GDPR Compliance
How Ecolyxis protects your data under the UK GDPR
Ecolyxis is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides a transparent overview of the technical and organisational measures we have implemented to protect your personal data and uphold your rights.
For the full legal text, see our Privacy Policy. Questions? Contact us or email ashley@ecolyxis.co.uk.
Compliance Status
Every processing activity has a documented legal basis under Art. 6 (contract or legitimate interest).
All 8 GDPR rights are supported — access, rectification, erasure, restriction, portability, objection, withdrawal, and information.
Self-service account deletion via Settings → Delete Account. All personal data is permanently cascade-deleted.
Request a full export of your data in JSON or CSV format (Art. 20). We respond within one month.
Documented incident response procedure. ICO notification within 72 hours (Art. 33). Affected users notified without delay (Art. 34).
We do not sell, trade, or share your data. No third-party analytics or tracking. No external AI processors.
All data remains on servers under our direct control. No data leaves UK-based infrastructure.
Account creation requires explicit acceptance of the Terms of Service and Privacy Policy via checkbox.
Data Retention
We retain personal data only as long as necessary for the purposes described in our Privacy Policy:
| Data Category | Retention Period | Basis |
|---|---|---|
| Chat messages (free tier) | 24 hours | Automatic hourly cleanup |
| Chat messages (premium) | Until deletion | User-initiated or account deletion |
| Account information | Until deletion | Required to provide the service |
| Rate-limit / security data | 24 hours | SHA-256 hashed (pseudonymised), auto-purged |
| Server access logs | 30 days | journald, auto-rotated |
| Usage analytics | 12 months (raw), indefinite (anonymised aggregates) | Service improvement |
Technical & Organisational Security Measures
Your Rights Under the UK GDPR
| Right | Article | How to Exercise |
|---|---|---|
| Be informed | Art. 13–14 | Privacy Policy |
| Access | Art. 15 | Contact us — JSON/CSV export provided |
| Rectification | Art. 16 | Account settings |
| Erasure | Art. 17 | Settings → Delete Account |
| Restrict processing | Art. 18 | Contact us |
| Data portability | Art. 20 | Contact us — JSON/CSV export |
| Object | Art. 21 | Contact us |
| Withdraw consent | Art. 7(3) | Delete account at any time |
We respond to all requests within one month (Art. 12(3)). If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Data Architecture
A key GDPR advantage of Ecolyxis is that all AI processing runs on our own self-hosted infrastructure. Unlike services that send your data to third-party AI providers (OpenAI, Google, Anthropic), your chat messages and images never leave servers under our direct control. There are:
- No external AI processors — no sub-processor data sharing agreements needed
- No third-party analytics — no Google Analytics, no tracking pixels, no advertising networks
- No international data transfers — all data remains within our UK-based infrastructure
- No advertising — your data is never used for ad targeting
Last updated: 27 July 2026 · Privacy Policy · Terms of Service · Contact