Data Protection Policy
Company No. 17265533 • Last updated: September 2026
1. Who We Are & Scope of Policy
RegLogix Limited ("Provider", "we", "us", or "our") provides regulatory intelligence, AI-assisted consultation response generation, and corporate compliance services to businesses operating in the UK energy sector via our marketing website (reglogixapp.com) and our web application portal (reglogix.web.app / reglogix.app).
This Data Protection Policy explains how we collect, store, process, and protect personal data across our public website and our full suite of SaaS platform services—including the Horizon, Meridian, Vector, and Market Pulse modules—in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What Data We Collect & Processing Purposes
2.1 User Accounts & Authentication Data
To provide secure, authenticated access to the RegLogix Portal:
- Personal Data: Full name, corporate email address, encrypted password credentials, phone number (where MFA/TOTP is enabled), assigned user role, and associated Customer Legal Entity / employer name.
- Purpose: Account creation, identity verification, Multi-Factor Authentication (MFA), role-based access control (RBAC), and user administration.
- Legal Basis: Performance of a Contract (executing platform access for your employer/organisation).
2.2 Telemetry, Security & Performance Monitoring
To maintain platform security, prevent unauthorised access, and monitor seat allocations:
- Data Collected: IP addresses, login timestamps, browser/device telemetry, multi-location access patterns, API call logs, and click-wrap terms acceptance audit records.
- Purpose: Ensuring system stability, monitoring platform performance, detecting fraudulent access or credential sharing in breach of subscription seat limits, and maintaining immutable audit logs for legal compliance.
- Legal Basis: Legitimate Interests (protecting platform security, operational integrity, and intellectual property rights).
2.3 Meridian Profile & Corporate Configuration Data
Within the Meridian profile module:
- Data Collected: Corporate regulatory posture, entity/division structures, compliance priorities, corporate persona configurations, and organizational reference documentation uploaded by users.
- Purpose: Structuring tenant-isolated AI context to tailor regulatory intelligence and consultation response strategies to your organisation's commercial requirements.
- Legal Basis: Performance of a Contract.
2.4 Vector Module Content Generation & Consultation Inputs
Within the Vector brief builder and consultation response generator:
- Data Collected: User prompts, regulatory consultation feedback inputs, strategic draft responses, document revisions, and technical synthesis outputs.
- Purpose: Generating structured consultation skeletons, technical briefing summaries, and custom policy submissions.
- Restricted Data Warning: Customers must not upload sensitive personal data, trade secrets, or un-anonymised employee data into AI generation workflows.
- Legal Basis: Performance of a Contract.
2.5 Billing, Commercial & Account Management Data
For commercial operations and subscription management:
- Data Collected: Billing contact name, corporate invoicing address, corporate email, credit usage ledgers, payment transaction history, and subscription plan tier details.
- Purpose: Issuing invoices, managing subscription renewals, tracking credit consumption, and fulfilling accounting/tax compliance obligations.
- Legal Basis: Performance of a Contract and Compliance with Legal Obligations.
2.6 Website Enquiries & Newsletter Subscriptions
For visitors to reglogixapp.com:
- Data Collected: Email address, name, job title, and enquiry message text.
- Purpose: Delivering the Horizon Pulse newsletter, responding to sales enquiries, and scheduling platform demonstrations.
- Legal Basis: Consent (newsletter) and Legitimate Interests (sales enquiries).
3. Tenant Isolation & Data Security
We employ enterprise-grade technical and organisational security measures to protect your data:
- Infrastructure Security: Data is hosted on enterprise-grade, secure cloud platforms within UK data centres.
- Tenant Isolation: Multi-tenant architecture strictly isolates customer profile data.
- No Third-Party AI Model Training: Customer inputs submitted to the Vector module or Meridian profile are processed strictly via private API endpoints and are never used to train public foundation LLMs or shared across tenants.
4. Data Retention
We retain personal data for no longer than is necessary for the purposes outlined above:
- Active Accounts: Account credentials, Meridian profiles, and Vector drafts are retained for the duration of the active subscription or evaluation period.
- Trial & Expired Accounts: Upon trial expiry or subscription termination, customer tenant data is archived and deleted within ninety (90) days, unless longer retention is required for legal or statutory tax accounting obligations.
- Marketing Data: Newsletter subscribers may opt out at any time using the unsubscribe link. Upon unsubscription, marketing data is purged from active lists within 30 days.
5. Your Rights Under UK GDPR
Under UK GDPR, individual data subjects have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your personal data ("right to be forgotten").
- Object to or restrict specific data processing operations.
- Data portability (receiving personal data in a structured, machine-readable format).
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
6. Contact Us
For any data protection enquiries, data subject access requests, or security disclosures, please contact us via the Request Early Access contact form on our homepage.