Loading...
Legal
This Privacy Policy explains how Pericls Ltd ("Pericls", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you use our regulatory compliance intelligence platform available at https://app.pericls.com and our website at https://www.pericls.com (together, the "Service").
We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation ("UK GDPR", as retained under the Data Protection Act 2018), the EU General Data Protection Regulation (EU) 2016/679 ("EU GDPR"), the Privacy and Electronic Communications Regulations 2003 ("PECR"), the ePrivacy Directive 2002/58/EC, and all applicable data protection legislation. References to "GDPR" in this policy refer to both the UK GDPR and the EU GDPR as applicable.
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this policy. If you do not agree with our data practices, please do not use the Service.
The data controller responsible for your personal data is:
Pericls Ltd
A company incorporated in England and Wales, company number 16288279
Registered office: Charterhouse Millburgh Hall, Graffham, Petworth, England, GU28 0QH
We have appointed a Data Protection Officer whom you may contact regarding any questions about this Privacy Policy or the processing of your personal data:
Data Protection Officer
Pericls Ltd
London, United Kingdom
Email: dpo@pericls.com
| Data Category | Specific Data Elements | When Collected |
|---|---|---|
| Account registration | Full name, email address, password (stored as bcrypt hash) | Account creation |
| Organisation details | Organisation name, organisation size, industry sector | Organisation setup |
| Profile information | Avatar URL, display name, timezone preference | Profile configuration |
| Assessment data | Company data, regulatory scope, compliance maturity responses | Compliance assessment |
| Uploaded documents | Documents submitted for regulatory analysis (may contain personal data controlled by you) | Document upload feature |
| Billing information | Name, email, billing address, payment method details (processed by Stripe; we do not store full card numbers) | Subscription purchase |
| Communications | Support enquiries, feedback, correspondence content | When you contact us |
| SSO/OAuth data | OAuth tokens, SSO configuration, provider identifiers | SSO setup / Google OAuth login |
| Data Category | Specific Data Elements | Collection Method |
|---|---|---|
| Device & browser data | IP address, user agent string, browser type and version, operating system, device type | Server logs, HTTP headers |
| Usage data | Pages visited, features used, clickstream data, session duration, timestamps | PostHog analytics |
| Authentication data | Login timestamps, session identifiers, refresh token metadata | Authentication system |
| Error & performance data | Error messages, component stack traces, user ID at time of error, request metadata | Sentry error tracking |
| Legal acceptance records | Accepted document type and version, acceptance timestamp, IP address, user agent | When you accept our Terms of Service, Privacy Policy, or other legal documents (e.g., during onboarding) |
| Source | Data Received | Purpose |
|---|---|---|
| Google OAuth | Email address, full name, profile picture URL, Google account identifier | Account authentication |
| Stripe | Payment status, subscription status, billing events (via webhooks) | Billing management |
We do not intentionally collect special categories of personal data (as defined in GDPR Article 9), such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.
If you upload documents to the Service that contain special category data, you are solely responsible for ensuring a lawful basis for such processing under Article 9(2) GDPR.
