Privacy Policy
Last updated: July 2026
GLLUZ LTD ("we", "us", "our") is a company registered in England and Wales. We operate Axidex, a signal intelligence platform for sales teams. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
1. Data We Collect
We collect the following categories of information:
- Account information— name, email address, company name, and role when you create an account.
- Usage data— pages visited, features used, search queries, and interaction patterns within the platform.
- Signal data— publicly available business information we aggregate from open sources (job postings, press releases, regulatory filings) to generate buying signals.
- Prospect data— names, job titles, email addresses, LinkedIn profiles, and phone numbers of third-party business contacts identified through the platform's contact-finding and lead search features.
- Technical data— IP address, browser type, device information, and operating system collected automatically.
- Payment data— billing details processed securely through Stripe. We do not store full card numbers.
2. How We Use Your Data
- To provide, maintain, and improve the Axidex platform and its features.
- To generate and deliver buying signals and AI-powered outreach suggestions.
- To process transactions and manage your subscription.
- To communicate with you about updates, security alerts, and support.
- To analyse platform usage and optimise performance (analytics cookies only with your consent).
- To detect and prevent fraud, abuse, or security incidents.
3. Lawful Basis for Processing
Under UK GDPR and EU GDPR, we must have a valid lawful basis for processing personal data. The basis we rely on depends on the type of data and purpose:
- Contract performance— processing your account data (name, email, payment details) is necessary to provide the Axidex service you have subscribed to.
- Legitimate interests — B2B contact research — when you use Axidex's contact-finding, company search, and people-search features, the platform retrieves publicly available B2B contact information (names, job titles, work email addresses, LinkedIn profiles) about third-party business professionals. We rely on legitimate interests (Article 6(1)(f) UK/EU GDPR) as the lawful basis for this processing.
What this means: Sales professionals have a genuine, recognised business need to identify and contact relevant decision-makers at companies that may benefit from their products or services. This is the same lawful basis relied upon by established B2B data providers such as Apollo, ZoomInfo, Hunter, and Clearbit.
How we source this data: Contact information is retrieved in real time from licensed third-party data providers (including Apollo.io via Apify, and Hunter.io) and from publicly accessible company websites and professional directories. We do not build or maintain a proprietary contact database.
Balancing test: We have assessed that our legitimate interest in enabling B2B sales outreach is not overridden by the rights and freedoms of the individuals whose contact details appear, given that: (a) the information is limited to professional, work-context data voluntarily made public; (b) individuals can reasonably expect their publicly listed business contact details to be used for professional outreach; and (c) we provide a straightforward opt-out mechanism below.
Your right to object: If you are a business professional whose contact information has been surfaced through the Axidex platform and you wish to have it suppressed or deleted, please email privacy@axidex.ai with the subject line "Contact Data Removal Request". We will process your request within 30 days and add your details to our suppression list to prevent future retrieval.
- Legal obligation— where we are required to process data to comply with applicable law (e.g. fraud prevention, tax obligations).
- Consent— for non-essential analytics cookies, where you have given explicit consent via the cookie banner.
4. Data Sharing and Sub-Processors
We do not sell your personal data. We share data only with the following service providers ("sub-processors") who are contractually bound to protect it:
- Vercel— platform hosting and edge delivery.
- Supabase— database and authentication (EU region).
- Stripe— payment processing.
- Resend— transactional email delivery.
- OpenRouter / Groq— AI providers used to generate outreach emails and classify signals. We send minimal data (contact first name, job title, company name) for email personalisation. We do not share full contact records or sensitive personal data with AI providers, and we do not consent to our data being used to train third-party AI models.
- Legal compliance— when required by law, court order, or to protect our legal rights.
For business customers, a full list of sub-processors and transfer mechanisms is available in our Data Processing Agreement.
5. Data Security
We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, row-level security policies on our database, short-lived session tokens, and regular security reviews. Access to personal data is restricted to authorised personnel on a need-to-know basis. While no system is perfectly secure, we take reasonable steps to protect your information and will notify you within 72 hours of becoming aware of a personal data breach affecting your account.
6. Your Rights (UK & EU GDPR)
Under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and equivalent EU legislation, you have the following rights:
- Access— request a copy of the personal data we hold about you.
- Rectification— request correction of inaccurate or incomplete data.
- Erasure— request deletion of your personal data, subject to legal retention obligations.
- Portability— receive your data in a structured, machine-readable format.
- Objection— object to processing based on legitimate interests or for direct marketing.
- Restriction— request that we limit processing of your data in certain circumstances.
To exercise any of these rights, contact us at privacy@axidex.ai. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Data Retention
We retain your account data for as long as your account is active. Upon account deletion, personal data is deleted within 30 days, except where retention is required by law (e.g. financial records under UK tax legislation, which are retained for 7 years). Anonymised, aggregated usage statistics may be retained indefinitely.
9. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
GLLUZ LTD
Email: privacy@axidex.ai