Products
Services
Company
XPLORENCE PRIVACY POLICY
Privacy Policy
Last Updated: March 2026
Consulting company Xplorence (hereinafter referred to as the 'Company', 'we', 'us', or 'our') deeply respects the privacy of your data. As a strategic partner for market leaders and a pioneer in ESG transformation, we view information protection (Data Governance) as a fundamental element of sustainable corporate governance.
This Privacy Policy (hereinafter the 'Policy') explains in detail how we collect, organize, use, store, transfer, and protect information from our website users, B2B corporate clients, and candidates for our global Expert Network. The Policy is developed in strict accordance with the applicable laws of the Republic of Uzbekistan (including Law No. ZRU-547 'On Personal Data') and integrates international information protection best practices, including the key principles of the EU General Data Protection Regulation (GDPR), which is particularly important for our international projects involving institutional donors.
01What Information We Collect
To ensure the seamless delivery of high-tech consulting services and the design of intelligent business architectures, we collect information from various sources. Data is categorized into the following broad categories:
- Automatically Collected Technical Data and Metadata:Every time you visit our digital portal, we automatically register your IP address, browser type and version, operating system information, language settings, unique device identifiers (Device ID), and approximate geolocation (city/region). Using cookies (session and persistent), web beacons, and analytical systems, we track navigation paths, time spent on specific pages, and entry/exit points. This information is critical for cybersecurity (detecting anomalies and DDoS attacks) and UI/UX optimization.
- B2B Client Data and Project Documentation:During the initiation of cooperation (e.g., when requesting Market Intelligence, Intelligent Automation, or ISO implementation services), we collect contact information for representatives: Full Name, corporate email, phone numbers, job title, and company name. Additionally, during preliminary negotiations (prior to signing a commercial contract), we may collect tender documentation (RFP), organizational charts, public financial reports, and other business process details voluntarily shared via secure communication channels for preliminary audits.
- Expert Network Participant Profiles:When applying to our closed network of independent consultants, data collection goes beyond a standard resume. We collect: employment history, academic transcripts, certification records, technical stack proficiency (AI, RPA, Data Science), and financial/contractual expectations. We may also store results of video interviews, chat transcripts generated by AI agents, technical test results, and links to professional repositories (LinkedIn, GitHub). For this data category, obtaining separate, detailed Consent for processing personal data is mandatory.
02How We Use Your Information
The collected data is integrated into our operational processes solely to achieve the following legitimate business purposes:
- Service Delivery and Project Management:Fulfilling contractual obligations to our clients, conducting deep econometric research, and developing ESG strategies using anonymized datasets.
- Intelligent Matching and AI Analytics:Expert selection for complex transformation projects is conducted using our proprietary machine learning algorithms and natural language processing (NLP) systems. Your data (resume text, experience) helps train our internal models to recognize non-obvious professional connections and competencies; however, final personnel decisions are always made by a human (Human-in-the-loop).
- Compliance, KYC, and AML Procedures:When working with large capital and international organizations, we are required to perform 'Know Your Customer' (KYC) procedures, anti-money laundering (AML) checks, and conflict of interest audits. Your data is used for background integrity checks.
- Thought Leadership and Institutional Memory:Aggregating and fully anonymizing data to create industry benchmarks, publish Uzbekistan labor market research, and send relevant analytical reports to subscribers (with a one-click unsubscribe function).
03Data Transfer and Disclosure
Xplorence strictly does not sell, rent, or monetize your personal data by transferring it to advertising brokers. Information disclosure is strictly regulated:
- Strategic Clients and Partners:Excerpts from expert profiles undergo preliminary pseudonymization (removal of direct contacts) and are shared with clients (banks, ministries) solely for project team approval. Full data is disclosed only upon transition to contracting.
- Authorized IT Service Providers:We delegate part of the computational tasks to trusted technology partners (secure cloud hosting providers, CRM/ERP system developers). Access for such parties is limited and strictly governed by Non-Disclosure Agreements (NDA) and Data Processing Agreements (DPA).
- Mergers and Acquisitions (M&A):In the event of a reorganization, merger, sale of Company assets, or investment capital raising, databases (as a Company asset) may be transferred to the successor, provided the protection level stated in this Policy is maintained.
- Cross-border Transfer via Security Standards:Given our work with development institutions, data may be exported to secure servers outside the Republic of Uzbekistan. Such transfers are carried out only to jurisdictions with an adequate level of protection or based on Standard Contractual Clauses (SCC) guaranteeing security.
- Law Enforcement:Disclosure of information to law enforcement and judicial authorities is carried out solely in response to reasonable and legal procedural requests.
04Security Architecture and Retention Periods
Information security is an Xplorence priority. Our IT infrastructure is built on the 'Zero Trust' paradigm.
- Protection:We apply continuous data encryption both in transit (SSL/TLS protocols) and at rest (At-Rest Encryption). We regularly conduct penetration testing (Pen-testing), maintain access audit logs, and use multi-factor authentication (MFA) for employees.
- Storage:The data retention period is strictly determined. Expert Pool participant data is stored for up to 5 years to ensure participation in long-term infrastructure projects. B2B client data is stored for the duration of the contract and at least 3 years after its completion in accordance with financial audit requirements.
05Your Digital Rights and Data Control
You retain full sovereignty over your personal information. At any time, you have the right to:
- Right to Access and Portability:Request an export of a copy of your personal data in a structured, machine-readable format (e.g., CSV or JSON).
- Right to Rectification:Demand the immediate correction of factual errors or outdated information in your profile.
- Right to be Forgotten (Deletion):Withdraw consent for processing and initiate the total destruction of your data from our active systems (except for data subject to mandatory archival storage by law).
- Protection from Automated Decisions:Request the involvement of a human specialist (review) if an automated AI algorithm rejected your project application.
To exercise any of the above rights, submit official requests, or receive clarification on technical aspects of information protection, please contact our Data Protection Officer.
Emailcontact@xplorence.comWe commit to providing a reasoned response to any requests regarding privacy within 30 calendar days.


