XOVEREIGN A division of White Crown Enterprises Back to XOVEREIGN

XOVEREIGN Technologies — Legal

Privacy Policy

This site sets no cookies, runs no analytics, carries no tracking pixel or beacon, and loads no font, script, stylesheet, image or frame from any other origin. It has no account, no form and no login. This document states precisely what is nonetheless processed when you read a page or make a request to us, who processes it, on what legal basis, for how long, and what you may require of us.

Who the controller is

White Crown Enterprises Inc., a South Dakota corporation, is the sole controller of the personal data described in this policy. XOVEREIGN is an unincorporated division of that corporation and has no separate legal personality. Processing between divisions of the Corporation is internal to one legal person: it is not a disclosure to a third party, not a sale, not a sharing, and not an onward transfer.

Article I The short version

A privacy policy is usually long because the site it describes does a great deal. This one is long because it is specific about how little this site does. In summary:

What this site does and does not do with data about you. Each row is stated in full in the article referenced.
PracticePositionSee
CookiesNone are set, of any kind, including none that would be described as strictly necessary.Art. IV
Analytics and measurementNone. No analytics script, no tag manager, no pixel, no beacon, no server-side event collection.Art. III
Third-party contentNone. No font, script, stylesheet, image, frame or embed is loaded from any other origin, so no other origin observes your visit.Art. III
Accounts and formsNone exist. There is nothing to register for and no form to submit.Art. III
Stored on your deviceOne preference key recording whether you chose narrative mode. It is never transmitted.Art. IV
Network-level dataServing a page necessarily involves your IP address and request metadata reaching the hosting network. This is disclosed rather than glossed.Art. III
Sale or sharing of personal dataWe do not sell personal data and do not share it for cross-context behavioural advertising. We never have.Art. XII
Advertising and profilingNone. No advertising, no audience building, no profiling, no automated decision-making.Art. XIII

You can verify most of the rows above without trusting this document: open your browser’s developer tools, load any page of this site, and inspect the network and storage panels. That is the intended way to read this policy.

Article II Controller, scope and structure

Section 2.1 — Controller

White Crown Enterprises Inc., a corporation organised under the laws of the State of South Dakota (the “Corporation,” “we,” “us”), is the controller of the personal data described in this policy, and is the “business” for the purposes of California law. XOVEREIGN is an unincorporated division of the Corporation. It has no separate legal personality and is not a separate controller, processor or recipient.

Section 2.2 — Inter-divisional processing

The Corporation operates through four divisions: XOVEREIGN, XIGNET, Nexus Blue and Arloom. Where personal data moves between divisions, it moves within a single legal person. Under Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR that is not a disclosure to a third party and does not require a separate legal basis, a controller-to-processor agreement or a transfer mechanism. Under the California Consumer Privacy Act as amended it is neither a sale nor a sharing. Access between divisions is nonetheless restricted internally: personal data is made available to a division only where that division needs it for the purpose for which it was collected.

Section 2.3 — Entities outside the Corporation

White Crown Entertainment LLC is a separate legal person in which the Corporation holds a majority interest. It has no access to any division of the Corporation and receives no personal data collected through this Site. The LXM Holdings Perpetual Dynasty Trust holds title to intellectual property and receives no personal data collected through this Site.

Section 2.4 — Scope

This policy applies to the XOVEREIGN Technologies site and to the correspondence routes described in Articles V and VI. It does not apply to any other White Crown Enterprises platform, each of which publishes its own policy, and it does not apply to any site you reach by leaving this one.

Article III What happens when you read a page

Section 3.1 — What the page itself does

Every page of this site is a single self-contained document. It makes no network request of any kind after it has loaded: no analytics call, no telemetry, no error reporting, no font fetch, no image fetch, no frame, no embed and no beacon on page unload. It runs identically with no network connection at all. Because nothing is loaded from another origin, no other organisation is placed in a position to observe that you visited, what you read, or how long you stayed.

