Oxalis.AI

Talent intelligence for frontier industries

Privacy Notice

Last updated: 16 May 2026

1. Who we are

Oxalis (operated by Oxalis.AI Ltd, a company registered in England & Wales) provides intelligence products derived from public financial-services registers. We are the data controller for the personal data described in this notice. Contact us at privacy@oxalis.ai.

2. What this notice covers

We process two categories of personal data: register data (about individuals listed on public financial-services registers) and account data (information you provide as a subscriber). The lawful basis, retention and rights below differ between the two.

3. Register data

3.1 Where it comes from

We obtain it from the public-facing online registers maintained by global financial regulatory authorities.

3.2 Why we process it

To produce market-intelligence reports.

3.3 Lawful basis

Article 6(1)(f) UK GDPR — legitimate interests. Our legitimate interest is providing market intelligence to our subscribers; we have balanced this against the interests of the individuals concerned, taking into account that the original publication of this data by the regulators is itself lawful, mandated, and continuing.

3.4 Retention

We retain register-derived records while they remain on the source register, and for a limited period after.

3.5 Your rights — register data

Note on erasure. Because the source regulators continue to publish this data on their own registers, an erasure request to Oxalis will not remove your information from the public source. We will still consider every erasure request, but where the source publication is current and lawful we may decline under Article 17(3)(b) UK GDPR (legal obligation / public interest).

Email privacy@oxalis.ai to ask us to:

Please include your name as it appears on the register and your regulator reference if you know it — it helps us locate your record.

4. Account data (subscribers)

4.1 What we hold

Account and subscription details, plus basic usage logs.

4.2 Lawful basis

Article 6(1)(b) UK GDPR — contract. We need this data to provide the service you signed up for. Some optional analytics rely on Article 6(1)(f) — legitimate interests in improving the product.

4.3 Retention

For as long as your account is active. After you close your account we delete personal data within a reasonable period, except where law requires longer retention.

4.4 Your rights — account data

You have the full set of UK GDPR rights: access, rectification, erasure, restriction, portability and objection. Most are available directly from your account page; for the rest, contact privacy@oxalis.ai.

5. Sharing

We share personal data only with the suppliers we need to run the service. We do not sell personal data.

6. International transfers

Our infrastructure is in the European Economic Area. Where data is processed outside the EEA / UK we use the safeguards required by UK GDPR.

7. Cookies and tracking

Our public pages (this notice, the landing page, the sign-in form) set no cookies and no client-side storage — nothing is stored on your device when you browse unauthenticated. There is no banner because there is nothing to consent to.

Once you sign in as a subscriber, the application stores a session token in your browser (essential for authentication) and uses first-party analytics to record which pages you visit, the broad device class (operating system, browser, mobile / desktop, screen size), and how long you spend in the app. This processing is under Art 6(1)(b) — necessary for performing the contract we have with you. We retain individual analytics records for up to 90 days.

We also capture server-side error messages and browser JavaScript errors that occur while you're using the service. These are used strictly to fix bugs you'd otherwise hit silently — the same 90-day retention applies. No third-party error-tracking services are involved (no Sentry, no LogRocket); errors stay on our infrastructure.

We use no third-party trackers — no Google Analytics, no advertising pixels, no behavioural-ad networks. To object to analytics collection, email privacy@oxalis.ai; we will flag your account so subsequent sessions are excluded.

8. Security

We take appropriate technical and organisational measures to protect personal data.

9. Complaints

You can complain to the UK Information Commissioner's Office (ico.org.uk) at any time. We'd appreciate the chance to address your concern first — privacy@oxalis.ai.

10. Changes

We may update this notice; the date above shows the latest version.