Privacy Policy & Cookie Policy
Effective Date: September 29, 2026
Last Updated: September 29, 2026
This Privacy Policy and Cookie Policy ("Policy") explains how XJOSE LLC, a Florida limited liability company ("XJOSE," "Company," "we," "us," or "our"), collects, uses, discloses, retains, and protects Personal Information when individuals visit our website, communicate with us, receive marketing from us, or otherwise interact with our business.
This Policy is a notice of our privacy practices. It is not intended to obtain consent where applicable law requires a separate affirmative consent, and it does not waive or limit any privacy right that cannot lawfully be waived or limited.
XJOSE primarily provides business-to-business consulting, custom software development, marketing, growth, technology, and related professional services. This Policy may therefore apply to business contacts, prospective clients, client personnel, vendors, contractors, website visitors, and other individuals whose Personal Information we process.
1. Scope of This Policy
This Policy applies to Personal Information that XJOSE collects or controls through xjose.com, related subdomains and web properties operated by XJOSE, our business communications, consultations, proposals, client onboarding, marketing activities, events, and other interactions with our business (collectively, the "Services").
This Policy does not govern the independent privacy practices of third parties, including websites, platforms, applications, advertising networks, payment processors, social networks, or other services that are not controlled by XJOSE.
When XJOSE processes Personal Information solely on behalf of a business client under that client's instructions, the client's privacy notice and the applicable Service Agreement or data processing agreement may govern that processing instead of, or in addition to, this Policy.
2. Our Privacy Roles
2.1 XJOSE as Controller or Business
XJOSE generally determines the purposes and means of processing Personal Information relating to our own website visitors, prospects, business contacts, vendors, marketing recipients, and administrative business operations. In those circumstances, XJOSE acts as a "controller," "business," or comparable responsible entity where those terms apply under applicable law.
2.2 XJOSE as Processor or Service Provider
When we process Personal Information on behalf of a client to provide contracted services, such as operating a marketing campaign, managing analytics, implementing software, processing client-provided audience information, or supporting a client-controlled system, XJOSE may act as a "processor," "service provider," "contractor," or comparable entity. In those circumstances, the client generally determines the purposes of the processing, subject to the applicable agreement and law.
2.3 Role May Depend on the Processing Activity
XJOSE may act in different privacy roles for different processing activities involving the same client relationship. Nothing in this Policy is intended to characterize XJOSE as a controller of information where applicable law or the parties' agreement treats XJOSE as a processor or service provider.
3. Personal Information We Collect
The categories we may collect depend on how you interact with us and may include:
3.1 Identifiers and Contact Information
Name, business email address, personal email address when provided, telephone number, business address, mailing address, IP address, online identifiers, account identifiers, and similar contact or identification information.
3.2 Business and Professional Information
Employer or business name, job title, professional role, industry, business needs, project information, professional profile information, and information supplied during consultations, proposals, or client engagements.
3.3 Commercial and Transaction Information
Services requested, considered, or purchased; proposals; contracts; order information; invoicing information; payment status; transaction history; and records associated with the business relationship. Payment-card and banking information may be collected directly by our payment processors rather than by XJOSE.
3.4 Device, Internet, and Network Activity
IP address, browser and device type, operating system, referring and exit pages, pages viewed, timestamps, approximate location derived from IP address, interaction data, advertising or device identifiers where available, and other technical information generated when you use our website.
3.5 Communications and Submitted Content
Emails, form submissions, support requests, consultation information, files, images, documents, feedback, survey responses, and other content you choose to provide.
3.6 Marketing, Preference, and Engagement Information
Communication preferences, subscription status, campaign source, advertising attribution, email delivery information, link clicks, website conversions, and other engagement information, subject to applicable consent and opt-out requirements.
3.7 Inferences
We may derive reasonable business-related inferences from information described above, such as likely service interests, business needs, lead qualification, campaign attribution, or preferred communication channels. We do not use such inferences to make decisions that produce legal or similarly significant effects about individuals unless separately disclosed and permitted by applicable law.
