Privacy

Privacy Policy

Last updated: April 2026

At Immutis, we take your privacy seriously. This policy explains how we collect, use, and protect your data.

What we collect

Immutis stores the details needed to verify a matter: the receiving bank account details, identity documents, payslips, proof of funds, and source-of-funds documents, along with the results of each check and a recording of the confirmation call. We also collect basic account information like email and firm name.

How we use your data

The details and documents you provide are used solely to run verification checks and produce the signed report for the matter. We never sell your data to third parties.

Data security

All matter data is encrypted at rest and in transit. Files are stored in UK and EU data residency, firm-isolated at the database level, and each check and report is written to a signed record that cannot be altered.

Your rights (GDPR & UK)

As a UK-based company, we comply with the UK GDPR and Data Protection Act 2018. You have the following rights:

  • Access - Request a copy of your personal data
  • Rectification - Correct inaccurate personal data
  • Erasure - Request deletion of your personal data ("right to be forgotten")
  • Portability - Request your data in a structured, machine-readable format
  • Restriction - Request limitation of processing
  • Objection - Object to processing based on legitimate interests
  • Withdraw consent - Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at privacy@immutis.com. We will respond within 30 days.

International data transfers

Your data is primarily stored and processed in the United Kingdom and European Economic Area (EEA). If data is transferred outside the UK/EEA, we ensure adequate protection through:

  • UK adequacy decisions
  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office (ICO)
  • Binding Corporate Rules for intra-group transfers

Third-party processors

We use trusted third-party services to provide the Immutis service:

  • Neon (US/AWS) - Postgres database, firm-isolated schema per customer
  • Cloudflare R2 (EU) - Encrypted document and recording storage
  • Clerk (US/Global) - Authentication
  • Stripe (EU) - Payment processing
  • Render (US) - Backend API hosting
  • Vercel (US/Global) - Frontend and dashboard hosting
  • Resend (EU/Global) - Transactional email sending

All processors are contractually bound to protect your data in accordance with this policy.

Data retention

We retain different types of data for different periods:

  • Matter documents and call recordings - 90 days, then securely deleted
  • Signed verification reports and verify records - 7 years, for dispute and audit purposes
  • Account data - Duration of your subscription plus 2 years for legal/compliance
  • Audit logs - 7 years for compliance purposes
  • Marketing data - Until consent is withdrawn

After retention periods expire, data is securely deleted or anonymised.

Data breaches

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware. We will also notify affected users without undue delay.

Complaints

If you have concerns about how we handle your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

ico.org.uk

We hope to resolve any concerns internally. Please contact us first at privacy@immutis.com.

Cookies & analytics

We use essential cookies for authentication and service functionality. We may use anonymised analytics to understand website usage. We do not use advertising cookies or share data with advertising networks.

Contact

Questions about this policy? Reach us at privacy@immutis.com.