Privacy Policy

Consulnex — Web-Based Business Management Platform

Last updated: 15 September 2026


1. Introduction

This Privacy Policy ("Policy") explains how Consulnex ("Consulnex," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with our website and the Consulnex platform (together, the "Services"). It applies to visitors to our website, prospective customers, registered customers, and Authorized Users of customer Accounts, as those terms are defined in our Terms and Conditions.

This Policy should be read together with our Terms and Conditions and our Cookie Policy, both of which are incorporated by reference and available on our website. Where this Policy refers to "you," it means the individual whose personal data is being processed, whether you are browsing our website, evaluating Consulnex as a prospective customer, or using the Services as a registered customer or Authorized User.

We know that the Services involve handling sensitive business information, including personal data relating to your own clients and employees. In addition to personal data about you, this Policy is written to be as clear as possible about two related but distinct things: how we, as the provider of the Platform, handle personal data about you directly, and the respective roles and responsibilities that apply when your Content includes personal data about third parties, such as your clients or employees, which you enter into the Platform.

2. Scope and Our Role

This Policy primarily describes how we process personal data where we act as a data controller (or the equivalent role under Applicable Law) — broadly, personal data relating to your interactions with our website and marketing, your Account registration and administration, your purchase and use of Packages, and your communications with our support team.

Where your Content, as defined in our Terms and Conditions, includes personal data relating to third parties — such as client records in the CRM module, employee records in the HR module, or names and details appearing in project or financial records — you act as the data controller (or equivalent role) in respect of that personal data, and we act as a data processor (or equivalent role), processing that personal data on your instructions and for the purpose of providing the Platform to you. This distinction matters because it determines who is primarily responsible for meeting certain obligations under Applicable Law, as described further in Section 11 (Your Content and Your Responsibilities as a Controller).

Where we process personal data as a processor on your behalf, we do so in accordance with your instructions, as reflected in our Terms and Conditions and this Policy, and in accordance with any separate data processing terms we may make available to customers who require them for their own compliance purposes.

3. Personal Data We Collect

We collect personal data from several sources, depending on how you interact with us.

Information you provide directly. When you register for an Account, purchase a Package, contact our support team, or otherwise interact with us directly, we collect information such as your name, email address, business name, job title, billing address, and any other information you choose to provide, including the content of any messages you send us.

Information collected automatically. When you visit our website or use the platform, we automatically collect certain technical information, including your IP address, browser type and version, device information, operating system, referring website, pages viewed, and the dates and times of your visits. This information is collected primarily through cookies and similar technologies, as described in more detail in our Cookie Policy.

Information generated through your use of the Services. As you use the platform, we collect information about your usage patterns, such as which features you access, how frequently you log in, and general usage volume relative to your Package's usage limits, which helps us operate, secure, and improve the Services, and manage your Package appropriately.

Payment information. When you purchase a Package, payment is processed through Stripe, our third-party payment processor, as described in our Terms and Conditions. We do not directly collect or store your full payment card details; Stripe collects and processes this information in accordance with its own privacy practices. We may receive limited information from Stripe confirming that a payment has been made, such as the last four digits of a card or a transaction reference, for our own billing and support purposes.

Content you submit to the Platform. As described in Section 2, Content you enter into the Platform, including client records, employee records, project data, and financial records, may include personal data relating to third parties. We process this Content as a data processor on your behalf, as described in Section 11.

Information from third parties. We may receive limited information about you from third parties, such as a business partner who refers you to us, or publicly available business information used to verify Account records for legitimate business purposes, such as fraud prevention.

4. How We Use Personal Data

We use personal data we collect for the following purposes, relying on the legal bases described in Section 5:

  • To provide and maintain the Services, including creating and administering your Account, granting access to the features and usage limits associated with your Package, and processing your purchases through Stripe.
  • To communicate with you, including responding to support enquiries, sending transactional communications such as Order Confirmations and security notices, and, where you have consented or as otherwise permitted by Applicable Law, sending marketing communications about Consulnex.
  • To improve and develop the Services, including analysing usage patterns to understand how features are used, identifying and fixing technical issues, and informing our product development priorities. To maintain the security and integrity of the Services, including detecting and preventing fraud, unauthorised access, and other security threats, and enforcing our Terms and Conditions and Acceptable Use provisions.
  • To comply with legal obligations, including responding to lawful requests from public authorities, maintaining records required by tax and accounting laws applicable to us, and meeting other regulatory requirements that apply to our business. To establish, exercise, or defend legal claims, including in connection with disputes arising from your use of the Services.
  • We do not sell personal data to third parties, and we do not use personal data to build advertising profiles for sale to unrelated third parties. Where we engage in any marketing-related processing involving cookies or similar technologies, this is described in more detail in our Cookie Policy, including the consent mechanisms that apply.

