Privacy Policy

Last Updated: 05/10/2026

1. Introduction — how we handle your data

This policy explains what personal data xDV DataVault Ltd ("we", "us", "our") collects, how we use it, who we share it with, and the choices and rights you have. xDV DataVault Ltd (XDV DATAVAULT LTD, a company registered in England and Wales, company number 17253184, registered office 157 Whitehall Road, Bradford, BD12 9LE, United Kingdom; ICO registration reference 00014970519) is the controller of personal data processed through the Platform. This policy applies wherever you live. Sections 7A and 7B give extra information for people in the European Economic Area and the United States.

2. What we collect

xDV DataVault is a research platform. Some of what we collect runs your account; the rest is research data that you choose to contribute and that we license, in pseudonymised form, to research and analytics customers. This section lists everything, so that what we say here matches what our apps do and what we declare to the app stores.

2.1 Running your account

  • Account information — name, email address, password, account type and, for corporate accounts, organisation details.
  • Identity verification (KYC) — name, date of birth, address, nationality and identity-document details. We are legally required to collect this to meet our anti-money-laundering obligations. It is used for that purpose only and is never included in the research data we license.
  • Sanctions and politically-exposed-person (PEP) screening — as part of identity verification, we check the identity details above against the UK Sanctions List (a public list published by OFSI, part of HM Treasury) and, where a screening vendor is engaged, against politically-exposed-person and adverse-media indicators. This is a distinct check from standard KYC identity verification, described separately in section 4.
  • Payout bank details — the account holder name and bank account details you provide when you request a withdrawal (for example sort code and account number in the UK, IBAN in Europe, or routing and account number in the US), so we can pay you by bank transfer.
  • Usage data — how you use the Platform, including earnings and withdrawal history.
  • Technical data — IP address, device and browser information, and cookie data (see our Cookie Policy).

2.2 Research data you volunteer

Collected when you fill in a form or answer a questionnaire, and only if you choose to:

  • Demographics — age, gender, the country or region you tell us you live in, income bracket, education, occupation and household details.
  • Questionnaire and survey responses.
  • MindVault psychographics — the attitude and preference assessments you complete.
  • Stated intent — the purchase or behaviour intentions you tell us about.

2.3 Research data collected by our apps, only with your explicit consent

Our desktop and mobile apps can collect the categories below. None of it is collected unless you switch it on. You are shown what each option collects before you enable it, you can turn any of it off at any time in your Data Rights Dashboard, and turning it off stops future collection.

  • App and device usage — which applications you use and for how long. (Desktop and mobile.)
  • Browsing history — the sites you visit. (Desktop only. Our mobile app cannot read your browsing history.)
  • Search queries — the searches you run. (Desktop only.)
  • Behavioural and interaction events — how you interact with the Platform and with your device.
  • Device information — device model, operating system, and device identifiers.
  • Precise location — while you are using the app only. We collect location only when the xDV app is open and in the foreground. We do not collect location in the background, and we do not track your location when the app is closed.

2.4 What we do not collect

We want to be specific about this, because a research platform that is vague about its limits is not being transparent:

  • No health, fitness or wearable data. We do not connect to Apple Health, Google Health Connect, or any fitness tracker.
  • No social-media data. We do not scrape, read or import your social-media accounts, posts, followers or messages.
  • No contacts, SMS messages or call logs. These are records about other people who cannot consent to us holding them.
  • No microphone, camera, screen or call recording.
  • No genetic or biometric data.
  • No background location. See section 2.3.
  • No cryptocurrency wallet addresses or cryptoasset information.

Special-category data. Our apps and forms do not ask for, and do not collect, information about your ethnicity, religion or beliefs, political opinions, trade-union membership, health conditions or sexual orientation. These are "special category" data under UK data-protection law. If we ever introduce a question of this kind, it will be a separate, clearly-labelled, optional opt-in for that specific category, it will never be a condition of using the Platform, and you will be able to withdraw it independently of everything else.

