Privacy Policy

INQYRE LTD respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect and process personal data when you visit our website or use our services. When we collect and use your personal data, we are subject to the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

Our website may contain links to third-party websites. Those websites may gather information about you in accordance with their own separate privacy policies. We do not control third-party websites and are not responsible for how they handle your personal data, so please consult their privacy policies as appropriate.

Who are we?

INQYRE LTD (referred to as "we", "us" or "our" in this privacy policy) is the controller of the personal data described in this policy and is responsible for it. Where we process personal data on behalf of a business customer in order to provide our services to them, we do so under our contract with that customer, and their privacy policy will apply to that processing.

If you have any questions about this privacy policy or our privacy practices, please contact us in the following ways:

Full name of legal entity: INQYRE LTD

Email address: hello@inqyre.ai

Postal address: 167-169 Great Portland Street, London, England, W1W 5PF

How do you use my data?

Under data protection law, we can only use your personal data if we have a proper reason for doing so, for example: where you have given consent; to perform our contract with you or to take steps at your request before entering into a contract; to comply with our legal and regulatory obligations; for the purposes of a recognised legitimate interest; or for our legitimate interests or those of a third party. A legitimate interest is when we have a business or commercial reason to use your personal data, so long as this is not overridden by your own rights and interests. Where we rely on legitimate interests, we carry out an assessment to balance our interests against your own; you can obtain details of these assessments by contacting us using the details above. The list below explains what we use your personal data for and why.

  • When you create and log into your account we will collect your name, email address, phone number, address, company name and address (if applicable) and your payment details. We collect this in order to take steps to enter into a contract with you and allow you to purchase our services. If you do not provide this information, we may not be able to set up your account or provide our services to you.
  • When your organisation gives you access to our platform. If your employer or another organisation you work with is an Inqyre customer, or has been invited to use our platform, and registers you as a user, we will collect your name, business contact details and role from them, or from you when you activate your access, together with your login and security details. We use this information to provide our services under our contract with that organisation, to manage, secure and administer your access, and to send you service communications, because it is in our legitimate interests to administer access for our business customers and their invited users.
  • When you are a merchant being onboarded by one of our customers. If a payment company that uses our platform (for example, a payment service provider, payment facilitator, independent sales organisation or acquirer) invites you or your business to complete its merchant onboarding or due diligence process, we process the information and documents submitted through our platform, including details of your business and of its directors, owners and representatives, together with information about your business obtained from public and third-party sources (such as Companies House and other public registers, and web and media sources). We process this information on behalf of, and under the instructions of, the customer that invited you: that customer is the controller of this information, its privacy notice applies to that processing, and any decision about whether to onboard you is made by that customer, not by us. This information is retained and deleted in accordance with our agreement with that customer. We act as a controller in our own right only for limited purposes: administering and securing platform accounts (including authentication and security logs), sending service communications such as document requests and status updates, complying with our own legal obligations, and producing aggregated and anonymised statistics and analytics that do not identify you or any individual.
  • When you use our services. We collect information about how you use our website and services, together with technical data such as your IP address, browser and device type, and server logs. We use this data because it is in our legitimate interests to operate our services reliably, keep them available, understand how they are used and improve them.
  • To keep our services secure. We use technical data, log data and account data to monitor for, prevent and investigate fraud, misuse and threats to the security of our systems and our users. This kind of security processing is a recognised legitimate interest under UK data protection law.
  • To manage our relationship with you. We use your contact and billing details to manage your subscription, take payment, and send you important non-marketing messages about your account and our services, such as changes to our terms, security notices, renewal reminders and invoices. We do this to perform our contract with you and to comply with our legal, accounting and tax obligations, and to establish, exercise or defend legal claims where necessary.
  • When you sign up to receive our news updates. We will collect your name and email address to provide you with our news updates in line with any preferences you have told us about. When we send you our news updates because you have opted-in to receive them, we rely on your consent to contact you. You can unsubscribe from our updates at any time by clicking the unsubscribe link in any marketing email we send you or by responding to any email you receive from us to tell us you wish to unsubscribe.
  • When you contact us either by phone, email, via our 'contact us' page or via social media, we will usually collect your name, social media handle and contact details, because it’s in our legitimate interest to make sure we can properly respond to your query.
  • When we obtain your details from other sources. We also collect business contact details (such as your name, job title, organisation and contact details) when we meet you at events and conferences, when you connect or interact with us on LinkedIn or other professional networks, when you are introduced to us by others, and from publicly available sources such as company websites and public registers. We store these details in our customer relationship management (CRM) system and use them to build and manage our business relationships and to develop and promote our business, because it is in our legitimate interests to do so. Where we use these details to send you marketing, we will do so in accordance with applicable direct marketing laws, and you can ask us to stop at any time.
  • When you use our website and consent to our use of cookies we will collect information about how you use our website. We use this information to improve our website and to better understand how people use it. More detail on the information we collect and how we do this is set out in our Cookie Policy.
  • If our business is sold. We process your personal information for this purpose because we have a legitimate interest to ensure our business can be continued by the buyer. If you object to our use of your personal information in this way, the buyer of our business may not be able to provide services to you.

