on our servers instead, we would know who made which report — which is precisely what we are trying to avoid.

Your phone’s own backup may include it, and that is worth knowing. If you use Google or Apple device backup, the reference is backed up with the rest of the app’s data to your own cloud account. It does not come to us, and it does not go to your employer — the point above still holds, because we never hold the link at all. It does mean the reference can survive you replacing your phone, which is usually helpful given we cannot recover it for you. If you would rather it existed nowhere but the handset, turn off backup for this app in your phone’s settings.

The app also stores your sign-in state, your messages, and your preferences locally, so that it works and so conversations load without being re-fetched each time.

None of this requires your consent, because it is necessary for the app to do what you asked it to do. We describe it here because you should know what is held on your device, not because permission is needed.

Deleting the app deletes what it has stored locally. If you made anonymous reports, this includes the only copy of the references to them — we cannot recover those for you afterwards, for the same reason described above.

WHY WE ARE ALLOWED TO PROCESS THIS INFORMATION

For reports and case data, the lawful basis is your organisation’s, not ours — typically their legal obligations under whistleblowing law, or their legitimate interest in investigating misconduct. We process it under our contract with them.

For our own business contacts, we rely on our legitimate interest in operating and providing the service.

YOUR RIGHTS, AND ONE LIMIT WE WANT TO BE STRAIGHTFORWARD ABOUT

You have the usual rights over your personal information: to see it, correct it, ask for its deletion, object to how it is used, and receive a copy. For anything held through your employer’s account, those requests go to them.

Closing your account does not delete reports you have made, and this is deliberate.

We want to explain this rather than bury it. A report, once made, becomes part of your organisation’s own records — they may be legally required to retain it, an investigation may still be running, and the audit trail proving a case was handled properly has to remain intact. If a report vanished whenever a reporter closed their account, the record could be erased by pressure on the reporter, which is the opposite of what a whistleblowing system is for.

So closing your account removes the account. Reports remain with your organisation as their records, subject to their retention policy.

If you reported anonymously, there was never a link between you and the report to remove.

WHO ELSE IS INVOLVED

We use a small number of service providers to deliver the platform — for sending email, storing files, delivering notifications, and processing payments. We publish a current list of them, what each does, and where they operate, rather than embedding it here where it would go out of date.

WHERE YOUR INFORMATION IS HELD

Our systems run in Germany, with encrypted file storage and backups in the United Kingdom and Ireland.

If you are in a country outside those, your information is transferred to and processed in them. Where the law requires a specific safeguard for that transfer, we rely on the standard mechanisms available, including the arrangements our service providers maintain.

HOW WE PROTECT IT

Report content is encrypted with a separate key for each customer organisation, and our AI features run on infrastructure we operate ourselves rather than being sent to an external AI provider.

CONTACT AND COMPLAINTS

Xono Limited is the company behind this service — registered in the Isle of Man, company number 134387C, registered office 96 Fairways Drive, Mount Murray, Santon, IM4 2JF. We are registered with the Isle of Man Information Commissioner under Data Controller Reference IC513032I. For any privacy question, including requests about information we hold directly:

  • Information Officer: Marc de Villiers
  • Email: marc@xono.online
  • Phone: +27 76 603 8577
  • Post: G3 Highbury, 353 Main Road, Cape Town, 7708

If you are unhappy with our response, you can complain to your local data protection authority — in South Africa, the Information Regulator; in the UK, the Information Commissioner’s Office; in the EU, your national supervisory authority.