Privacy Policy
How we collect, use and protect your personal data.
Last updated: June 2026
Who we are
Endaxi Brief is operated by IOLIS Ltd, a company registered in Wales (Company No. 11968202). Our registered address is C5 Business Centre, C5 North Road, Bridgend Industrial Estate, Bridgend, Wales, CF31 3TP.
We are the data controller for personal data collected through this website and the Brief application. For any questions about this policy, contact us at [email protected].
Legal framework
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where our customers are based in the European Economic Area (EEA), we also comply with EU GDPR (Regulation 2016/679). Where we act as a data processor on behalf of a customer organisation, the terms of our Data Processing Addendum govern that processing.
What data we collect
When you use this website or the Brief application, we may collect the following categories of personal data:
- Account data — your name, email address and organisation, provided when your account is created by an administrator
- Case and document data — investigation records and documents uploaded by your organisation; this data is owned and controlled by your organisation and processed by us on their behalf
- Usage and log data — IP address, browser type, pages visited, actions taken within the application and timestamps
- Communication data — messages sent to us via the contact form or by email
How we use your data
We process personal data for the following purposes, each supported by a lawful basis under UK/EU GDPR:
- Providing the service (contract performance) — to operate the Brief platform and deliver features to your organisation
- Authentication and security (legitimate interests / contract) — to verify user identity, maintain session security and prevent unauthorised access
- Account communications (contract) — to send verification codes, password reset links and account notices
- Support (legitimate interests) — to respond to enquiries and support requests
- Legal obligations (legal obligation) — to comply with applicable law, including responding to lawful requests from authorities
We do not sell, rent or share your personal data with third parties for marketing purposes.
Case and investigation data
All documents and case records uploaded to Brief are encrypted at rest using AES-256-GCM encryption with a three-tier key hierarchy. We process this data solely to provide the Brief service. Your organisation is the data controller for case and investigation data; IOLIS Ltd acts as data processor. Please refer to our Data Processing Addendum for the full terms governing processor-level obligations.
AI analysis and European data sovereignty
When you use the AI Analysis features within Brief, relevant document text is submitted to our AI service provider for processing. We use Mistral AI SAS, a French company headquartered in Paris, with infrastructure operating within the European Union. This means your data remains within European jurisdiction at all times during AI processing.
Mistral AI does not retain submitted data beyond the scope of the individual API request. No case content is used to train or improve AI models. You should take care not to include unnecessary identifying personal data in documents submitted for AI analysis where that data is not relevant to the analytical task.
Data hosting and transfers
The Brief application and its data are hosted on infrastructure located in the United Kingdom and/or the European Economic Area. We do not transfer personal data to countries outside the UK or EEA unless adequate safeguards are in place (such as the UK’s adequacy decisions or Standard Contractual Clauses). Mistral AI’s processing occurs within the EU.
Data retention
Account data is retained for as long as your account is active. Case and document data is retained in accordance with your organisation’s data retention requirements and the terms agreed at onboarding. On termination of your organisation’s subscription, data is deleted within 30 days unless a longer retention period is required by law or has been agreed in writing.
You may request deletion of your personal data by contacting us at [email protected].
Your rights
Under UK GDPR (and EU GDPR where applicable) you have the following rights in relation to your personal data:
- Access — to request a copy of personal data we hold about you
- Rectification — to have inaccurate data corrected
- Erasure — to request deletion of your personal data in certain circumstances
- Restriction — to restrict processing in certain circumstances
- Portability — to receive your data in a structured, machine-readable format
- Objection — to object to processing based on legitimate interests
To exercise any of these rights, contact us at [email protected]. We will respond within one calendar month.
If you are based in the UK, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk. If you are based in the EEA, you may also complain to your local supervisory authority.
Cookies
This website and the Brief application use session cookies that are strictly necessary for authentication and security. We do not use advertising, tracking or analytics cookies. No consent is required for strictly necessary cookies under the UK PECR and EU ePrivacy rules.
Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. These include AES-256-GCM encryption at rest, two-factor authentication for all application access, and comprehensive audit logging.
Changes to this policy
We may update this policy from time to time. We will notify active users of any material changes by email at least 14 days before they take effect. The current version is always available at endaxibrief.com/privacy.
Contact
For any questions about this policy or how we handle your data, contact us at [email protected] or write to IOLIS Ltd at the address above.
