Privacy Policy
Last updated: 2 September 2026.
This policy explains what personal data Regsure collects, why, how it's used, who it's shared with, and the rights you have over it. It applies to visitors to our website and to firms and individual users of the Regsure application.
1. Who we are
Regsure is operated by iBuzz Ltd, a company registered in England and Wales (company number 13378925). iBuzz Ltd is the data controller responsible for your personal data under UK GDPR and the Data Protection Act 2018.
Questions about this policy or how your data is handled can be sent to hello@regsure.uk.
2. What data we collect
We collect the following categories of data:
- Account data - name, work email address, and firm details you provide when you sign up or are added to a firm's account.
- Firm and policy data - your firm's uploaded policy documents, and the metadata generated from them (e.g. which Handbook provisions they're matched against).
- Usage data - questions you ask, answers generated, audit requests, applications and sign-off records created inside the product, so that the audit trail and history features work.
- Technical data - IP address, browser type, and device information collected automatically when you use our website or application, for security and reliability purposes.
- Communications - any correspondence you send us, such as support requests.
We do not knowingly collect special category data (e.g. health or biometric information) through the product. Please don't include such data in policy documents or questions you submit.
3. How we use your data
We use your data to:
- Provide the Regsure service: answering Handbook questions, matching your policies against FCA updates, drafting audit and application responses, and maintaining your audit trail.
- Create and manage your account and your firm's access to the product.
- Secure the service, including detecting and preventing misuse, and keeping each firm's data isolated from every other firm's.
- Communicate with you about your account, service updates, or in response to a support request.
- Meet our legal and regulatory obligations.
4. Legal basis for processing
We rely on the following legal bases under UK GDPR:
- Contract - processing your account and firm data is necessary to provide the service you've signed up for.
- Legitimate interests - for security, fraud prevention, and improving the service, balanced against your rights.
- Consent - where we ask separately, e.g. for optional marketing communications, which you can withdraw at any time.
- Legal obligation - where we're required to retain or disclose data by law.
5. AI processing
Questions you ask and the policy documents you upload are processed by third-party AI models to generate answers and match content against the FCA Handbook. This processing happens in real time to produce your answer; none of your firm's data is used to train any AI model, ours or any third party's.
6. Who we share data with
We don't sell your data. We share it only with the following sub-processors, each engaged under a data processing agreement, strictly to provide the service:
- Supabase - database, file storage, and authentication.
- Anthropic - AI processing of Handbook questions and policy analysis (Claude).
- Voyage AI - text embeddings used to power search and Handbook-matching.
- Stripe - payment processing for subscriptions. Stripe receives your billing details directly; we don't store your card details ourselves.
Some of these providers may process data outside the UK, including in the United States. Where that happens, we rely on an approved legal transfer mechanism, such as the UK-US Data Bridge or Standard Contractual Clauses, to ensure your data continues to receive an equivalent standard of protection. We may also disclose data where required by law or to a regulator such as the FCA, if compelled to do so.
7. Data retention
We retain account and firm data for as long as your firm has an active subscription, and for a reasonable period afterwards to meet our own legal and audit obligations. Audit trail records (queries, answers, sign-offs) are retained as part of your firm's compliance evidence for the same period, since their value depends on completeness. You can request deletion of your account data at any time, subject to what we're required to retain by law.
8. Data security
Your data is encrypted in transit and at rest. Access to firm data is restricted by row-level security so that one firm can never see another firm's records. We restrict internal access to production data to what's necessary to operate and support the service. Full security documentation is available on request.
9. Cookies
Our website and application use only strictly necessary cookies required to keep you signed in and to operate the service securely. We don't currently use analytics, advertising, or tracking cookies.
10. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data, subject to our legal retention obligations.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact hello@regsure.uk. You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), if you believe your data hasn't been handled correctly.
11. Children's data
Regsure is a business product intended for use by professionals at FCA-regulated firms. It isn't directed at, and we don't knowingly collect data from, children.
12. Changes to this policy
We may update this policy as the product or our data practices change. We'll update the "Last updated" date above, and for material changes we'll take reasonable steps to notify firm admins directly.
13. Contact us
For any question about this policy or your data, email hello@regsure.uk.