This Privacy Policy explains how Elevyn Technology Group Limited ("we", "us", "our", "Elevyn", or "the Company") collects, uses, stores, shares and protects personal data in connection with Regulyn ("Regulyn", the "Service", or the "Platform"), our HR compliance and handbook management platform.
We are committed to handling personal data lawfully, fairly and transparently in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and other applicable data-protection law.
1. Who We Are
Regulyn is operated by Elevyn Technology Group Limited, a company registered in England and Wales.
- Company: Elevyn Technology Group Limited
- Company number: 16954601
- Registered address: 167-169 Great Portland Street, London, W1W 5PF, United Kingdom
- Email: support@regulyn.co.uk
- ICO registration number: ZC078522
For personal data relating to our customers, users, website visitors, prospects and business contacts, Elevyn Technology Group Limited is generally the data controller.
Where a customer uses Regulyn to upload, create, analyse or otherwise process personal data relating to its employees, workers, applicants or other individuals, the customer will normally be the data controller and Elevyn Technology Group Limited will act as a data processor on the customer's behalf, in accordance with our contractual and data-processing obligations.
2. Data We Collect
We collect and process different types of personal data depending on how you interact with Regulyn.
2.1 Account Information
When an account is created or managed, we may process:
- full name;
- email address;
- company or organisation name;
- job title, where provided;
- account preferences and settings;
- authentication and security information; and
- information relating to account access and activity.
Authentication credentials are handled using secure authentication services. We do not intentionally store passwords in plain text.
2.2 Handbook, Policy and HR Content
When you use Regulyn, we may process content that you create, upload, import, generate or analyse, including:
- employee handbook content;
- individual policies and policy sections;
- HR documents;
- policy and compliance analysis;
- generated recommendations and redrafts;
- version history and change records;
- organisation profile information used to tailor content;
- tone, style and drafting preferences; and
- related metadata required to provide the Service.
This content may contain personal data relating to employees, workers, applicants or other individuals. Customers are responsible for ensuring that they have an appropriate lawful basis for providing such personal data to Regulyn and for complying with their own transparency and data-protection obligations.
Customers should avoid including personal data, and particularly special category or highly sensitive personal data, where it is not necessary for the feature being used.
2.3 Chat and Interactive Features
If you use chat, assistant or other interactive features within Regulyn, we may process:
- questions, prompts and instructions submitted to the Service;
- relevant handbook, policy or document content required to answer the request;
- conversation history within the relevant feature or session;
- generated responses;
- citations or source references; and
- technical metadata associated with the interaction.
2.4 Payment and Billing Information
When you subscribe to a paid plan, we may process:
- billing name and address;
- transaction information;
- invoices;
- subscription status;
- VAT information, where applicable; and
- limited payment-related information supplied by our payment processor.
Payment card details are processed securely by our payment provider. Regulyn does not store full payment card numbers.
2.5 Technical and Usage Data
We may automatically collect:
- IP address;
- browser type and version;
- device type and operating system;
- pages visited and features used;
- dates and times of access;
- referring website or source;
- error, diagnostic and performance information;
- security and authentication logs; and
- information about how users interact with the Service.
2.6 Communications and Support
When you contact us, we may process:
- email correspondence;
- support requests and tickets;
- information you provide when requesting assistance;
- feedback;
- survey responses; and
- records of communications with us.
2.7 Email Newsletter
If you subscribe to The Regulyn Brief or another Regulyn marketing communication, we process your email address and any related subscription preferences for the purpose of sending those communications.
The legal basis for this processing is normally your consent. You can unsubscribe at any time using the link included in our marketing emails or by contacting us.
3. How We Use Personal Data
We use personal data only where we have a lawful basis and where it is reasonably necessary for the relevant purpose.
3.1 Providing and Operating Regulyn
We may use personal data to:
- create and manage user accounts;
- authenticate users and maintain account security;
- store and manage handbook, policy and HR content;
- analyse policies and documents;
- provide compliance-related analysis and recommendations;
- generate, redraft and improve documents;
- answer questions about handbook and policy content;
- perform automated quality, consistency and validation checks;
- export content in supported formats;
- provide integrations and API functionality;
- maintain version history and audit information; and
- provide other features requested by the user.
