Terms of Use

Please read these terms carefully before using Endaxi Brief.

Last updated: June 2026

1. About these Terms

These Terms of Use (“Terms”) govern access to and use of the Endaxi Brief platform (“Brief”, “the Service”), operated by IOLIS Ltd, a company registered in Wales (Company No. 11968202), with registered address at C5 Business Centre, C5 North Road, Bridgend Industrial Estate, Bridgend, Wales, CF31 3TP (“IOLIS”, “we”, “us”).

By accessing or using the Service, you and the organisation on whose behalf you act (“Customer”, “you”) agree to be bound by these Terms. If you do not agree, you must not use the Service.

2. Access and Accounts

Access to Brief is provided on an invitation-only basis during the current supervised rollout phase. Each organisation using Brief (“Customer”) must have a valid account. User accounts are created by an organisation administrator and are personal to the individual named on the account.

You are responsible for maintaining the confidentiality of your login credentials. You must notify us immediately at [email protected] if you believe your account has been compromised. You are responsible for all activity conducted through your account.

3. Permitted Use

Brief is licensed to you for the purpose of managing investigation cases and preparing papers for disciplinary or regulatory hearings within your organisation. The Service may only be used for lawful purposes and in accordance with these Terms.

You may not:

  • use the Service for any purpose that is unlawful or prohibited by these Terms
  • attempt to gain unauthorised access to any part of the Service or its infrastructure
  • use the Service to store or transmit any material that is defamatory, unlawful or infringes any third-party rights
  • reverse engineer, decompile or attempt to extract source code from the Service
  • resell or sublicense access to the Service to any third party without our prior written consent
  • upload content to the AI analysis features that includes unnecessary personal data unrelated to the analytical task being performed

4. Data and Privacy

Our collection and use of personal data in connection with the Service is governed by our Privacy Policy. Where IOLIS processes personal data on your behalf as data processor, the terms of the Data Processing Addendum below also apply and form part of these Terms.

You are the data controller for case and investigation data uploaded to Brief. You are responsible for ensuring you have an appropriate lawful basis for processing any personal data held within Brief, and that such processing is disclosed in your own privacy notices.

5. AI Features

The AI analysis features within Brief are provided to assist with document review and hearing preparation. AI outputs are provided as an aid to professional judgement and must be reviewed carefully before being relied upon. IOLIS does not warrant the accuracy or completeness of any AI-generated output, and you remain solely responsible for all decisions made in connection with your cases.

AI processing is performed by Mistral AI SAS, a French company operating within the European Union. By using the AI features, you consent to relevant document text being transmitted to Mistral AI for the purpose of generating analysis. Please refer to the Data Processing Addendum for details of this sub-processor arrangement.

6. Intellectual Property

The Service, including all software, design, text and documentation, is owned by IOLIS Ltd and protected by copyright and other intellectual property laws. Nothing in these Terms transfers any ownership of intellectual property to you.

Data and documents uploaded by your organisation remain your property. You grant IOLIS a limited, non-exclusive licence to store, process and transmit that data solely as necessary to provide the Service.

7. Availability and Support

We aim to keep Brief available and operating normally, but we do not warrant that the Service will be uninterrupted or error-free. Planned maintenance will be communicated to administrators in advance where possible. We provide support by email at [email protected] and aim to respond within one business day.

8. Limitation of Liability

To the fullest extent permitted by applicable law, IOLIS shall not be liable for any indirect, incidental, special, consequential or punitive damages, or loss of profits, data or business opportunities, arising out of or in connection with your use of the Service, even if we have been advised of the possibility of such damages.

Our total aggregate liability to you in connection with the Service, whether in contract, tort (including negligence) or otherwise, shall not exceed the total fees paid by your organisation in the twelve months preceding the event giving rise to the claim, or £500, whichever is greater.

Nothing in these Terms limits or excludes our liability for death or personal injury caused by our negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded by law.

9. Indemnification

You agree to indemnify and hold harmless IOLIS Ltd and its officers, employees and contractors from and against any claims, losses, damages, costs and expenses (including reasonable legal fees) arising out of your use of the Service in violation of these Terms or applicable law.

10. Termination

Either party may terminate access to the Service on written notice. We reserve the right to suspend or terminate access immediately if you breach these Terms, fail to pay applicable fees, or if we are required to do so by law. On termination, your organisation’s data will be deleted in accordance with our Privacy Policy and the Data Processing Addendum.

11. Changes to these Terms

We may update these Terms from time to time. We will notify you of material changes by email at least 14 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised Terms.

12. Governing Law

These Terms are governed by the laws of England and Wales. Any disputes arising under or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales, except where mandatory consumer protection law in your jurisdiction requires otherwise.

13. Contact

For questions about these Terms, contact us at [email protected] or write to IOLIS Ltd at the address above.


Data Processing Addendum

This Addendum forms part of the Terms of Use and governs the processing of personal data by IOLIS Ltd on behalf of the Customer.