3. How we use your data

  • To run your account and provide the Platform.
  • To review questionnaire responses and calculate, credit and pay your earnings.
  • To process corporate purchases and committed questionnaire budgets.
  • To send service messages and, with your consent, marketing.
  • To keep the Platform secure and prevent fraud and manipulation.
  • To meet our legal obligations, including anti-money-laundering identity checks and accounting and tax record-keeping.
  • To produce research datasets and analytics that we license to research and analytics customers — only from data you have consented to contribute, and only in the pseudonymised form described in section 6. This is a commercial purpose and it is how the Platform pays you. Your data is licensed to research buyers; it is not sold to advertisers or advertising networks.

4. Legal bases

We rely on the legal bases below. The Article numbers are the same in the UK GDPR and, for people in the European Economic Area, the EU GDPR.

  • Consent (UK GDPR Article 6(1)(a)) — for everything you contribute as research data: questionnaire participation, the volunteered data in section 2.2, and each app-collected category in section 2.3. Consent is given per category, is never bundled, and you can withdraw it at any time for future processing. Also for marketing and non-essential cookies.
  • Contract (Article 6(1)(b)) — running your account, paying your earnings, and fulfilling corporate purchases.
  • Legal obligation (Article 6(1)(c)) — identity verification for anti-money-laundering purposes, and accounting, tax and regulatory record-keeping. We must collect the KYC information in section 2.1 by law; it is not based on your consent, and we cannot offer the Platform without it.
  • Legitimate interests (Article 6(1)(f)) — security, fraud prevention and service improvement, and sanctions/PEP screening to the extent it falls outside our legal obligations above — see below.

Sanctions and PEP screening — basis stated provisionally. We rely on legal obligation to the extent this screening is required under UK money-laundering regulations, or otherwise on our legitimate interest in preventing financial crime and complying with sanctions law. Which of these applies is being confirmed by our external legal advisers; until that confirmation lands, we describe the controls we apply rather than claiming full compliance validation. This does not change the basis for the underlying KYC identity check above, which remains a legal obligation.

Special-category data (Article 9). We do not currently collect any. Were we to do so, the only basis we would rely on is your explicit consent under Article 9(2)(a), given separately for that specific category. Access to the Platform will not be made conditional on giving it.

5. Who we share data with

We do not sell your personal data to advertisers or data brokers, and we never share your name, contact details or anything else that directly identifies you. With your consent, we license pseudonymised research data to research and analytics customers; some US state laws call this a "sale" (see section 7B). We share data with the following categories of recipient:

  • Research and analytics customers — businesses and researchers who license insights from our datasets. They receive pseudonymised output only (see section 6): aggregated results, and individual questionnaire responses that carry no personal identifiers. They never receive your name, contact details, KYC information or payout details, and only data from contributions you consented to share. This is a licensing arrangement for research purposes.
  • Service providers (processors) acting under contract for us — currently DigitalOcean (hosting, database and backups), Stripe (collection of payments from corporate customers), Brevo (service and account emails), Microsoft Azure (the AI service that writes plain-language summaries of aggregated results; it never receives your individual data), Grafana Labs (system monitoring) and Google (website analytics, only if you accept analytics cookies, and protection against automated sign-ups). Section 10 explains how we protect data that leaves the UK. Outbound payouts to members are made by bank transfer from our own company account — no third-party payout processor holds your funds or receives your bank details.
  • Sanctions and PEP screening sources — sanctions screening is checked against the UK Sanctions List, a public list published by the UK government (OFSI); this is not a data-sharing arrangement with a third-party processor. We do not currently use a third-party vendor for PEP screening. If we engage one in future, it will act as our data processor under a data-processing agreement, and this policy will be updated before any data is shared with it.
  • Authorities — where the law requires disclosure.

6. Pseudonymised research data, and closed accounts

We describe our research datasets as pseudonymised, not anonymised, because that is what they are, and the difference matters to you. Direct identifiers — your name, email address, contact details and KYC information — are removed before any data reaches a research customer. But the remaining data is still personal data under UK law, because a combination of attributes can in principle point back to a person. Calling it "anonymised" would overstate the protection.

