Legal
Privacy Policy
Last updated: 11 July 2026 · Version 1.0
Vera · Marco · Lilly · Atlas
This Privacy Policy explains how Pennix collects, uses, shares, and protects personal data through the Pennix website and our monthly and annual processing-capacity plans (Solo and Firm), the lawful bases we rely on, how long we keep data, who we share it with, and the rights you have under the EU/UK General Data Protection Regulation (GDPR), US state privacy laws, Canada’s PIPEDA, and other applicable laws.
Contents
- Who we are & scope
- Our two roles
- What personal data we collect
- How we use it & lawful bases
- Cookies & similar technologies
- Marketing & communications
- Sharing & subprocessors
- International data transfers
- How long we keep data
- Security
- Your rights (GDPR / UK)
- US state privacy rights
- Canada (PIPEDA)
- GCC, MENA & other regions
- Automated processing & AI
- Children’s data
- Third-party links & services
- Exercising rights & complaints
- Changes to this policy
- Contact us
01Who we are & scope
The controller of personal data collected through the Pennix website and application form is Pennix LLC (“Pennix”, “we”, “us”, “our”), a Wyoming limited liability company, operating from 308 N Fairfield Rd, Devon, PA 19333, USA, and part of the Peregrine X group. For any privacy question, to exercise your rights, or to reach the person responsible for data protection at Pennix, contact info@getpennix.ai.
This policy covers the website and the monthly and annual processing-capacity plans (Solo and Firm). It should be read together with our Terms of Service, Cookie Policy, and Security & Data-Handling Brief. If we are ever required to appoint an EU or UK representative or a Data Protection Officer, their contact details will be published here.
02Our two roles
As a controller — for information you submit through the website (for example the application form) and for operating, securing, and improving the site, we determine the purposes and means of processing.
As a processor — during a paid plan, we process the client-file data you provide (client contact details in the list you supply and documents your clients upload) on your firm’s behalf and on your documented instructions. Your firm is the controller of that data, and a Data Processing Agreement (DPA) governs it. This policy focuses on our controller processing; the DPA and the Security & Data-Handling Brief govern the processor processing.
03What personal data we collect
- Information you provide — firm name, website, contact name, role, email, phone, the firm-profile, current-pain, readiness and purchase-fit answers you choose to enter, and billing and order details when you purchase.
- Installation data (as processor) — the client information in the list you supply and the documents your clients upload during a plan. You are responsible for the lawfulness of this data.
- Technical data — limited server/log data such as IP address, device and browser type, pages viewed and timestamps; and strictly necessary local storage that remembers your cookie choice. See the Cookie Policy.
- Data from third parties — limited information from payment, hosting, or analytics providers (where enabled) and from public professional sources where relevant.
We do not intentionally collect special-category data through the website and ask that you do not submit it.
04How we use it & lawful bases
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Respond to your application, assess fit, and communicate with you | Consent (6(1)(a)) and pre-contract steps taken at your request (6(1)(b)) |
| Provide, administer, and support the Solo and Firm plans, and process payments | Performance of a contract (6(1)(b)) |
| Secure the service, prevent misuse and fraud, keep business records, and improve the service | Legitimate interests (6(1)(f)); legal obligation (6(1)(c)) |
| Send service and transactional messages about your account | Performance of a contract (6(1)(b)); legitimate interests (6(1)(f)) |
| Optional analytics or marketing (only if you enable it) | Consent (6(1)(a)) — you may withdraw at any time |
Where we rely on legitimate interests, we balance them against your rights and freedoms; contact us if you would like our assessment.
05Cookies & similar technologies
By default the website uses only strictly necessary storage. Analytics or marketing technologies load only with your consent, where consent is required. You can accept, reject, or change your choices at any time via the consent banner or “Manage cookies” in the footer. Full details are in the Cookie Policy.
06Marketing & communications
We send service and transactional messages about your account and packages. Marketing messages are sent only where permitted — on the basis required by applicable law, for example prior consent under Canada’s CASL and, where relevant, the EU/UK; or the opt-out and sender-identification requirements of the US CAN-SPAM Act. You can unsubscribe at any time using the link in the message or by contacting info@getpennix.ai.
