Last updated: 20 July 2026. This explains what personal data XENA collects, why, and what rights you have over it.
XENA (xenadefence.com) is a defence-industry market intelligence platform operated by Xena Defence, registered in the United Arab Emirates [registration number pending], registered address Sharjah Research Technology and Innovation Park (SRTIP), Sharjah, United Arab Emirates. For anything in this policy, contact [email protected]. We are the data controller for the personal data described below.
We collect only what's needed to run the service. Specifically:
Account data. When you sign up: your email address (required), your name (optional), and a password. Your password is never stored in plain text — it's hashed with PBKDF2 and a per-user random salt before it touches our database; we cannot see or recover your actual password. If you enable two-factor authentication, we store the TOTP secret needed to verify your authenticator app codes.
Payment data. Subscriptions are billed at $499 per user per month via Stripe. We never see or store your card number — Stripe handles that entirely under its own PCI-compliant systems. We store only what Stripe needs us to reference your subscription (a Stripe customer ID and subscription status), plus your billing email if different from your account email.
Product usage data you create. If you build a Watchlist, subscribe to Alerts, or generate reports, we store what you've chosen to track (company names, tickers, countries, capabilities, keywords) tied to your account, so the feature works and persists across sessions/devices.
Site analytics. We run our own lightweight, self-hosted, cookieless analytics — page path, an optional UI-interaction label, referrer, and timestamp. We do not assign you a persistent visitor ID, and we do not use any third-party analytics or advertising trackers (no Google Analytics, no ad pixels, no cross-site tracking). See our Cookie & Tracking Notice for detail.
Support & correspondence. If you email us, we keep that correspondence to respond to you and to maintain a record of support history.
We do not collect or infer sensitive categories of data (health, religion, political opinion, etc.), and we do not buy personal data about you from third-party data brokers.
Account, payment and product-usage data: processed under contract necessity — we need it to provide the subscription you're paying for. Site analytics and security logging: processed under legitimate interest — understanding product usage and keeping the platform secure, in a way that doesn't override your own privacy interests given how limited the data is. Marketing communications, if we ever introduce them, would be sent only with your separate consent, which you could withdraw at any time.
We don't sell personal data. We use a small number of specific processors to run the service, each bound by their own data-processing terms:
Stripe — payment processing and subscription billing.
Resend — transactional email (signup confirmations, alert notifications). We do not use a marketing email platform.
Cloudflare — hosting, our database (Cloudflare D1), and edge infrastructure. This is where account and product data physically lives.
We do not share your data with data brokers, ad networks, or any third party for their own marketing purposes. We may disclose data if legally required to (e.g. a valid court order), or to protect the security or legal rights of XENA or our users.
Xena Defence is registered in the United Arab Emirates, and our processors (Stripe, Resend, Cloudflare) operate global infrastructure — so if you're located in the UK, EEA, or elsewhere, your data will typically be processed outside your home country, including in the UAE. [Placeholder — this needs specific legal confirmation, not just a rewording: as a UAE-registered controller serving UK/EU residents, data flowing from the UK/EEA into the UAE requires its own transfer safeguard under UK/EU GDPR (the UAE is not on the UK/EU adequacy list), separate from whatever safeguard each processor (Stripe/Resend/Cloudflare) applies to its own infrastructure. This is more involved than the transfer story for a UK-based company and should be reviewed with a lawyer familiar with both UAE PDPL and UK/EU GDPR before this section is treated as accurate.]
We keep account data for as long as your account is active, plus a reasonable period afterward [Mal to specify exact retention window, e.g. 90 days] to handle billing disputes, support queries, or reactivation. You can request earlier deletion at any time (see Section 8). Analytics data is not tied to an identifiable person in a way that would make a "how long" answer meaningful in the same sense, but we periodically prune old raw analytics logs.
Passwords are hashed (PBKDF2, per-user salt), sessions use a secure, HTTP-only cookie, and optional two-factor authentication (TOTP) is available on every account. Payment details never touch our servers — that's handled entirely by Stripe. No system is perfectly secure, but we design for the principle of storing the minimum data necessary and never storing what we don't have to (like raw card numbers or plaintext passwords).
Depending on where you're located, applicable data protection law gives you rights over your personal data — this may include the UAE's Federal Personal Data Protection Law (as the law of the jurisdiction Xena Defence is registered in) and/or UK or EU GDPR, which can still apply to a non-UK/EU company that offers services to UK/EU residents. Common rights across these frameworks include the right to: access the personal data we hold on you; correct it if it's wrong; request erasure; request a portable copy; and object to or restrict certain processing. To exercise any of these, email [email protected]. [Placeholder — exactly which regulator(s) you can complain to, and the precise scope of rights available to you, depends on your location and needs confirming with a lawyer familiar with UAE PDPL; this section currently describes rights common across likely-applicable frameworks rather than a jurisdiction-specific guarantee.]
XENA is a professional B2B intelligence product and is not directed at, or intended for use by, anyone under 18.
If we materially change how we handle your data, we'll update the date at the top of this page and, where the change is significant, notify active subscribers by email.
Questions, requests, or complaints about your data: [email protected].