3.8 Approximate Location
We may infer approximate city, region, or country from an IP address. We do not intentionally collect precise geolocation through the public website unless we separately disclose the collection and obtain any consent required by law.
4. Sources of Personal Information
We may obtain Personal Information from the following categories of sources:
- Directly from you, including forms, emails, calls, consultations, contracts, and other communications.
- Automatically from devices and browsers, including through cookies, tags, pixels, server logs, and similar technologies.
- Clients and business partners where they lawfully provide information needed for an engagement, referral, campaign, or other business purpose.
- Service providers, such as analytics, advertising, CRM, email, hosting, fraud-prevention, and payment providers.
- Publicly available sources, including public business websites, professional directories, government records, professional networking services, and other information lawfully made available to the public.
- Third-party business data providers, where used and where their collection and provision of information are permitted by applicable law and contract.
5. How We Use Personal Information
We may use Personal Information for the following business and commercial purposes:
- responding to inquiries and consultation requests;
- preparing proposals, estimates, and Service Agreements;
- providing, administering, supporting, and improving the Services;
- communicating about projects, accounts, invoices, support, and contractual matters;
- authenticating users and protecting accounts, systems, and credentials;
- processing and reconciling payments and maintaining accounting records;
- operating, securing, debugging, maintaining, and improving our website and systems;
- measuring website, campaign, and marketing performance;
- performing analytics, attribution, testing, optimization, forecasting, and reporting;
- personalizing business communications and service recommendations;
- marketing our Services where permitted by law;
- detecting, investigating, and preventing fraud, abuse, security threats, and unlawful activity;
- enforcing contracts and protecting our legal rights;
- complying with legal, regulatory, tax, accounting, and recordkeeping obligations;
- evaluating or completing a financing, merger, acquisition, restructuring, asset sale, or similar corporate transaction; and
- other purposes disclosed at collection or otherwise permitted by applicable law.
We seek to collect and use information that is reasonably relevant to the disclosed purpose. Where applicable law requires consent for a particular processing activity, we will rely on consent rather than this Policy alone.
6. Legal Bases Where Applicable
Where a law such as the GDPR or UK GDPR applies to a particular processing activity, our legal basis may include:
| Processing Activity | Potential Legal Basis |
|---|---|
| Responding to business inquiries | Legitimate interests; steps requested before entering a contract |
| Providing contracted Services | Contractual necessity; legitimate interests |
| Billing and accounting | Contractual necessity; legal obligation; legitimate interests |
| Security and fraud prevention | Legitimate interests; legal obligation where applicable |
| Direct business marketing | Legitimate interests or consent, depending on the communication and jurisdiction |
| Non-essential cookies and behavioral advertising | Consent where required |
| Compliance and legal claims | Legal obligation; legitimate interests |
The legal basis depends on the specific activity, jurisdiction, relationship, and information involved. This Section does not represent that GDPR or UK GDPR applies to every interaction with XJOSE.
7. Client Data and Service Provider Processing
7.1 Client-Controlled Data
A business client may provide XJOSE with information concerning its customers, prospects, employees, contractors, users, audiences, or other individuals ("Client Data") so that we can perform Services. As between XJOSE and the client, rights in underlying Client Data remain allocated as stated in the applicable Service Agreement.
7.2 Client Responsibility
Unless XJOSE expressly agrees otherwise in writing, the client is responsible for determining whether it has a lawful basis to collect, disclose, upload, transfer, and instruct XJOSE to process Client Data, including providing required notices and obtaining required consents.
7.3 XJOSE Processing
XJOSE may process Client Data as reasonably necessary to provide, secure, administer, measure, analyze, optimize, and support the contracted Services and as otherwise permitted by the applicable Service Agreement, data processing agreement, and law.
7.4 Aggregated and De-Identified Information
Subject to applicable law and contractual restrictions, XJOSE may create and use aggregated, statistical, or de-identified information derived from the Services or Client Data for analytics, benchmarking, security, service improvement, research, product development, capacity planning, and similar legitimate business purposes, provided the information is not reasonably capable of identifying the client or an identifiable individual.
