Legal

Privacy Policy

Last updated: 21 September 2026

This Privacy Policy explains how Elevyn Technology Group Limited ("we", "us", "our", "Elevyn", or "the Company") collects, uses, stores, shares and protects personal data in connection with Regulyn ("Regulyn", the "Service", or the "Platform"), our HR compliance and handbook management platform.

We are committed to handling personal data lawfully, fairly and transparently in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and other applicable data-protection law.

1. Who We Are

Regulyn is operated by Elevyn Technology Group Limited, a company registered in England and Wales.

  • Company: Elevyn Technology Group Limited
  • Company number: 16954601
  • Registered address: 167-169 Great Portland Street, London, W1W 5PF, United Kingdom
  • Email: support@regulyn.co.uk
  • ICO registration number: ZC078522

For personal data relating to our customers, users, website visitors, prospects and business contacts, Elevyn Technology Group Limited is generally the data controller.

Where a customer uses Regulyn to upload, create, analyse or otherwise process personal data relating to its employees, workers, applicants or other individuals, the customer will normally be the data controller and Elevyn Technology Group Limited will act as a data processor on the customer's behalf, in accordance with our contractual and data-processing obligations.

2. Data We Collect

We collect and process different types of personal data depending on how you interact with Regulyn.

2.1 Account Information

When an account is created or managed, we may process:

  • full name;
  • email address;
  • company or organisation name;
  • job title, where provided;
  • account preferences and settings;
  • authentication and security information; and
  • information relating to account access and activity.

Authentication credentials are handled using secure authentication services. We do not intentionally store passwords in plain text.

2.2 Handbook, Policy and HR Content

When you use Regulyn, we may process content that you create, upload, import, generate or analyse, including:

  • employee handbook content;
  • individual policies and policy sections;
  • HR documents;
  • policy and compliance analysis;
  • generated recommendations and redrafts;
  • version history and change records;
  • organisation profile information used to tailor content;
  • tone, style and drafting preferences; and
  • related metadata required to provide the Service.

This content may contain personal data relating to employees, workers, applicants or other individuals. Customers are responsible for ensuring that they have an appropriate lawful basis for providing such personal data to Regulyn and for complying with their own transparency and data-protection obligations.

Customers should avoid including personal data, and particularly special category or highly sensitive personal data, where it is not necessary for the feature being used.

2.3 Chat and Interactive Features

If you use chat, assistant or other interactive features within Regulyn, we may process:

  • questions, prompts and instructions submitted to the Service;
  • relevant handbook, policy or document content required to answer the request;
  • conversation history within the relevant feature or session;
  • generated responses;
  • citations or source references; and
  • technical metadata associated with the interaction.

2.4 Payment and Billing Information

When you subscribe to a paid plan, we may process:

  • billing name and address;
  • transaction information;
  • invoices;
  • subscription status;
  • VAT information, where applicable; and
  • limited payment-related information supplied by our payment processor.

Payment card details are processed securely by our payment provider. Regulyn does not store full payment card numbers.

2.5 Technical and Usage Data

We may automatically collect:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • pages visited and features used;
  • dates and times of access;
  • referring website or source;
  • error, diagnostic and performance information;
  • security and authentication logs; and
  • information about how users interact with the Service.

2.6 Communications and Support

When you contact us, we may process:

  • email correspondence;
  • support requests and tickets;
  • information you provide when requesting assistance;
  • feedback;
  • survey responses; and
  • records of communications with us.

2.7 Email Newsletter

If you subscribe to The Regulyn Brief or another Regulyn marketing communication, we process your email address and any related subscription preferences for the purpose of sending those communications.

The legal basis for this processing is normally your consent. You can unsubscribe at any time using the link included in our marketing emails or by contacting us.

3. How We Use Personal Data

We use personal data only where we have a lawful basis and where it is reasonably necessary for the relevant purpose.

3.1 Providing and Operating Regulyn

We may use personal data to:

  • create and manage user accounts;
  • authenticate users and maintain account security;
  • store and manage handbook, policy and HR content;
  • analyse policies and documents;
  • provide compliance-related analysis and recommendations;
  • generate, redraft and improve documents;
  • answer questions about handbook and policy content;
  • perform automated quality, consistency and validation checks;
  • export content in supported formats;
  • provide integrations and API functionality;
  • maintain version history and audit information; and
  • provide other features requested by the user.

