Privacy Notice

Endaxi AIG — Website & Service

IOLIS Ltd (Company no. 11968202)  |  30 June 2026  |  Version 1.0

This Privacy Notice explains how IOLIS Ltd (“we”, “us”, “our”), the operator of Endaxi AIG, collects, uses, and protects personal data when you visit our website, sign up for an account, or use the Service. It applies to visitors, prospective customers, and individual Users of Endaxi AIG. If you are a User accessing the Service through your employer’s or client’s subscription, please also see the note in Section 9 on the separate role of your organisation.

1. Who We Are

IOLIS Ltd is the data controller for the personal data described in this notice, except where stated otherwise in Section 9. We are a company registered in England and Wales, company number 11968202, with our registered office at Wales, United Kingdom.

Contact us about this notice or any privacy matter at [email protected].

2. What Personal Data We Collect

2.1 Information you give us directly

  • Account details — name, work email address, job title, organisation name, when you register for an account or request a demo
  • Billing details — billing contact name, email, and address (we do not collect or store full card numbers; payment processing is handled by our payment provider)
  • Communications — anything you send us by email, contact form, or support request, including the content of your message
  • Newsletter sign-up — email address, if you subscribe to receive updates

2.2 Information collected automatically

  • Website usage data — pages visited, time spent, referring URL, browser type and version, device type, and approximate location (derived from IP address)
  • Service usage data — login times, IP address recorded against actions taken within the platform (for audit and security purposes), and feature usage patterns
  • Cookies and similar technologies — see Section 6

2.3 Information generated through your use of the Service

If you are a User of Endaxi AIG, your organisation’s subscription involves storing data you and your colleagues enter into the platform — including your name, role, and actions you take (recorded in the append-only audit log for compliance purposes). Where your organisation’s data includes personal data about other individuals (for example, named AI system owners, individuals referenced in risk assessments), that processing is governed by our Data Processing Agreement with your organisation, not directly by this notice — see Section 9.

3. How We Use Your Personal Data and Our Legal Basis

Under UK GDPR, we must have a lawful basis for each use of your personal data. The table below sets out our purposes and the relevant basis.

PurposeLegal Basis
Creating and administering your accountPerformance of a contract (Art. 6(1)(b))
Providing and maintaining the Service, including security and audit loggingPerformance of a contract; Legitimate interests (Art. 6(1)(b) and (f)) — ensuring platform security and integrity
Processing payments and billingPerformance of a contract; Legal obligation (Art. 6(1)(b) and (c)) — accounting and tax records
Responding to enquiries and support requestsLegitimate interests (Art. 6(1)(f)) — operating a responsive support function; Performance of a contract where you are already a customer
Sending service-related communications (e.g. security notices, changes to these terms)Legal obligation; Legitimate interests (Art. 6(1)(c) and (f))
Sending marketing communications about Endaxi AIGConsent, where required (Art. 6(1)(a)); Legitimate interests for existing customers regarding similar products, subject to your right to object (Art. 6(1)(f))
Website analytics and improving our website and ServiceLegitimate interests (Art. 6(1)(f)) — understanding how our website and Service are used; Consent for non-essential cookies
Preventing fraud, abuse, and security incidentsLegitimate interests (Art. 6(1)(f)); Legal obligation where applicable
Complying with legal and regulatory obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have considered that interest against your rights and freedoms and concluded our processing is proportionate and within your reasonable expectations. You can ask us for more detail about this balancing assessment at any time.

4. Who We Share Your Data With

We do not sell your personal data. We share personal data only with the following categories of recipient, and only as necessary for the purposes described in Section 3:

RecipientPurpose
Hetzner Online GmbH (EU — Helsinki, Finland)Infrastructure hosting for our website and the Service. All Service data is hosted within the EU/EEA.
Postmark (ActiveCampaign LLC, USA)Transactional email delivery — account verification, two-factor authentication codes, password resets, and service notifications. Limited to your email address and the specific message content required.
Payment processor (details provided at checkout)Processing of subscription payments. We do not store full payment card details ourselves.
Professional advisers (accountants, auditors, lawyers)Where necessary for legal, accounting, or audit purposes, subject to confidentiality obligations.
Regulators and law enforcementWhere required by law, court order, or to protect our legal rights, the rights of others, or to prevent fraud or harm.
A buyer in the event of a business transferIf we sell or transfer all or part of our business, personal data may be transferred as part of that transaction, subject to equivalent protections being maintained.