We process your personal data only where we have a valid legal basis under Article 6(1) GDPR. The table below sets out each processing purpose alongside its corresponding legal basis:
| Purpose | Data Used | Legal Basis (Art. 6(1)) |
|---|---|---|
| Providing and maintaining the Service | Account data, organisation data, uploaded documents, assessment data | (b) Performance of contract — necessary to deliver the Service you have subscribed to |
| Account creation and authentication | Email, name, password hash, OAuth tokens | (b) Performance of contract — necessary to create and secure your account |
| Processing uploaded documents through AI/LLM analysis | Document content, extracted text | (b) Performance of contract — core Service functionality you have requested |
| Generating compliance reports and gap analyses | Assessment data, company data, regulatory data | (b) Performance of contract — core Service deliverable |
| Billing and subscription management | Email, name, billing address, Stripe customer ID, payment events | (b) Performance of contract — necessary to process payments and manage subscriptions |
| Sending transactional emails (account verification, password resets, billing receipts) | Email address, name | (b) Performance of contract — necessary operational communications |
| Providing customer support | Name, email, communication content, account data | (b) Performance of contract — necessary to respond to your requests |
| Ensuring platform security (fraud prevention, abuse detection, rate limiting) | IP address, user agent, authentication logs | (f) Legitimate interest — protecting the Service and users from security threats |
| Monitoring and improving Service performance | Usage data, error data, performance metrics | (f) Legitimate interest — improving Service reliability and user experience |
| Product analytics and feature development | Anonymised/pseudonymised usage data, page views, feature interactions | (f) Legitimate interest — understanding how the Service is used to improve it; balanced against your rights through pseudonymisation |
| Sending marketing communications (product updates, newsletters) | Email address, name | (a) Consent — only with your explicit opt-in; you may withdraw at any time |
| Compliance with legal and regulatory obligations (tax reporting, lawful data requests) | Billing records, account data, usage logs | (c) Legal obligation — where required by applicable law |
| Enforcing our Terms of Service | Account data, usage data | (f) Legitimate interest — protecting our rights and the integrity of the Service |
| Recording acceptance of legal documents (Terms of Service, Privacy Policy, and related policies) | Accepted document version, acceptance timestamp, IP address, user agent | (f) Legitimate interest — maintaining evidence of contract formation and demonstrating compliance with our accountability obligations |
| Displaying cookie consent preferences | Cookie consent choices | (c) Legal obligation — compliance with ePrivacy Directive requirements |
Where we rely on legitimate interest as a legal basis, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting our DPO at dpo@pericls.com.
The Service uses third-party AI/LLM providers to deliver core functionality, including:
Content you submit for analysis may be processed by:
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. As our AI features provide analytical assistance rather than automated decisions, Article 22 does not apply; however, you may contact us at dpo@pericls.com with any concerns.
We share your personal data with the following categories of recipients:
We use third-party service providers ("sub-processors") to help deliver the Service. Each sub-processor processes data only on our instructions and subject to a Data Processing Agreement.
| Sub-Processor | Purpose | Data Categories | Location |
|---|---|---|---|
| Hetzner Online GmbH | Application hosting (frontend and backend), PostgreSQL database, Redis cache, S3-compatible object storage for documents and reports | All Service data | Germany (Nuremberg, Falkenstein) — EU |
| Stripe | Payment processing, subscription management | Email, name, billing address, payment data | US + EU |
| Resend | Transactional email delivery | Email addresses, notification content | US |
| PostHog | Product analytics | User ID, email, name, page views, feature events | US (Cloud) |
| Sentry | Error monitoring and performance tracking | User ID, error context, component stacks | US |
| OpenAI | LLM-powered regulatory analysis | Content submitted for analysis | US |
| Anthropic | LLM-powered regulatory analysis | Content submitted for analysis | US |
| Google (Gemini) | LLM-powered regulatory analysis | Content submitted for analysis | US |
| Google (OAuth) | User authentication | OAuth tokens, email, name | US |
| GitHub | Source code hosting, CI/CD, container image registry | Source code (no customer personal data) | US |
For the complete and current list of sub-processors, including transfer mechanisms, see our Sub-Processor List.
We may also share personal data with:
We do not sell your personal data to any third party.
The Service is hosted in the European Union (Germany), where your account data, organisation data, uploaded documents, and analysis results are stored. However, certain personal data may be transferred to, stored in, and processed in countries outside the United Kingdom and the European Economic Area ("EEA") — in particular the United States — by the sub-processors listed in Section 7.1 (payment, email delivery, analytics, error monitoring, and AI/LLM analysis).
Where personal data is transferred outside the UK or the EEA, we ensure an adequate level of protection through one or more of the following mechanisms:
| Mechanism | Application |
|---|---|
| UK International Data Transfer Agreement (IDTA) / UK Addendum to EU SCCs | For transfers from the UK, as approved by the ICO under UK GDPR |
| EU-US Data Privacy Framework | Where the recipient is certified under the DPF (e.g., Google, Stripe) |
| Standard Contractual Clauses (SCCs) | Executed with all US-based sub-processors, using the European Commission's approved SCCs (Commission Implementing Decision (EU) 2021/914) for EU data transfers |
| Supplementary Measures | Where required by Transfer Impact Assessments, including encryption in transit and at rest, pseudonymisation, and contractual prohibitions on government access disclosure |
We conduct Transfer Impact Assessments for each international transfer to evaluate the legal framework of the recipient country and determine whether supplementary measures are required to ensure an essentially equivalent level of protection for your personal data.
