This Privacy Policy explains how XO8 Media SAGL ("XO8 Media", "we", "us" or "our") handles personal data in connection with the website https://xo8.media (the "Site"). The Site is a static, brochure-style website that presents our services as an AI-powered content and media agency. It has no user accounts, no contact forms, no database and no e-commerce. Because of this, the personal data we process through the Site is very limited, as described below.
1. Who we are (data controller)
The controller responsible for the processing of personal data described in this policy is:
- XO8 Media SAGL
- Email: hello@xo8.media
We are based in Ticino, Switzerland, and also operate from Milano, Italy. For privacy matters you can reach us using the contact details above.
2. The personal data we process and how
We only process a small amount of personal data in connection with the Site:
2.1 Server access logs
Our web server (nginx) automatically records standard technical information each time the Site is accessed. This typically includes your IP address, browser type and user agent, the date and time of the request, the URL or resource requested, and the referring page. These logs are generated by the server itself and are used for security, troubleshooting and the reliable operation of the Site.
2.2 Data you choose to provide by email
The Site does not contain any contact form. The only way to contact us from the Site is an email link (hello@xo8.media). If you choose to email us, we receive and process the information you decide to share, such as your name, your contact details and the content of your message, so that we can read and respond to your enquiry.
2.3 Data Google may receive via Google Fonts
The Site loads web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com). When your browser requests these fonts, Google may receive your IP address and related request data. This processing takes place on Google's infrastructure and is outside our direct control. We do not use Google Fonts to identify you, and we do not combine this data with other information.
2.4 What we do not do
To be clear about how limited the Site is, we confirm that the Site:
- does not set first-party cookies and does not run first-party analytics;
- has no user accounts, no login and no user-generated content;
- has no contact forms, no database and no e-commerce;
- hosts its videos directly on our own server, with no YouTube, Vimeo or other third-party video embeds.
3. Purposes and legal bases
We process the limited personal data above for the following purposes and on the following legal bases:
- Security and reliable operation of the Site (server access logs): our legitimate interest in keeping the Site secure, preventing abuse and ensuring it works correctly. Under the Swiss FADP this processing is justified by an overriding legitimate interest; under the EU GDPR the legal basis is Article 6(1)(f) (legitimate interests).
- Responding to your enquiries (email): our legitimate interest in answering people who contact us and, where relevant, in taking steps before entering into a contract. Under the GDPR this corresponds to Article 6(1)(f) and, where applicable, Article 6(1)(b).
- Loading web fonts (Google Fonts): our legitimate interest in presenting the Site with a consistent visual design (Article 6(1)(f) GDPR). Where consent is required for such third-party requests in your jurisdiction, we will instead rely on your consent.
Where we ask for and rely on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Third parties and processors
We rely on a small number of third parties to operate the Site and to communicate with you:
- Hosting provider: the Site is hosted on a dedicated server (VPS) operated by DigitalOcean, LLC, which processes server access logs on our behalf as part of hosting the Site. HTTPS is enabled.
- Google (Google Fonts): serves the web fonts used on the Site and may receive your IP address and request data as described above.
- Email provider: if you email us, your message is handled by the email providers used by you and by us in order to deliver and store the correspondence.
We do not sell your personal data, and we do not share it for advertising purposes.
5. International data transfers
Our primary location is Switzerland, and we also operate in the EU (Milano, Italy). Personal data may therefore be processed within Switzerland and the European Economic Area, which the relevant authorities recognise as offering an adequate level of data protection for transfers between them.
Some of the third parties named above, in particular Google, are based in or may process data in the United States or other countries. Where personal data is transferred to such countries, it is protected by appropriate safeguards, such as the providers' own standard contractual clauses, applicable adequacy decisions and additional measures, in line with the Swiss FADP and the EU GDPR.
6. How long we keep your data
- Server access logs are kept only for the limited period needed for security and operational purposes, after which they are deleted or anonymised.
- Enquiry data (email messages) is kept for as long as needed to handle and follow up on your request, and thereafter only where we have a legitimate or legal reason to retain it.
7. Your rights
Subject to the conditions and exceptions set out in the Swiss Federal Act on Data Protection (FADP / nLPD) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:
- request access to the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure of your data;
- request restriction of processing;
- object to processing based on our legitimate interests;
- request data portability where applicable;
- withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at hello@xo8.media. You also have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). In the EU you may contact the supervisory authority in your country of residence, place of work or the place of the alleged infringement.
8. No automated decision-making or profiling
We do not use the personal data processed through the Site to carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
9. Children
The Site is intended for a general, professional audience and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can address it.
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Site or to legal requirements. The current version is always published on this page, with the effective date shown below. We encourage you to review it periodically.
11. Contact for privacy requests
For any question or request regarding this Privacy Policy or your personal data, please contact:
- XO8 Media SAGL
- Email: hello@xo8.media
Effective date: 2026-06-29