Privacy Policy
Last updated: July 2026
Template notice: This document is a starting draft and does not constitute legal advice. Have it reviewed by a qualified solicitor before relying on it, particularly given NexIntent's regulated-sector customers.
This Privacy Policy explains how NexIntent RegTech Ltd ("NexIntent", "we", "us") collects, uses, stores, and protects personal data when you use our FCA compliance platform and website. We are the data controller for the personal data described here. We are committed to handling data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who we are
NexIntent RegTech Ltd is a United Kingdom company providing compliance-audit software to regulated firms. For any privacy questions or to exercise your rights, contact us at privacy@nexintent.co.uk.
What data we collect
We collect and process the following categories of personal data:
- Account data — your name, work email, company name, and role.
- Authentication data — password hashes (managed by our authentication provider) and, if enabled, two-factor authentication details.
- Compliance content — the audit responses, notes, and framework data you enter into your workspace.
- Usage and security data — sign-in events, IP addresses, and activity logs used to secure your account.
- Billing data — subscription and invoice information (payment card details are handled by our payment processor, not stored by us).
How we use your data
We process personal data to provide and secure the service, on the following legal bases:
- Performance of a contract — to create and operate your workspace, run audits, and provide support.
- Legitimate interests — to secure our platform, prevent abuse, and improve the product.
- Legal obligation — to meet our own regulatory, tax, and accounting duties.
- Consent — for optional analytics cookies and marketing, where applicable.
AI processing
Our AI compliance assistant processes compliance metadata (such as audit scores and control statuses) to answer your questions. It is designed on a zero-trust basis and does not require access to your raw customer records. Where third-party AI infrastructure is used, data is processed under contractual data-protection terms.
Sharing and sub-processors
We share data with vetted sub-processors who help us run the service — for example our hosting, database, email-delivery, and payment providers. Each is bound by data-protection terms. We do not sell your personal data.
Where your data is stored
We host data in the United Kingdom where possible. Where any processing occurs outside the UK, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses.
How long we keep data
We retain personal data for as long as your account is active and as needed to provide the service, then for any period required to meet legal obligations, after which it is deleted or anonymised.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You can:
- Access and export your workspace data from your account settings.
- Delete your account and associated data from account settings, or by contacting us.
- Contact privacy@nexintent.co.uk to exercise any right.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Security
We use encryption in transit, role-based access controls, tenant isolation, optional two-factor authentication, and audit logging to protect your data. No system is perfectly secure, but we work to protect your information using appropriate technical and organisational measures.
Changes to this policy
We may update this policy from time to time. Material changes will be notified through the service or by email. The "last updated" date above reflects the current version.