3.2 Payments and Administration
We may use personal data to:
- process subscriptions and payments;
- issue invoices;
- manage billing;
- process refunds;
- administer customer accounts; and
- maintain records required for accounting, tax and legal purposes.
3.3 Communications
We may use personal data to:
- send service-related notifications;
- provide password reset, authentication and security messages;
- respond to support requests;
- communicate about changes to the Service;
- send product information where permitted; and
- send marketing communications where you have consented or where otherwise permitted by law.
3.4 Improvement, Analytics and Service Quality
We may use appropriate account, usage, technical and service information to:
- monitor performance and reliability;
- identify and resolve errors;
- understand how the Service is used;
- improve existing features;
- develop new features;
- monitor the quality of generated and analysed content;
- detect misuse, abuse or security threats; and
- maintain and improve the overall quality and safety of Regulyn.
Where possible, we use aggregated, anonymised or minimised information for these purposes.
3.5 Legal, Security and Compliance Purposes
We may process personal data to:
- comply with legal and regulatory obligations;
- respond to lawful requests;
- establish, exercise or defend legal claims;
- enforce our agreements and policies;
- investigate fraud or misuse;
- protect the security and integrity of Regulyn; and
- protect the rights, property or safety of Elevyn, our customers, users or others.
4. Legal Bases for Processing
Depending on the circumstances, we rely on one or more of the following legal bases under UK GDPR.
4.1 Contract
We process personal data where necessary to enter into or perform a contract with you, including to:
- provide access to Regulyn;
- provide requested features and services;
- manage your account;
- process subscriptions and payments; and
- provide customer support.
4.2 Legitimate Interests
We process personal data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms.
These interests may include:
- operating and improving Regulyn;
- ensuring service reliability;
- information security;
- fraud and misuse prevention;
- product development;
- business administration;
- service analytics; and
- understanding and improving customer experience.
4.3 Consent
We rely on consent where required, including for:
- certain marketing communications; and
- non-essential cookies or similar technologies.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing that took place before consent was withdrawn.
4.4 Legal Obligation
We may process personal data where necessary to comply with a legal obligation, including tax, accounting, regulatory and law-enforcement requirements.
4.5 Special Category Data
Regulyn is not designed to require special category personal data for ordinary handbook drafting and compliance analysis.
However, customers may choose to include information that constitutes special category data within HR content. Where Regulyn processes such information on behalf of a customer, the customer is responsible for identifying an appropriate lawful basis and condition for processing.
Customers should not provide special category or other highly sensitive personal data unless it is genuinely necessary for the relevant use of the Service.
5. Data Sharing
We do not sell personal data.
We share or make personal data available only where necessary for the purposes described in this policy, where required by law, or where you have asked or authorised us to do so.
5.1 Service Providers
We use carefully selected third-party service providers to help us operate and deliver Regulyn.
These may include:
- cloud hosting and infrastructure providers;
- artificial intelligence and automated analysis providers;
- specialist automated quality-assurance and validation providers;
- authentication and security providers;
- payment processors;
- transactional email and communications providers;
- analytics and website-performance providers;
- monitoring, logging and error-diagnostic providers; and
- newsletter and marketing communications providers.
Depending on their function, these providers may process account data, technical information, billing information, document content or other limited information necessary to provide their services to us.
We require service providers that process personal data on our behalf to do so subject to appropriate contractual, confidentiality, security and data-protection obligations.
We seek to minimise the information shared with external providers to what is reasonably necessary for the relevant processing.
Further information about the categories of service providers we use, including information relating to international transfers, is available by contacting support@regulyn.co.uk.
5.2 Legal and Regulatory Disclosures
We may disclose personal data where required or permitted by law, including in response to:
- court orders or other valid legal process;
- requests from law-enforcement or regulatory authorities;
- requirements to protect legal rights;
- security incidents or suspected unlawful activity; or
- requirements to establish, exercise or defend legal claims.
5.3 Business Transfers
If Elevyn Technology Group Limited is involved in a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, personal data may be transferred as part of that transaction subject to appropriate safeguards.
5.4 At Your Direction
We may disclose or transfer personal data to another organisation where you or the relevant customer instructs or authorises us to do so.
6. International Data Transfers
Regulyn's primary service data is hosted within the United Kingdom or European Economic Area where this is practicable for the relevant service.
Some specialist technology providers supporting Regulyn may process limited personal data in countries outside the United Kingdom.
