Dark Logo
Dark Logo

Privacy Policy

SOAX LTD — Privacy Policy.

Version

1.0

Effective date

1 June 2026

Last updated

1 June 2026

Publisher

SOAX LTD, a company incorporated under the laws of England and Wales (registered no. 11828506)

Registered office

The Charter Building, Uxbridge, England, UB8 1JG

Contact

support@soax.com

We respect Your privacy and are committed to protecting Your personal data. This Privacy Policy explains how we collect, use, manage and safeguard it.

Please read this Privacy Policy carefully together with our Terms of Use and Cookie Policy. Unless otherwise defined, capitalised terms used in this Privacy Policy have the same meaning as those set out in the Terms of Use.


1. Introduction

This Privacy Policy explains how SOAX LTD ("SOAX", "we", "us" or "our") collects, uses, processes and protects personal data in connection with our Platform and Services.

This Privacy Policy applies to the processing of Your personal data in the following situations:

Our Platform is primarily intended for business use; however, individual Users may also access the Platform. In such cases, the provision of personal data may be necessary for entering into or performing a contract. If You do not provide such data, we may not be able to provide access to the Platform and Services.

2. Who we are (Data Controller)

For the purposes of applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and the EU General Data Protection Regulation ("GDPR"), the controller of Your personal data is:

SOAX LTD, a company incorporated in the United Kingdom (registration number 11828506), with its registered address at The Charter Building, Uxbridge, England, UB8 1JG.

If You have any questions regarding this Privacy Policy or how we process Your personal data, You can contact us at:

3. Categories of Data Subjects

We process personal data relating to the following categories of individuals:

4. Categories of Personal Data

Depending on how You interact with our Platform and Services, we may collect and process the following categories of personal data:

Account Data

Information provided during registration and used for Account management, including:

Login and Authentication Data

Information related to access to and use of the Platform, including:

Billing and Transaction Data

Information related to purchases and payments, including:

KYC / KYB Data

Information collected for identity verification and compliance purposes, including:

Usage Data (Request / Usage Logs)

Information generated in connection with the use of our Platform and Services, including metadata relating to individual requests processed through our Platform:

We do not inspect or store the content of communications or request payloads. We do not store full URLs beyond the hostname level. Our infrastructure is not technically designed to retain such content.

Security Logs

Information collected for security monitoring and incident detection, including:

Marketing Data

Information used for marketing and outreach purposes, including:

Communication Data

Information provided when communicating with us, including:

Cookies and Tracking Data

Information collected automatically when You interact with our Site or Platform, including:

For more detailed information about the types of cookies we use, their purposes and how You can manage Your preferences, please refer to our Cookie Policy.

We may also create aggregated or anonymised data that no longer identifies individuals. Such data is not considered personal data and may be used for analytics, product improvement and business purposes.

5. Sources of Personal Data

We collect personal data:

6. How we use Your data (Purposes)

Depending on how You interact with our Platform and Services, we use the categories of personal data described above for the following purposes:

Provision of Services

We use personal data, in particular usage data, login and authentication data, and Account data, to provide access to and operate our Platform and Services, including:

Account Management

We use personal data, in particular Account data and login and authentication data, to create, maintain and manage Accounts, including:

Billing and Payments

We use personal data, in particular billing and transaction data, Account data and relevant usage data, to manage billing and financial operations, including:

Identity Verification (KYC / KYB)

Where applicable, we use personal data, in particular KYC / KYB data and Account data, to verify identity and assess eligibility for certain Services or payment methods, including:

Security and Abuse Prevention

We use personal data, in particular login and authentication data, usage data and security logs, to ensure the security of our Platform and Services, including:

Analytics and Product Improvement

We use personal data, in particular usage data, cookies and tracking data, communication data and Account data, to analyse and improve our Platform and Services, including:

Customer Support and Communications

We use personal data, in particular communication data and Account data, to communicate with users and provide support, including:

Marketing and Communications

We use personal data, in particular marketing data, Account data, relevant usage data and cookies and tracking data, to communicate with users about our Platform and Services and manage marketing activities, including:

Legal and Compliance

We use personal data, in particular Account data, billing and transaction data, KYC / KYB data, usage data and security logs, to comply with legal obligations and protect our rights, including:

7. Legal Bases for Processing

We process Your personal data only where we have a valid legal basis to do so under applicable data protection laws, including the UK GDPR, the EU GDPR and the Data Protection Act 2018.

