Privacy Notice
1. Who we are
Oxalis (operated by Oxalis.AI Ltd, a company registered in England & Wales) provides intelligence products derived from public financial-services registers. We are the data controller for the personal data described in this notice. Contact us at privacy@oxalis.ai.
2. What this notice covers
We process two categories of personal data: register data (about individuals listed on public financial-services registers) and account data (information you provide as a subscriber). The lawful basis, retention and rights below differ between the two.
3. Register data
3.1 Where it comes from
We obtain it from the public-facing online registers maintained by global financial regulatory authorities.
3.2 Why we process it
To produce market-intelligence reports.
3.3 Lawful basis
Article 6(1)(f) UK GDPR — legitimate interests. Our legitimate interest is providing market intelligence to our subscribers; we have balanced this against the interests of the individuals concerned, taking into account that the original publication of this data by the regulators is itself lawful, mandated, and continuing.
3.4 Retention
We retain register-derived records while they remain on the source register, and for a limited period after.
3.5 Your rights — register data
Email privacy@oxalis.ai to ask us to:
- Confirm what we hold about you (access);
- Correct anything inaccurate (rectification);
- Stop further processing or remove our record (erasure / restriction / objection).
Please include your name as it appears on the register and your regulator reference if you know it — it helps us locate your record.
4. Account data (subscribers)
4.1 What we hold
Account and subscription details, plus basic usage logs.
4.2 Lawful basis
Article 6(1)(b) UK GDPR — contract. We need this data to provide the service you signed up for. Some optional analytics rely on Article 6(1)(f) — legitimate interests in improving the product.
4.3 Retention
For as long as your account is active. After you close your account we delete personal data within a reasonable period, except where law requires longer retention.
4.4 Your rights — account data
You have the full set of UK GDPR rights: access, rectification, erasure, restriction, portability and objection. Most are available directly from your account page; for the rest, contact privacy@oxalis.ai.
5. Sharing
We share personal data only with the suppliers we need to run the service. We do not sell personal data.
6. International transfers
Our infrastructure is in the European Economic Area. Where data is processed outside the EEA / UK we use the safeguards required by UK GDPR.
7. Cookies and tracking
Our public pages (this notice, the landing page, the sign-in form) set no cookies and no client-side storage — nothing is stored on your device when you browse unauthenticated. There is no banner because there is nothing to consent to.
Once you sign in as a subscriber, the application stores a session token in your browser (essential for authentication) and uses first-party analytics to record which pages you visit, the broad device class (operating system, browser, mobile / desktop, screen size), and how long you spend in the app. This processing is under Art 6(1)(b) — necessary for performing the contract we have with you. We retain individual analytics records for up to 90 days.
We also capture server-side error messages and browser JavaScript errors that occur while you're using the service. These are used strictly to fix bugs you'd otherwise hit silently — the same 90-day retention applies. No third-party error-tracking services are involved (no Sentry, no LogRocket); errors stay on our infrastructure.
We use no third-party trackers — no Google Analytics, no advertising pixels, no behavioural-ad networks. To object to analytics collection, email privacy@oxalis.ai; we will flag your account so subsequent sessions are excluded.
8. Security
We take appropriate technical and organisational measures to protect personal data.
9. Complaints
You can complain to the UK Information Commissioner's Office (ico.org.uk) at any time. We'd appreciate the chance to address your concern first — privacy@oxalis.ai.
10. Changes
We may update this notice; the date above shows the latest version.