Privacy
Privacy notice
Effective 25 August 2026. This describes what this site collects, why, and what you can ask us to do about it.
Who is responsible
Kairos Dynamics is a Delaware C corporation in formation and cannot yet be a data controller, because it does not yet legally exist. Today XG Capital Strategies LLC (California Secretary of State entity no. 202357810793), of 1500 Tacoma Way, Redwood City, California 94063, operates this site and the systems behind it, and is the controller of anything you submit here.
When Kairos Dynamics is formed, this page will be updated, the change will be dated, and anyone whose details we hold will be told. Records do not move automatically.
What the contact form collects
The contact form asks for, and stores, exactly these:
- Your name
- Your email address
- Your organization and your role
- The description of what you want validated
- The page you submitted from
- The time of submission, and your consent to be replied to
What the investor briefing form collects
The briefing form on the investors page is a longer one, and unlike the contact form it does ask about money. It requires your name, work email, organization, role, what kind of enquiry this is, how you heard about us, a description of what you want validated, and your consent to be replied to.
It also offers three optional fields:
- Investment focus
- Typical check range
- Geographic focus
All three are optional in the literal sense that the form submits without them. We ask because the answers decide who replies and how fast, and because an investor, a prospective customer and a strategic partner need three different conversations. We do not sell this, share it, or use it for anything other than that reply.
What we do not store
Your IP address is received in the request and is sent to Cloudflare Turnstile to check the security challenge. It is not stored. What is stored is a one-way salted hash of it, used only to rate-limit abuse. From the stored value we cannot recover your address. Because we hold the salt, though, the hash remains personal data and is treated as such.
This site sets no cookies. There is no advertising tag and no cross-site tracking.
Browser storage and measurement
Cloudflare Turnstile stores a short-lived challenge token in your browser while it verifies you are not automated. Page-view measurement, where enabled, is cookieless and aggregate: it records that a page was viewed, not who viewed it. There is nothing here to consent to, which is why you are not being asked to.
Why we hold it, and on what basis
To reply to you and to keep a record of what was asked and answered. To prevent abuse of the form. And, only if you separately opt in, to send occasional updates.
Which data-protection regimes reach us has not been formally determined. Our position, stated so you can hold us to it: replying to an enquiry rests on steps taken at your request before any contract, and on our legitimate interest in answering people who contact us; abuse prevention rests on legitimate interests; and ongoing updates rest on your consent, which you may withdraw at any time.
Who else processes it
- Cloudflare serves the site, runs the security challenge, and stores submissions.
- Titan (Hostinger) carries the acknowledgement and notification email.
Cloudflare and Titan are each engaged under their own published data processing terms. Both are US-based, so if you are in the UK or EEA your details are transferred to the United States. We have not yet executed processor agreements or a transfer mechanism of our own, and would rather state that than imply one exists.
How long we keep it
We keep enquiry records for 24 months after our last substantive contact with you, and then delete them. An enquiry may legitimately be picked up months later, which is why the period is measured in a small number of years rather than weeks; it is not a reason to keep the record forever.
Deletion against that period is currently carried out by a person rather than by a scheduled job. The period is the commitment; the manual step is how it is met today, and saying so is more useful to you than implying an automation that does not yet exist.
Removing your details
Email info@xgcapitalstrategies.com from the address you used, or reply to the acknowledgement you received. We ask you to write from that address because it is the simplest way to establish the request is yours. Otherwise anyone holding a forwarded email could have someone else's record deleted.
There is deliberately no self-service deletion button. A public endpoint that destroys records on an unverified email is a way to attack other people, not a convenience. Requests are handled by a person, within 30 days.
Changes
If this notice changes materially, particularly when Kairos Dynamics is formed and becomes the controller, the date above changes and we will say what changed.