Legal
Privacy Policy
How Duckham Meridian Group Limited (DMG-Ltd), operator of Regulyse, collects, uses, and protects your personal data under the UK GDPR and Data Protection Act 2018.
Last updated: 18 September 2026
1. Who we are
Regulyse is operated by Duckham Meridian Group Limited (“DMG-Ltd”, “Regulyse”, “we”, “us”, “our”), a company registered in England & Wales. We are the “data controller” responsible for your personal data and are registered with the Information Commissioner’s Office (ICO).
For any privacy matter, including exercising your rights, contact our data protection team at [email protected].
2. The personal data we collect
We only collect data we genuinely need to provide the service:
- Account data — your name, work email address, company name, sector, and company size, provided when you register.
- Authentication data — a securely hashed password (we never store passwords in plain text).
- Service data — the compliance documents, alerts, and preferences associated with your account.
- Technical data — essential session cookies and basic log data needed to keep the platform secure and running.
We do not knowingly collect special category data. Please do not upload sensitive personal data into the platform unless strictly necessary for a compliance task.
3. How and why we use your data (lawful bases)
- To provide the service (lawful basis: performance of a contract) — creating your account, delivering regulatory intelligence, and generating compliance documents.
- To secure and improve the platform (lawful basis: legitimate interests) — preventing fraud, maintaining reliability, and understanding aggregate usage.
- To communicate with you (lawful basis: legitimate interests / consent) — sending service and, where you have opted in, product updates.
- To meet our legal obligations (lawful basis: legal obligation) — including tax, accounting, and regulatory record-keeping.
4. Artificial intelligence and automated processing
Regulyse is an AI-powered platform. Our AI models analyse public regulatory sources to forecast likely changes and to draft compliance documents. In the interest of transparency:
- Our regulatory predictions and generated documents are produced with the assistance of AI and are always subject to human director oversight.
- We do not make solely automated decisions that produce legal or similarly significant effects concerning you as an individual.
- AI outputs are regulatory intelligence to support your decision-making — they are not legal advice and should be reviewed by a qualified professional before you act.
5. Cookies
We use a small number of cookies. Strictly necessary cookies keep you signed in and the platform secure; optional cookies are only set with your consent. See our Cookie Policy for full details and to manage your choices.
6. Who we share data with
We never sell your personal data. We share it only with trusted providers who help us run the service:
- Cloud hosting and infrastructure providers that store and serve the platform.
- AI/LLM processing providers used to generate predictions and documents, acting as our processors under contract.
- Professional advisers and authorities where required by law.
All processors are bound by written agreements requiring appropriate security and confidentiality.
7. International transfers
Where personal data is transferred outside the UK, we ensure an adequate level of protection through UK adequacy regulations or the ICO’s International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses.
8. How long we keep your data
We retain your account data for as long as your account is active. If you close your account, we delete or anonymise your personal data within a reasonable period, except where we must retain limited records to meet legal, tax, or accounting obligations (typically up to 6 years).
9. Your rights under UK GDPR
You have the right to:
- Be informed about how your data is used (this policy).
- Access a copy of the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erasure — ask us to delete your data (“right to be forgotten”).
- Restrict or object to certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
Signed-in users can download their data and permanently delete their account at any time from Dashboard → Settings & Privacy. You can also email [email protected] and we will respond within one month.
10. Security
We protect your data with encryption in transit, hashed passwords, access controls, and regular review of our security practices. No system is perfectly secure, but we take our responsibilities seriously and will notify you and the ICO of any qualifying data breach without undue delay.
11. Children
Regulyse is a business-to-business service and is not intended for anyone under 18 years of age.
12. Complaints
We hope to resolve any concern directly, but you have the right to complain to the ICO at any time — ico.org.uk or by calling 0303 123 1113.
13. Changes to this policy
We may update this policy from time to time. We will post the revised version here and update the “Last updated” date above. Material changes will be communicated to registered users.