Section 3.2 — What the network necessarily involves

A page cannot be delivered to you without your device asking for it. That request carries your IP address, the page requested, the time, and the user-agent string and preference headers your browser sends. Our hosting provider processes that information in order to route and return the response, and to protect the service against denial-of-service and abuse. We do not use it to build a profile, we do not join it to any other data, and we do not use it for measurement or advertising.

We describe this because it is true of every website and is frequently omitted. It is processing, it involves data that can in some circumstances identify you, and it is disclosed here rather than treated as invisible.

Section 3.3 — Do Not Track and Global Privacy Control

This site performs no tracking to disable. A Do Not Track header or a Global Privacy Control signal therefore requires no change in our behaviour, and we honour both by construction rather than by configuration.

Article IV The one thing stored on your device

The site stores exactly one value in your browser’s local storage:

Complete inventory of client-side storage used by this site. There are no cookies, no session storage entries, no IndexedDB databases and no cache entries beyond your browser’s ordinary HTTP cache.
KeyPurposeContentsLifetime
xovereign.mode Records whether you chose narrative mode, so the site presents the document the way you last asked for it rather than resetting on every visit. A short presentation-mode value. It contains no identifier, nothing derived from you, and nothing that could distinguish you from any other reader who made the same choice. Until you clear site data for this origin.

This value is never transmitted to us or to anyone else — there is no request in which it could travel, because the page makes none. It is not a cookie and is not used for any purpose other than the one stated. Under GDPR Article 5(3) of Directive 2002/58/EC as implemented, storage strictly necessary to provide a facility explicitly requested by the user does not require consent; this value is stored only after you have explicitly selected the mode. You may delete it at any time by clearing site data for this origin, or by never selecting narrative mode, in which case nothing is ever written.

If storage is unavailable — in a private window, or where your browser blocks it — the site honours your choice for the session and stores nothing.

Article V Verification Instrument requests

If you request a build of the XOVEREIGN Verification Instrument, that request is correspondence: it reaches us through the route stated in the Terms of Service, not through this site, which has no form.

Personal data processed in connection with a Verification Instrument request.
CategoryWhy it is neededLegal basis
Your name, role and institutionTo know who a build was issued to, which is a condition of issuing one at all.Legitimate interests; performance of a contract at your request.
A contact routeTo deliver the build and to reach you about it, including if a measurement it reported is later corrected.Performance of a contract at your request.
A hardware identifier for the Designated HostA build is bound to the machine it was issued for, so that a result cannot be produced on favourable hardware and presented as having come from yours. The identifier identifies a machine, not a person, but is treated as personal data where the machine is yours.Performance of a contract at your request.
A record of issuance, build identifier and expiryTo answer the question “was this build genuinely issued by you, and when did it expire” if a published result is later disputed.Legitimate interests in the integrity of published results; legal claims.
Export-control and sanctions screening dataTo meet obligations under Article XVI of the Terms of Service before a build is issued.Compliance with a legal obligation.

We do not receive the Results your build produces. The Instrument reports to you, on your machine. There is no telemetry, no callback and no reporting channel to us: if you want us to see a result, you send it to us. You are free to publish any result without telling us, as Section 7.4 of the Terms of Service expressly provides.

Article VI Licensing and other correspondence

If you write to us about licensing, about a technical statement on the site, about accessibility, or about anything else, we process the content of your correspondence and the details you choose to include in it — typically your name, your organisation and a contact route — in order to read it, answer it and keep a record of the exchange.

Where correspondence proceeds to substantive licensing discussion, an executed non-disclosure agreement governs the confidential information exchanged, and the personal data of the individuals negotiating is processed for the performance and administration of that agreement.

Do not send us special category data as defined in GDPR Article 9, or any sensitive personal information as defined under California law. We do not ask for it and have no purpose for it.

Article VII Legal bases for processing

Where GDPR or UK GDPR applies, we rely on the following bases. We do not rely on consent for anything described in this policy, because nothing described in this policy requires it.

