Xelthron Business Network (XBN) és un producte i servei operat per Bobardt Enterprises Inc., 4321 W College Ave, Appleton, WI 54914, Estats Units.
Section 1 — Controller and scope
The controller is Bobardt Enterprises Inc., 4321 W College Ave, Appleton, WI 54914, United States. Telephone: +1 920-806-0263. XBN privacy contact: info@x-bn.com. Company contact: info@bobardt-enterprises.com. Xelthron Business Network (XBN) is a product and service of Bobardt Enterprises Inc.
This Policy applies to the XBN website and currently implemented Platform functions. Other Users, Organizations and linked providers may be independent controllers for their own purposes.
TODO: LEGAL REVIEW – EU representative under Article 27 GDPR. TODO: LEGAL REVIEW – UK representative. TODO: LEGAL REVIEW – necessity and, where applicable, appointment of a data protection officer.
Section 2 — Principles, definitions and roles
Personal Data, processing, controller, processor, special categories, sale, sharing and targeted advertising have the meanings given by applicable law. XBN processes data lawfully, for specified purposes, with data minimization, accuracy, storage limitation and appropriate protection. This Policy does not guarantee worldwide legal compliance.
Organizations are responsible for data they independently collect about applicants, employees, customers, contacts or marketplace counterparties. Whether XBN acts as processor in a particular business-customer scenario must be determined from the function and contract concerned.
Section 3 — Data categories, sources and current technical state
The current prototype stores many User-entered data items only in the local browser storage of the device used. These may include personal and company profiles, contacts, posts, comments, media as local data representations, messages, calendar events, newsletters, marketplace listings, application/project data, reviews, settings, demo email accounts and demo emails. Based on the reviewed source code, these data are not transmitted to a general XBN backend.
Server-side requests to the XBN web application can generate technical connection data such as IP address, time, requested resource, browser/device information and error data; the actual hosting-log content and retention remain to be confirmed. External news feeds are retrieved through an XBN API. Payment-provider interfaces are prepared and are used only when configured by an administrator.
Sources are User input, technical use, User-entered feed URLs and—only for actively configured payment flows—the selected payment provider. Identity or company verification, actual address-book imports, actual email/calendar synchronization and production file uploads are not confirmed as complete backend processing in the reviewed prototype.
TODO: TECHNICAL VERIFICATION – fully inventory production hosting, logging, upload, authentication, analytics, moderation and payment data flows before launch.
Section 4 — Processing operations and legal bases
Accounts and Platform delivery: registration, profile, function and preference data; source is the User; purpose is requested Platform use; legal basis is Article 6(1)(b) GDPR. Without required information, the account or function cannot be provided.
Security and abuse prevention: connection, log, account and security signals; sources are technical use and reports; purposes are protection of Users, the Platform and legal claims; bases are Article 6(1)(f) and, where required, (c) GDPR. Legitimate interests are availability, integrity, fraud prevention and legal defense.
Optional functions: consent under Article 6(1)(a) GDPR is used only where processing is not required for contract performance, such as consent-required non-essential device access. Consent may be withdrawn prospectively.
Billing: order, invoice, status and transaction data; sources are Users and payment providers; purposes are contract, payment, accounting and fraud prevention; bases are Article 6(1)(b), (c) and (f) GDPR. Required payment data must be provided to purchase a Paid Service.
Vital interests under Article 6(1)(d) GDPR are relied on only in genuine emergencies. Recipients, third countries and retention are further described in Sections 10 to 12.
TODO: TECHNICAL VERIFICATION – complete records of processing and function-specific mandatory/optional disclosures. TODO: LEGAL REVIEW – final legal-basis review.
Section 5 — Profiles, visibility and search engines
The prototype contains visibility controls for certain profile fields. Which fields are public by default, members-only or private, and whether public pages are indexable by search engines, has not been fully technically confirmed. No privacy-by-default claim is made until verification is complete.
Profiles, company pages, posts, reviews and newsletters released publicly may be copied by recipients or shared outside XBN. External copies and search-engine caches can persist beyond XBN's control after a change or deletion.
TODO: TECHNICAL VERIFICATION – default visibility for every field, robots/indexing and enforcement of privacy settings.
Section 6 — Messages, email, calendar and conference integrations
Direct messages, demo emails and events are stored in local browser storage in the current prototype. Attachments are in some cases handled only as a local representation or file name. Production end-to-end encryption is not claimed.
The interface names email connections for Gmail, Outlook, Apple/iCloud and IMAP/SMTP and calendar connections for Google and Apple. The reviewed prototype does not perform actual OAuth, IMAP, SMTP or CalDAV synchronization; it only stores local demo or setup data. No confirmed OAuth scopes, mailbox contents, subject lines, recipients, attachments, contacts or external calendar data are therefore currently synchronized server-side by XBN.