Depending on the context in which Your personal data is processed, we rely on one or more of the following legal bases:

Performance of a Contract

We process personal data where it is necessary for the performance of a contract with You or to take steps at Your request prior to entering into a contract.

This includes, in particular:

Compliance with Legal Obligations

We process personal data where it is necessary to comply with legal and regulatory obligations.

This includes, in particular:

Legitimate Interests

We process personal data where it is necessary for the purposes of our legitimate interests, provided that such interests are not overridden by Your rights and freedoms.

Our legitimate interests include, in particular:

You may contact us to obtain further information about our legitimate interest assessments.

Consent

Where required by applicable law, we process personal data on the basis of Your consent.

This includes, in particular:

You may withdraw your consent or update your marketing preferences at any time by contacting us using the contact details set out in this Privacy Policy or, where available, by using the unsubscribe link or preference-management tools provided in our communications, on the Site or on the Platform. This will not affect the lawfulness of processing carried out before the withdrawal of consent.

8. How we share Your data

We may share Your personal data with third parties where necessary for the provision of our Platform and Services, for business operations, or to comply with legal obligations. We share personal data with such recipients only where this is necessary for the purposes described above and in accordance with the applicable legal bases.

Such third parties may act as processors (processing data on our behalf) or, in certain cases, as independent controllers. In particular, some providers (such as payment and identity verification providers) may act as independent controllers in relation to the personal data they process in accordance with their own privacy policies.

We share personal data with the following categories of recipients:

Infrastructure Providers

We use cloud and infrastructure providers to host and operate our systems and data processing environments.

This includes providers such as Servers.com and ClickHouse Cloud, which may process login and authentication data, billing and transaction data, Account data, usage data and security logs.

Identity and Access Management Providers

We use identity and authentication providers to manage user access and authentication.

This includes providers such as WorkOS, which may process Account data, login and authentication data, security logs, KYC / KYB data, cookies and tracking data.

Billing, Payment and Accounting Providers

We use third-party providers to process payments, manage Subscriptions, support billing operations and maintain related accounting and tax processes.

This includes providers such as Stripe, Orb, Eukapay, Anrok and Xero, which may process billing and transaction data, Account data and relevant usage data.

Identity Verification Providers

We use third-party providers to perform identity verification and compliance checks.

This includes providers such as SumSub, which may process Account data, KYC / KYB data and security logs.

Analytics Providers

We use analytics providers to understand how our Platform and Services are used and to improve performance.

This includes providers such as Posthog, which may process Account data, login and authentication data, billing and transaction data, security logs and marketing data.

CRM and Customer Support Providers

We use customer relationship management and support tools to manage communications and provide support.

This includes providers such as Attio and Pylon, which may process Account data, KYC / KYB data, communication data and marketing data.

Marketing and Advertising Providers

We use marketing and advertising partners to communicate with users and analyse campaign performance.

This includes providers such as Flodesk, which may process Account data and marketing data.

Internal Tools and Business Systems

We use internal tools and business systems to support our operations, including communication, documentation, reporting, email, issue tracking and internal analytics. These tools may incidentally contain or process personal data where such data is included in communications, documentation or internal workflows.

This includes tools such as Slack, Notion, Google and Linear.

Legal and Regulatory Authorities

We may disclose personal data to courts, law enforcement agencies, regulators or other public authorities where required by applicable law or to protect our legal rights.