7.5 Data Processing Addenda
If applicable law requires a controller-processor, business-service-provider, or similar data processing agreement for an engagement, the parties may execute an appropriate data processing addendum addressing the relevant processing.
8. No Current Sale of Personal Information
As of the Effective Date of this Policy, XJOSE does not sell Personal Information or Client Data to data brokers or other third parties in exchange for monetary consideration.
We may disclose information to service providers, processors, contractors, technology vendors, professional advisers, advertising and analytics providers, and other recipients for the purposes described in this Policy. Depending on the jurisdiction and technology involved, certain advertising-related disclosures may be legally defined as "sharing," "targeted advertising," or, in some jurisdictions, a "sale" even when no money is paid for the information. Where applicable law provides an opt-out right for those activities, we will provide the required mechanism.
Our business and data practices may evolve. If XJOSE begins selling Personal Information, materially expands advertising-related sharing, or adopts another materially broader use of previously collected Personal Information, we will update the applicable privacy disclosures and provide any advance notice, consent mechanism, opt-out right, or other protection required by applicable law before applying the new practice where legally required.
We will not rely solely on a silent or retroactive amendment to this Policy to override a privacy choice or consent right where applicable law requires additional notice or consent.
9. How We Disclose Personal Information
We may disclose Personal Information to the following categories of recipients:
9.1 Service Providers and Processors
Hosting companies, cloud infrastructure providers, analytics providers, CRM systems, email providers, communications platforms, security vendors, payment processors, accounting systems, customer-support tools, project-management providers, and other vendors that perform services for us.
9.2 Advertising and Analytics Providers
Advertising networks, analytics providers, attribution vendors, social platforms, and comparable providers where used for measurement, optimization, audience development, remarketing, or advertising, subject to applicable consent and opt-out requirements.
9.3 Affiliates
Present or future entities under common ownership or control with XJOSE, where the disclosure is consistent with this Policy and applicable law.
9.4 Professional Advisers
Lawyers, accountants, auditors, consultants, insurers, banks, and similar professional advisers where reasonably necessary for professional services, compliance, or risk management.
9.5 Legal and Protective Disclosures
Courts, law enforcement, regulators, governmental authorities, counterparties, or others when we reasonably believe disclosure is required by law, legal process, contractual enforcement, fraud prevention, security, or protection of rights, property, or safety.
9.6 Corporate Transactions
Prospective or actual purchasers, investors, lenders, advisers, successors, or counterparties in connection with a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, due diligence process, or similar transaction, subject to commercially reasonable confidentiality protections where appropriate.
9.7 At Your Direction
Recipients that you direct us to interact with or to whom you authorize us to disclose information.
9.8 Aggregated or De-Identified Information
We may use and disclose information that has been aggregated or de-identified so that it does not reasonably identify an individual, subject to applicable law.
10. Advertising, Analytics, and Attribution
We may use analytics and advertising technologies to understand website use, measure campaign performance, attribute leads and conversions, optimize content, and advertise our Services. Technologies currently or potentially used as part of our marketing stack may include services provided by Google, Meta, LinkedIn, and comparable providers.
These providers may receive identifiers, IP address, browser or device information, page-event data, advertising-event data, conversion information, and similar information depending on our configuration and your consent or privacy choices.
Advertising and analytics providers may process information under their own terms and privacy policies in addition to processing information on our behalf. XJOSE does not control a third party's independent processing and is not responsible for the third party's privacy practices.
10.1 Google Analytics
We may use Google Analytics 4 ("GA4") to measure website traffic, referral sources, page interactions, approximate geography, browser/device characteristics, and conversion activity. Where required, non-essential analytics storage will not be activated until the user makes the applicable consent choice.
10.2 Advertising Pixels and Conversion Tags
We may deploy Google Ads tags, Meta Pixel, LinkedIn Insight Tag, or comparable technologies for advertising measurement, conversion tracking, audience creation, and remarketing. Such technologies are treated as non-essential tracking technologies where required by applicable law and by our consent configuration.
13. Global Privacy Control and Do Not Track
13.1 Global Privacy Control
Where XJOSE is legally required to recognize an opt-out preference signal, such as Global Privacy Control ("GPC"), and the signal applies to the relevant browser or device interaction, we will treat the signal as an opt-out request for the legally covered sale, sharing, or targeted-advertising activity as required by applicable law.