What actually protects you is aggregation with a minimum group size: research output is released only as part of a group of similar contributors large enough that no individual can be picked out of it. We apply a minimum-group-size threshold to every dataset we release, and queries that would return a group smaller than that threshold are hidden or refused rather than shown. The minimum group size is higher when a result combines more details that could help identify someone, such as location, age, job or salary, and some combinations are never released. When a business commissions a questionnaire, it receives the individual answers to that questionnaire. Each answer set is labelled with a random code that is different for every questionnaire, contains no name, contact or account details, and has personal details removed from free-text answers. The business is contractually forbidden from trying to identify you.

If you close your account, we delete or pseudonymise your personal data (see section 8). Pseudonymised data you contributed may remain in datasets and analytics for up to 3 years after closure. As set out in our Terms of Use, earnings generated by that data after you close your account belong to xDV DataVault.

7. Your rights

You have rights over your personal data under UK data-protection law, including to: access it; correct it; have it deleted; restrict or object to processing; receive a portable copy; and withdraw consent at any time (for future processing). To exercise any of these, contact us at the address below. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk). We respond to rights requests within one month. For complex requests we may extend this by up to two further months, and we will tell you if we do. These rights apply wherever you live. People in the European Economic Area and the United States should also read sections 7A and 7B. If you live elsewhere, your local law may give you further rights, and we will respond to requests made under it.

7A. If you live in the European Economic Area

If you live in the European Economic Area (EEA), the EU General Data Protection Regulation (EU GDPR) also applies to how we handle your personal data, because we offer our services to you and, where you switch on app data collection, observe how you use your device. The legal bases in section 4 are the same Articles of the EU GDPR, and you have the rights in section 7 under the EU GDPR as well. You can also complain to the data protection authority in the EEA country where you live or work, or where you think a breach of your rights took place.

Our EU representative. We are appointing a representative in the European Union under Article 27 of the EU GDPR, and their contact details will be shown here. Until then, please contact us at privacy@xdv-datavault.com.

7B. If you live in the United States

Some US states, including California, give their residents specific privacy rights. We offer the rights below to everyone in the United States who uses the Platform.

What we collect, where it comes from and why. Section 2 lists everything we collect: identifiers and account details; identity-verification information; payout bank details; commercial information such as earnings and payments; internet and device activity (only the app categories you switch on); precise location (only while the app is open, and only if you switch it on); demographic information you choose to give us; and inferences drawn from your questionnaire and MindVault answers. It comes from you, from your device (only with your consent) and from our own systems. We use it for the purposes in section 3 and keep it for the periods in sections 6 and 8.

Sensitive personal information. Some of this is "sensitive" under some state laws: identity-document details, bank account details and precise location. We use identity and bank details only to verify who you are, meet our legal obligations and pay you. We collect precise location only with your opt-in consent, and you can switch it off at any time.

Licensing research data (a "sale" under some state laws). We do not sell your personal information to advertisers or data brokers, and we do not share it for cross-context behavioural advertising. We do license pseudonymised research data to research and analytics customers for money: questionnaire answers, demographics, MindVault answers and app data that you choose to contribute, with your name, contact details, identity and payout details removed. Some state laws, including California's, may treat this licensing as a "sale" of personal information. You decide what is licensed. Each category is off until you switch it on, and you can stop future licensing of any category at any time in your Data Rights Dashboard. We do not knowingly sell or share the personal information of anyone under 18.

Being paid for your data (notice of financial incentive). We pay you for approved questionnaire responses and for research data you choose to contribute. California law calls this a "financial incentive". You join by switching on a category or taking part in a questionnaire, and you can withdraw at any time, without penalty, by switching the category off or closing your account. Our Terms of Use explain what happens to earnings you have already built up. The material terms are in our Terms of Use, section 5. What we pay reflects our good-faith estimate of the value of your data to us. Questionnaire rewards are set by the business commissioning the questionnaire, at no less than the minimum published on the Platform. Data-sharing earnings are a published share of the revenue we receive when analytics uses your data. We calculate this value from the revenue we receive for licensing research data and the share of it we pay to contributors.