Who do you share my data with?

  • Service providers we use to run our business, such as cloud hosting and data storage providers, payment processors, analytics providers, and email, customer support and similar software tools. They only receive the personal data they need to provide their service to us, act on our instructions, and are bound by contracts which require them to protect your personal data.
  • The customer that invited you to our platform where you use our platform as a merchant, or on behalf of one, at the invitation of one of our business customers. For example, we provide onboarding information, documents and reports to that customer on its instructions as controller of that information, and we may report suspected fraud, misuse or security issues affecting our platform to it.
  • Professional advisers including lawyers, accountants, auditors, insurers and bankers, where necessary in the course of running our business.
  • Regulators/ Authorities/ Enforcement Agencies if we are under a duty to disclose or share your personal data in order to comply with any legal obligation, or in order to enforce or apply our terms of use and other agreements; or to protect the rights, property, or safety of our clients or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection. We share and receive this information in order to comply with our legal obligations and because it is in our legitimate interests, and those of others, to protect against fraud and other criminal activity. Where we receive information about you from other organisations in this way, we will only use it for these purposes.
  • Prospective buyers of our business under our legitimate interest to ensure our business can be continued by the buyer.

We do not sell your personal data, and we never share it with other organisations for their own marketing purposes.

Where do you store my data?

Our platform is hosted on Amazon Web Services infrastructure in the London (eu-west-2) region, so your personal data is primarily stored in the UK. When working with third parties we may need to transfer your personal data outside of the UK. Personal data can move freely between the UK and the European Economic Area (EEA), because each treats the other as providing an adequate level of protection for it.

Whenever we transfer your personal data outside of the UK or the EEA, we make sure it receives a similar level of protection by ensuring at least one of the following safeguards is in place: the country we send it to has been approved as providing an adequate level of protection under UK adequacy regulations (or, where EU law applies to the transfer, EU adequacy decisions); or we have entered into a contract with the recipient which requires them to protect your personal data to the standard required in the UK such as the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses where EU law applies to the transfer. You can contact us using the details above for more information about these safeguards or to request a copy of them.

How do you keep my data safe?

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, contractors and other third parties who have a business need to know it. We also have procedures in place to deal with any suspected personal data breach, and we will notify you and any applicable regulator of a breach where we are legally required to do so.

How long do you keep my data for?

We will only retain your personal information for as long as we need it unless we are required to keep it for longer to comply with our legal, accounting or regulatory requirements. When deciding how long we need personal data for, we consider its amount, nature and sensitivity, the potential risk of harm from unauthorised use or disclosure, the purposes we process it for, and any legal, accounting or reporting requirements to keep it.

As a general rule, we keep: account and profile data for as long as your account is active, deleting or anonymising it within 90 days of your account being closed; billing, tax and accounting records for 6 years from the end of the financial year they relate to; marketing data until you unsubscribe or after 2 years of inactivity; and server logs and similar technical data for no more than 12 months. We may keep specific data for longer where we need it to deal with a legal claim, complaint or investigation.

In some circumstances we may carefully anonymise your personal data so that it can no longer be associated with you, and we may use this anonymised information indefinitely without notifying you. We use this anonymised information to improve the way we work and our services. This includes producing aggregated statistics and analytics, and developing, training, testing and improving our platform, the AI models used in it and our other products and services. We will not attempt to re-identify you, or anyone else, from information that has been anonymised.

What are my rights under data protection law?

You have the right to:

  • Request access to your personal data (commonly known as a "data subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
  • Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:
    • If you want us to establish the data's accuracy.
    • Where our use of the data is unlawful but you do not want us to erase it.
    • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
    • You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • Not be subject to significant decisions based solely on automated processing without appropriate safeguards. A significant decision is one which produces a legal or similarly significant effect on you. Where such a decision is made without meaningful human involvement, you are entitled to safeguards, including being given information about the decision and being able to make representations, obtain human intervention and contest the decision. We do not make any such decisions based on the personal data described in this policy.
  • Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

You will not usually have to pay a fee to exercise any of these rights. If you would like to exercise any of them, please contact us using the details above and let us know which right you want to exercise and the information to which your request relates. We may need to request specific information from you to help us confirm your identity before acting on your request; this is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. If your request relates to information we process on behalf of one of our business customers (for example, in connection with a merchant onboarding), that customer is the controller of the information; we will pass your request to the customer and provide reasonable assistance.

You also have the right to complain to us about the way we use your personal data. You can do this using any of the contact details above; we will acknowledge your complaint within 30 days of receiving it and let you know the outcome of our investigation without undue delay. You can also complain at any time to the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection (www.ico.org.uk; telephone 0303 123 1113), although we would welcome the chance to address your concerns first. If you are based in the EU, you can find your local supervisory authority on the European Data Protection Board’s website.

Please keep in mind that privacy law is complicated, and these rights will not always be available to you all of the time.

Do we review this policy?

We keep our privacy policy under regular review. If we make significant changes, we will update the date at the top of this policy and, where appropriate, let you know by email or by a notice on our website. This policy was last updated on 28 August 2026.