Where you receive marketing communications from us, whether by email or another channel, each such communication will include a straightforward way to unsubscribe or otherwise opt out of future marketing messages. Opting out of marketing communications does not affect our ability to send you transactional or service-related communications necessary for the operation of your Account, such as Order Confirmations, security notices, and important updates about the Services, which are sent on the basis of our contract with you or our legitimate interest in keeping customers informed of matters that affect their use of the Platform, rather than on the basis of marketing consent.

5. Legal Bases for Processing

Where Applicable Law requires us to identify a legal basis for processing personal data, we rely on the following, as appropriate to the specific processing activity:

Performance of a contract: where processing is necessary to provide the Services you have purchased, to administer your Account, or to take steps at your request prior to entering into a contract, such as responding to a pre-sale enquiry.

Legitimate interests: where processing is necessary for our legitimate interests in operating, securing, and improving our business and the Services, provided those interests are not overridden by your own rights and interests. Examples include analysing aggregated usage data to improve the platform, maintaining the security of our systems, and communicating with existing customers about relevant updates to the Services.

Consent: Where we rely on your consent, such as for certain marketing communications or non-essential cookies as described in our Cookie Policy, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Legal obligation: where processing is necessary for us to comply with a legal obligation to which we are subject, such as retaining certain billing records for tax purposes.

Where you are located in a jurisdiction that recognises additional or different legal bases, or that requires a different framework for describing the basis for processing, we will apply the equivalent basis available under that jurisdiction's law and will provide further information on request.

6. How We Share Personal Data

We do not sell personal data. We share personal data only in the following limited circumstances:

Service providers. We engage third-party service providers to help us operate the Services, including hosting and infrastructure providers, payment processing (Stripe), analytics providers, customer support tools, and email delivery services. These providers are only permitted to process personal data on our behalf, for the specific purposes we have engaged them for, and are subject to contractual obligations to protect that data and to use it only as instructed.

Professional advisors. We may share personal data with professional advisors, such as lawyers, accountants, auditors, and insurers, where necessary for them to provide advice or services to us, subject to appropriate confidentiality obligations.

Legal and regulatory disclosures. We may disclose personal data where required to comply with Applicable Law, a court order, or a lawful request from a public or governmental authority, or where we believe disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

Business transfers. If we are involved in a merger, acquisition, reorganisation, financing, or sale of all or a portion of our business or assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality protections and, where required by Applicable Law, notice to affected individuals.

With your direction or consent. We may share personal data with other third parties where you have specifically directed or consented to such sharing.

We require service providers and other recipients of personal data to implement appropriate safeguards to protect that data, consistent with the standards described in this Policy.

7. International Data Transfers

Consulnex and its service providers may process personal data in countries other than the country in which you are located, including countries that may not provide the same level of data protection as your home jurisdiction. Where we transfer personal data internationally, we take steps designed to ensure the transfer complies with Applicable Law and that appropriate safeguards are in place.

These safeguards may include reliance on standard contractual clauses approved by relevant authorities, reliance on an adequacy decision made by a relevant regulator recognising that the destination country provides an adequate level of protection, or other legally recognised transfer mechanisms appropriate to the jurisdictions involved. Where required by Applicable Law, we will provide further information about the specific safeguards used for a particular transfer upon reasonable request.

8. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by Applicable Law. In determining retention periods, we consider factors including the amount, nature, and sensitivity of the personal data, the purposes for which it is processed, whether those purposes can be achieved through other means, and any applicable legal, regulatory, tax, accounting, or other requirements.

Account and Content data. Personal data associated with your Account, and Content you have submitted to the Platform, is generally retained for as long as your Account remains active, and for a limited period following termination of your Account to allow for reactivation, dispute resolution, or compliance with legal obligations, as described in our Terms and Conditions, after which it is deleted or anonymised in accordance with our internal retention schedules.

Billing records. Records relating to payments and invoices are generally retained for the period required by applicable tax and accounting laws, which may extend beyond the life of your Account.

