XRlabs Ltd ("XRlabs", "we", "us") is committed to protecting and respecting your privacy. This policy explains what personal data we collect, how we use it, who we share it with and the rights you have over it.
It applies when you visit xrlabs.ai, contact us, request a demonstration, meet us at a conference or event, apply to work with us, or deal with us as a representative of a hospital, OEM partner, supplier, investor or other organisation.
We process personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Where we process the personal data of people in the European Economic Area, the EU GDPR applies in addition.
This policy does not cover patient data or surgical imaging processed in clinical research or product evaluations. See the section on clinical research and product evaluation data below.
Who we are
XRlabs Ltd is the data controller responsible for your personal data.
Legal entityXRlabs Ltd, registered in England and Wales, company number 15433851
Registered office71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
XRlabs Ltd has a wholly owned US subsidiary, Saena Labs, Inc., a Delaware corporation based in Palo Alto, California. Where Saena Labs, Inc. handles personal data for the purposes described in this policy, it does so on behalf of XRlabs Ltd under an intra-group data transfer agreement.
If you have any question about this policy, or want to exercise your rights, contact us at the email address above or write to our registered office.
The data we collect
We collect only the personal data we need for the purposes set out in this policy.
CategoryExamples
Identity dataName, title, and where you give it as part of a job application, date of birth
Contact dataEmail address, phone number, postal or work address
Professional dataEmployer or institution, job title, clinical specialty, areas of interest, professional profile information you make public
CorrespondenceEmails, enquiries, demo requests, meeting notes and messages you send us
Event dataRegistration and attendance at events we host or attend, business cards and attendee lists shared with us by organisers
Recruitment dataCV, work history, qualifications, references, interview notes, right to work documentation, and any adjustments you ask us to make
Technical dataIP address, browser and device type, pages visited, time and date of visits, referring site
Marketing preferencesWhether you have opted in to or out of communications from us
We do not intentionally collect special category data (such as health data, racial or ethnic origin, or religious beliefs) or criminal offence data through our website or in our business dealings. If you apply to work with us, we may handle limited special category data where the law requires or permits it, for example to confirm your right to work or to make reasonable adjustments. We handle it under the conditions in Schedule 1 of the Data Protection Act 2018.
How we collect your data
Most of the data we hold comes directly from you: when you complete a form on our website, email us, request a demonstration, speak to us at an event, apply for a role or enter into an agreement with us.
Some data is collected automatically when you use our website, through cookies and server logs. See the cookies section below.
We also receive personal data from third parties: event and conference organisers who share attendee lists, people who refer or introduce you to us, your employer or institution when it deals with us, recruitment agencies and search firms, and publicly available professional sources such as LinkedIn, institutional web pages and published work.
Legal bases for processing
We process your personal data only where we have a lawful basis to do so.
Lawful basisWhen we rely on it
ContractTo perform an agreement with you or take steps you ask for before entering one, for example providing a demonstration or evaluation you requested, or processing a job application
Legitimate interestsTo run and grow our business where this does not override your rights: contacting clinicians, hospitals and industry partners about our work, following up after events, maintaining business relationships, keeping our systems secure, developing and improving our products and services, administering our group, and establishing or defending legal claims
ConsentWhere you opt in to marketing communications as an individual, or accept non-essential cookies. You can withdraw consent at any time
Legal obligationWhere we must process data to comply with the law, for example tax and accounting records, right to work checks, or responding to lawful requests from regulators and authorities
The UK GDPR recognises direct marketing, transferring data within a corporate group for internal administration, and network and information security as examples of processing that may be carried out in a controller's legitimate interests. Where we rely on legitimate interests we have assessed the impact on you, and you can object at any time (see Your rights).
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
How we use your information
We use your personal data to:
Respond to your enquiries and provide the services, demonstrations or information you request
Manage our relationships with hospitals, clinicians, OEM and technology partners, suppliers, advisers and investors
Organise and follow up on events, meetings and conferences
Assess job applications, carry out pre-employment checks and manage recruitment
Send you information about our work, products and events where you have opted in or where we may lawfully do so for business contacts, with an easy way to opt out in every message
Operate, secure and improve our website and systems
Keep records we are required to keep by law, and establish, exercise or defend legal claims
We use your data only for the purpose we collected it for, unless we reasonably consider another use to be compatible with that purpose. If we need to use your data for an unrelated purpose, we will tell you and explain the lawful basis.
Clinical research and product evaluation data
This policy does not cover patient data, surgical video or medical images processed in clinical research studies or product evaluations.
That data is handled under the governing study protocol, the relevant ethics approval, and data processing or data sharing agreements with the hospital or institution concerned. In most cases the hospital remains the data controller and XRlabs processes data on its instructions. Where XRlabs sponsors a study, participants receive a separate participant information sheet and consent form that explain how their data is used.
Our website does not collect or process patient data. If you have a question about a study you took part in, contact the hospital or study team named in your participant information, or contact us at general@xrlabs.ai and we will direct your question.