6.1 International Processing
Where an external provider processes personal data outside the United Kingdom, we seek to:
- limit the information provided to what is necessary for the relevant task;
- assess the nature and purpose of the processing;
- use appropriate contractual and technical safeguards; and
- avoid unnecessary transfer of identifying or sensitive information.
International processing may arise in connection with services such as artificial intelligence processing, automated analysis, quality assurance, authentication, communications, analytics, monitoring and other supporting technology services.
6.2 Transfer Safeguards
Where required by UK data-protection law, we use an appropriate international-transfer mechanism. Depending on the circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved Standard Contractual Clauses;
- Standard Contractual Clauses where applicable; or
- another legally recognised transfer mechanism.
Where required, we also carry out appropriate assessments of the transfer and the protections available for the personal data concerned.
You may request further information about safeguards relevant to your personal data by contacting support@regulyn.co.uk.
7. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to meet contractual, legal, accounting, security and regulatory requirements.
The actual retention period may vary depending on the type of information and the circumstances.
7.1 Typical Retention Periods
| Data type | Typical retention period |
|---|---|
| Account information | Duration of account and up to 2 years after closure, where necessary |
| Handbook, policy and HR content | Duration of account, subject to deletion and backup processes |
| Deleted customer content | Normally removed from active systems promptly and from applicable backups within the relevant backup lifecycle |
| Chat or assistant conversation history | Normally up to 90 days unless a different retention period applies to the feature |
| Payment, invoice and accounting records | Up to 7 years where required for tax, accounting or legal purposes |
| Support communications | Normally up to 3 years after resolution |
| Analytics data | In accordance with the configured analytics retention period and applicable consent |
| Security, server and diagnostic logs | Normally up to 90 days unless required longer for security or legal reasons |
We may retain information for longer where required by law, where reasonably necessary for security, fraud prevention or dispute resolution, or where a legal claim may arise.
7.2 Account and Data Deletion
When an account is closed or a valid deletion request is completed:
- customer content will be deleted or rendered inaccessible in accordance with our deletion processes;
- account information will be deleted, anonymised or retained only where there is a lawful reason to keep it;
- applicable backups will be purged or overwritten according to their normal retention cycle; and
- information required for legal, tax, accounting, fraud-prevention or dispute purposes may be retained for the applicable period.
8. Data Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure.
8.1 Technical Measures
Depending on the component of the Service, these measures may include:
- encryption of data in transit;
- encryption of stored data where appropriate;
- role-based and least-privilege access controls;
- secure authentication mechanisms;
- multi-factor authentication where supported;
- logging and monitoring;
- vulnerability and dependency management;
- infrastructure and application security controls; and
- backup and recovery processes.
We deliberately do not publish detailed security architecture in this Privacy Policy where doing so could weaken the security of Regulyn.
8.2 Organisational Measures
These may include:
- access to personal data on a need-to-know basis;
- confidentiality obligations;
- security and data-protection procedures;
- incident-management processes;
- supplier and processor assessment;
- periodic security reviews; and
- appropriate contractual controls with service providers.
8.3 Security Standards
Regulyn uses infrastructure and service providers that maintain recognised security and compliance programmes where appropriate to the services they provide.
Any statement regarding a third party's certification applies to that provider and does not imply that Regulyn itself holds the same certification.
8.4 Personal Data Breaches
If a personal data breach occurs, we will assess the risk and comply with applicable notification requirements.
Where required by UK GDPR, this may include:
- notifying the Information Commissioner's Office within the applicable statutory period; and
- notifying affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
We also document relevant incidents and the steps taken in response.
9. Your Data Protection Rights
Subject to applicable law and any relevant exemptions, you may have the following rights.
9.1 Access
You may request confirmation of whether we process your personal data and request a copy of that data.
9.2 Rectification
You may request correction of inaccurate personal data and completion of incomplete personal data.
9.3 Erasure
You may request deletion of your personal data in certain circumstances.
9.4 Restriction
You may request restriction of processing in certain circumstances.
9.5 Data Portability
Where applicable, you may request personal data you have provided to us in a structured, commonly used and machine-readable format or request its transfer to another controller where technically feasible.
9.6 Objection
You may object to processing based on legitimate interests in certain circumstances.
