Aligned with the EU GDPR, UK Data Protection Act 2018, US CCPA & CPRA,
India DPDP Act 2023, UAE Federal Decree-Law No. 45 of 2021, and ISO/IEC 27701 privacy principles.
Last updated: 8 May 2026
This Privacy Policy explains how we collect, use, store, share and protect personal information when you visit our websites, engage our consulting services, attend our events, or otherwise interact with us. It applies to individuals in every jurisdiction in which we operate, with specific protections incorporated for residents of the United Kingdom, the European Economic Area, the United States, India, and the United Arab Emirates.
This Policy is designed to comply with the EU GDPR, the UK Data Protection Act 2018 / UK GDPR, the US CCPA and CPRA and equivalent state laws, India's Digital Personal Data Protection Act 2023 (DPDPA), the UAE Federal Decree-Law No. 45 of 2021 (PDPL) including the free-zone-specific regimes of DIFC and ADGM, and other applicable privacy frameworks.
By using our website or services, you acknowledge that you have read and understood this Policy. Where required by law, we will obtain your explicit consent before processing your personal information.
For the purposes of the EU GDPR, the UK GDPR, and equivalent global privacy laws, the data controller is SPNX ("we", "us", "our"). We are a professional services and AI consulting firm operating globally, with offices in India, the UAE, and partner relationships across the United Kingdom, the United States, and the European Union.
If you have any questions about this Policy or our data practices, please contact us using the details in Section 16.
We collect personal information that is necessary to deliver our services, respond to your inquiries, manage our client relationships, and meet our legal obligations. The categories of personal information we collect include:
Name, job title, employer, business email address, business phone number, postal address, professional credentials, and other information you provide when you complete a form, request a proposal, or engage us as a client.
Details of the services you have engaged us for, contractual terms, billing information, payment records, project deliverables, and correspondence relating to engagements. Where the engagement requires it (audit, advisory, due diligence, tax, transaction support), we may also receive and process client financial documents, draft accounts, audit working papers, tax filings, and other regulated records, which are handled under the applicable professional standards and confidentiality obligations.
IP address, browser type and version, device identifiers, operating system, time-zone setting, referral source, pages visited, and time spent on our websites. This information is collected through cookies and similar technologies — see Section 12.
Your preferences in receiving updates, insights, invitations and marketing communications from us, and the channels through which you prefer to receive them.
We do not knowingly collect special category data (such as health, religion, biometric or genetic data) or sensitive personal information as defined under the CPRA, except where strictly necessary, lawful, and supported by your explicit consent or another valid legal basis.
Directly from you — when you fill out a form on our website, request a meeting, sign up for our newsletter, attend our events, or correspond with us via email, phone, or messaging platforms.
Automatically — through cookies, server logs, analytics tools, and similar technologies that record how you interact with our digital properties.
From third parties — including business contact databases, professional networks (such as LinkedIn), referral sources, public registries, regulatory filings, and our group affiliates and partners, where the source has the lawful right to share that information with us.
Where the EU GDPR or UK GDPR applies, we process personal information only when we have a valid legal basis. The bases we rely on are:
Contract — to negotiate, enter into, or perform a contract with you or your organization, including service delivery, billing, and support.
Legitimate interests — to operate, secure, and improve our business; to manage client relationships; to communicate with prospects in a business-to-business context; and to protect our legal rights. Where we rely on this basis, we balance our interests against your rights and freedoms.
Consent — where required, for example to send certain marketing communications or to place non-essential cookies. You may withdraw your consent at any time without affecting the lawfulness of processing carried out beforehand.
Legal obligation — to comply with applicable laws, regulatory requirements, court orders, tax obligations, anti-money-laundering rules, and similar duties.
We use your personal information to deliver our consulting and advisory services, respond to inquiries, prepare proposals, manage engagements, issue invoices, comply with legal and regulatory obligations, send service updates, share thought leadership, organize and run events, protect against fraud and abuse, and continually improve our services and digital properties.
Several SPNX products and services use artificial intelligence — including agentic tools (such as IT in a Box and Agentic Swarm Intelligence), data and forecasting platforms (Analytics in a Box, Benchmarking Tool), and our learning programs (AI Academy). When you interact with these tools, the following applies.
Inputs you provide — instructions, files, queries, and other content you submit to our AI tools are used to deliver the service requested. We do not use client-provided inputs to train our underlying models or those of our model providers, except where the data has been anonymized or where you have given explicit consent.
Model providers and sub-processors — we may use third-party large language models, vector databases, and inference infrastructure to operate our products. These providers are bound by data-processing agreements and operate as sub-processors under this Policy.
Human oversight — outputs that inform consequential decisions (financial, regulatory, or risk-related) are reviewed by qualified SPNX professionals before being acted upon. Where AI outputs may produce legal or similarly significant effects on individuals, meaningful human oversight is maintained at all times.
