Effective Date: 11 September 2026
Issued by: The Xdemor Group Limited · Company No. 14456444
Registered Office: 86-90 Paul St., London, EC2A 4NE, United Kingdom
Jurisdiction: England and Wales
1. Purpose #
This policy governs the creation, usage, suspension, and termination of user accounts and system access across Xdemor’s infrastructure, services, and customer-facing platforms. It ensures secure access control, traceability, and protection of both client and platform data.
2. Scope #
Applies to:
- All clients, subcontractors, and partners with access to Xdemor-controlled systems (including the Client Account at secure.shared-services.co and the Support Portal)
- Xdemor personnel with access to internal systems
- Any platform account managed or hosted by Xdemor infrastructure
3. Account Creation #
- User accounts are created only upon verified request from the Controller (client, partner, or authorized staff)
- All user accounts must be associated with a valid, monitored email address
- Multi-user accounts must have a designated Account Owner and defined access roles (Admin, Editor, Viewer, etc.)
- Default access is granted on a least privilege basis
4. Account Access & Roles #
- Role-based access is enforced to restrict users only to required data or tools
- Admin roles may manage team members, billing, projects, and sensitive settings
- User actions may be logged for audit purposes
- Shared credentials are strictly prohibited
- Two-factor authentication (2FA) is required for Admin-level roles
5. Access to Third-Party Accounts #
- Where Xdemor operates under delegated access (e.g., Google Ads, Meta, GA4), client must provide admin-level credentials via secure means
- Client acknowledges that such delegated access may be suspended or revoked upon contract termination or misuse
- Changes to third-party credentials must be reported within 24–48 hours to avoid service disruptions
6. Account Usage Guidelines #
Users must not:
- Share access credentials with unauthorized persons
- Use platform accounts for unlawful, abusive, or prohibited activities
- Attempt to bypass security protocols, interfere with system functionality, or access restricted areas
- Store or process Special Category Data unless explicitly agreed
Violation of these terms may lead to suspension or permanent deactivation of access.
7. Account Deactivation #
Accounts may be deactivated:
- Upon request by the Client or user
- Upon project completion, subscription expiry, or contract termination
- If inactive for more than 180 days (archival may apply)
- In case of detected abuse, breach, or compromise
Xdemor reserves the right to retain metadata for audit and legal compliance even after deactivation.
8. Access to Client Systems #
- All credentials must be delivered via secure channel (e.g., vault, encrypted email)
- Xdemor will not retain access beyond the agreed project scope unless otherwise specified
- Xdemor will store credentials securely and may use privileged access logging internally
9. Data Security & Logging #
- All access to production systems is logged and monitored
- Access logs may include IP address, timestamp, user ID, and actions
- Logs are retained in accordance with the [Data Retention Policy]
10. Incident Response & Breaches #
Suspected access breaches or policy violations must be reported via:
- Online Violation Request Form ↗
- Support Portal: https://support.shared-services.co/support/tickets/create
Please include your full name, contact details, and a clear description of the issue. For verification, we may respond within 24–48 hours.
Xdemor will notify clients of any unauthorized access to their environments or accounts without undue delay, per our Data Breach Response Policy.
11. Changes to Policy #
Xdemor may update this Account & Access Policy to reflect changes in access protocols, security posture, or legal requirements. Material changes will be communicated in advance.
12. Contact #
If you have questions or concerns regarding this policy or wish to exercise any rights under data protection laws, contact us at:
The Xdemor Group Limited
Compliance & Legal
86-90 Paul St., London, EC2A 4NE, United Kingdom
Support Portal: https://support.shared-services.co/support/tickets/create
Data Protection Officer: dpo@xdemor.com
Additional contact addresses:
- privacy@xdemor.com – For personal information requests (access, correction, deletion, objection)
- legal@xdemor.com – For formal legal correspondence
To submit a Data Subject Access Request (DSAR):
- Submit Online Data Request Form ↗
- Include full name, contact details, and clear description of your request
Controlled Exit, Verified Instructions and Support Channels #
Integration rule: This section forms part of the policy from 11 September 2026 and controls any inconsistent wording in this document concerning its subject matter.
Document Hierarchy and Operational Instructions #
If governing documents are inconsistent, mandatory applicable law prevails, followed by: (a) an express Individual Agreement or Order Form; (b) the Shared Services Data Processing Agreement solely for personal-data processing; (c) the Shared Services Terms of Service; (d) the applicable brand or service-specific policy; (e) the applicable Service Description or pricing schedule; and (f) an Accepted Client Instruction for the specific operation.
An accepted service-change, access or handover form controls only the requested operational action. It cannot amend a higher-ranking document, remove an applicable payment requirement, require a technically unavailable action, or override mandatory law, the DPA or Registry/Registrar requirements.
Restricted Instructions #
Restricted Instruction means an instruction concerning a domain transfer or change of Registrant; DNS record or nameserver change; hosting migration or cutover; full or partial data export; backup release or restoration; cPanel, FTP, SFTP, SSH or other administrative access; credential reset or disclosure; mailbox or email-routing change; third-party access or appointment; suspension, cancellation, deletion or another destructive action; ownership or account-holder change; or release of personal, confidential or regulated data.
A Restricted Instruction must be submitted through the approved secure form or another instrument expressly accepted for that purpose. The accepted form and generated scope schedule control the requested operational action within the existing contractual framework. A message recorded within the authoritative ticket may clarify but may not add a domain, recipient, dataset, access right or technical action. A material change requires a new instruction or an audited amendment approved through the same verification level.
Material contradictions place the request into Clarification Required. No affected technical action is taken until they are resolved. Blanket authority for unspecified future Restricted Instructions is ineffective.
Granular Third-Party Authority #
Third-party authority is not general permission. Separate scopes apply to submitting technical information; communicating about the case; issuing approved technical instructions; receiving a specified export; performing the Client-side migration; providing DNS or nameserver instructions; receiving time-limited access; and receiving transfer or authorisation codes. Authority to communicate does not imply authority to receive data, access systems, change DNS or transfer domains.
Where relevant, the authority record must identify the third party’s full legal name, legal form or trading status, registration number, full registered or principal business address, named natural-person representative, business email and telephone, exact scope, start date and expiry, approved recipient, receiving provider, destination country and secure destination. Final account-holder approval must be completed through the registered account email or another approved step-up verification method.
Reasonable Communication Adjustments #
We will consider reasonable communication adjustments for a disabled Client or representative, including plain-language communication, accessible formatting, additional explanation, assistance from an authorised representative, or a proportionate alternative where the Support Portal creates a genuine accessibility barrier. Any alternative communication will be transferred into the authoritative case record.
An adjustment does not by itself waive payment, renew or extend a Service, remove identity or authority verification, weaken security controls, expand scope, include free custom migration, or guarantee retention or recovery. Medical evidence will not be requested unless necessary and proportionate. Disability or health information will be minimised, handled as sensitive personal data and, where practicable, kept separate from routine technical correspondence. An adjustment request will not be treated as an adverse billing or risk factor.
Official Support and Reporting Channels #
Customer and technical support requests must be submitted through the Support Ticket form at https://support.shared-services.co/support/tickets/create. A request is received only when the system creates a ticket or reference.
Email aliases, WhatsApp, Viber, telephone, live chat and social-media messages are not support-intake channels. They do not create a case, expand scope, restart a review or establish priority. An email reply counts only if the Support Portal successfully records it within an existing ticket and confirms receipt.
Reports of abuse or policy violations must be submitted at https://policies.shared-services.co/submit-request/. Specifically published @xdemor.com privacy, data-protection and formal legal contacts remain valid for their stated purposes.