Conference functions store preferred provider links locally; credentials should not be entered. External providers are independent controllers for their own processing. Disconnection currently occurs by removing the local connection or clearing browser storage.
TODO: TECHNICAL VERIFICATION – before activating any real integration, document scopes, content, synchronization direction, storage, revocation, deletion and provider role.
Section 7 — Special categories and Sensitive Data
XBN generally does not request health data, biometric identifiers, racial or ethnic origin, political opinions, religion, trade-union membership, sex-life or sexual-orientation data. Users should not publish such data in profiles, posts, files or messages unless necessary and legally permitted.
A User who voluntarily makes special-category data public remains responsible for that disclosure; processing by XBN must rely on an applicable Article 9(2) GDPR condition. Blanket consent is not assumed. Sensitive Data under U.S. law is used only for requested functions, security or legally permitted purposes.
TODO: LEGAL REVIEW – procedure and Article 9 basis for unavoidable sensitive Content. TODO: TECHNICAL VERIFICATION – detection, access restriction and deletion of sensitive Content.
Section 8 — Recommendations, ranking and automated systems
In the prototype, interests, language, location information, relationships, recency and interactions may influence feed, contact suggestions, search, jobs and marketplace displays. This can constitute profiling where personal aspects are used to predict interests.
No solely automated decision producing legal or similarly significant effects is confirmed in the reviewed code. Automated moderation, fraud detection, human case review and an appeal workflow are also not fully evidenced and are not claimed to be active.
TODO: TECHNICAL VERIFICATION – ranking parameters, profiling logic, moderation and fraud systems, effects, human review and appeals.
Section 9 — Recipients, processors and third parties
Verifiable recipient categories are the User-selected payment provider when payment is enabled, external news sources when public feeds are retrieved and recipients with whom Users intentionally share Content. Browser-local data generally remain on the device used unless a function expressly triggers transmission.
A complete list of production hosting, infrastructure, support, analytics, communication, storage, security and payment providers is not present in the reviewed project. No specific subprocessor, processing location or transfer mechanism is therefore claimed as complete.
TODO: TECHNICAL VERIFICATION – complete processor and subprocessor inventory: provider name, purpose, data category, processing country, role and transfer mechanism.
Section 10 — Sale, sharing, advertising and User-selected recipients
Based on the reviewed technical state, XBN does not sell Personal Data for money and does not conduct confirmed sharing for cross-context behavioral advertising. Personalized Content within XBN is distinct from such sharing. Users may themselves transmit data to contacts, Organizations, marketplace counterparties or external providers.
If sale, CCPA sharing or targeted advertising is introduced, clear prior notice and effective opt-outs must be implemented. Global Privacy Control is not currently claimed as technically supported.
TODO: TECHNICAL VERIFICATION – advertising, analytics and preference-signal audit, including Global Privacy Control.
Section 11 — International transfers
The operator is located in the United States. Information transmitted to XBN servers or configured providers may therefore be processed in the United States and the actual provider processing locations. Browser-local data are not transferred internationally by XBN merely because they are stored locally.
XBN does not generally rely on the EU-U.S. Data Privacy Framework; it applies only to actually certified recipients. Standard Contractual Clauses, the UK Addendum, transfer impact assessments or supplementary measures are used or claimed only when actually executed, performed and documented.
Information about or copies of appropriate safeguards may be requested at info@x-bn.com where such safeguards exist, subject to redaction of protected business or security information.
TODO: TECHNICAL VERIFICATION – actual processing locations and provider certifications. TODO: LEGAL REVIEW – transfer mechanisms for EEA, Switzerland, UK and other origin countries.
Section 12 — Retention, deletion and legal holds
Data currently stored locally in the browser generally remain until deleted through the relevant function, the website data are cleared in the browser, or the device is lost. Central account deletion does not automatically remove browser-local copies unless and until implemented.
Binding production retention periods and deletion jobs remain to be set for active and closed accounts, profiles, companies, posts, files, private messages, email/calendar data, marketplace, applications, projects, support, invoice/tax records, consent evidence, security logs, backups and litigation. Statutory retention and legal holds may postpone deletion to a limited extent.
TODO: LEGAL REVIEW / DATA RETENTION SCHEDULE – specific periods by data category and jurisdiction. TODO: TECHNICAL VERIFICATION – verify deletion logic, backups, local data and central account deletion.
Section 13 — Security and breaches
The reviewed project evidences a server-side encrypted local file for administrator-saved payment-provider credentials and client-side access separation for certain views. This does not establish a complete production security architecture. In particular, encryption of stored User data, MFA, central role-based access control, complete logging, backups, vulnerability management, incident response, vendor review and a secure-development program are not generally claimed as implemented.