13.2 Do Not Track
Some browsers transmit a "Do Not Track" ("DNT") signal. Because DNT does not have a single universally applicable legal or technical standard, our response to DNT may differ from our response to legally recognized opt-out preference signals such as GPC.
14. Email and Marketing Communications
We may send service-related, transactional, administrative, and marketing communications. Marketing communications may include tracking technologies that provide delivery, open, click, and conversion signals. These signals can be incomplete or inaccurate because of privacy features, automated image loading, security scanners, proxy services, and other technical factors.
You may opt out of promotional email by using the unsubscribe mechanism included in the message or by contacting us. Opting out of marketing does not prevent us from sending communications reasonably necessary to administer an active business relationship, perform a contract, provide requested support, deliver legal notices, or address security matters.
We process commercial communications in accordance with applicable marketing and communications laws. A particular communication may be governed by different rules depending on the recipient, content, jurisdiction, and communication channel.
15. Artificial Intelligence and Automated Tools
We may use commercially available artificial intelligence, machine-learning, automation, transcription, coding, analytics, or productivity tools in our business and in providing Services.
We apply contractual and operational controls appropriate to the information and tool involved. We do not intentionally submit highly sensitive or regulated Personal Information to a third-party generative-AI service for unrestricted model training unless that practice is separately disclosed, contractually permitted, and legally authorized.
We do not currently use solely automated processing of website visitor Personal Information to make decisions that produce legal or similarly significant effects about an individual. If that practice changes, we will provide any additional notice, assessment, consent, or opt-out mechanism required by applicable law.
16. Data Retention
We retain Personal Information for no longer than reasonably necessary for the purposes for which it was collected or subsequently authorized, including to provide Services, maintain business and tax records, resolve disputes, enforce agreements, preserve security records, respond to legal claims, satisfy legal obligations, and maintain appropriate backup and archival systems.
Retention periods may depend on factors such as:
- the duration and nature of our relationship with the individual or client;
- the sensitivity, volume, and nature of the information;
- legal, tax, accounting, regulatory, and contractual requirements;
- applicable limitation periods and litigation holds;
- security, fraud-prevention, and abuse-prevention needs;
- the configuration and retention controls of service providers; and
- whether deletion is technically feasible from active systems, backups, or archives.
As an operational guideline, we may retain lead and prospect records while an opportunity remains active and for a reasonable period thereafter; client, contractual, accounting, and tax records may be retained for approximately seven years or longer where reasonably required; and security logs, analytics data, consent records, and marketing records may be retained according to the applicable operational, vendor, legal, or compliance need.
We may retain de-identified or aggregated information for longer periods where permitted by law and where the information is maintained in a form not reasonably capable of identifying an individual.
17. Data Security
XJOSE maintains administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, acquisition, use, alteration, disclosure, or destruction, taking into account the nature of the information and the circumstances of processing.
Safeguards may include, as appropriate:
- TLS or comparable encryption for data transmitted over public networks;
- access controls and least-privilege practices;
- authentication and credential-management controls;
- security patching and system maintenance;
- vendor and service-provider review appropriate to risk;
- confidentiality obligations for personnel and contractors;
- logging, backup, monitoring, and incident-response measures where appropriate; and
- administrative procedures for handling security and privacy incidents.
No security program, network, transmission method, or storage system can guarantee absolute security. Accordingly, we cannot warrant that information will never be accessed, used, disclosed, altered, lost, or destroyed through unauthorized or accidental means.
Where a security incident triggers a legally applicable notification obligation, XJOSE will provide or support legally required notifications in accordance with the applicable law and XJOSE's role in the affected processing.
18. International Data Transfers
XJOSE is based in the United States. Personal Information may be processed in the United States and in other jurisdictions in which our clients, personnel, contractors, or service providers operate. Those jurisdictions may have privacy laws different from the laws where you reside.
