Xigna
About Contact Log in

Privacy Policy

Xigna Privacy Policy

Version: 1.0

Effective Date: 1st of July 2026


1. Introduction

Xigna ("Xigna", "we", "our", or "us") is committed to protecting the privacy, confidentiality, and security of Customer information.

This Privacy Policy explains how Xigna collects, uses, stores, protects, and discloses information when Customers use the Xigna platform, including its websites, software applications, APIs, artificial intelligence features, accounting integrations, and related services (collectively, the "Service").

This Privacy Policy forms part of the Xigna Software as a Service Agreement.

By using the Service, Customers acknowledge that they have read and understood this Privacy Policy.


2. Scope

This Privacy Policy applies to:

  • business Customers;
  • Authorized Users;
  • visitors to the Xigna website;
  • users connecting supported accounting platforms;
  • users uploading accounting or financial data.

Xigna is designed exclusively for business use.

The Service is not intended for consumer or household purposes.


3. Information We Collect

Depending on how the Service is used, Xigna may collect the following categories of information.

3.1 Account Information

Including:

  • business name;
  • contact name;
  • email address;
  • telephone number;
  • password (encrypted);
  • authentication credentials;
  • subscription details.

3.2 Business Information

Examples include:

  • legal entity name;
  • registered business address;
  • tax registration numbers;
  • fiscal year information;
  • industry classification;
  • accounting preferences.

3.3 Accounting Information

When Customers connect supported accounting software or upload accounting files, Xigna may collect:

  • chart of accounts;
  • general ledger;
  • journal entries;
  • trial balances;
  • balance sheets;
  • income statements;
  • cash flow statements;
  • invoices;
  • bills;
  • vendor information;
  • customer information;
  • payroll summaries;
  • tax information;
  • inventory information;
  • financial reports.

Xigna collects only the information necessary to provide the requested Services.


3.4 Integration Information

When Customers connect supported accounting systems, Xigna may receive:

  • OAuth authorization tokens;
  • refresh tokens;
  • organization identifiers;
  • accounting company identifiers;
  • synchronization timestamps;
  • metadata necessary to maintain the integration.

Currently supported integrations include:

  • QuickBooks Online
  • Xero

Additional integrations may be added in the future.


3.5 Technical Information

Xigna automatically collects technical information including:

  • browser type;
  • operating system;
  • device information;
  • IP address;
  • session identifiers;
  • application logs;
  • performance metrics;
  • security events;
  • crash reports.

3.6 Usage Information

Examples include:

  • pages visited;
  • features used;
  • reports generated;
  • simulations executed;
  • dashboards viewed;
  • settings changed;
  • synchronization history.

3.7 Cookies

Xigna uses cookies and similar technologies.

Additional details are provided in the Cookie Policy.


4. Information We Do Not Collect

Xigna does not intentionally collect:

  • personal social media information;
  • biometric information;
  • government-issued identification unless required by law;
  • personal banking credentials;
  • payment card numbers (payments are processed by third-party payment providers);
  • information from children.

5. How We Use Information

Customer information is used only for legitimate business purposes.

Examples include:

  • providing the Service;
  • operating Customer accounts;
  • synchronizing accounting systems;
  • generating Financial Intelligence;
  • generating Compliance analysis;
  • producing reports;
  • producing dashboards;
  • producing Decision Simulations;
  • generating AI Insights;
  • improving performance;
  • maintaining security;
  • responding to support requests;
  • preventing fraud;
  • complying with legal obligations.

6. Artificial Intelligence

Xigna may use artificial intelligence technologies to generate:

  • summaries;
  • explanations;
  • analytical observations;
  • financial insights;
  • recommendations.

AI-generated outputs are intended solely to improve Customer understanding of financial information.

Customers remain responsible for verifying all AI-generated outputs.


7. Customer Data Ownership

Customer Data always remains the property of the Customer.

Xigna receives only a limited license necessary to:

  • store Customer Data;
  • process Customer Data;
  • analyze Customer Data;
  • synchronize Customer Data;
  • generate reports;
  • provide Financial Intelligence;
  • provide Compliance monitoring;
  • provide Decision Simulations;
  • provide AI Insights.

Nothing in this Privacy Policy transfers ownership of Customer Data to Xigna.


8. No AI Model Training

Xigna does not use Customer Data to train public or proprietary artificial intelligence models.

Customer financial information is never sold, licensed, or contributed to AI training datasets without the Customer's explicit written consent.

This commitment applies to both structured accounting information and uploaded documents.


9. Legal Basis for Processing

Where applicable, Xigna processes information because:

  • processing is necessary to provide the Service;
  • processing is necessary to fulfill contractual obligations;
  • processing is required to comply with legal obligations;
  • processing is necessary to protect the security of the Service;
  • Customers have provided consent where required.

10. Information Sharing

Xigna does not sell Customer information.

Customer information is disclosed only where necessary to:

  • operate the Service;
  • provide requested integrations;
  • comply with applicable law;
  • respond to lawful governmental requests;
  • protect legal rights;
  • investigate fraud or security incidents.

11. Third-Party Service Providers

Xigna may use carefully selected service providers to operate the Service.

Examples may include:

  • cloud infrastructure providers;
  • database providers;
  • email providers;
  • authentication providers;
  • accounting platform providers;
  • artificial intelligence providers (where enabled).

All providers are required to protect Customer information in accordance with contractual obligations.

A current list of subprocessors is maintained separately.


12. International Transfers

At launch, Xigna intends primarily to serve Canadian business Customers.