Business Transfers

We may share or transfer personal data in connection with any actual or potential merger, acquisition, reorganisation, asset sale or other corporate transaction.

Business Partners

We may share data with business partners, resellers or affiliates where necessary to provide access to or distribute our Platform and Services.

Professional Advisors

We may share personal data with our professional advisors, including legal, tax and audit advisors, where necessary for compliance, risk management and business operations.

9. International Data Transfers

Due to the global nature of our business and the use of third-party service providers, Your personal data may be transferred to, and processed in, countries outside the United Kingdom and the European Economic Area (EEA).

In particular, some of our service providers are located in the United States and other jurisdictions where data protection laws may differ from those in the United Kingdom or the European Economic Area (EEA).

Where we transfer personal data to such countries, we ensure that appropriate safeguards are in place to protect Your personal data in accordance with applicable data protection laws.

These safeguards may include:

You may request further information about the safeguards we apply to international data transfers by contacting us using the details set out in this Privacy Policy.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, regulatory, accounting or reporting requirements.

The retention periods applied by us depend on the type of personal data and the context in which it is processed.

Account Data

We retain Account data for the duration of the contractual relationship with You and thereafter for a limited period, as necessary for legitimate business purposes, including fraud prevention, dispute resolution and compliance with legal obligations.

Where You request deletion of Your Account, we will delete or anonymise Your Account data, unless retention is required or permitted by law.

Login and Authentication Data

We retain login and authentication data for as long as Your Account is active and for a limited period thereafter, including for security monitoring and incident investigation.

In particular, certain authentication data may be retained for up to one (1) year after Account deletion for the purposes of preventing fraud and detecting repeated abusive activity.

Billing and Transaction Data

We retain billing and transaction data in accordance with applicable accounting and tax laws and regulatory requirements.

Certain billing records, including payment data, may be retained for longer periods where required for financial reporting, audit or legal purposes.

KYC / KYB Data

We retain KYC / KYB data for the duration of the customer relationship and for a period thereafter as required for compliance with legal and regulatory obligations and audit purposes.

In particular, certain KYC / KYB data may be retained for up to one (1) year after Account deletion for the purposes of preventing fraud.

Usage Data (Request / Usage Logs)

We retain usage data in accordance with operational, legal and security requirements.

Security Logs

We retain security logs for as long as necessary to ensure system security, detect and investigate incidents and comply with legal obligations.

Certain security-related data may be retained for up to one (1) year after Account deletion for fraud prevention and monitoring purposes.

Communication Data

We retain communication data for as long as necessary to handle inquiries, provide support, manage the customer relationship and resolve disputes.

Marketing Data

We retain marketing data until You delete Your Account, withdraw Your consent or object to receiving marketing communications, unless longer retention is justified for legal or operational purposes.

Cookies and Tracking Data

We retain cookies and similar tracking data in accordance with the applicable cookie lifetimes and Your preferences.

Further details are available in our Cookie Policy.

11. Your Data Protection Rights

If You are located in the United Kingdom or the European Economic Area (EEA), You have certain rights in relation to Your personal data under applicable data protection laws, including the UK GDPR and the GDPR.

Please note that we do not sell personal data and do not use it for automated decision-making or profiling that produces legal or similarly significant effects.

How to Exercise Your Rights

To exercise Your rights, please contact us using the contact details set out in this Privacy Policy.

We will respond to Your request as soon as reasonably practicable and, in any event, within the time limits prescribed by applicable law.

In certain cases, we may need to verify Your identity before processing Your request.

Your Rights

You have the following rights:

Right of access. You have the right to obtain confirmation as to whether we process Your personal data and, where that is the case, to access that data and information about how it is processed.

Right to rectification. You have the right to request that we correct inaccurate or incomplete personal data.

