Legal

Privacy Policy

Last updated: March 27, 2026

SevenX Ltd ("SevenX," "we," "us," or "our") is a software development, technology consulting, and training company. This Privacy Policy explains how we collect, use, store, and protect your information when you engage our services, visit our website at sevenxhq.com, use any platforms or tools we build or maintain, or participate in our training programs (collectively, the "Services").

By using our Services, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Client and Contact Information

When you engage SevenX for services, we may collect:

  • Full name, job title, and role within your organization
  • Email address and phone number
  • Company name, address, and billing details
  • Payment and invoicing information

1.2 Project and Engagement Data

In the course of delivering software development, fractional CTO, team management, and consulting services, we may receive or create:

  • Project requirements, specifications, and documentation
  • Source code, design files, and technical assets
  • Access credentials to client systems (stored securely and used only for authorized purposes)
  • Communication records related to active engagements (emails, Slack messages, meeting notes)
  • Project management data (task assignments, timelines, status updates)
  • Technical architecture documents, system designs, and infrastructure configurations

1.3 Managed Team and HR Data

When SevenX manages technical teams on your behalf (including payroll, HR, recruitment, and team operations), we may collect and process:

  • Employee and contractor personal details (names, contact information, identification documents)
  • Payroll data (compensation, tax information, banking details)
  • Employment records (contracts, performance reviews, leave records, onboarding documentation)
  • Recruitment data (candidate applications, interview records, assessments)
  • Benefits and insurance information
  • Organizational charts, reporting structures, and role descriptions

This data is collected and processed solely to deliver the managed team services you have engaged us to provide. We act as a data processor on your behalf for this information, and you remain the data controller.

1.4 Training and Education Data

When you participate in our training programs (including CodeX, DesignX, DataX, or any workshops), we may collect:

  • Name, email address, and contact details
  • Enrollment and attendance records
  • Assessment results and course progress
  • Certificates and completion records
  • Feedback and survey responses

1.5 Job Applicant Data

When you apply for a position at SevenX, we may collect:

  • Resume/CV and cover letter
  • Professional references
  • Assessment and interview records
  • Background information relevant to the role

1.6 Website and Technical Data

We automatically collect:

  • IP address and approximate location
  • Browser type and version
  • Device type and operating system
  • Pages visited and session duration
  • Error logs and performance data

1.7 Cookies and Similar Technologies

We use cookies and similar tracking technologies to maintain sessions, remember preferences, and understand how our website is used. See Section 8 for details.

2. How We Use Your Information

We use the information we collect to:

  • Deliver, manage, and improve our software development, fractional CTO, managed team, and consulting services
  • Administer payroll, HR, recruitment, and team operations on behalf of clients
  • Administer training programs, track progress, and issue certifications
  • Process payments and manage billing
  • Communicate with you about projects, support, and service updates
  • Respond to inquiries and provide customer support
  • Comply with legal and contractual obligations
  • Improve our internal processes, methodologies, and service offerings
  • Maintain security and prevent fraud
  • Generate anonymized, aggregated insights for internal analysis and benchmarking

2.1 AI and Automation

Where we use AI tools or automation in the course of delivering services (for example, code review, document processing, or analytics), we do so in accordance with client agreements. We do not train AI models on identifiable client data without explicit consent. We may use anonymized, non-identifiable data derived from engagements to improve our internal tools and processes.

2.2 Communications

We may contact you for service-related purposes such as project updates, invoice reminders, training schedules, and security notices. You may opt out of non-essential communications at any time, but service-critical messages (such as security alerts, billing notices, and contractual communications) cannot be opted out of.

We do not sell your personal information to third parties. We do not use your data for advertising purposes.

3. Client Data Ownership and Separation

3.1 Work Product and Licensing

By default, all source code, designs, documentation, and other work product created by SevenX during a client engagement is jointly retained by SevenX and licensed to the Client. The Client receives a license to use the deliverables for their business purposes upon full payment, while SevenX retains the right to reuse code patterns, architectural approaches, components, and non-client-specific elements in future work. Specific ownership or exclusive licensing arrangements may be established in the applicable Statement of Work or service agreement, which will take precedence over this default.

3.2 Data Isolation

Client project data is kept separate from other clients' data. Access is restricted to SevenX team members assigned to that engagement and is managed through role-based access controls.

3.3 SevenX Intellectual Property

General methodologies, frameworks, internal tools, templates, processes, training materials, and non-client-specific knowledge developed or refined by SevenX remain the sole intellectual property of SevenX, including any improvements, refinements, or derivative works created during a client engagement. SevenX also retains the right to reuse code patterns, architectural solutions, and technical approaches developed during engagements, provided that client-specific business data and confidential information are not disclosed.