07Sharing & subprocessors
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only with service providers who help us run Pennix under written contract — for example hosting and cloud infrastructure, email delivery, payment processing, and AI document processing. The current list, with roles and locations, is described in the Security & Data-Handling Brief and is available on request. We may also disclose data where required by law, to protect rights and safety, or in connection with a merger, financing, or sale of assets (with continued protection for your data).
08International data transfers
Pennix is based in the United States. Where personal data is transferred across borders — including from the EEA, the UK, or other regions to the US — we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement (or Addendum), or an adequacy decision, together with additional measures where needed. Details are available on request.
09How long we keep data
We keep personal data only as long as necessary for the purposes above. Application and marketing data is retained for up to 24 months, or until you ask us to delete it, whichever is sooner. Billing and tax records are kept for as long as the law requires. Installation (client-file) data is returned or deleted in line with the DPA, typically within 30 days of the plan ending or on your written instruction.
10Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and least-privilege access. See the Security & Data-Handling Brief for specifics and our conservative stance on certifications. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
11Your rights (GDPR / UK)
Subject to conditions in the GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent at any time (without affecting processing already carried out). To exercise a right, contact info@getpennix.ai; we will respond within the period the law requires (generally one month under the GDPR). You also have the right to complain to your supervisory authority — in the EU, your local Data Protection Authority; in the UK, the Information Commissioner’s Office (ICO).
12US state privacy rights
Depending on your US state (for example California, Virginia, Colorado, Connecticut, Utah, Texas and others), you may have the right to know about and access, delete, and correct your personal information, to obtain a portable copy, and to opt out of any “sale” or “sharing” and certain targeted advertising or profiling. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We do not discriminate against you for exercising these rights. To exercise them, contact info@getpennix.ai; we will verify your request as the law requires, and you may use an authorised agent where permitted. California residents may also request information about disclosures under the “Shine the Light” law.
13Canada (PIPEDA)
For individuals in Canada, we handle personal information consistent with PIPEDA and applicable provincial laws, obtain consent where required, and honour access and correction requests. Commercial electronic messages follow CASL. You may complain to the Office of the Privacy Commissioner of Canada.
14GCC, MENA & other regions
Where local data-protection laws apply to you — for example the UAE PDPL, the KSA PDPL, and free-zone regimes such as those of the DIFC and ADGM — we process personal data consistent with those laws, and you may have rights of access, correction, and deletion under them. You remain responsible for your own compliance and licensing obligations. Where local law requires data residency or local dispute resolution, that mandatory law applies.
15Automated processing & AI
The Service uses artificial intelligence to process intake data and generate drafts. We do not make solely automated decisions that produce legal or similarly significant effects about individuals — your firm reviews and approves client communications. We may use aggregated, de-identified data to maintain and improve the Service, and we do not use your client-file data to train third-party foundation models except as permitted by your Order and the DPA. See the Terms for more.
16Children’s data
Pennix is a business service and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under the applicable age of digital consent in the EEA/UK). If you believe a child has provided us data, contact us and we will delete it.
17Third-party links & services
The website may link to or integrate third-party services (for example a payment processor or scheduling tool) that are governed by their own privacy policies. We are not responsible for the privacy practices of third parties; please review their policies before providing personal data.
18Exercising rights & complaints
Contact info@getpennix.ai for any request or question about your data. We may need to verify your identity before acting on a request. If you are not satisfied with our response, you may contact your supervisory authority or privacy regulator (for example your EU Data Protection Authority, the UK ICO, or the Office of the Privacy Commissioner of Canada).
19Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the “last updated” date and, where required by law or reasonable in the circumstances, give additional notice. Your continued use of the Service after changes take effect means you accept the updated policy.
20Contact us
Pennix LLC
308 N Fairfield Rd, Devon, PA 19333, USA
Email: info@getpennix.ai — for all privacy and data-protection matters.