Where applicable law requires a specific transfer mechanism for a cross-border transfer, we will use an available lawful mechanism appropriate to the transfer, which may include contractual safeguards, an adequacy decision, an approved certification framework, a statutory derogation, or another mechanism recognized by applicable law.
We do not represent that a particular international-transfer framework applies to every processing activity merely because this Policy is accessible internationally.
19. Privacy Rights and Requests
Depending on where you reside, the law that applies to XJOSE, and the context in which we process your information, you may have rights such as:
- confirming whether we process your Personal Information;
- accessing Personal Information we maintain about you;
- correcting inaccurate Personal Information;
- requesting deletion, subject to exceptions;
- obtaining a portable copy of certain information;
- objecting to or restricting certain processing;
- withdrawing consent where processing is based on consent;
- opting out of legally defined sale, sharing, targeted advertising, or certain profiling;
- limiting certain uses or disclosures of Sensitive Personal Information where the right applies;
- appealing a privacy-request decision where applicable law provides an appeal right; and
- receiving non-discriminatory treatment for exercising a legally protected privacy right.
19.1 How to Submit a Request
Submit a request by emailing [email protected] with the subject line Privacy Rights Request. If a web-based privacy-request form is made available, you may also use that form.
19.2 Verification
We may need to verify your identity or authority before acting on a request. Verification requirements will be proportionate to the nature of the request and information involved. We may request information reasonably necessary to match you to our records or confirm an authorized agent's authority.
19.3 Response Timing
We will acknowledge and respond to verified requests within the period required by the law applicable to the request. Different privacy laws provide different deadlines, extension rights, verification rules, exceptions, and appeal procedures; therefore, this Policy does not impose a shorter universal deadline on XJOSE than applicable law requires.
19.4 Requests Relating to Client-Controlled Data
If your request concerns Personal Information that XJOSE processes solely on behalf of one of our clients, we may refer the request to that client or instruct you to contact the client directly. We may assist the client as required by our agreement and applicable law.
20. Florida Privacy Disclosures
20.1 Florida Information Protection Act
XJOSE handles Personal Information subject to the Florida Information Protection Act ("FIPA"), Fla. Stat. § 501.171, in accordance with obligations applicable to XJOSE, including reasonable measures to protect covered information and legally required breach-notification procedures.
20.2 Florida Digital Bill of Rights
The Florida Digital Bill of Rights ("FDBR"), Fla. Stat. §§ 501.701–501.722, has specific statutory applicability requirements. To the extent XJOSE is a covered controller for a particular processing activity, eligible Florida consumers may exercise the rights provided by that law, subject to its definitions, exceptions, authentication requirements, and other statutory conditions.
Where the FDBR applies, covered rights may include confirmation and access, correction, deletion, data portability, and opt-out rights concerning targeted advertising, sale of Personal Information, or qualifying profiling. We will provide any privacy notice, request mechanism, appeal process, sensitive-data consent, or data-protection assessment required of XJOSE by the statute.
21. California Privacy Disclosures
California law may provide additional rights to California residents where XJOSE satisfies the legal definition of a covered "business" for the relevant processing. Nothing in this Section represents that every CCPA requirement applies to XJOSE regardless of statutory applicability.
21.1 Categories of Personal Information
Depending on the interaction, categories described by California law that we may collect can include identifiers; customer-record information; commercial information; internet or other electronic-network activity; approximate geolocation; professional or employment-related information; and inferences derived from such information.
21.2 Purposes and Sources
The sources from which we collect information are described in Section 4. The business and commercial purposes for which we use information are described in Section 5.
21.3 Disclosure Categories
Categories of recipients to whom information may be disclosed are described in Section 9. Depending on the technology used, disclosures to advertising providers may constitute "sharing" for cross-context behavioral advertising under California law.
21.4 Sale and Sharing
XJOSE does not currently sell Personal Information to data brokers or other third parties for monetary consideration. If advertising-related disclosures constitute a "sale" or "sharing" under applicable California law, eligible consumers may exercise the legally required opt-out right through our privacy controls, a recognized opt-out preference signal such as GPC where applicable, or another method we make available.
