This policy explains how Strategic Edge Solutions Limited collects, uses and protects personal data through the Complyax platform. We comply with the UK General Data Protection Regulation, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
1. Data Controller
Strategic Edge Solutions Limited is the data controller for personal data collected through Complyax.
Registered office: 60 Tottenham Court Road, Office 1292, Fitzrovia, London, W1T 2EW
Company number: 15071492 | ICO registration: ZC132439
Contact for data protection matters: hello@complyax.com
2. Data We Collect
Data you provide:
- Account data — name, firm name, email address, phone number, billing information.
- Uploaded files — HMRC correspondence, financial data exports, client documents.
- Support communications — emails and messages sent to us.
Data collected automatically:
- Usage data — features used, pages visited, session duration.
- Technical data — IP address, browser type, device type, operating system.
- Payment data — processed by Stripe. We receive payment confirmation only. We do not store card numbers.
3. Lawful Bases for Processing
- Contract — to provide the Complyax service, manage your subscription and process payments.
- Legal obligation — to comply with UK law including the Companies Act 2006 and tax legislation.
- Legitimate interests — to improve the platform, detect fraud and send service communications.
- Consent — where you have given specific consent, such as for marketing emails. You may withdraw consent at any time.
4. Client Data You Upload
When you upload documents or data relating to your clients, you are the data controller for that data and we act as your data processor under Article 28 of the UK GDPR. We process that data solely to provide the Complyax service to you. We do not use client data for any other purpose.
A Data Processing Agreement setting out our obligations is available at complyax.com/dpa.
5. International Data Transfers
The Complyax platform uses Anthropic's API to process certain data for AI-generated outputs. Anthropic Inc. is based in the United States. Data processed through the API may be transferred to and processed in the United States. This constitutes an international transfer under UK GDPR.
This transfer is made under Standard Contractual Clauses incorporated into Anthropic's Data Processing Addendum, which forms part of Anthropic's Commercial Terms. Anthropic does not use API customer data to train its models under those Commercial Terms.
All other data is stored on servers within the United Kingdom or the European Economic Area.
6. Sub-Processors
We use the following sub-processors to deliver the Complyax service:
- Stripe — payment processing. Stripe processes data under its own privacy policy and is PCI-DSS compliant.
- Cloudflare R2 — file storage. Data is stored in UK region servers.
- Resend — transactional email delivery.
- Anthropic — AI processing of documents uploaded to the platform. See section 5 regarding international transfers.
We will notify you of any change to our sub-processors with reasonable advance notice.
7. Security
- Data in transit is encrypted using TLS 1.3.
- Data at rest is encrypted using AES-256.
- Access to personal data is restricted to staff on a need-to-know basis.
- We carry out regular security assessments of our systems and suppliers.
In the event of a personal data breach, we will notify the ICO within 72 hours where required, and will notify affected data controllers without undue delay.
8. Data Retention
- Account data — retained for the duration of your subscription and for 6 years after termination.
- Uploaded documents — retained during your subscription and deleted within 30 days of termination.
- Usage and technical data — 12 months.
- Payment records — 7 years in line with HMRC requirements.
9. Your Rights
Under the UK GDPR you have the right to:
- Access — request a copy of personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data where there is no lawful reason to retain it.
- Restriction — ask us to pause processing in certain circumstances.
- Portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interests.
To exercise any right, contact hello@complyax.com. We will respond within one calendar month. You may also complain to the ICO at ico.org.uk or by calling 0303 123 1113.
11. Changes
We may update this policy. We will notify you of material changes by email or platform notice. The current version is always at complyax.com/privacy.
12. Contact
Strategic Edge Solutions Limited
Registered office: 60 Tottenham Court Road, Office 1292, Fitzrovia, London, W1T 2EW
Company number: 15071492
ICO registration number: ZC132439
General enquiries: hello@complyax.com
Complyax support: hello@complyax.com
Website: complyax.com