A full list of sub-processors used in connection with the Service itself (as opposed to our general business operations) is maintained in our Data Processing Agreement, available on request.

5. International Transfers

Personal data relating to your use of the Service is hosted on servers located in Helsinki, Finland, within the European Economic Area. Some personal data — specifically, transactional email delivery via Postmark/ActiveCampaign — is processed in the United States. Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or reliance on an applicable UK adequacy regulation. You can request further details of the safeguards we use by contacting us at [email protected].

6. Cookies and Similar Technologies

6.1 What cookies we use

Our website uses cookies and similar technologies to make the site function, understand how visitors use it, and improve it over time.

CategoryPurpose
Strictly necessaryRequired for the website and Service to function — for example, maintaining your login session and security tokens. These cannot be disabled.
AnalyticsHelp us understand how visitors use our website so we can improve it. Used only with your consent where required by law.
FunctionalRemember your preferences (for example, cookie consent choices) to improve your experience on return visits.

6.2 Managing cookies

Where consent is required, you will be shown a cookie banner on first visiting our website allowing you to accept or decline non-essential cookies. You can change your preferences at any time via the cookie settings link in our website footer, or by adjusting your browser settings to block or delete cookies. Blocking strictly necessary cookies may affect the functionality of our website and Service.

7. Data Retention

Data TypeRetention Period
Account and billing dataDuration of your subscription, plus 6 years after termination for accounting and tax purposes
Service data (Customer Data, audit logs)Duration of your organisation’s subscription, plus 30 days after termination to allow data export, then securely deleted (see our Data Processing Agreement)
Marketing contact detailsUntil you unsubscribe or object, or 24 months of inactivity, whichever is earlier
Website analytics dataUp to 26 months, in line with standard analytics provider retention periods
Support and enquiry correspondence3 years from the date of the last communication, unless a longer period is needed to resolve a dispute

We retain personal data only for as long as necessary for the purposes set out in this notice, or as required by law.

8. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — ask us to correct inaccurate or incomplete data
  • Right to erasure — ask us to delete your personal data, subject to certain legal exceptions
  • Right to restrict processing — ask us to limit how we use your data in certain circumstances
  • Right to data portability — ask us to provide your data in a structured, machine-readable format, or transfer it to another provider
  • Right to object — object to processing based on legitimate interests, or to direct marketing at any time
  • Rights related to automated decision-making — we do not make any decisions about you using solely automated means that produce legal or similarly significant effects

To exercise any of these rights, contact us at [email protected]. We will respond within one month, extendable by a further two months for complex requests, in which case we will explain why. We may need to verify your identity before acting on a request.

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or the data protection authority in your EU member state if applicable.

9. If You Access the Service Through Your Employer or a Client

If you use Endaxi AIG as a User under your employer’s or another organisation’s subscription, that organisation is the data controller for the Customer Data you enter into the platform — including AI system records, risk assessments, and other governance content (see our Data Processing Agreement). We act as a data processor for that data, processing it only on the organisation’s instructions.

This Privacy Notice covers our role as data controller for the account and platform-level data described in Sections 2–8 above — your account credentials, login activity, and your direct communications with us. For questions about how your organisation processes your personal data within the Service, please contact your organisation’s data protection lead or DPO in the first instance.

10. Children’s Privacy

Our website and Service are intended for business use by adults acting in a professional capacity. We do not knowingly collect personal data from children, and the Service is not directed at or designed for use by children.

11. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS/HSTS), Argon2id password hashing, email-based two-factor authentication, role-based access controls, append-only audit logging, and hosting on EU-based bare-metal infrastructure with no public cloud exposure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to protect your data using industry-appropriate safeguards and review these measures regularly.

12. Changes to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices or legal requirements. We will post the updated notice on our website with a revised “last updated” date, and where changes are material, we will notify registered Users by email. We encourage you to review this notice periodically.

13. Contact Us

If you have any questions about this notice or how we handle your personal data, please contact us:

[email protected]

You also have the right to contact the Information Commissioner’s Office (ICO), the UK’s independent regulator for data protection, at ico.org.uk or by telephone on 0303 123 1113.