Marketing data. Where we hold personal data for marketing purposes on the basis of your consent, we retain that data until you withdraw your consent or until it is no longer needed for the relevant marketing purpose, whichever occurs first.

Where retention periods are not fixed by Applicable Law, we apply retention periods designed to be no longer than reasonably necessary for the purposes described in this Policy, reviewed periodically as part of our internal data governance practices.

9. Data Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction, consistent with industry practices appropriate to a platform of this nature. These measures include encryption of data in transit, access controls limiting who within our organisation can access personal data and Content, and regular review of our security practices as the Services evolve.

No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security of personal data. You also play an important role in protecting your own Account, including by maintaining the confidentiality of your Account credentials and promptly notifying us of any suspected unauthorised access, as described in our Terms and Conditions.

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected individuals and relevant regulators as required by Applicable Law, and will provide reasonable cooperation to assist customers acting as data controllers in meeting their own notification obligations where the breach affects Content they have submitted to the Platform.

Access to personal data and Content within our own organisation is limited on a need-to-know basis to personnel who require such access to perform their roles, such as engineering staff maintaining the Platform's infrastructure or support staff assisting with a specific customer enquiry. Personnel with access to personal data are subject to confidentiality obligations, and we provide training designed to ensure that our team understands its responsibilities in handling personal data appropriately and in line with this Policy.

10. Your Rights

Depending on the jurisdiction in which you are located, you may have certain rights in relation to personal data we hold about you, which may include the right to: request access to the personal data we hold about you; request correction of inaccurate or incomplete personal data; request deletion of your personal data, subject to certain exceptions, such as where we are required to retain it for legal or legitimate business purposes; request restriction of, or object to, certain processing of your personal data; request portability of personal data you have provided to us, in a structured, commonly used, machine-readable format; and withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us using the details in Section 17. We will respond to your request within the timeframe required by Applicable Law, and may need to verify your identity before processing certain requests, to protect against unauthorised access to personal data.

Where a request relates to personal data contained within Content submitted by a Consulnex customer — for example, where you are a client or employee of a business using Consulnex, and your personal data appears in that business's Account — we will generally direct your request to the relevant customer, who acts as the data controller for that Content, as described in Section 11, unless Applicable Law requires us to respond directly.

If you are not satisfied with how we have handled your request or any concern you raise with us, you may have the right to lodge a complaint with a data protection authority in your jurisdiction of residence, place of work, or the place where the alleged issue occurred.

We aim to make exercising your rights as straightforward as possible, and we do not charge a fee for handling a reasonable request. Where a request is manifestly unfounded, excessive, or repetitive, Applicable Law may permit us to charge a reasonable administrative fee, or to decline to act on the request, in which case we will explain our reasoning to you in writing.

11. Your Content and Your Responsibilities as a Controller

If you are a Consulnex customer, Content you submit to the Platform will frequently include personal data relating to third parties, such as your clients, prospective clients, and employees. In relation to this personal data, you act as the data controller; and you are responsible for ensuring that your collection, use, and submission of such personal data to the Platform complies with Applicable Law.

This includes, among other things, ensuring you have a valid legal basis for processing the personal data of your clients and employees, such as their consent, the performance of a contract with them, or another basis available under Applicable Law; providing appropriate privacy notices to your own clients and employees explaining how their personal data is collected and used, including through your use of a platform like Consulnex; responding to requests from your clients or employees seeking to exercise rights in relation to their personal data, such as access or deletion requests, using the tools available within the Platform where applicable; and ensuring that any special category or otherwise sensitive personal data you choose to store within the Platform is handled in accordance with any heightened requirements applicable under Applicable Law.

We process this Content strictly in accordance with your instructions, as reflected in our Terms and Conditions and this Policy, and solely for the purpose of providing the Platform to you. We do not independently use Content you submit for our own separate purposes, such as marketing to your clients or employees, or building profiles unrelated to providing the Services to you.

Where required by Applicable Law, and particularly for customers subject to regulatory frameworks that require a formal data processing agreement between controllers and processors, we make separate data processing terms available on request, setting out in greater detail the nature, scope, and duration of our processing on your behalf, the safeguards we apply, and the arrangements for assisting you in meeting your own obligations as a controller.

We also encourage customers to take advantage of the tools built into the Platform that support good data-handling practice on your own part, such as the ability to organise records clearly, restrict access to sensitive HR or financial Content to appropriate team members through your own internal processes, and the ability to export or delete Content when it is no longer needed for the purposes you originally collected it for. While the ultimate responsibility for compliance with Applicable Law in respect of your own clients' and employees' personal data rests with you as the controller, the structure of the Platform is designed to make responsible data practices easier to implement, rather than harder.