You may request a copy of the applicable transfer mechanisms by contacting dpo@pericls.com.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account data (name, email, profile) | Duration of account + 30 days after deletion request | Service delivery; 30-day grace period for accidental deletion |
| Organisation data | Duration of organisation account + 90 days | Data export period for remaining members |
| Authentication logs | 12 months from creation | Security monitoring, fraud detection |
| Uploaded documents | Duration of account; deleted within 30 days of account deletion | Service delivery |
| Analysis results and reports | Duration of account; deleted within 30 days of account deletion | Service delivery |
| Assessment data | Duration of account; deleted within 30 days of account deletion | Service delivery |
| Billing records | 7 years from transaction date | UK tax and accounting requirements (HMRC) |
| Transactional email logs | 6 months | Delivery troubleshooting |
| Analytics data (PostHog) | 24 months, then anonymised | Product improvement |
| Error tracking data (Sentry) | 90 days | Debugging and performance improvement |
| Server access logs | 12 months | Security and compliance |
| Cookie consent records | 3 years | Demonstrating compliance with consent requirements |
| Legal document acceptance records | Duration of account + 6 years | Evidence of contract formation and acceptance of terms (limitation period for contractual claims in England and Wales) |
| Support correspondence | Duration of account + 12 months | Service quality and dispute resolution |
After the applicable retention period, personal data is securely deleted or irreversibly anonymised.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:
For further details on our security measures, please contact security@pericls.com.
Under the GDPR, you have the following rights regarding your personal data:
You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about the processing.
You have the right to have inaccurate personal data corrected and incomplete data completed. You can update most account information directly through the Service settings.
You have the right to request deletion of your personal data where:
This right does not apply where processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.
You have the right to restrict processing where:
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON or CSV) and to transmit that data to another controller, where processing is based on consent or contract and is carried out by automated means.
You have the right to object to processing based on legitimate interest (Article 6(1)(f)). We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
You have an absolute right to object to processing for direct marketing purposes at any time.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. See Section 6.3 for details on how this applies to our Service.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. You can withdraw consent by:
To exercise any of these rights, please contact us at:
We will respond to your request within 30 days of receipt. If the request is complex or we receive a high volume of requests, we may extend this period by a further 60 days, and we will notify you of any extension within the initial 30-day period.
We may ask you to verify your identity before processing your request to protect your personal data from unauthorised access.
If you believe that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
United Kingdom
If you are located in the EU/EEA, you may also lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence or place of work.
We use cookies and similar technologies on our Service. A summary is provided below; for full details, please see our Cookie Policy.
| Category | Examples | Legal Basis |
|---|---|---|
| Strictly Necessary | Authentication cookie (refresh_token), cookie consent preference (pericls-cookie-consent), Stripe payment cookies (__stripe_*) | Exempt from consent (PECR Reg. 6; ePrivacy Art. 5(3)) |
| Functional | UI state (pericls-ui-storage), assessment progress (pericls-assessment) | Legitimate interest / consent |
| Analytics | PostHog browser storage (ph_*) | Consent |
You can manage your cookie preferences at any time through our cookie consent banner or by adjusting your browser settings.
The Service is designed for business use and is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without valid parental consent, we will take steps to delete that data promptly. If you believe we have inadvertently collected data from a child, please contact us at dpo@pericls.com.
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party sites you visit.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
We encourage you to review this Privacy Policy periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
General Enquiries:
Email: legal@pericls.com
Data Protection Officer:
Email: dpo@pericls.com
Customer Support:
Email: support@pericls.com
Postal Address:
Pericls Ltd
Charterhouse Millburgh Hall, Graffham, Petworth
England, GU28 0QH
| Date | Version | Change Description |
|---|---|---|
| 4 April 2026 | 1.0 | Initial publication |
| 5 July 2026 | 1.1 | Hosting moved to Hetzner (Germany, EU) — replaced Render/Vercel/AWS S3 entries; added legal document acceptance records (collection, purpose, retention); corrected cookie/storage names; added company number and registered office |
This Privacy Policy is provided in English. If there is any conflict between a translated version and the English version, the English version shall prevail.