Last updated 1 August 2026
Privacy Policy
How Integrox collects, uses, shares, stores and protects personal data, including identity documents submitted during client onboarding.
1. Controller and scope
Integrox Consultancy Group Ltd is the controller of the personal data described in this policy. It applies to visitors to our website, users of the client platform, contacts at our clients and prospective clients, and individuals whose data is provided to us in the course of an engagement. Where we process personal data on a client's instructions as part of a deliverable, we act as processor and the client's own privacy notice applies.
2. Personal data we collect
- Account data: name, email address, telephone number, organisation and role.
- Client acceptance and verification data: legal name, date of birth, nationality, residential address, government-issued identity documents, proof of address, ownership and control information, source of funds and source of wealth information.
- Engagement data: intake responses, supporting documents, correspondence and file notes.
- Transaction data: orders, invoices and payment status. Full card details are handled by our payment processor and are never stored on our systems.
- Technical data: IP address, device and browser information, authentication events and security logs.
3. How we collect it
Directly from you, from your organisation or its representatives, from public registers and sanctions or adverse media databases, from our partner firms and subcontractors, and automatically through the platform's security and audit logging.
4. Purposes and legal bases
- Delivering the services you purchase and administering your account — contract.
- Client acceptance, anti-money laundering, sanctions screening, conflict checks and record-keeping — legal obligation and substantial public interest.
- Securing the platform, preventing fraud, managing risk and quality, and improving our services — legitimate interests.
- Marketing communications you have asked to receive — consent, withdrawable at any time.
5. Special category and criminal offence data
Identity documents may reveal special category data (for example biometric image data or data revealing racial or ethnic origin), and screening may return criminal offence or sanctions data. We process this only where a lawful condition applies, in particular the prevention and detection of unlawful acts and compliance with regulatory requirements, and under an appropriate policy document with restricted access.
6. Recipients and disclosure
We share personal data with: licensed identity verification and AML screening providers; our payment processor; cloud hosting, storage and communications providers acting as processors under contract; regulated partner firms and subcontractors delivering part of your engagement; our professional advisers, auditors and insurers; and regulators, law enforcement or courts where we are legally required or permitted to disclose. We do not sell personal data and we do not use it for automated decision-making producing legal effects.
7. International transfers
Where personal data is transferred outside the UK or EEA, we rely on an adequacy decision or on approved standard contractual clauses together with a transfer risk assessment and supplementary technical measures such as encryption in transit and at rest.
8. Security
Identity documents and engagement files are held in private, access-controlled storage, encrypted in transit and at rest. Access follows least privilege and is limited to you, your assigned reviewer and compliance administrators. Every access-relevant status change is written to a timestamped audit trail. We operate role-based access control, multi-factor authentication for staff, logging and monitoring, and a documented incident response process, including notification to the supervisory authority and to affected individuals where required.
9. Retention
We keep personal data only as long as necessary. Client acceptance and AML records are retained for the period required by applicable legislation, typically five years after the end of the business relationship. Engagement files are retained for the period required by professional and limitation rules, typically six to seven years. Marketing preferences are retained until withdrawn. Data is then deleted or irreversibly anonymised.
10. Your rights
Subject to our legal and professional obligations you may request access to, correction, erasure, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent where processing relies on it. Where AML law requires retention or prohibits disclosure, we may be unable to comply with an erasure or access request in full and will explain this where permitted.
11. Cookies and analytics
We use strictly necessary cookies for authentication, session management and security, and optional analytics cookies only where you consent. You can manage optional cookies through your browser or our cookie controls; disabling strictly necessary cookies will prevent the platform from functioning.
12. Children
The platform is intended for business users aged 18 or over. We do not knowingly collect data from children except where a client engagement (for example a dependant visa application) requires it and it is provided by a parent or legal guardian.
13. Contact and complaints
Contact our privacy team at privacy@integrox.com. You also have the right to complain to your data protection supervisory authority; in the UK this is the Information Commissioner's Office.