Your rights. You can ask us to: tell you what personal information we have collected, used, disclosed and licensed about you, and give you a copy in a portable format; correct it; delete it; stop licensing it (opt out of sale); and limit our use of sensitive personal information to what is needed to provide the Platform. We will not discriminate against you for using these rights. If you choose not to contribute a category of data, you will not earn from that category.

How to make a request, and appeals. Email privacy@xdv-datavault.com or use your Data Rights Dashboard. We will verify your identity by matching your request to your account before acting, and respond within 45 days. Where the law allows, we may extend this once by a further 45 days, and we will tell you if we do. You can use an authorised agent; we may ask for proof of the agent's authority and ask you to confirm your identity directly. If we turn down your request, you can appeal by replying to our decision with "Appeal" in the subject line, and we will respond within the time your state's law requires. If we turn down your appeal, you can contact your state's Attorney General.

8. Retention

We keep personal data while your account is active. When your account is closed, we delete or pseudonymise personal data within 30 days, except where we must keep records longer for legal, tax or accounting reasons — in particular identity-verification records, which we are required to retain for anti-money-laundering purposes. Pseudonymised data is handled as described in section 6.

9. Security

Data is encrypted in transit and at rest, access is restricted on a need-to-know basis, and we review our security measures regularly.

10. International transfers

Your personal data is stored in the United Kingdom, in our hosting provider's London data centre. This applies wherever you live: if you join from the European Economic Area, the United States or anywhere else, your data is transferred to and stored in the UK. For people in the European Economic Area, this is covered by the European Commission's decision that the UK provides an adequate level of data protection. Some of our providers process limited data in other places, as explained below. Where a provider processes personal data outside the UK — for example, a payment processor, or a hosting, email or analytics provider based in the United States or elsewhere — we put a safeguard recognised under UK data-protection law in place before the transfer takes place. Depending on the recipient and destination country, this is one of:

  • a UK adequacy regulation, where the UK government has recognised the destination country as providing an adequate level of protection; or
  • the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses as modified by the UK's International Data Transfer Addendum, entered into with the recipient, together with an assessment of the law and practice of the destination country relevant to the transfer.

Several of the providers named in section 5 are US companies or process limited data outside the UK. Where they do, we rely on the UK-US data bridge and the EU-US Data Privacy Framework for certified providers, or on Standard Contractual Clauses with the UK Addendum. Business customers outside the UK and the European Economic Area must agree to our Data Processing Agreement before they receive any research data. Details of the safeguard used for any provider are available on request from privacy@xdv-datavault.com. Where you are a corporate customer and require contractual detail of these transfers as part of your own compliance obligations, see our Data Processing Agreement below.

11. Monitoring your use of our analytics service (corporate accounts)

When you use the xDV analytics service, we record how your account uses it — the queries and cohorts you build, the analyses you save, and the credits you spend. This activity is separate from, and does not draw on, the research data described in sections 2.2–2.3.

Authorised xDV staff may review this activity to provide support, resolve billing queries, keep the service secure and prevent misuse (including exceeding your usage limits or attempting to extract data outside what your subscription permits), and to understand which insights our subscribers need so we can improve and expand the Platform. Access is limited to staff who need it for these purposes. We do not sell this usage activity, and it is never combined with or treated as research data.

Legal bases: contract (Article 6(1)(b) — running your subscription and billing) and legitimate interests (Article 6(1)(f) — security, abuse prevention and service improvement).

This activity is retained in line with our retention policy (see section 8).

12. Children

The Platform is not intended for anyone under 18.

13. Changes

We may update this policy; material changes will be notified on the Platform or by email, and the date shown on this page will be revised.

14. Contact

Privacy questions or rights requests: privacy@xdv-datavault.com. Postal address: XDV DATAVAULT LTD, 157 Whitehall Road, Bradford, BD12 9LE, United Kingdom. People in the European Economic Area can also contact our EU representative (see section 7A).