Legal
Privacy policy
Three forms on this site collect personal data. This page states exactly which fields, why they exist, where they go, how long they stay, and how to have them deleted.
Effective date: 25 August 2026
Who controls what
Two organizations appear on this site and they are not the same organization. Which one is answerable for a given piece of data depends on which form produced it.
XG Capital Strategies
XG Capital Strategies (XGCS) operates this website. XGCS is the controller for the diagnostic briefing form at /contact, the XG Capital Insights subscription list, and the operation and security of the site itself.
- Legal entity: XG Capital Strategies LLC, California Secretary of State entity no. 202357810793
- Address: 1500 Tacoma Way, Redwood City, California 94063
- Email: info@xgcapitalstrategies.com
Kairos Dynamics
Kairos Dynamics is a separate company — a Delaware C corporation in formation — that licenses selected XGCS research and turns it into products. It is not a division, brand, or trading name of XGCS. Its investor briefing page collects the investor briefing form described below.
Because Kairos Dynamics is not yet formed, XGCS currently operates that page and the systems behind it, and is today the controller for investor briefing submissions. On formation, Kairos Dynamics is intended to become the controller for that data, with XGCS continuing to operate the intake infrastructure on its behalf. Until that happens, send any request about briefing data to XGCS at the address above and it will be handled there. This page will be updated when the position changes, and the change will be dated.
What we collect
All three forms post to the same Cloudflare Worker and are stored in a single Cloudflare D1 database. Nothing else on the site collects personal data. There is no account, no login, and no tracking pixel.
1. Kairos Dynamics investor briefing
Required: full name, work email, organization, role, inquiry type, and your message.
Optional, only if you fill them in: investment focus, typical check range, geographic focus, referral source.
Recorded automatically with the submission:
- the page you submitted from;
-
referral parameters present in the URL you arrived on —
utm_source,utm_medium,utm_campaign,utm_content, andref. No other query parameter is read; - the time of submission;
- both consent flags, described below;
- a salted hash of your IP address, described below;
- a hash of your email, organization, and message. It detects a duplicate submission of the same enquiry, and its first twelve characters become the reference ID quoted back to you in the acknowledgement email.
2. XG Capital Strategies diagnostic briefing
Required: name, email, decision environment, and the decision you are trying to improve. Optional: organization, the signals you are watching, and your timing or risk constraint.
The same automatic fields are recorded: source page, referral parameters, timestamp, consent, IP hash, and the duplicate-detection hash. This form does not collect role, investment focus, check range, or geographic focus, and is not permitted to.
3. XG Capital Insights subscription
Your email address, and nothing else you type. The same automatic fields are recorded. A subscription is stored with both consent flags set, because subscribing is itself the request for ongoing contact.
What we do not collect
- Your IP address. It is used during the request and never written down. See below.
- Accounts, passwords, or payment details. The site takes none of these.
- Advertising or cross-site tracking data. There are no advertising tags on this site.
- Data bought or enriched from third-party data brokers. Everything held about you is what you typed into a form.
- Special-category data. Do not put it in a free-text field; nothing here is built to hold it.
The IP hash
Every submission stores a one-way, salted SHA-256 hash of the submitting IP address — not the address. The address itself is visible to the Worker while the request is being handled, because Cloudflare Turnstile needs it to verify the anti-spam challenge, and it is discarded when the request ends.
The hash exists for one purpose: counting repeat submissions from the same visitor so the form can be rate limited. It is salted with a secret, so the small IPv4 address space cannot be brute-forced back to an address.
The consequence is deliberate and worth stating: from the stored data we cannot recover your IP address, locate you, or identify your network. Abuse is blocked at the Cloudflare edge instead, before a request reaches the database.
Why we hold it, and on what basis
- To reply to you. Every form requires you to tick a consent box before it will submit, and that consent is what we rely on. Without the tick the form does not send.
- To send ongoing updates. A second, separate, optional consent. Only submissions carrying it are ever added to a mailing list.
- To keep the forms usable. The IP hash, the anti-spam challenge, and the duplicate check exist to stop automated abuse. We rely on our legitimate interest in running a working contact channel.
- To keep a record of what was asked and answered. Submissions are retained so an enquiry can be picked up later in the conversation it belongs to.
Where the GDPR, the UK GDPR, or a comparable law applies to you, the first two bases above are consent and the third is legitimate interests. Which of those regimes reaches us has not been formally determined; the bases above are the position we hold ourselves to in the meantime.