3.2 Payments and Administration

We may use personal data to:

  • process subscriptions and payments;
  • issue invoices;
  • manage billing;
  • process refunds;
  • administer customer accounts; and
  • maintain records required for accounting, tax and legal purposes.

3.3 Communications

We may use personal data to:

  • send service-related notifications;
  • provide password reset, authentication and security messages;
  • respond to support requests;
  • communicate about changes to the Service;
  • send product information where permitted; and
  • send marketing communications where you have consented or where otherwise permitted by law.

3.4 Improvement, Analytics and Service Quality

We may use appropriate account, usage, technical and service information to:

  • monitor performance and reliability;
  • identify and resolve errors;
  • understand how the Service is used;
  • improve existing features;
  • develop new features;
  • monitor the quality of generated and analysed content;
  • detect misuse, abuse or security threats; and
  • maintain and improve the overall quality and safety of Regulyn.

Where possible, we use aggregated, anonymised or minimised information for these purposes.

3.5 Legal, Security and Compliance Purposes

We may process personal data to:

  • comply with legal and regulatory obligations;
  • respond to lawful requests;
  • establish, exercise or defend legal claims;
  • enforce our agreements and policies;
  • investigate fraud or misuse;
  • protect the security and integrity of Regulyn; and
  • protect the rights, property or safety of Elevyn, our customers, users or others.

5. Data Sharing

We do not sell personal data.

We share or make personal data available only where necessary for the purposes described in this policy, where required by law, or where you have asked or authorised us to do so.

5.1 Service Providers

We use carefully selected third-party service providers to help us operate and deliver Regulyn.

These may include:

  • cloud hosting and infrastructure providers;
  • artificial intelligence and automated analysis providers;
  • specialist automated quality-assurance and validation providers;
  • authentication and security providers;
  • payment processors;
  • transactional email and communications providers;
  • analytics and website-performance providers;
  • monitoring, logging and error-diagnostic providers; and
  • newsletter and marketing communications providers.

Depending on their function, these providers may process account data, technical information, billing information, document content or other limited information necessary to provide their services to us.

We require service providers that process personal data on our behalf to do so subject to appropriate contractual, confidentiality, security and data-protection obligations.

We seek to minimise the information shared with external providers to what is reasonably necessary for the relevant processing.

Further information about the categories of service providers we use, including information relating to international transfers, is available by contacting support@regulyn.co.uk.

5.2 Legal and Regulatory Disclosures

We may disclose personal data where required or permitted by law, including in response to:

  • court orders or other valid legal process;
  • requests from law-enforcement or regulatory authorities;
  • requirements to protect legal rights;
  • security incidents or suspected unlawful activity; or
  • requirements to establish, exercise or defend legal claims.

5.3 Business Transfers

If Elevyn Technology Group Limited is involved in a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, personal data may be transferred as part of that transaction subject to appropriate safeguards.

5.4 At Your Direction

We may disclose or transfer personal data to another organisation where you or the relevant customer instructs or authorises us to do so.

6. International Data Transfers

Regulyn's primary service data is hosted within the United Kingdom or European Economic Area where this is practicable for the relevant service.

Some specialist technology providers supporting Regulyn may process limited personal data in countries outside the United Kingdom.

6.1 International Processing

Where an external provider processes personal data outside the United Kingdom, we seek to:

  • limit the information provided to what is necessary for the relevant task;
  • assess the nature and purpose of the processing;
  • use appropriate contractual and technical safeguards; and
  • avoid unnecessary transfer of identifying or sensitive information.

International processing may arise in connection with services such as artificial intelligence processing, automated analysis, quality assurance, authentication, communications, analytics, monitoring and other supporting technology services.

6.2 Transfer Safeguards

Where required by UK data-protection law, we use an appropriate international-transfer mechanism. Depending on the circumstances, this may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved Standard Contractual Clauses;
  • Standard Contractual Clauses where applicable; or
  • another legally recognised transfer mechanism.

Where required, we also carry out appropriate assessments of the transfer and the protections available for the personal data concerned.

You may request further information about safeguards relevant to your personal data by contacting support@regulyn.co.uk.

7. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to meet contractual, legal, accounting, security and regulatory requirements.

The actual retention period may vary depending on the type of information and the circumstances.

