Back to site

Legal

Privacy Policy

Effective 20 September 2026 · Last updated 20 September 2026

This policy explains what personal data Exoctic Group collects, why we collect it, who we share it with and the choices you have. We have written it to be read, not skimmed past.

1. Who we are

Exoctic Group ("Exoctic", "we", "us" or "our") provides business management software, including billing, payroll and HR, travel management, reporting, custom systems and custom trip management applications (together, the "Services"), and operates this website (the "Site").

For personal data we collect for our own purposes, such as Site visitors, prospective customers and account administrators, Exoctic is the data controller.

2. Scope and our role for customer data

Our customers upload and manage information about their own employees, travellers, clients and suppliers in the Services ("Customer Data"). For Customer Data, the customer is the controller and Exoctic acts only as a processor (or service provider) on the customer's documented instructions, under our Data Processing Agreement ("DPA").

If your employer or another organisation uses the Services and you have questions about how your information is handled, please contact that organisation first. We will assist them in responding to your request as required by the DPA.

3. Personal data we collect

Information you give us

  • Contact and enquiry data: name, work email, company, job title, team size, interests and anything you write in a form or email.
  • Account data: login credentials, user roles, profile settings and security preferences such as two-factor authentication.
  • Billing data: billing contact, company address, tax identifiers and payment details. Card data is processed by our payment providers and is never stored on our servers.
  • Support data: messages, call notes, screenshots and files you share with our support team.

Information collected automatically

  • Usage and device data: IP address, browser type, operating system, pages viewed, referring URLs, timestamps and in-product events.
  • Cookie data: see section 11.

Information from third parties

  • Business contact details from event organisers, partners or public professional sources, and information from integrations you choose to connect.

4. How we use personal data

  • To provide, operate, maintain and secure the Services and the Site.
  • To create and manage accounts, authenticate users and process payments.
  • To respond to enquiries, arrange demos and provide support.
  • To send service, security and billing notices, which you cannot opt out of while you hold an account.
  • To send product updates and marketing where permitted, which you can opt out of at any time.
  • To analyse usage in aggregated or de-identified form and improve the Services.
  • To detect, prevent and investigate fraud, abuse, security incidents and violations of our Terms.
  • To comply with legal obligations and to establish, exercise or defend legal claims.

We do not sell personal data, and we do not use Customer Data to train generalised models or for advertising.

5. Legal bases for processing

Where the EU or UK General Data Protection Regulation applies, we rely on: performance of a contract; our legitimate interests in running, securing and improving our business (balanced against your rights); your consent, where required, which you may withdraw at any time; and compliance with legal obligations.

6. How we share personal data

We share personal data only as described here:

  • Sub-processors and service providers for hosting, email delivery, payments, analytics, support tooling and security, bound by written contracts that require confidentiality and appropriate safeguards. A current list is available on request.
  • Integrations you enable, such as payment, accounting or travel providers, which receive data under their own terms and privacy policies.
  • Professional advisers such as lawyers, auditors and insurers, under duties of confidentiality.
  • Authorities, where we are legally required to or where disclosure is necessary to protect the rights, property or safety of Exoctic, our customers or others.
  • Corporate transactions, such as a merger, acquisition, financing or sale of assets, subject to continued protection of the data.

7. International transfers

We and our providers may process personal data in countries other than your own. Where data protection law requires it, we protect transfers with recognised safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where appropriate.

8. Retention

We keep personal data only for as long as needed for the purposes in this policy. Account and billing records are kept for the life of the account and then for the period required by tax and accounting law. Enquiry data is deleted or anonymised within 24 months of our last interaction unless a relationship continues. Customer Data is retained and deleted in line with the customer agreement and DPA, and in any case within 90 days of termination unless the law requires otherwise.

9. Security

We use administrative, technical and physical safeguards appropriate to the risk, including encryption in transit and at rest, role-based access controls, multi-factor authentication for staff, logging and monitoring, regular backups and staff confidentiality obligations. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as the law requires.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete or port your personal data; to restrict or object to certain processing; to withdraw consent; and not to be subject to decisions based solely on automated processing that significantly affect you. California residents have the right to know, delete and correct personal information and to opt out of its sale or sharing, which we do not do, and we will not discriminate against you for exercising these rights.

To exercise a right, email info@exocticgroup.com. We will verify your request and reply within the time the law requires. You may also complain to your local data protection authority, although we would welcome the chance to address your concern first.

11. Cookies and similar technologies

We use strictly necessary cookies to keep the Site and Services working and secure. With your consent where required, we also use analytics cookies to understand how the Site is used. You can control cookies through your browser settings; blocking some cookies may affect functionality.

12. Trip management apps

Trip apps we build for customers are published under the customer's brand and developer accounts. The customer is the controller of traveller data processed through those apps, and its own privacy notice applies. Location, camera and notification features are used only when the traveller grants permission in the device settings, and only to provide the app's functions, such as receipt capture and trip alerts.

13. Children

The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal data from children. Where a customer uses the Services to arrange travel for minors, the customer is responsible for obtaining any required parental consent.

14. Changes to this policy

We may update this policy from time to time. We will post the new version on this page with a new effective date and, where changes are material, give account holders reasonable advance notice by email or in the product.

15. Contact

Questions or requests about this policy or your personal data: info@exocticgroup.com.