Legal
Privacy policy
X-Radius is billing software for internet providers. That puts data in three different places with three different owners, and most questions about privacy here are really questions about which of the three you mean. This page separates them, then says what is in each.
Which of the three you are asking about
Three places, three owners
-
01
This website
The pages you are reading. It sets no cookie, loads no third-party script and runs no analytics. The only thing it can learn about you is what its server log records and what you type into the contact form.
-
02
An internet provider's own system
Where subscriber records live: names, plans, sessions, payments. The provider runs that system and answers for it. If you are somebody's internet subscriber, this is the one that holds your data, and they are who to ask.
-
03
X-Radius Control
What we keep in order to supply the software: which systems exist, which licence each holds, what version it runs, and the encrypted backups an operator chooses to send us. No subscriber record is in it.
1. Who we are
X-Radius publishes this website and the X-Radius platform. Where an internet provider hosts their system with us, we hold it on their instructions; where they run it on their own server, we hold nothing of theirs at all. Section 4 is the part that says which of those you are in.
Write to info@x-radius.com about anything on this page. Security reports have their own address in security.txt.
The registered company name and postal address are available on request from that address.
2. What this site collects
Two things, and nothing else.
The server log
Every web server keeps one. Ours records the time, the address you asked for, the response code, your IP address and your browser's user-agent string. Query strings are stripped from the log before it is written, so a link that carries a token in its address does not leave that token in a log file.
What you type into the contact form
Only if you send it. Section 3 lists the fields.
What this site does not do
- No cookie is set. There is nothing to consent to, which is why you are not being asked.
- No analytics product, no tag manager, no advertising pixel, no social widget, no embedded video, no web font loaded from somebody else's server. The page you are reading comes from one host.
- The light or dark setting you pick is kept by your own browser and never sent to us.
- The contact form is protected by a small calculation your browser performs and a hidden field robots fill in. Both run here. There is no third-party challenge, so no other company learns that you visited.
3. When you send us a message
The contact form stores what you typed: name, email address, phone, company, country, the type of operator you said you are, the rough number of subscribers you said you have, and your message. Alongside it we keep the page you sent it from, the language you were reading in, any campaign parameters that were in the link you arrived by, your IP address, your user-agent string and the time.
The IP address and user-agent are there for one reason: the form is public, and they are what separates a person from a flood. The same pair is what a rate limit counts.
The message is then passed from the website's server to X-Radius Control, so that a person sees it and replies. It is not passed anywhere else, and it is never used to build an advertising profile or sold to anyone.
4. Who controls what in the product
When an internet provider runs X-Radius, their subscribers' records — names, contact details, plans, sessions, invoices, payments, support tickets — live in their system's database. They decide what is in it, and they answer for it. In data-protection language they are the controller.
Our position depends on where that system runs:
- On their own server. We supply the software and nothing more. Their subscribers' data never reaches us, and we could not produce it if asked.
- Hosted by us. We hold their system on their behalf and act only on their instructions. We do not use what is in it for any purpose of our own.
So if you are an internet subscriber and you want to know what is held about you, or want it corrected or deleted, the provider you buy your service from is who to ask. We cannot answer for them, and passing your request to them is the only lawful thing we can do with data that is theirs.
5. What Control holds
X-Radius Control is the system we use to supply and support the software. It holds:
| What | Why |
|---|---|
| A record of each system: its name, its address, its size and the version it runs. | So updates can be built and shipped, and so support knows what it is looking at. |
| Licence records: what was bought, for how many subscribers, until when. | Because the licence is what the software checks. |
| The account of the person who operates it, and the people they invite. | So they can sign in. |
| Messages sent through the contact form on this site. | So somebody answers them. |
| Backups an operator chooses to configure, encrypted before they leave their server. | So a system can be restored. The encryption is applied at their end; a backup is not readable by us in passing. |
Subscriber records are not in Control. They stay on the system that holds them.
6. Where data is stored
An internet provider's system runs on the server chosen when it was installed. If they chose their own, the answer is their own data centre and nobody else's. If they asked us to host it, it runs on the hosting we provide, and the region it runs in is part of what was agreed when it was set up. An operator who needs the answer in writing for their own compliance should ask for it and we will state it for their system specifically, because a single answer for every system would be wrong for most of them.
This website and X-Radius Control run on our own hosting.
7. How long things are kept
- Server logs. They rotate: old files are discarded as new ones are written, and they are not archived anywhere.
- Contact messages. Kept while they are useful for answering you and for the conversation that follows. Ask us to delete yours and we will.
- Licence and system records. Kept while a system exists, and afterwards only as long as our accounting and tax obligations require.
- Backups. Kept to the schedule the operator sets. Older ones are discarded as newer ones arrive.
- Subscriber records inside a system. Their operator sets this, not us. The software ships the controls for it — per-plan cleanup rules, an archival step, and a recycle bin that holds deleted records for a window before they go for good — and which of those are switched on is the operator's decision.
8. Who else can see it
Nobody, for advertising or measurement: there is no analytics company, no advertising network and no data broker in any part of this. Nothing is sold or rented.
Three kinds of third party can be involved in a running system, and in every case it is because the operator turned them on and gave them their own credentials:
- A payment gateway, when an operator accepts card or wallet payments. The payment is made at the gateway; what comes back to the system is the outcome and a reference.
- A message channel, when an operator sends email, SMS, Telegram or WhatsApp notifications to their subscribers. What the channel carries is whatever the notification says.
- Storage for backups, when an operator points backups at their own cloud storage. The backup is encrypted before it leaves their server.
We can also be required to disclose something by law. If that happens and we are allowed to say so, we will.
9. How it is protected
Traffic to this site, to a provider's system and to Control is HTTPS throughout. Each provider's data is separated inside the database by the database itself, not only by application code, so a query cannot reach another provider's rows even if the code above it is wrong.
Staff passwords are stored as a modern password hash, never in a form that can be read back. Sessions can be revoked, and a second factor can be switched on. Support access to a customer's system is not standing: it is granted for a task and it is recorded.
If you believe you have found a vulnerability, the address in security.txt is the one to use.
10. Your rights, and how to use them
You can ask for a copy of what is held about you, ask for it to be corrected, ask for it to be deleted, object to a particular use, or ask for it to be handed over in a portable form.
Where to send that request is the whole point of this page:
- You are an internet subscriber. Ask your internet provider. They hold your record and they can act on it the same day. We cannot.
- You run X-Radius, or you contacted us through this site. Write to us. We will answer within a month, and sooner where we can; if a request will take longer than that we will tell you why before the month is out.
We do not charge for this, and we will not make you give a reason. If you are unhappy with how we handled it, you can complain to the data-protection authority where you live.
11. Children
This is business software, sold to businesses and used by their staff. It is not directed at children and has no content aimed at them. We do not knowingly hold data about a child. Whether an internet provider's own subscriber list includes a minor is a question for that provider.
12. Changes and contact
Changes are published here with the date they take effect. A change that widens what we collect or who sees it will also be sent to the operators it affects, so it is not possible to meet it only by re-reading this page.
The X-Radius Operator mobile app has its own policy: mobile app privacy. Everything else goes to the address on the contact page.
In effect from .