Personal Data breaches are assessed under applicable legal requirements. Individuals and authorities are notified where statutory thresholds and deadlines are met.
TODO: TECHNICAL VERIFICATION – complete security measures, key management, roles, MFA, logs, backups, vulnerability and incident processes and vendor review.
Section 14 — GDPR and UK GDPR rights
Where applicable, rights include information, access and a copy, correction, deletion, restriction, objection, portability, consent withdrawal, complaint to a competent supervisory authority and protection concerning solely automated decisions under Article 22 GDPR. Direct marketing may be objected to at any time.
Requests sent to info@x-bn.com are generally answered within one month. For complexity or numerous requests, applicable law may permit an extension of up to two further months; the reason and extension are communicated within the first month. Only proportionate identity evidence is requested. Statutory exceptions and others' rights may limit scope.
TODO: TECHNICAL VERIFICATION – operational privacy-request, export, deletion and appeal process. TODO: LEGAL REVIEW – competent EU/UK authority and representative duty.
Section 15 — United States privacy rights
To the extent Bobardt Enterprises Inc. meets the applicable statutory thresholds, residents of certain U.S. states may request knowledge or access, correction, deletion, portability, opt-out of sale, sharing or targeted advertising, opt-out of certain profiling, limits on certain Sensitive Data use, appeal of denied requests and non-discrimination.
Requests may be sent to info@x-bn.com. Authorized agents must prove authority; direct confirmation may be required. Verification uses only reasonable information already available or necessary.
Based on the reviewed state, no sale for money and no confirmed CCPA sharing occurs. Universal opt-out signals are honored only if and to the extent technical support is implemented and legally required.
TODO: LEGAL REVIEW – applicability and thresholds by state. TODO: TECHNICAL VERIFICATION – opt-out, agent, verification and appeal workflow.
Section 16 — Notice at Collection
Notice at collection: depending on the function used, XBN may collect identifiers and contact data, profile and company information, Content and communications, professional and commercial information, usage, device, log and approximate-location data and payment-status data. Purposes are account and function delivery, communication, networking, security, support, billing and legal obligations. Details appear in Sections 3 and 4 of this Policy.
The current prototype does not yet evidence function-specific short notices displayed at every relevant collection point. This Policy alone does not replace a required point-of-collection notice.
TODO: TECHNICAL VERIFICATION – implement notices at registration, profile, upload, payment, contact, newsletter, application, marketplace and integration collection points.
Section 17 — Children and minors
XBN is intended exclusively for persons aged 18 or older. Registration by minors is prohibited. XBN is not directed to children under 13 and does not knowingly collect their data.
Suspected inadvertent collection of minors' data should be reported to info@x-bn.com. Following proportionate identity and factual verification, such data are restricted or deleted unless law requires otherwise.
TODO: TECHNICAL VERIFICATION – age gate, minor-data report and deletion workflow.
Section 18 — Cookies, local storage and electronic communications
The prototype uses local browser storage for language, profiles, posts, messages, calendar, newsletters, marketplace, account preferences and other demo state. A complete cookie and storage inventory is not yet available. Non-essential cookies, SDKs or external Content may be loaded in the EEA and UK only in accordance with applicable consent requirements.
External maps or comparable Content must not load automatically where prior consent is required. Marketing email must include accurate sender information and a working unsubscribe method. Details and actually available choices appear in the Cookie Policy and Privacy Options.
TODO: TECHNICAL VERIFICATION – complete cookie/local-storage inventory, consent management, external Content and unsubscribe mechanism.
Section 19 — Other countries and local rights
Individuals in the United Kingdom, Canada and other countries may have additional rights under local law. UK GDPR and UK transfer rules apply only where their territorial scope is met. PIPEDA and Canadian provincial law are considered only where actually applicable.
XBN does not guarantee blanket compliance with every privacy law worldwide. Local rights may be submitted to info@x-bn.com and are assessed under applicable law.
TODO: LEGAL REVIEW – target countries, market offering and local representative, consent and registration requirements.
Section 20 — Changes, accountability and contact
Last updated: July 23, 2026. Material changes are communicated by prominent Platform notice, account message or email where contact details exist and this is appropriate. Renewed consent is requested only where legally required. Changes do not retroactively restrict existing statutory rights.
Privacy requests: info@x-bn.com. Operator contact: info@bobardt-enterprises.com. Telephone: +1 920-806-0263.
TODO: TECHNICAL VERIFICATION – records of processing, data-processing agreements, deletion schedule, incident-response process and operational privacy-request procedure. TODO: LEGAL REVIEW – final counsel review before production launch.