Privacy Notice
Endaxi AIG — Website & Service
IOLIS Ltd (Company no. 11968202) | 30 June 2026 | Version 1.0
This Privacy Notice explains how IOLIS Ltd (“we”, “us”, “our”), the operator of Endaxi AIG, collects, uses, and protects personal data when you visit our website, sign up for an account, or use the Service. It applies to visitors, prospective customers, and individual Users of Endaxi AIG. If you are a User accessing the Service through your employer’s or client’s subscription, please also see the note in Section 9 on the separate role of your organisation.
1. Who We Are
IOLIS Ltd is the data controller for the personal data described in this notice, except where stated otherwise in Section 9. We are a company registered in England and Wales, company number 11968202, with our registered office at Wales, United Kingdom.
Contact us about this notice or any privacy matter at [email protected].
2. What Personal Data We Collect
2.1 Information you give us directly
- Account details — name, work email address, job title, organisation name, when you register for an account or request a demo
- Billing details — billing contact name, email, and address (we do not collect or store full card numbers; payment processing is handled by our payment provider)
- Communications — anything you send us by email, contact form, or support request, including the content of your message
- Newsletter sign-up — email address, if you subscribe to receive updates
2.2 Information collected automatically
- Website usage data — pages visited, time spent, referring URL, browser type and version, device type, and approximate location (derived from IP address)
- Service usage data — login times, IP address recorded against actions taken within the platform (for audit and security purposes), and feature usage patterns
- Cookies and similar technologies — see Section 6
2.3 Information generated through your use of the Service
If you are a User of Endaxi AIG, your organisation’s subscription involves storing data you and your colleagues enter into the platform — including your name, role, and actions you take (recorded in the append-only audit log for compliance purposes). Where your organisation’s data includes personal data about other individuals (for example, named AI system owners, individuals referenced in risk assessments), that processing is governed by our Data Processing Agreement with your organisation, not directly by this notice — see Section 9.
3. How We Use Your Personal Data and Our Legal Basis
Under UK GDPR, we must have a lawful basis for each use of your personal data. The table below sets out our purposes and the relevant basis.
| Purpose | Legal Basis |
| Creating and administering your account | Performance of a contract (Art. 6(1)(b)) |
| Providing and maintaining the Service, including security and audit logging | Performance of a contract; Legitimate interests (Art. 6(1)(b) and (f)) — ensuring platform security and integrity |
| Processing payments and billing | Performance of a contract; Legal obligation (Art. 6(1)(b) and (c)) — accounting and tax records |
| Responding to enquiries and support requests | Legitimate interests (Art. 6(1)(f)) — operating a responsive support function; Performance of a contract where you are already a customer |
| Sending service-related communications (e.g. security notices, changes to these terms) | Legal obligation; Legitimate interests (Art. 6(1)(c) and (f)) |
| Sending marketing communications about Endaxi AIG | Consent, where required (Art. 6(1)(a)); Legitimate interests for existing customers regarding similar products, subject to your right to object (Art. 6(1)(f)) |
| Website analytics and improving our website and Service | Legitimate interests (Art. 6(1)(f)) — understanding how our website and Service are used; Consent for non-essential cookies |
| Preventing fraud, abuse, and security incidents | Legitimate interests (Art. 6(1)(f)); Legal obligation where applicable |
| Complying with legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have considered that interest against your rights and freedoms and concluded our processing is proportionate and within your reasonable expectations. You can ask us for more detail about this balancing assessment at any time.
4. Who We Share Your Data With
We do not sell your personal data. We share personal data only with the following categories of recipient, and only as necessary for the purposes described in Section 3:
| Recipient | Purpose |
| Hetzner Online GmbH (EU — Helsinki, Finland) | Infrastructure hosting for our website and the Service. All Service data is hosted within the EU/EEA. |
| Postmark (ActiveCampaign LLC, USA) | Transactional email delivery — account verification, two-factor authentication codes, password resets, and service notifications. Limited to your email address and the specific message content required. |
| Payment processor (details provided at checkout) | Processing of subscription payments. We do not store full payment card details ourselves. |
| Professional advisers (accountants, auditors, lawyers) | Where necessary for legal, accounting, or audit purposes, subject to confidentiality obligations. |
| Regulators and law enforcement | Where required by law, court order, or to protect our legal rights, the rights of others, or to prevent fraud or harm. |
| A buyer in the event of a business transfer | If we sell or transfer all or part of our business, personal data may be transferred as part of that transaction, subject to equivalent protections being maintained. |
A full list of sub-processors used in connection with the Service itself (as opposed to our general business operations) is maintained in our Data Processing Agreement, available on request.