  • Performance of a contract, or steps at your request before entering into one (Art. 6(1)(b)) — issuing and supporting a Verification Instrument build; responding to a licensing enquiry you initiated.
  • Legitimate interests (Art. 6(1)(f)) — delivering and securing the site; keeping a record of what we published and to whom a build was issued; establishing, exercising or defending legal claims; protecting trade secrets. We have assessed in each case that these interests are not overridden by your interests or fundamental rights, principally because the data involved is minimal, is not used to profile anyone, and is not disclosed outside the Corporation except as Article VIII states.
  • Compliance with a legal obligation (Art. 6(1)(c)) — export control and sanctions screening; retention required by law; responding to a lawful request from an authority.

Where we rely on legitimate interests you have a right to object; see Article XI.

Article VIII Recipients and processors

We disclose personal data to the following categories of recipient, and to no others:

Every category of recipient. There is no advertising network, no data broker, no analytics provider and no audience platform in this list, because none is used.
RecipientRoleWhat it receives
Cloudflare, Inc.Processor — hosting and content delivery for this site, under a written data processing agreement.Network-level request data as described in Section 3.2. It receives no correspondence and no Verification Instrument records.
Professional advisersIndependent controllers or processors, as applicable — external legal counsel, auditors.Only what a specific matter requires, under professional duties of confidence.
Authorities and courtsRecipients where disclosure is required by law or is necessary to establish, exercise or defend a legal claim.Only what the obligation or claim requires. We assess each request and do not disclose more than is required.
An acquirer or successorController, in the event of a reorganisation, merger or transfer of the business or assets to which the data relates.The data relating to the transferred business, subject to this policy continuing to apply until superseded by a policy no less protective.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We do not disclose personal data to any division of the Corporation as a third party, because a division is not a third party.

Article IX International transfers

The Corporation is established in the United States and processes personal data there. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred to the United States.

Where a transfer requires a safeguard under Chapter V of GDPR or the equivalent UK provision, we rely on the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), together with the UK International Data Transfer Addendum where the UK GDPR applies, and we carry out a transfer risk assessment for each such transfer. A copy of the clauses relied on for a transfer relating to you is available on request using the details in Article XVII.

Given the categories described in this policy, the volume of personal data transferred is small and consists principally of business-contact details and correspondence.

Article X Retention

How long each category is kept, and what determines the period.
CategoryPeriod
Network-level request dataRetained by the hosting processor for its own operational and security period and not separately retained by us. We do not maintain an access log of this site.
xovereign.modeHeld on your device until you clear it. We never hold it at all.
Verification Instrument issuance recordsFor the Term of the build and for six years afterwards, so that a published result can be authenticated if it is later disputed.
Export-control screening recordsFive years from the date of the transaction, as required by 15 C.F.R. pt. 762.
Licensing and general correspondenceFor the duration of the discussion and for six years afterwards, aligned to the limitation period for a contractual claim.
Records subject to a legal holdUntil the hold is lifted, notwithstanding any shorter period above.

At the end of a period, records are deleted or irreversibly anonymised.

Article XI Your rights

Subject to the conditions and exemptions in the applicable law, you may:

  • Ask what we hold about you, and receive a copy of it;
  • Have it corrected if it is inaccurate, or completed if it is incomplete;
  • Have it erased where we no longer need it, where you withdraw a consent we relied on, or where you successfully object;
  • Restrict our processing while an accuracy or objection question is resolved;
  • Receive it in a portable form, and have it transmitted to another controller, where processing is based on contract or consent and is carried out by automated means;
  • Object to processing based on legitimate interests, on grounds relating to your particular situation; and
  • Withdraw consent at any time where we relied on consent. We do not currently rely on consent for anything in this policy.

Write to us using Article XVII. We respond within one month, and will tell you if we need a further two months because a request is complex, together with our reasons. There is no charge unless a request is manifestly unfounded or excessive. We may need to verify your identity, and will ask only for what is necessary to do so.