Customer information may nevertheless be processed or stored outside Canada where necessary to operate the Service.

Where information is transferred internationally, Xigna will implement commercially reasonable safeguards designed to protect Customer information.


13. Information Security

Protecting Customer information is a core design principle of Xigna.

Xigna implements commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer information from unauthorized access, alteration, disclosure, or destruction.

Security measures may include:

  • encryption of data in transit using TLS;
  • encryption of stored data where appropriate;
  • secure authentication mechanisms;
  • role-based access controls;
  • tenant isolation;
  • audit logging;
  • continuous monitoring;
  • automated backups;
  • infrastructure security controls;
  • secrets management;
  • vulnerability management;
  • software update management.

Additional technical details are published separately in the Security & Data Protection Statement.


14. Tenant Isolation

Xigna is designed as a multi-tenant Software-as-a-Service platform.

Each Customer's information is logically isolated from every other Customer.

Xigna implements technical controls intended to prevent unauthorized cross-tenant access.

Internal administrative access is restricted to authorized personnel with legitimate operational responsibilities.


15. Data Retention

Xigna retains Customer information only as long as reasonably necessary to:

  • provide the Service;
  • maintain Customer accounts;
  • comply with legal obligations;
  • resolve disputes;
  • maintain security records;
  • enforce contractual rights.

Retention periods may vary depending on:

  • subscription status;
  • applicable legislation;
  • accounting record requirements;
  • backup schedules;
  • regulatory obligations.

Additional details are published in the Data Retention Policy.


16. Account Deletion

Customers may request deletion of their accounts.

Upon verified account deletion:

  • access credentials are revoked;
  • integrations are disconnected;
  • synchronization stops;
  • Customer Data enters the deletion process according to the Data Retention Policy.

Certain information may be retained where required by law or necessary for:

  • fraud prevention;
  • legal claims;
  • audit requirements;
  • accounting obligations;
  • security investigations.

17. Backup Copies

For operational resilience, encrypted backup copies may continue to exist for a limited period after deletion.

Backups are used solely for disaster recovery and security purposes.

Backup data is not restored except where operationally necessary.


18. Customer Rights

Subject to applicable law, Customers may request:

  • access to their information;
  • correction of inaccurate information;
  • deletion of eligible information;
  • restriction of processing where applicable;
  • export of Customer Data;
  • withdrawal of consent where processing relies upon consent.

Xigna may require reasonable verification before fulfilling requests.


19. Access to Customer Data

Only authorized personnel may access Customer information.

Access is granted strictly on a need-to-know basis for purposes including:

  • customer support;
  • technical troubleshooting;
  • infrastructure maintenance;
  • security investigations;
  • legal compliance.

Internal access is logged where reasonably practicable.


20. QuickBooks Online and Xero Data

When Customers authorize Xigna to connect with supported accounting platforms, Xigna accesses only the information necessary to provide requested Services.

Depending on Customer authorization, Xigna may retrieve:

  • chart of accounts;
  • transactions;
  • journal entries;
  • invoices;
  • bills;
  • customers;
  • vendors;
  • financial reports;
  • accounting metadata.

Xigna does not modify Customer accounting records unless the Customer explicitly authorizes such functionality.

Customers may revoke integration access at any time through the applicable accounting platform or within Xigna where supported.


21. Data Accuracy

Xigna relies upon information provided by:

  • Customers;
  • supported accounting systems;
  • authorized integrations.

Xigna cannot guarantee the completeness, accuracy, or timeliness of imported information.

Customers remain responsible for verifying accounting records before relying upon reports, forecasts, simulations, or AI-generated insights.


22. Incident Response

If Xigna becomes aware of a security incident affecting Customer information, Xigna will respond in accordance with its Incident Response procedures.

Where required by applicable law, Xigna will notify affected Customers within a commercially reasonable timeframe.

Notifications may include:

  • description of the incident;
  • categories of affected information;
  • mitigation measures;
  • recommended Customer actions.

23. Regulatory Compliance

Xigna intends to operate in accordance with applicable Canadian privacy legislation.

As Xigna expands internationally, additional privacy frameworks may become applicable, including but not limited to:

  • GDPR;
  • UK GDPR;
  • CCPA;
  • other regional privacy legislation.

This Privacy Policy may be updated accordingly.


24. Children's Privacy

The Service is intended exclusively for business Customers.

Xigna does not knowingly collect information from children.

If Xigna becomes aware that information relating to a child has been collected inadvertently, reasonable steps will be taken to remove such information.


25. Changes to this Privacy Policy

Xigna may revise this Privacy Policy periodically.

Material changes will be communicated through reasonable means, including:

  • website notices;
  • application notifications;
  • email communication where appropriate.

Continued use of the Service following the effective date of revised policies constitutes acceptance of the updated Privacy Policy.


26. Contact Information

Questions regarding this Privacy Policy or privacy practices may be directed through the official contact information published on the Xigna website.

Following incorporation, this section will include:

  • legal entity name;
  • registered business address;
  • privacy contact email;
  • designated Privacy Officer.

27. Privacy Commitment

Xigna is committed to earning and maintaining Customer trust.

Our privacy principles include:

  • Customer ownership of Customer Data;
  • transparency regarding data practices;
  • no sale of Customer information;
  • no use of Customer Data for AI model training without explicit consent;
  • strong security practices;
  • responsible use of artificial intelligence;
  • continuous improvement of privacy and security controls.

Protecting Customer financial information is fundamental to the operation of the Service.