Controller and scope
The proposed controller for shop.exsel.ai is Exsel AI Inc., 254 Chapman Road, Newark, Delaware 19702, United States. Its incorporation details, dedicated privacy address and any local representative must be verified. This draft covers visitors, trade-account applicants, buyer representatives, delivery contacts and people who contact support. A separate employee or supplier notice may be needed for other relationships.
Information a person supplies
Account and enquiry forms may collect a person's name, work email, telephone number, role, company, tax or registration details, billing and shipping address, requested products, messages and attachments. Order handling may add purchase history, invoices, delivery instructions and claim evidence. Exsel should minimise free-text collection and avoid asking for sensitive personal information unless necessary and lawful.
Information produced by use of the site
The site and its hosting, security and commerce components may record IP address, device and browser characteristics, timestamps, pages visited, account events, basket state, selected country and language, error logs and fraud signals. If payment is enabled later, payment providers may process transaction identifiers and payment details under their own notices. No live card processing is claimed here.
Other sources and verification
Business identity and tax status may be checked against public registries or documents supplied by the company. Exsel should identify any credit reference, identity-verification, enrichment or sanctions-screening provider before using it. Product suppliers or carriers may provide fulfilment and claim data. These sources should not be described as active until verified.
Purposes and lawful bases
Possible purposes include answering enquiries, creating accounts, preparing and performing accepted orders, delivery, support, accounting, security, fraud prevention and legal compliance. Where GDPR or UK GDPR applies, the final notice should map each purpose to an actual lawful basis such as contract steps, legal obligation, legitimate interests or consent. Marketing consent and objection routes need a separate, verified explanation.
Who receives data
Only appropriate staff and contracted service providers should receive the data needed for their work. Potential categories include WordPress and WooCommerce hosting, email, translation, CRM, support, analytics, payment, logistics, accounting and security providers. The actual names, controller or processor roles, sub-processors and data-sharing terms require an inventory of the live environment before publication. Exsel should not assert that no data is sold without checking all advertising and data-sharing arrangements.
International transfers
A global site may involve access or storage outside a person's country. The final notice should list actual storage locations and transfer destinations and explain any required safeguards, such as adequacy decisions or contractual clauses, after vendor verification. Selecting a country or language does not imply that data remains in that jurisdiction.
Retention and deletion
Different records need different periods: account data, abandoned enquiries, completed orders, invoices, support records, security logs, consent records and backups. The final policy should publish a defensible schedule linked to tax, contract and security needs, including when an inactive account is deleted or anonymised. No specific period is promised in this draft.
Security and incidents
Exsel should use access controls, appropriate authentication, updates, backups and vendor controls proportionate to the information held. No internet system can guarantee absolute security. The final notice should identify the incident-reporting contact and describe how affected people and regulators will be notified when required by law.
Rights and requests
Depending on location and applicable law, a person may request access, correction, erasure, restriction, portability or information about sharing, and may object to certain processing or withdraw consent. Requests can currently be sent to https://shop.exsel.ai/contact-us/ while a privacy-specific address is confirmed. Identity checks may be needed. Exsel should explain any refusal and the relevant regulator or appeal route in the final country notice.
Marketing and communications
Order, security and quote messages are distinct from optional marketing. Any newsletter, remarketing or profiling practice requires its own verified basis and unsubscribe or preference controls. Exsel should not continue optional marketing after a valid opt-out, while necessary transaction messages may continue.
Children, changes and contact
The business shop is not intended for children. Material changes should be dated and explained. Privacy questions may be sent to https://shop.exsel.ai/contact-us/ pending confirmation of the dedicated privacy contact and full company details.