Cookies and website analytics
Our website uses only essential cookies, which are strictly necessary for the site to work and are set without consent as the law allows. We do not currently use analytics or marketing cookies.
If we introduce analytics cookies in future we will update this policy and our Cookie Policy. Under the Privacy and Electronic Communications Regulations as amended in February 2026, low risk statistical cookies may be set without consent provided you can easily object, and any other non-essential cookie will be set only with your consent.
You can block or delete cookies through your browser settings, though parts of the site may then not work. Full details of the cookies we set are in our Cookie Policy.
Disclosure of your information
We share personal data only where necessary and with appropriate protections in place.
RecipientWhy
Service providersHosting, IT and security, email and productivity tools, customer relationship management, applicant tracking, video conferencing, website analytics and event platforms. They act on our instructions under written contracts
Group companiesSaena Labs, Inc., our US subsidiary, for internal administration and to support our work in the United States
Professional advisersLawyers, accountants, auditors, insurers and consultants, where they need the data to advise us
Partners and institutionsWhere you ask us to introduce you, or where a joint activity (such as an event, demonstration or evaluation) requires it
Regulators and authoritiesWhere we are legally required to disclose data, for example to the Information Commissioner, HMRC, a court or a law enforcement body
Business transfersIf we merge with, acquire, or sell all or part of our business, your data may be transferred to the new owner under the same protections
We do not sell or rent personal data to anyone.
International data transfers
We are based in the United Kingdom and have a presence in the United States. Some of our service providers also operate outside the UK. Your personal data may therefore be transferred to and stored in countries outside the UK and the European Economic Area.
Whenever we transfer personal data outside the UK we make sure one of the following safeguards applies:
The destination country is covered by UK adequacy regulations (this includes the EEA, and US organisations certified under the UK Extension to the EU US Data Privacy Framework)
The transfer is governed by the ICO's International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, with a transfer risk assessment
For transfers within our group, an intra-group data transfer agreement incorporating those terms
You can ask us for information about the safeguard used for a particular transfer by contacting us.
Security of your information
We use technical and organisational measures appropriate to the risk to protect your personal data against unauthorised access, loss, alteration or disclosure. These include access controls on a need to know basis, multi-factor authentication, encryption in transit and at rest where supported by our systems, logging, staff training and contractual obligations on our service providers.
No system is entirely secure and we cannot guarantee the security of data transmitted over the internet. If a personal data breach is likely to result in a risk to your rights and freedoms we will notify the Information Commissioner within 72 hours of becoming aware of it, and we will tell you directly where the risk is high.
Data retention
We keep personal data only for as long as we need it for the purpose it was collected, and then delete or anonymise it securely. Our standard periods are:
DataRetention
Enquiries and correspondence2 years after our last contact with you
Business and partner contactsFor the life of the relationship, then 2 years
Marketing contactsUntil you opt out, and a suppression record thereafter so we do not contact you again
Unsuccessful job applications6 months after the decision, or 2 years if you agree to stay in our talent pool
Contractual and financial records6 years after the end of the contract or the financial year, as required by law
Website logs and analytics12 months
We may keep data for longer where we are required to by law, to resolve a dispute, or to establish, exercise or defend a legal claim.
Your rights
You have the following rights over your personal data:
Access: ask for a copy of the personal data we hold about you and information about how we use it
Rectification: ask us to correct inaccurate or incomplete data
Erasure: ask us to delete your data, subject to legal exceptions
Restriction: ask us to limit how we use your data in certain circumstances
Objection: object to processing based on legitimate interests, and object at any time to direct marketing, which we will stop
Portability: receive the data you gave us in a structured, machine readable format, or have it sent to another controller, where we process it by automated means on the basis of consent or contract
Withdraw consent: at any time, where we rely on consent, without affecting processing that took place before you withdrew it
To exercise any of these rights, email general@xrlabs.ai or write to our registered office. You do not need to use a form or legal wording.
We will respond within one month of receiving your request. We may extend this by up to two further months for complex or numerous requests, and will tell you within the first month if so. Where we need to confirm your identity or ask you to clarify what you are looking for, the time taken to receive your reply does not count towards that period. There is no fee unless a request is manifestly unfounded or excessive.
Complaints
If you are unhappy with how we have handled your personal data, or with our response to a request, you have the right to complain to us. Email general@xrlabs.ai with the word "complaint" in the subject line, or write to our registered office. You do not need to use any particular wording.
We will acknowledge your complaint within 30 days, investigate it, and tell you the outcome and any action taken without undue delay.
You also have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO), at any time:
Telephone: 0303 123 1113
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
If you are in the European Economic Area you may also complain to the supervisory authority in the country where you live or work.
Children
Our website and services are intended for professionals and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We review this policy at least once a year and whenever our processing or the law changes. The date at the top shows when it was last updated. Where a change materially affects how we use your data and we hold your contact details, we will tell you directly. Earlier versions are available on request.