3.4 Managed Team Data

Where SevenX manages teams on your behalf, you retain ownership of the underlying employee and HR data. SevenX processes this data as a service provider acting on your instructions. Upon termination of the managed team engagement, SevenX will return or securely delete this data in accordance with Section 5.

4. How We Share Your Information

We share your information only in the following circumstances:

4.1 Service Providers and Subcontractors

We use third-party service providers and, where necessary, subcontractors to deliver our Services. These parties process data on our behalf and are contractually required to protect your information. Categories include:

  • Cloud hosting and infrastructure providers
  • Project management and collaboration tools
  • Payment processors
  • Payroll and HR administration platforms
  • AI and development tool providers
  • Communication platforms (email, Slack, etc.)
  • Recruitment and applicant tracking systems

SevenX selects service providers at its discretion based on operational needs and may change providers without prior notice, provided equivalent data protection standards are maintained.

4.2 With Your Organization

If you are a member of a client organization, a managed team member, or a training participant sponsored by an organization, relevant information (such as project status, performance data, or training progress) may be shared with authorized contacts within your organization.

4.3 Legal Requirements

We may disclose your information if required to do so by law, in response to a valid legal process, or to protect the rights, property, or safety of SevenX, our clients, our team, or the public.

4.4 Business Transfers

If SevenX is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will make reasonable efforts to notify affected parties of any such change.

5. Data Retention

5.1 Active Engagements

We retain client and project data for the duration of the engagement and any applicable support, warranty, or transition period.

5.2 Post-Engagement

After an engagement concludes:

  • Client-provided data (documents, credentials, business data, and content supplied by the client) is retained for 90 days to allow for handoff and transition, unless a different period is specified in the service agreement. After the retention period, client-provided data is deleted from our active systems. Clients may request data export before the retention period expires.
  • Work product created by SevenX (source code, designs, architecture documentation, and technical deliverables) is retained by SevenX in accordance with our intellectual property rights as described in Section 3. Client-provided data embedded in work product will be removed or anonymized after the retention period.
  • We retain the right to keep anonymized, non-identifiable project metrics and learnings for internal analysis and process improvement indefinitely.

5.3 Managed Team Data

HR, payroll, and employee data from managed team engagements is retained for 90 days after the engagement ends. Clients may request earlier export. After the retention period, this data is deleted from our active systems unless retention is required by applicable employment or tax law.

5.4 Training Records

Training enrollment, completion, and certification records are retained for up to 3 years after program completion, or as required for certification validity. Participants may request deletion of their records at any time.

5.5 Financial Records

Invoicing and payment records are retained in accordance with applicable tax and accounting regulations.

6. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest
  • Role-based access controls for all systems and client data
  • Secure credential storage (client access credentials are stored in encrypted vaults and rotated as appropriate)
  • Regular security reviews and updates
  • Access to production systems restricted to authorized personnel

While we take reasonable steps to protect your information, no method of transmission or storage is 100% secure. SevenX is not liable for unauthorized access resulting from circumstances beyond our reasonable control. If you become aware of a security incident, contact us immediately through our Contact Form.

7. Your Rights

You may have the following rights regarding your personal data, subject to applicable laws in your jurisdiction:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate or incomplete data.
  • Deletion: Request that we delete your personal data, subject to our retention policies, contractual obligations, and legal requirements.
  • Portability: Request your data in a structured, machine-readable format.
  • Restriction: Request that we limit how we process your data.
  • Objection: Object to the processing of your data in certain circumstances.
  • Withdraw Consent: Where processing is based on consent, withdraw your consent at any time.

To exercise any of these rights, contact us through our Contact Form. We will respond within 30 days. SevenX reserves the right to verify your identity before processing any data rights request and may decline requests that are excessive, repetitive, or unfounded.

8. Cookies

8.1 What We Use

  • Necessary cookies: Session management, authentication, and security. These are required for our website and platforms to function.
  • Functional cookies: User preferences and settings.
  • Analytics cookies: Understanding usage patterns and improving our services.

8.2 Your Choices

You can control cookies through your browser settings. Disabling necessary cookies may prevent you from using parts of our website or platforms. We do not use cookies for advertising or third-party tracking.

9. International Data Transfers

Your data may be processed in jurisdictions other than your own. SevenX operates with team members across multiple countries. By engaging our Services, you consent to the transfer and processing of your data in any jurisdiction where SevenX or its service providers operate. We take reasonable steps to ensure appropriate safeguards are in place in accordance with applicable data protection laws.

10. Children's Privacy

Our Services are not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us through our Contact Form and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes take effect when posted to our website. We will make reasonable efforts to notify you of significant changes through our website or by email. Your continued use of our Services after changes are posted constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or how we handle your data, reach out through our Contact Form.

© 2026 SevenX Ltd. All rights reserved.