12. Additional Rights for Residents of Certain U.S. States

If you are a resident of a U.S. state that has enacted comprehensive consumer privacy legislation, such as California, Virginia, Colorado, Connecticut, or other states with similar laws, you may have additional or differently framed rights in relation to your personal data, which we honour in accordance with the applicable state law.

These rights may include the right to know what categories of personal data we have collected about you and the purposes for which it is used; the right to request deletion of personal data we hold about you, subject to certain exceptions; the right to correct inaccurate personal data; the right to opt out of the "sale" or "sharing" of personal data, or of processing for targeted advertising purposes, as those terms are defined under applicable state law; and the right not to receive discriminatory treatment for exercising any of these rights.

As noted elsewhere in this Policy, we do not sell personal data in the ordinary sense of exchanging it for monetary payment. To the extent any use of cookies or similar technologies described in our Cookie Policy could be considered a "sale" or "sharing" under the broader definitions used in certain state laws, we provide mechanisms to opt out of such processing through our cookie preference tool, as described in our Cookie Policy.

To exercise any state-specific rights described in this Section, please contact us using the details in Section 17. We will verify your identity using reasonable means appropriate to the sensitivity of the request before fulfilling it, and will respond within the timeframe required by the applicable state law. You may also have the right to designate an authorized agent to submit a request on your behalf, subject to our ability to verify that the agent has been properly authorized to act for you.

13. Additional Information for the European Economic Area, United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, certain additional information applies to the processing of your personal data, in addition to the general information provided elsewhere in this Policy.

Where we process personal data on the basis of legitimate interests, as described in Section 5, we have considered the balance between our interests and your rights and freedoms, and we are satisfied that our processing does not unduly prejudice you. You have the right to object to processing carried out on the basis of legitimate interests, and we will consider any such objection on its merits, ceasing the relevant processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

Where personal data is transferred outside the European Economic Area, United Kingdom, or Switzerland, we rely on the safeguards described in Section 7, including standard contractual clauses in their applicable form for each jurisdiction, or an applicable adequacy decision, to ensure that such transfers provide an adequate level of protection consistent with the requirements of the General Data Protection Regulation, the UK GDPR, and the Swiss Federal Act on Data Protection, as applicable.

You have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data infringes Applicable Law, without prejudice to any other administrative or judicial remedy available to you. We would, however, appreciate the opportunity to address your concerns directly first, and encourage you to contact us using the details in Section 17 before escalating a complaint, where practicable.

14. Children's Privacy

The Services are intended for use by businesses and business professionals and are not directed at, or intended for use by, children. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take reasonable steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us using the details in Section 17.

15. Automated Decision-Making

We do not use your personal data to make decisions that produce legal effects concerning you, or similarly significant effects, based solely on automated processing without human involvement. Where the Platform includes features that generate reports, summaries, or suggestions based on Content you have entered, these are provided as informational tools to support your own decision-making, and do not constitute automated decisions made about you or on your behalf. If this changes in the future, such as through the introduction of new automated features, we will update this Policy accordingly and provide any additional information or rights required by Applicable Law.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or Applicable Law. Where we make a material change to this Policy, we will update the "last updated" date shown on this document and, where appropriate, provide additional notice, such as by email or through a notice on our website or within the platform.

We encourage you to review this Policy periodically to stay informed about how we collect, use, and protect personal data. Your continued use of the Services after a material update to this Policy takes effect constitutes your acknowledgment of the updated Policy, to the extent permitted by Applicable Law; where Applicable Law requires your renewed consent for a particular change, such as a new use of personal data based on consent, we will seek that consent separately before relying on it.

A record of prior versions of this Policy will be made available on request, so you can review how our practices have changed over time if that is relevant to your own compliance or record-keeping needs.

17. Contact Us

If you have any questions about this Privacy Policy, would like to exercise any of the rights described in Section 10, or have any concerns about how we handle personal data, please contact us using the details published on our website. If we have appointed a data protection officer or an equivalent representative, as required by Applicable Law in certain jurisdictions, their contact details will also be made available through the same channel.

This Privacy Policy should be read together with our Terms and Conditions and our Cookie Policy, both of which are available on our website and, together with this Policy, form part of the overall terms governing your use of our website and the Consulnex platform.