Privacy
Privacy Policy
Privacy is not a section of our policy. It is a condition of the work.
Our approach
Xion Group collects the minimum personal data required to do the work properly, holds it only for as long as there is a reason to, and grants access on the principle of least privilege.
Personal data is never treated as a commodity. Xion does not sell personal data and does not use it for advertising profiling.
Personal data we collect
Depending on how you interact with us, we may collect: your name and the organization you represent; contact details such as email address, telephone number, or WhatsApp number; the content of messages you send us; enquiry or intake details you choose to provide; consent records; and limited technical information generated when a message or request is delivered to us.
This website does not require an account and does not display advertising. Sound and narration preferences are kept in your own browser. Where sensitive personal data — including health information — may be involved, it is requested only through a separate, explicit consent step and never through a general enquiry form.
WhatsApp and Meta platforms
Aegis-assisted conversations may take place over WhatsApp, which is operated by Meta. When you message us there, WhatsApp processes your phone number, profile name, message content, and delivery metadata in order to transmit the conversation, and Meta's own terms and privacy policy apply to that transmission.
We use WhatsApp Business messaging only for conversations you start or agree to. We do not import contact lists, and we do not send marketing messages. Message content received through WhatsApp is handled under this notice once it reaches us. If you prefer not to use WhatsApp, write to us by email instead.
Purposes and lawful basis
We process personal data to respond to enquiries, to carry out intake and registration for Aegis-assisted processes, to deliver and administer services requested of us, to keep records required for governance and accountability, to protect the security and integrity of our systems, and to meet legal obligations.
Our lawful bases are: your consent, where consent is requested and given; the performance of a contract or steps taken at your request; compliance with a legal obligation; and our legitimate interests in operating and securing the institution, where those interests do not override your rights. Sensitive personal data, including health data, is processed only on explicit consent or another basis specifically permitted by law.
Automated and AI-assisted processing
Aegis is an AI-assisted system. Where it drafts, summarises, routes, or prioritises information, a named human remains accountable for consequential decisions. We do not make decisions producing legal or similarly significant effects about you by automated means alone, and you may ask for human review of any Aegis-assisted outcome that affects you.
Third parties and processors
We share personal data only with categories of recipients necessary to operate: communications and messaging providers (including WhatsApp/Meta and email providers); cloud hosting, database, and storage infrastructure providers; security, logging, and monitoring providers; AI processing providers used by Aegis; and professional advisers, auditors, or regulators where we are legally required to disclose.
Processors act on documented instructions, are bound by confidentiality and security obligations, and are not permitted to use your data for their own purposes.
Cross-border processing
Some of the infrastructure and communications providers we rely on operate outside Tanzania. Where personal data is transferred abroad, we do so only for the purposes described here and rely on the conditions permitted under Tanzanian data protection law, including your consent where required, contractual protections with the recipient, and the necessity of the transfer to provide the service you have asked for.
Retention and deletion
Enquiry and conversation records are kept only as long as needed to deal with the matter and to keep a defensible record of it, then deleted or de-identified. Consent records are kept for as long as the related processing continues, plus the period needed to demonstrate that consent was properly obtained. Records relating to care or to statutory obligations are retained for the period the law requires, which may limit deletion.
Security safeguards
We apply least-privilege access, encryption of data in transit, access logging, separation of clinical and non-clinical environments, and review of changes to systems that hold personal data. Protection is treated as a continuing obligation subject to review rather than a one-time implementation. No unverified certification or compliance claims are made.
Your rights
Subject to applicable law, you may request confirmation of whether we hold data about you and access to it; correction of inaccurate or incomplete data; deletion where no legal or clinical obligation requires retention; restriction of processing; objection to processing based on legitimate interests; withdrawal of a consent you previously gave, without affecting processing already carried out; and human review of an AI-assisted outcome.
You may also lodge a complaint with the relevant supervisory authority in Tanzania.
Making a privacy or deletion request
Write to privacy@xion.group with the subject "Privacy request" or "Delete my data", describing what you are asking for. Our data rights page explains the process and what to expect. We confirm receipt, verify that the request comes from you or an authorised representative, and respond within the timeframe required by law.
Please do not include clinical or other sensitive detail in the request itself.
Contact
Privacy and data protection enquiries: privacy@xion.group. General institutional enquiries: office@xion.group. Postal address and registered entity details will be published once domain and entity configuration is confirmed.
PlaceholderNotice version 2026-08-07. This notice states our operating commitments and is written with reference to Tanzania's Personal Data Protection Act, 2022 (Cap. 44) and its regulations. It does not state or imply that Xion Group or Aegis is registered, certified, approved, endorsed, or assessed as compliant by the Personal Data Protection Commission. Jurisdiction-specific terms, retention schedules, and processor lists remain subject to legal review.