Legal
Privacy Policy
Last updated: April 2026
1. Who we are
Heulex is an AI-powered tenancy agreement risk analysis service. For the purposes of UK data protection law, Heulex is the data controller for personal data processed through this service.
ICO registration number: ZC116171
Contact: privacy@heulex.com
2. What data we collect and why
Your tenancy agreement
When you upload a document, it is transmitted to our processing infrastructure, where text is extracted and passed to an AI model for risk analysis. The raw document is deleted immediately after text extraction is complete. It is never stored, indexed, or used for any purpose other than generating your report.
Your email address
If you complete payment, Stripe collects your email address as part of the checkout process. We use this address solely to send you a link to your full report. We do not add you to any marketing list. We do not share your email with third parties other than those named in this policy.
Your risk report
The structured risk report generated from your agreement is stored in our database for 30 days from the date of payment. After 30 days, it is automatically and permanently deleted. We do not retain any information that identifies which agreement the report was generated from.
Usage data
We use PostHog to collect anonymised analytics about how the service is used (for example, how many users complete an upload, or where users drop off in the flow). PostHog does not receive your email address or any content from your report. You can opt out of analytics tracking via our Cookie Policy.
3. Legal basis for processing
We process your email address and payment data on the basis of contract: delivering the paid report you purchased.
We process anonymised usage data on the basis of legitimate interests: understanding how the service is used so we can improve it.
We process your tenancy agreement on the basis of contract: it is necessary to analyse the document in order to provide the service you requested.
4. Who we share data with
We use the following sub-processors. All infrastructure is located in AWS eu-west-2 (London) unless otherwise stated.
- Amazon Web Services (AWS) — hosting, storage, and email delivery (AWS SES). Data processed in eu-west-2 (London). AWS is a signatory to the UK International Data Transfer Agreement.
- Amazon Bedrock — AI model inference for risk analysis. Document text is processed in eu-west-2 (London) and is not retained by Amazon Bedrock after the API call completes.
- Stripe— payment processing. Stripe is certified to PCI DSS Level 1. Stripe’s privacy policy is available at stripe.com/gb/privacy.
- PostHog— anonymised product analytics. PostHog does not receive any personal data or document content. PostHog’s privacy policy is available at posthog.com/privacy.
We do not sell your data. We do not share your data with advertisers or data brokers.
5. Data retention
- Your tenancy agreement (raw document): deleted immediately after text extraction
- Your risk report: deleted 30 days after payment
- Your email address: retained by Stripe in accordance with their privacy policy; we do not store it separately
- Anonymised analytics: retained by PostHog for up to 12 months
6. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data (where we hold any)
- Object to processing based on legitimate interests
- Lodge a complaint with the ICO at ico.org.uk
Because we do not create user accounts or link reports to identities, the data we hold is limited to your email address (via Stripe) and an anonymised report associated with a randomly generated token. To exercise your rights, contact us at privacy@heulex.com with your report token or the email address used at checkout.
7. Cookies
We use analytics cookies from PostHog only. We do not use advertising or tracking cookies. See our Cookie Policy for full details.
8. Changes to this policy
We may update this policy from time to time. The version on this page applies from the “last updated” date shown above. Material changes will be noted at the top of this page.
9. Contact
For privacy queries or to exercise your rights, contact us at privacy@heulex.com.