Right to erasure. You have the right to request the deletion of Your personal data in certain circumstances, including where:

Right to restriction of processing. You have the right to request that we restrict the processing of Your personal data in certain circumstances, including where:

Right to data portability. Where processing is based on consent or contract and carried out by automated means, You have the right to receive personal data that You have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where technically feasible.

Right to object. You have the right to object to processing of Your personal data where such processing is based on our legitimate interests, unless we can demonstrate compelling legitimate grounds to continue such processing.

You also have the right to object at any time to the processing of Your personal data for direct marketing purposes.

Right to withdraw consent. Where we rely on Your consent to process personal data, You have the right to withdraw your consent at any time by contacting us using the contact details set out in this Privacy Policy. This will not affect the lawfulness of processing carried out before the withdrawal.

Right to lodge a complaint. You have the right to lodge a complaint with a competent supervisory authority, in particular in the UK or the EU Member State of Your habitual residence, place of work or place of the alleged infringement.

12. Security

We implement and maintain appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures are designed taking into account the nature, scope, context and purposes of processing, as well as the risks to individuals' rights and freedoms.

Our security measures include, in particular:

We also implement organisational measures, including internal policies and procedures, to ensure that personal data is handled securely and in accordance with applicable data protection laws.

13. Incident Handling

We maintain internal processes and procedures for the detection, assessment and management of security incidents.

In the event of a personal data breach, we will:

Our incident response processes are designed to ensure timely and appropriate handling of security incidents in accordance with applicable data protection requirements.

14. Cookies

We use cookies and similar tracking technologies on our Site and Platform to ensure functionality, enhance user experience, analyse usage and support marketing activities.

Cookies may include strictly necessary cookies, as well as analytics and marketing cookies, depending on Your preferences.

For more detailed information about the types of cookies we use, their purposes and how You can manage Your preferences, please refer to our Cookie Policy.

15. Children

Our Platform and Services are not intended for individuals under the age of 18.

We do not knowingly collect personal data from children. If You believe that a child has provided personal data to us, please contact us. If we become aware that personal data has been provided by a child without appropriate authorisation, we will take steps to delete such data as soon as reasonably practicable.

16. Data Relating to Users of Third-Party Solutions (SDK Integrations)

Participation via Third-Party Solutions

Our Platform and Services may be supported by a network of devices provided by users of third-party applications or services that integrate SOAX technology (including the SOAX SDK) ("Partner Solutions").

In such cases, users of Partner Solutions may choose to enable optional functionality allowing their device to participate in the SOAX network (for example, by contributing limited device resources such as network connectivity when the device is not actively in use).

Participation in the SOAX network is voluntary and subject to user choice, including the ability to withdraw at any time, as implemented by the relevant Partner.

Role of the Partner

The relevant Partner is responsible for:

SOAX does not control the Partner's user interface, consent flows or user experience.

Categories of Data Processed

In connection with the operation of the SOAX network, we may process limited technical data relating to devices participating in the network, which may in certain cases constitute personal data under applicable law, including:

Purposes of Processing

We process such data for the following purposes:

Legal Bases

Depending on the context, we rely on one or more of the following legal bases:

Retention

Data relating to users of Partner Solutions and participating devices is retained for as long as necessary for network operation, security, fraud prevention, compliance and related technical purposes, unless a longer retention period is required or permitted by law.

Additional Information

This section is intended to provide information to individuals whose data we may receive indirectly via third-party Partners and their Partner Solutions.

If You have questions about how Your device participates in the SOAX network, we recommend contacting the relevant Partner in the first instance. You may also contact us using the details set out in this Privacy Policy.

17. Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, our Platform and Services, or applicable legal requirements.

Where appropriate, we will notify You of material changes, for example by posting a notice on our Site or through other appropriate communication channels.

The "Last updated" date at the top of this Privacy Policy indicates when it was last revised.

18. Contact

If You have any questions regarding this Privacy Policy or how we process Your personal data, You can contact us at:

Effective Date: 1 June 2026