You have an absolute right to object to the use of your personal data for direct marketing.
9.7 Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
9.8 Automated Decision-Making
You have rights in relation to decisions based solely on automated processing where those decisions produce legal or similarly significant effects.
Regulyn's AI-generated and automated outputs are designed to support human review and decision-making. Regulyn does not make employment decisions on behalf of customers.
9.9 Exercising Your Rights
To exercise your rights, contact:
- Email: support@regulyn.co.uk
- Suggested subject: Data Protection Request
We may need to verify your identity before completing a request.
We normally respond within one month, subject to any extension permitted by law.
Where Regulyn processes personal data solely as a processor on behalf of a customer, we may need to refer your request to that customer as the relevant data controller.
9.10 Complaints
If you are dissatisfied with how we handle your personal data, please contact us first so that we can investigate.
You also have the right to complain to the Information Commissioner's Office:
- Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
- Telephone: 0303 123 1113
- Website: https://ico.org.uk/
11. Artificial Intelligence and Automated Processing
Regulyn uses artificial intelligence and other automated technologies to provide document analysis, drafting, compliance support, interactive assistance and quality assurance.
11.1 How We Use AI and Automated Processing
Depending on the feature, automated systems may be used to:
- analyse policy and handbook text;
- identify possible gaps, inconsistencies or compliance issues;
- generate draft or revised policy wording;
- generate HR documents;
- answer questions about handbook or policy content;
- provide recommendations or explanations;
- perform automated quality, consistency and validation checks; and
- identify outputs that may require further review.
11.2 External AI and Technology Providers
Regulyn uses carefully selected specialist technology providers to support artificial intelligence processing, automated analysis and quality assurance.
Depending on the feature being used, limited portions of prompts, document content, policy content, organisation information or related metadata may be securely processed by these providers where necessary to provide the requested function.
We apply data-minimisation principles and seek to limit information supplied to external processing services to what is reasonably necessary for the relevant task.
Where practical, identifying or sensitive information is excluded from specialist automated quality-assurance processing when it is not required.
Our providers are subject to contractual and data-protection obligations governing their processing of personal data on our behalf. Where international processing occurs, the safeguards described in Section 6 apply.
We do not permit customer content to be used to train general-purpose artificial intelligence models except where this has been expressly agreed with the relevant customer.
11.3 Human Oversight
AI-generated or automated content provided by Regulyn is intended to assist users rather than replace appropriate human judgement.
Users retain control over matters such as:
- whether to accept, reject or modify generated content;
- what content is saved;
- what policies or documents are adopted;
- whether recommendations are acted upon; and
- what documents are exported, issued or otherwise used.
Regulyn does not make recruitment, dismissal, disciplinary, remuneration or other employment decisions on behalf of customers.
11.4 AI Limitations
Artificial intelligence and automated analysis can make mistakes, omit relevant context or produce output that requires correction.
Customers should review material before relying on it, particularly where it may affect legal rights, employee relations or significant business decisions.
Regulyn provides technology-assisted HR compliance and policy support. Unless expressly stated otherwise, Regulyn does not provide legal advice and is not a substitute for advice from a suitably qualified professional where legal advice is required.
12. Children's Privacy
Regulyn is a business service and is not intended for use by children.
We do not knowingly create accounts for, market the Service to, or directly collect personal data from children under 18 as users of Regulyn.
A customer's HR content may, in limited circumstances, contain information concerning a child or young person. Where this occurs, the customer remains responsible for ensuring that the information is processed lawfully and is necessary for the relevant purpose.
If you believe personal data relating to a child has been provided to us inappropriately, please contact support@regulyn.co.uk.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- our services and features;
- our processing activities;
- our service providers;
- applicable law or regulatory guidance; or
- our security and compliance practices.
When we update the policy, we will revise the Last updated date above.
Where a change is material, we may also provide notice through the Service, by email, or by another appropriate method.
We encourage you to review this policy periodically.
14. Contact Us
If you have questions, concerns or requests relating to this Privacy Policy or our handling of personal data, please contact:
Elevyn Technology Group Limited
- Address: 167-169 Great Portland Street, London, W1W 5PF, United Kingdom
- Email: support@regulyn.co.uk
- Company number: 16954601
- ICO registration number: ZC078522
For data-protection-specific enquiries, please include Data Protection in the email subject line.