1. Definitions

In this Addendum, the following definitions apply in addition to those in the main Terms:

  • “Controller” means the Customer organisation that determines the purposes and means of processing Personal Data uploaded to Brief.
  • “Processor” means IOLIS Ltd, which processes Personal Data on behalf of the Controller.
  • “Personal Data” has the meaning given in UK GDPR / EU GDPR.
  • “Processing” has the meaning given in UK GDPR / EU GDPR.
  • “Data Protection Law” means UK GDPR, the Data Protection Act 2018, and (where applicable) EU GDPR and other applicable data protection legislation.
  • “Sub-processor” means any third party engaged by IOLIS to process Personal Data under this Addendum.

2. Scope and Nature of Processing

IOLIS processes Personal Data on behalf of the Controller solely for the purpose of providing the Brief service as described in these Terms. The categories of data subjects and types of personal data processed are those uploaded to the Brief platform by the Controller’s users, which may include: names, contact details, statements, interview records and other information relating to individuals involved in investigations or disciplinary proceedings.

The duration of processing is for the term of the Customer’s access to Brief, plus any retention period agreed in writing or required by applicable law.

3. Controller Obligations

The Controller is responsible for:

  • ensuring it has an appropriate lawful basis for processing any Personal Data uploaded to Brief
  • ensuring its own privacy notices accurately describe the processing carried out via Brief
  • providing accurate and complete information to data subjects about the processing of their data
  • ensuring that only necessary and proportionate Personal Data is uploaded to the Service
  • responding to data subject rights requests in relation to Personal Data for which it is Controller

4. Processor Obligations

IOLIS Ltd, as Processor, undertakes to:

  • process Personal Data only on documented instructions from the Controller (namely, to provide the Service), except where required to do so by applicable law
  • ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations
  • implement appropriate technical and organisational security measures as described in Clause 7 below
  • assist the Controller in responding to data subject rights requests, to the extent technically practicable
  • notify the Controller without undue delay on becoming aware of a Personal Data breach affecting the Controller’s data
  • on termination, delete or return all Personal Data (at the Controller’s election) within 30 days, unless a longer retention period is required by law
  • make available to the Controller all information reasonably necessary to demonstrate compliance with this Addendum

5. Sub-processors

The Controller hereby grants general authorisation to IOLIS to engage sub-processors, subject to the conditions in this Clause. IOLIS will notify the Controller of any intended changes to sub-processor arrangements, giving the Controller a reasonable opportunity to object before the change takes effect.

Current approved sub-processors are:

  • Mistral AI SAS — 15 rue des Halles, 75001 Paris, France. Purpose: AI analysis of case documents submitted via the AI Analysis feature. Processing location: European Union. Data submitted to Mistral AI is not retained beyond the scope of the individual request and is not used for model training.

IOLIS will ensure that sub-processor agreements impose data protection obligations equivalent to those in this Addendum.

6. International Transfers

IOLIS will not transfer Personal Data outside the UK or EEA without ensuring that appropriate safeguards are in place. Mistral AI processes data within the European Union. Where any transfer to a third country is necessary, IOLIS will rely on an adequacy decision, Standard Contractual Clauses or another approved transfer mechanism under applicable Data Protection Law.

7. Security Measures

IOLIS implements and maintains the following technical and organisational measures:

  • AES-256-GCM encryption of all documents at rest, using a three-tier key hierarchy (system, organisation and case level)
  • Argon2id password hashing for all user credentials
  • Two-factor authentication (email-based OTP) for all application logins
  • Database-backed opaque session tokens with CSRF protection
  • Comprehensive audit logging of all case actions with user identity, timestamp and IP address
  • Strict data segregation between organisations at the application layer
  • Access controls limiting data access to authorised users within the relevant organisation

8. Personal Data Breaches

IOLIS will notify the Controller without undue delay (and in any event within 72 hours where feasible) upon becoming aware of a Personal Data breach affecting the Controller’s data. The notification will include: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.

9. Data Subject Rights

Where IOLIS receives a request directly from a data subject in relation to Personal Data for which the Controller is the data controller, IOLIS will promptly refer that request to the Controller. IOLIS will provide reasonable assistance to the Controller in fulfilling data subject rights requests, including access, rectification, erasure and portability, to the extent technically practicable.

10. Deletion and Return

On termination of the Customer’s access to Brief (for any reason), IOLIS will delete all Personal Data processed on behalf of the Controller within 30 days, unless retention is required by applicable law. IOLIS will confirm deletion in writing upon request. Where the Controller requests return of data prior to deletion, IOLIS will provide a data export in a portable format within 14 days of that request.

11. Audits

IOLIS will, upon reasonable written notice (not less than 14 days), provide the Controller with all information reasonably necessary to demonstrate compliance with this Addendum. Audits by the Controller or its appointed auditor may be requested no more than once per year and must be conducted during normal business hours, at the Controller’s expense, and in a manner that minimises disruption to IOLIS’s operations.

12. Governing Law

This Addendum is governed by the laws of England and Wales and is subject to the same jurisdiction clause as the main Terms of Use.