Where we cannot comply in full — for example where disclosure would reveal a trade secret, or where a record is subject to a legal hold — we will tell you which exemption we have relied on and why, rather than declining without explanation.

Article XII California residents

This Article supplements the rest of this policy for California residents under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (“CCPA”).

In the twelve months preceding the effective date of this policy we have collected the following categories of personal information as defined in Cal. Civ. Code § 1798.140(v): identifiers (name, business contact details, IP address, device identifier for a Designated Host), commercial information (the fact and subject of an enquiry), internet or network activity information (request metadata as described in Section 3.2), and professional or employment-related information (your role and institution, where you give it). The sources, purposes, legal bases, recipients and retention periods are stated in Articles III to X.

We have not sold personal information and have not shared personal information for cross-context behavioural advertising, in that period or at any other time. We do not have actual knowledge of selling or sharing the personal information of any consumer under sixteen years of age.

We collect no sensitive personal information as defined in § 1798.140(ae), and therefore make no use of it requiring a right to limit under § 1798.121.

You have the right to know, to delete, to correct, and to non-discrimination for exercising a right. We do not offer a financial incentive of any kind, so no notice under § 1798.125(b) arises. An authorised agent may make a request on your behalf on production of written authorisation and, where we cannot otherwise verify the request, confirmation directly from you. Use the details in Article XVII; we will not require you to create an account in order to make a request, because there are no accounts.

Article XIII Automated decisions and profiling

We do not carry out profiling, and we do not make any decision producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Article 22 of GDPR is not engaged by anything described in this policy.

Export-control and sanctions screening under Section 5 is assisted by list matching but is reviewed by a person before any decision to decline a request is taken.

Article XIV Children

This site is directed to institutional, professional and technical readers. It is not directed to children, offers no account and collects nothing from a reader of any age beyond what Article III describes. We do not knowingly collect personal information from a child under thirteen, and the Children’s Online Privacy Protection Act, 15 U.S.C. §§ 6501–6506, is not engaged by this site. If you believe a child has sent us personal information through the correspondence routes in Articles V and VI, tell us and we will delete it.

Article XV Security

We apply technical and organisational measures appropriate to the risk, taking into account the nature and scale of the processing described here. In respect of this site those measures include: serving every page over TLS; a document with no external subresource, which removes the entire class of risk arising from third-party code; no collection of what does not need to be collected, which is the only control that cannot fail; and internal restriction of correspondence records to the personnel who need them.

No measure eliminates risk. Where a personal data breach occurs and is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two hours of becoming aware of it, and will notify you without undue delay where the risk is high, in each case as GDPR Articles 33 and 34 and any applicable state breach-notification law require.

Article XVI Changes to this policy

We may amend this policy. The amended policy takes effect when posted with a new effective date and version, both of which appear at the head of this document. Where an amendment materially changes what we collect, why, or with whom we share it, we will say so prominently on this page and, where we hold a contact route for you and the change affects you, we will tell you directly.

We will not apply a materially different use to personal data already collected without a lawful basis for doing so.

Article XVII Contact and complaints

Privacy questions, data-subject requests and complaints should be addressed in writing to:

Where to write, and to whom.
RouteAddress
Privacy OfficeXOVEREIGN Privacy Office, White Crown Enterprises Inc., State of South Dakota, United States, at the registered address published on the corporate website. Mark your letter with the right you are exercising.
Legal counselBernard M. Resnick, Esq., external legal counsel to White Crown Enterprises.
Other legal noticesAs set out in Article XXI of the Terms of Service.

If you are not satisfied with our response, you may complain to a supervisory authority. In the European Economic Area that is the authority in your country of residence, place of work, or the place of the alleged infringement. In the United Kingdom it is the Information Commissioner’s Office. In the United States you may contact the attorney general of your state; California residents may also contact the California Privacy Protection Agency.

We would prefer you raise it with us first, and we will tell you which authority to approach if we cannot resolve it.