We do not sell your personal information.
We only share personal information with parties who have a legitimate need to receive it. These include:
Group affiliates — including SPNX entities, where group-wide service delivery requires it.
Trusted service providers — IT hosting, cloud infrastructure, customer relationship management, email and marketing platforms, video conferencing, payment processors, and professional advisors. Each provider is bound by written confidentiality and data-protection commitments.
Regulators, courts and authorities — where disclosure is required by law, by a valid order, or to protect our legal interests or the safety of others.
Successors and acquirers — in the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred subject to equivalent privacy protections.
Because we operate globally, your personal information may be transferred to, stored in, and processed in countries other than the one in which it was collected. These countries may have data-protection laws that differ from those in your home jurisdiction.
Where we transfer personal information out of the UK or the European Economic Area, we rely on recognized transfer mechanisms — including the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or your explicit consent — to ensure that your information continues to receive an essentially equivalent level of protection.
For personal information collected from individuals in India, transfers outside India are made in accordance with the Digital Personal Data Protection Act 2023, including any restrictions on transfers to jurisdictions notified by the Government of India under section 16 of that Act.
For personal information collected from individuals in the United Arab Emirates, transfers outside the UAE are made in accordance with the UAE Federal Decree-Law No. 45 of 2021, and where applicable the data-protection regimes of the DIFC and ADGM free zones, supported by adequate-protection assessments or contractual safeguards.
We retain personal information only for as long as necessary to fulfill the purpose for which it was collected, including any related legal, accounting, regulatory, or contractual obligations. Retention periods vary by data category. Client engagement records are typically retained for the duration of the engagement and for a defined period thereafter to comply with statutory limitation periods, professional standards, and tax laws.
When personal information is no longer needed, we securely delete or anonymize it.
If you are located in the United Kingdom or the European Economic Area, you have the following rights under the UK GDPR and the EU GDPR:
The right to access a copy of the personal information we hold about you; the right to rectify inaccurate or incomplete data; the right to erasure in certain circumstances; the right to restrict processing; the right to object to processing based on legitimate interests or for direct marketing; the right to data portability; and the right to withdraw consent at any time.
You also have the right to lodge a complaint with a supervisory authority — for example, the UK Information Commissioner's Office (ICO) or the data-protection authority of the EU member state in which you reside.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
The right to know what personal information we collect, use, disclose, and share, and the categories of sources and recipients; the right to delete personal information we have collected from you, subject to certain exceptions; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of your personal information; the right to limit the use and disclosure of sensitive personal information; and the right to non-discrimination for exercising any of these rights.
Residents of other US states with comprehensive privacy laws have substantially similar rights, and we honor those rights in line with the applicable state law.
We use cookies and similar technologies to operate our website, remember your preferences, analyze traffic, and improve user experience. Cookies fall into the following categories:
Strictly necessary — session and security cookies required for the site to load, authenticate users, and maintain secure connections. First-party; expire when you close the browser. These cannot be switched off.
Performance & analytics — measure traffic patterns and content engagement so we can improve the site. Typically Google Analytics or equivalent. Aggregated and anonymized; retention up to 14 months.
Functional — remember your language, region, consent choices, and other preferences so the site responds the way you expect. Retention up to 12 months.
Marketing — placed only with your consent. May include LinkedIn Insight Tag, Meta Pixel, and similar third-party identifiers used to surface relevant content and measure campaign effectiveness. Retention varies by provider; typically between 90 days and 12 months.
You can manage your cookie preferences at any time through your browser settings or through the cookie banner on our website. Non-essential cookies are not set until you give consent through the banner.
Our services are directed to organizations and business professionals. We do not knowingly collect personal information from children under the age of 13 (in the United States), under the age of 16 (in the European Economic Area and the United Kingdom), or under the age of 18 (in India, as defined under the Digital Personal Data Protection Act 2023). If we become aware that we have inadvertently collected personal information from a child without verifiable parental consent, we will delete it promptly.
We implement appropriate technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include access controls, encryption in transit and at rest, network segmentation, regular security testing, employee training, vendor due diligence, and an incident response capability.
While we strive to protect your personal information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we will notify you and the relevant authorities of any data breach in accordance with applicable law.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will revise the "Last updated" date at the top of this page and, where appropriate, notify you through our website or by email.
If you have any questions about this Privacy Policy, wish to exercise your rights, or have any other concerns about how we handle your personal information, please contact us at:
SPNX
Email: human001@spnx.ai
We will respond to verifiable requests within the timeframes prescribed by applicable law.
This Privacy Policy is provided as a general framework reflecting widely accepted privacy principles in the United Kingdom, the European Union, and the United States. It is not legal advice and should be reviewed by qualified counsel before publication.
Choose which cookies we can use. You can change these any time from the cookie settings pill at the bottom-left of any page.