The two consents
They are recorded as two separate flags, and they are not treated as one. Asking a question is not the same as asking to be subscribed.
- Consent to a reply — mandatory. The form will not submit without it.
- Consent to ongoing contact — optional, unticked by default, and recorded separately.
Only submissions with the second flag set may be added to an update or newsletter list. Records created before that flag existed default to not-consenting, because those people were never offered the choice.
The two organizations are kept apart here as well. Ticking the optional box on a Kairos Dynamics briefing is consent to hear from Kairos about that approach. It does not enrol you in an XG Capital Strategies publication, and the export used to build the newsletter list excludes those records by default.
You can withdraw either consent at any time by emailing info@xgcapitalstrategies.com, or by using the unsubscribe link in any newsletter issue.
How long we keep it
Submissions are kept for 24 months after our last substantive contact with you, and are then deleted. An enquiry may legitimately be picked up months later, which is why the period is measured in a small number of years rather than weeks; it is not a reason to keep the record forever.
Deletion against that period is carried out by a person rather than by a scheduled job. The period is the commitment; the manual step is how it is met today, and saying so is more useful to you than implying an automation that does not yet exist. If you would rather we did not keep it at all, ask, and it will be deleted. See the next section.
Erasure, access, and other requests
Email info@xgcapitalstrategies.com. If you have the reference ID from your acknowledgement email, include it — it identifies the exact record without any further questions about who you are.
Deletion is run manually by an operator against the database, and every matching record is printed and reviewed before anything is removed. There is deliberately no self-service deletion endpoint on the public API: an erasure route on a public Worker would be new attack surface for an operation that runs rarely, and would be a way for a stranger to destroy someone else's record.
You can ask us to:
- tell you what we hold about you, and give you a copy;
- correct something that is wrong;
- delete it;
- stop using it for ongoing contact, while keeping the record of your original enquiry;
- stop using it altogether.
Where a data protection law gives you these as enforceable rights, they apply as that law provides, including any right to complain to your local supervisory authority. Where it does not, we will do the above anyway. Requests are answered within 30 days.
Who else processes it
These are the only third parties involved. Nothing is sold, rented, or shared for advertising.
- Cloudflare — hosts this site, runs the intake API, stores the database, and provides the Turnstile anti-spam challenge on all three forms. Cloudflare therefore holds everything described in "What we collect", and sees your IP address as the network layer in front of the site.
- Titan (Hostinger) — carries outbound mail. Your
acknowledgement, and the internal notification of your submission, are sent through
Titan's SMTP service from
info@xgcapitalstrategies.com. Titan therefore handles your name, email address, and the content of your message. - Substack — sends the XG Capital Insights newsletter. Subscriptions are captured here, not there: the consent record with its timestamp and source page stays in our own database, and email addresses are uploaded to Substack in batches so there is one authoritative consent record rather than two that can disagree. Only addresses carrying the optional ongoing-contact consent are ever exported.
- XGCS-controlled infrastructure — the notifier that turns a stored submission into an email runs on a machine XGCS controls, with credentials held outside the code repository. Exports of the database to that machine are personal data and are deleted after use.
- Analytics — this site uses no cookie-based analytics, no advertising tags, and no cross-site tracking. Any measurement in use is cookieless and aggregate: it does not identify you, does not follow you between sites, and is never joined to a form submission.
Each provider above is engaged under its own published data processing terms. We have not yet executed processing agreements of our own with them.
Where it is processed
Cloudflare, Substack, and Hostinger are United States companies operating global infrastructure, so your data may be processed in the United States and in other countries where those providers operate.
These providers are US-based, so if you are in the UK or EEA your details are transferred to the United States. We have not yet put a transfer mechanism of our own in place, and would rather state that than imply one exists.
Security
- The site and the intake API are served over HTTPS only.
- All three forms are protected by Cloudflare Turnstile and by a per-visitor submission rate limit.
- The intake API accepts submissions only from this site's own origins.
- Database and mail credentials are held outside the code repository, readable only by the operator account.
- The public API can write a submission and read nothing back. Reading, exporting, and deleting are operator-only.
No system is perfect. If you find a weakness, report it rather than test it further — contact details are in the repository's security policy, and info@xgcapitalstrategies.com reaches us.
This site is not directed at children, and the forms are intended for people acting in a professional capacity.
Changes to this policy
If what the forms collect changes, this page changes with it, and the effective date at the top moves. We do not treat a silent edit as notice.
Questions about this policy, or about anything held about you, go to info@xgcapitalstrategies.com. See also the terms of use and the important notices.