Skip to content
LEGAL

Privacy Policy

Effective 24 July 2026

Volexi is operated by Joltclick Limited (company number 15175103), registered at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Volexi", "we", "us"). We are the controller for the personal data described in this policy, except where we act as a processor on behalf of our business customers (see section 8).

Contact: privacy@volexi.ai

1. Who this policy covers

  • Visitors to our websites.
  • Users — people with a Volexi account (including agency team members).
  • Portal contacts — people invited by our agency customers to view a client portal.
  • Business contacts — people who request a demo or correspond with us.

2. Personal data we collect

You provide:

  • Account data: full name, work email, password (stored by our authentication provider in hashed form), optional two-factor authentication enrolment, and a record of your acceptance of our Terms (version and timestamp).
  • Sign-in via Google (email, name, avatar) or SAML single sign-on (email), where you choose those methods.
  • Profile and notification preferences.
  • Demo requests: name, work email, company domain, and whether you are in-house or an agency. Demo requests are emailed to our sales inbox and are not stored in our product database.
  • Content you submit to the Service (brand information, prompts, uploaded documents, and connected-integration data). This is primarily business data but may incidentally include personal data — see section 8.

Collected automatically:

  • Product analytics (only if you accept analytics cookies): page views (including page URLs), page-leave events, and device/session information, via PostHog hosted in the EU. See our Cookie Policy.
  • Error and performance data: error reports, stack traces, and request context via Sentry; with your consent, a session replay may be captured for a small sample of sessions in which an error occurs.
  • IP addresses are used transiently for rate limiting and security on our API and portal endpoints; we do not store them in our database. Our hosting and infrastructure providers keep standard server logs.

We do not collect: phone numbers, card numbers, or billing addresses (payments are handled by Stripe on Stripe-hosted pages — see section 5), and we do not knowingly collect special category data.

3. Purposes and legal bases

Purpose Data Legal basis (UK GDPR)
Provide the Service (accounts, workspaces, monitoring, content generation) Account data, Customer Content Contract (Art. 6(1)(b))
Billing and subscription management Account email, subscription identifiers Contract; legal obligation (financial records)
Service emails (invitations, magic links, alerts, digests, trial and billing notices) Email, name Contract; legitimate interests (keeping you informed about your account)
Security, rate limiting, fraud and abuse prevention, audit logging IPs (transient), account identifiers, event logs Legitimate interests (Art. 6(1)(f))
Product analytics Pageview and device data Consent (Art. 6(1)(a)) — via our cookie banner
Error monitoring Error and request context; consent-gated session replay Legitimate interests (service reliability); consent for replay
Responding to demo requests and enquiries Contact details Legitimate interests / pre-contract steps
Establishing, exercising, or defending legal claims Relevant records Legitimate interests

We do not use your personal data for third-party advertising, and we do not sell it.

4. AI processing

The Service uses third-party AI providers to analyse content and generate output. Prompts you configure are submitted to third-party AI answer engines to measure brand visibility, and your brand content may be processed by our AI providers to generate briefs and articles. The providers involved are listed in our Subprocessor List. We recommend not including personal data in prompts or uploaded documents unless necessary.

Some features generate suggested outreach contacts using AI inference. These suggestions may be inaccurate, are provided to the customer as drafts only, and are never used by Volexi to send communications. If you believe your details appear in a customer's account, contact us or the relevant customer (section 8).

5. Who we share data with

  • Service providers (subprocessors): hosting, database and storage, background processing, email delivery, analytics, error monitoring, and AI providers — listed with roles and locations in our Subprocessor List.
  • Stripe: if you subscribe, your card and billing details are provided by you directly to Stripe on Stripe-hosted pages. Stripe acts as our payment processor; we store only customer and subscription identifiers.
  • Your organisation: if you use Volexi in a workspace or agency owned by your employer or an agency, workspace admins and agency members can see your name, email, role, and activity within that workspace.
  • Authorities and advisers where required by law or to protect our rights.
  • In a business transfer (merger, acquisition), data may transfer with appropriate protections.

6. International transfers

Our primary database and file storage are hosted in the EU (Frankfurt, Germany), and our analytics provider is EU-hosted. Some of our other providers process data outside the UK/EEA, including in the United States. Where personal data is transferred outside the UK, we rely on UK adequacy regulations or appropriate safeguards such as the UK International Data Transfer Agreement/Addendum or Standard Contractual Clauses. Our Subprocessor List identifies each provider's location.

7. Retention

  • Account and workspace data: retained while your account is active. Cancelling a subscription does not delete your data — you keep read access to your history until you delete workspaces or request account deletion.
  • Account deletion: you can request deletion under Account → Privacy & data. Requests are actioned by our operations team; we then delete your workspaces (including uploaded files), profile, and login. Deletion is permanent. We retain billing records with our payment processor as required for financial record-keeping (six years under UK law).
  • Audit logs: 24 months, then automatically purged.
  • Portal magic-link tokens: 15 minutes; portal sessions: 30 days; pending invitations: 7 days — all purged automatically after expiry.
  • Error monitoring data: retained by our provider for 90 days.
  • Analytics data: retained for up to 12 months.
  • Backups are retained on a rolling schedule and expire in the ordinary course.

8. When we act as a processor

Business customers (including agencies) may submit personal data belonging to their own clients, contacts, or end users — for example portal contact names and emails, data from connected integrations, uploaded documents, and digest recipient lists. For that data, the customer is the controller and Volexi is a processor acting on their instructions under our Data Processing Addendum. If your data appears in a customer's Volexi account, the customer is responsible for responding to your privacy requests, and we will assist them. You can also contact us at privacy@volexi.ai and we will refer your request to the relevant customer.

9. Your rights

Under UK GDPR you have the right to access, rectify, and erase your personal data; to restrict or object to processing; to data portability; and to withdraw consent at any time (for example via the "Cookie preferences" link). You can exercise most of these directly in-app: edit your profile, export your personal data (Account → Privacy & data), manage email preferences and unsubscribe links, delete workspaces, and request account deletion. Otherwise contact privacy@volexi.ai. We will respond within one month.

You have the right to complain to the UK Information Commissioner's Office (ico.org.uk). We'd appreciate the chance to address your concerns first.

10. Security

We use technical and organisational measures including encryption in transit (TLS, HSTS), encryption of integration credentials at rest (AES-256-GCM), hashed storage of passwords, API keys, and session tokens, role-based access controls, tenant isolation checks, immutable audit logging, and webhook signature verification. No system is perfectly secure; notify us at security@volexi.ai of any suspected vulnerability or incident.

11. Children

The Service is intended for business use by people aged 18 or over. We do not knowingly collect personal data from children.

12. Changes

We will post updates to this policy here and, for material changes, notify you by email or in-app. Please check back periodically.


Joltclick Limited trading as Volexi · Company no. 15175103 · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK · privacy@volexi.ai

Questions? privacy@volexi.ai · Terms of Service · Cookie Policy · Subprocessor List