21.5 California Rights
Where the CCPA applies, eligible California residents may have rights to know/access, delete, correct, opt out of sale or sharing, limit certain uses of Sensitive Personal Information, and receive non-discriminatory treatment, subject to statutory exceptions and verification rules.
21.6 Notice at Collection
Where legally required, we will provide a notice at or before the point of collection that identifies the applicable categories of Personal Information and purposes of collection and provides access to this Policy and relevant privacy choices.
22. EEA, UK, and Other International Rights
If GDPR, UK GDPR, or another international privacy law applies to our processing of your Personal Information, you may have rights provided by that law, which can include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to complain to an applicable supervisory authority.
If our processing is based on legitimate interests where that legal basis is available, the legitimate interests may include operating and securing our business, communicating with business contacts, preventing fraud, improving Services, performing B2B marketing where permitted, enforcing agreements, and protecting legal rights. We consider the nature of the information and effects on individuals when relying on legitimate interests.
If GDPR or UK GDPR applies and you believe our processing violates applicable law, you may have the right to complain to the competent supervisory authority in your jurisdiction.
23. Children's Privacy
Our Site and Services are designed for businesses and adults and are not directed to children. We do not knowingly use the public website to collect Personal Information from children under 13 in a manner subject to the Children's Online Privacy Protection Act ("COPPA") without the required authorization.
We do not knowingly sell or share Personal Information of children in circumstances requiring affirmative authorization under applicable law. If we learn that Personal Information was collected from a child in violation of applicable law, we will take reasonable steps to address the information as legally required.
24. Sensitive Personal Information
Our public website is not intended to collect highly sensitive information such as Social Security numbers, government identification credentials, account passwords for financial institutions, precise geolocation, biometric identifiers used for unique identification, health information, or similarly regulated information unless we specifically request the information for a legitimate and legally permitted purpose.
Please do not send highly sensitive or regulated Personal Information through ordinary web forms or unsecured email unless we specifically request it and provide an appropriate method for transmission.
If a client engagement requires XJOSE to process sensitive or regulated data, the applicable Service Agreement or data processing addendum may establish additional safeguards, instructions, restrictions, and responsibilities.
25. Third-Party Websites and Services
Our Site may contain links, embedded content, integrations, or connections to services operated by third parties. A link or integration does not mean XJOSE controls or endorses the third party's privacy practices. Information you provide directly to a third party is governed by that third party's privacy notice and terms.
26. Business Transfers
Personal Information and contractual rights relating to data may be evaluated, disclosed, or transferred as part of an actual or proposed merger, acquisition, investment, financing, corporate reorganization, bankruptcy, sale of assets, or similar transaction. We may use confidentiality agreements, diligence controls, data minimization, or other reasonable safeguards appropriate to the transaction.
A successor's subsequent use of Personal Information remains subject to applicable law and to privacy commitments that legally continue to bind the information.
27. Changes to This Policy
We may update this Policy to reflect changes in our business, technology, vendors, Services, or legal obligations. The "Last Updated" date indicates the date of the current version.
If a change materially affects how we use or disclose previously collected Personal Information, we will provide any notice, consent opportunity, or privacy choice required by applicable law before applying the change where legally required.
We do not treat continued website use as a substitute for affirmative consent where applicable law requires affirmative consent.
28. Relationship to Other Agreements
This Policy should be read together with XJOSE's Terms and Conditions / Terms of Service and any applicable Service Agreement, statement of work, data processing addendum, confidentiality agreement, or other written agreement.
If XJOSE processes Client Data under a signed agreement containing specific data-protection terms, those specific terms control the parties' contractual obligations concerning that Client Data to the extent of a direct conflict with this general Policy.
Contractual disclaimers or limitations contained in another agreement do not waive statutory privacy rights where applicable law prohibits waiver.
29. Contact and Privacy Requests
Questions, privacy inquiries, and privacy-rights requests may be directed to:
XJOSE LLCAttn: Privacy & Data Protection
Florida, United States
Email: [email protected]
When submitting a rights request, please provide enough information for us to identify the relevant interaction and process the request securely. Do not send passwords, full payment card numbers, Social Security numbers, or other highly sensitive information by ordinary email.