5. International Transfers
Personal data relating to your use of the Service is hosted on servers located in Helsinki, Finland, within the European Economic Area. Some personal data — specifically, transactional email delivery via Postmark/ActiveCampaign — is processed in the United States. Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or reliance on an applicable UK adequacy regulation. You can request further details of the safeguards we use by contacting us at [email protected].
6. Cookies and Similar Technologies
6.1 What cookies we use
Our website uses cookies and similar technologies to make the site function, understand how visitors use it, and improve it over time.
| Category | Purpose |
| Strictly necessary | Required for the website and Service to function — for example, maintaining your login session and security tokens. These cannot be disabled. |
| Analytics | Help us understand how visitors use our website so we can improve it. Used only with your consent where required by law. |
| Functional | Remember your preferences (for example, cookie consent choices) to improve your experience on return visits. |
6.2 Managing cookies
Where consent is required, you will be shown a cookie banner on first visiting our website allowing you to accept or decline non-essential cookies. You can change your preferences at any time via the cookie settings link in our website footer, or by adjusting your browser settings to block or delete cookies. Blocking strictly necessary cookies may affect the functionality of our website and Service.
7. Data Retention
| Data Type | Retention Period |
| Account and billing data | Duration of your subscription, plus 6 years after termination for accounting and tax purposes |
| Service data (Customer Data, audit logs) | Duration of your organisation’s subscription, plus 30 days after termination to allow data export, then securely deleted (see our Data Processing Agreement) |
| Marketing contact details | Until you unsubscribe or object, or 24 months of inactivity, whichever is earlier |
| Website analytics data | Up to 26 months, in line with standard analytics provider retention periods |
| Support and enquiry correspondence | 3 years from the date of the last communication, unless a longer period is needed to resolve a dispute |
We retain personal data only for as long as necessary for the purposes set out in this notice, or as required by law.
8. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data
- Right to erasure — ask us to delete your personal data, subject to certain legal exceptions
- Right to restrict processing — ask us to limit how we use your data in certain circumstances
- Right to data portability — ask us to provide your data in a structured, machine-readable format, or transfer it to another provider
- Right to object — object to processing based on legitimate interests, or to direct marketing at any time
- Rights related to automated decision-making — we do not make any decisions about you using solely automated means that produce legal or similarly significant effects
To exercise any of these rights, contact us at [email protected]. We will respond within one month, extendable by a further two months for complex requests, in which case we will explain why. We may need to verify your identity before acting on a request.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or the data protection authority in your EU member state if applicable.
9. If You Access the Service Through Your Employer or a Client
If you use Endaxi AIG as a User under your employer’s or another organisation’s subscription, that organisation is the data controller for the Customer Data you enter into the platform — including AI system records, risk assessments, and other governance content (see our Data Processing Agreement). We act as a data processor for that data, processing it only on the organisation’s instructions.
This Privacy Notice covers our role as data controller for the account and platform-level data described in Sections 2–8 above — your account credentials, login activity, and your direct communications with us. For questions about how your organisation processes your personal data within the Service, please contact your organisation’s data protection lead or DPO in the first instance.
10. Children’s Privacy
Our website and Service are intended for business use by adults acting in a professional capacity. We do not knowingly collect personal data from children, and the Service is not directed at or designed for use by children.
11. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/HSTS), Argon2id password hashing, email-based two-factor authentication, role-based access controls, append-only audit logging, and hosting on EU-based bare-metal infrastructure with no public cloud exposure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your data using industry-appropriate safeguards and review these measures regularly.
12. Changes to This Notice
We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. We will post the updated notice on our website with a revised “last updated” date, and where changes are material, we will notify registered Users by email. We encourage you to review this notice periodically.
13. Contact Us
If you have any questions about this notice or how we handle your personal data, please contact us:
You also have the right to contact the Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection, at ico.org.uk or by telephone on 0303 123 1113.