7.1 Typical Retention Periods

Data typeTypical retention period
Account informationDuration of account and up to 2 years after closure, where necessary
Handbook, policy and HR contentDuration of account, subject to deletion and backup processes
Deleted customer contentNormally removed from active systems promptly and from applicable backups within the relevant backup lifecycle
Chat or assistant conversation historyNormally up to 90 days unless a different retention period applies to the feature
Payment, invoice and accounting recordsUp to 7 years where required for tax, accounting or legal purposes
Support communicationsNormally up to 3 years after resolution
Analytics dataIn accordance with the configured analytics retention period and applicable consent
Security, server and diagnostic logsNormally up to 90 days unless required longer for security or legal reasons

We may retain information for longer where required by law, where reasonably necessary for security, fraud prevention or dispute resolution, or where a legal claim may arise.

7.2 Account and Data Deletion

When an account is closed or a valid deletion request is completed:

  • customer content will be deleted or rendered inaccessible in accordance with our deletion processes;
  • account information will be deleted, anonymised or retained only where there is a lawful reason to keep it;
  • applicable backups will be purged or overwritten according to their normal retention cycle; and
  • information required for legal, tax, accounting, fraud-prevention or dispute purposes may be retained for the applicable period.

8. Data Security

We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure.

8.1 Technical Measures

Depending on the component of the Service, these measures may include:

  • encryption of data in transit;
  • encryption of stored data where appropriate;
  • role-based and least-privilege access controls;
  • secure authentication mechanisms;
  • multi-factor authentication where supported;
  • logging and monitoring;
  • vulnerability and dependency management;
  • infrastructure and application security controls; and
  • backup and recovery processes.

We deliberately do not publish detailed security architecture in this Privacy Policy where doing so could weaken the security of Regulyn.

8.2 Organisational Measures

These may include:

  • access to personal data on a need-to-know basis;
  • confidentiality obligations;
  • security and data-protection procedures;
  • incident-management processes;
  • supplier and processor assessment;
  • periodic security reviews; and
  • appropriate contractual controls with service providers.

8.3 Security Standards

Regulyn uses infrastructure and service providers that maintain recognised security and compliance programmes where appropriate to the services they provide.

Any statement regarding a third party's certification applies to that provider and does not imply that Regulyn itself holds the same certification.

8.4 Personal Data Breaches

If a personal data breach occurs, we will assess the risk and comply with applicable notification requirements.

Where required by UK GDPR, this may include:

  • notifying the Information Commissioner's Office within the applicable statutory period; and
  • notifying affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

We also document relevant incidents and the steps taken in response.

9. Your Data Protection Rights

Subject to applicable law and any relevant exemptions, you may have the following rights.

9.1 Access

You may request confirmation of whether we process your personal data and request a copy of that data.

9.2 Rectification

You may request correction of inaccurate personal data and completion of incomplete personal data.

9.3 Erasure

You may request deletion of your personal data in certain circumstances.

9.4 Restriction

You may request restriction of processing in certain circumstances.

9.5 Data Portability

Where applicable, you may request personal data you have provided to us in a structured, commonly used and machine-readable format or request its transfer to another controller where technically feasible.

9.6 Objection

You may object to processing based on legitimate interests in certain circumstances.

You have an absolute right to object to the use of your personal data for direct marketing.

9.7 Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time.

9.8 Automated Decision-Making

You have rights in relation to decisions based solely on automated processing where those decisions produce legal or similarly significant effects.

Regulyn's AI-generated and automated outputs are designed to support human review and decision-making. Regulyn does not make employment decisions on behalf of customers.

9.9 Exercising Your Rights

To exercise your rights, contact:

  • Email: support@regulyn.co.uk
  • Suggested subject: Data Protection Request

We may need to verify your identity before completing a request.

We normally respond within one month, subject to any extension permitted by law.

Where Regulyn processes personal data solely as a processor on behalf of a customer, we may need to refer your request to that customer as the relevant data controller.

9.10 Complaints

If you are dissatisfied with how we handle your personal data, please contact us first so that we can investigate.

You also have the right to complain to the Information Commissioner's Office:

  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
  • Telephone: 0303 123 1113
  • Website: https://ico.org.uk/

10. Cookies and Analytics

We use cookies and similar technologies to operate, secure, understand and improve Regulyn.

