GDPR Compliance

How Ecolyxis protects your data under the UK GDPR

Ecolyxis is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This page provides a transparent overview of the technical and organisational measures we have implemented to protect your personal data and uphold your rights.

For the full legal text, see our Privacy Policy. Questions? Contact us or email ashley@ecolyxis.co.uk.

Compliance Status

Lawful Basis

Every processing activity has a documented legal basis under Art. 6 (contract or legitimate interest).

Data Subject Rights

All 8 GDPR rights are supported — access, rectification, erasure, restriction, portability, objection, withdrawal, and information.

Right to Erasure

Self-service account deletion via Settings → Delete Account. All personal data is permanently cascade-deleted.

Data Portability

Request a full export of your data in JSON or CSV format (Art. 20). We respond within one month.

Breach Response

Documented incident response procedure. ICO notification within 72 hours (Art. 33). Affected users notified without delay (Art. 34).

No Third-Party Sharing

We do not sell, trade, or share your data. No third-party analytics or tracking. No external AI processors.

No International Transfers

All data remains on servers under our direct control. No data leaves UK-based infrastructure.

Explicit Consent

Account creation requires explicit acceptance of the Terms of Service and Privacy Policy via checkbox.

Data Retention

We retain personal data only as long as necessary for the purposes described in our Privacy Policy:

Data Category Retention Period Basis
Chat messages (free tier) 24 hours Automatic hourly cleanup
Chat messages (premium) Until deletion User-initiated or account deletion
Account information Until deletion Required to provide the service
Rate-limit / security data 24 hours SHA-256 hashed (pseudonymised), auto-purged
Server access logs 30 days journald, auto-rotated
Usage analytics 12 months (raw), indefinite (anonymised aggregates) Service improvement

Technical & Organisational Security Measures

TLS encryption (HTTPS) on all connections
bcrypt password hashing (irreversible)
HttpOnly, SameSite, Secure session cookies
CSRF protection on all forms
Rate limiting & brute-force protection
IP addresses pseudonymised (SHA-256)
Self-hosted AI inference (no external processors)
Strict access controls & role-based auth
Automated data deletion (hourly cron)
API keys stored as SHA-256 hashes only
WebAuthn / FIDO2 passwordless login support
Structured logging with automatic 30-day rotation

Your Rights Under the UK GDPR

Right Article How to Exercise
Be informed Art. 13–14 Privacy Policy
Access Art. 15 Contact us — JSON/CSV export provided
Rectification Art. 16 Account settings
Erasure Art. 17 Settings → Delete Account
Restrict processing Art. 18 Contact us
Data portability Art. 20 Contact us — JSON/CSV export
Object Art. 21 Contact us
Withdraw consent Art. 7(3) Delete account at any time

We respond to all requests within one month (Art. 12(3)). If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Data Architecture

A key GDPR advantage of Ecolyxis is that all AI processing runs on our own self-hosted infrastructure. Unlike services that send your data to third-party AI providers (OpenAI, Google, Anthropic), your chat messages and images never leave servers under our direct control. There are:

  • No external AI processors — no sub-processor data sharing agreements needed
  • No third-party analytics — no Google Analytics, no tracking pixels, no advertising networks
  • No international data transfers — all data remains within our UK-based infrastructure
  • No advertising — your data is never used for ad targeting

Last updated: 27 July 2026 · Privacy Policy · Terms of Service · Contact