10.1 Essential Technologies

Essential cookies and similar technologies may be used for purposes such as:

  • authentication;
  • security;
  • fraud prevention;
  • session management;
  • account preferences; and
  • core service functionality.

These technologies are required for parts of Regulyn to function correctly.

10.2 Analytics

Where you have provided the required consent, we may use analytics and website-interaction technologies to understand how visitors and users interact with our website and Service.

Depending on the tools in use, this may include information such as:

  • pages visited;
  • approximate geographic region;
  • traffic source;
  • browser and device type;
  • clicks, scrolling and navigation behaviour; and
  • performance and interaction information.

We seek to configure analytics tools to minimise unnecessary collection of personal data and to mask or exclude sensitive content where supported.

10.3 Managing Cookies

You can manage non-essential cookies through our consent controls and, where applicable, your browser settings.

Disabling essential technologies may prevent parts of Regulyn from functioning correctly.

For further information, please see our Cookie Policy.

11. Artificial Intelligence and Automated Processing

Regulyn uses artificial intelligence and other automated technologies to provide document analysis, drafting, compliance support, interactive assistance and quality assurance.

11.1 How We Use AI and Automated Processing

Depending on the feature, automated systems may be used to:

  • analyse policy and handbook text;
  • identify possible gaps, inconsistencies or compliance issues;
  • generate draft or revised policy wording;
  • generate HR documents;
  • answer questions about handbook or policy content;
  • provide recommendations or explanations;
  • perform automated quality, consistency and validation checks; and
  • identify outputs that may require further review.

11.2 External AI and Technology Providers

Regulyn uses carefully selected specialist technology providers to support artificial intelligence processing, automated analysis and quality assurance.

Depending on the feature being used, limited portions of prompts, document content, policy content, organisation information or related metadata may be securely processed by these providers where necessary to provide the requested function.

We apply data-minimisation principles and seek to limit information supplied to external processing services to what is reasonably necessary for the relevant task.

Where practical, identifying or sensitive information is excluded from specialist automated quality-assurance processing when it is not required.

Our providers are subject to contractual and data-protection obligations governing their processing of personal data on our behalf. Where international processing occurs, the safeguards described in Section 6 apply.

We do not permit customer content to be used to train general-purpose artificial intelligence models except where this has been expressly agreed with the relevant customer.

11.3 Human Oversight

AI-generated or automated content provided by Regulyn is intended to assist users rather than replace appropriate human judgement.

Users retain control over matters such as:

  • whether to accept, reject or modify generated content;
  • what content is saved;
  • what policies or documents are adopted;
  • whether recommendations are acted upon; and
  • what documents are exported, issued or otherwise used.

Regulyn does not make recruitment, dismissal, disciplinary, remuneration or other employment decisions on behalf of customers.

11.4 AI Limitations

Artificial intelligence and automated analysis can make mistakes, omit relevant context or produce output that requires correction.

Customers should review material before relying on it, particularly where it may affect legal rights, employee relations or significant business decisions.

Regulyn provides technology-assisted HR compliance and policy support. Unless expressly stated otherwise, Regulyn does not provide legal advice and is not a substitute for advice from a suitably qualified professional where legal advice is required.

12. Children's Privacy

Regulyn is a business service and is not intended for use by children.

We do not knowingly create accounts for, market the Service to, or directly collect personal data from children under 18 as users of Regulyn.

A customer's HR content may, in limited circumstances, contain information concerning a child or young person. Where this occurs, the customer remains responsible for ensuring that the information is processed lawfully and is necessary for the relevant purpose.

If you believe personal data relating to a child has been provided to us inappropriately, please contact support@regulyn.co.uk.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • our services and features;
  • our processing activities;
  • our service providers;
  • applicable law or regulatory guidance; or
  • our security and compliance practices.

When we update the policy, we will revise the Last updated date above.

Where a change is material, we may also provide notice through the Service, by email, or by another appropriate method.

We encourage you to review this policy periodically.

14. Contact Us

If you have questions, concerns or requests relating to this Privacy Policy or our handling of personal data, please contact:

Elevyn Technology Group Limited

  • Address: 167-169 Great Portland Street, London, W1W 5PF, United Kingdom
  • Email: support@regulyn.co.uk
  • Company number: 16954601
  • ICO registration number: ZC078522

For data-protection-specific enquiries, please include Data Protection in the email subject line.