regulation10.com

Privacy policy

Effective 2 July 2026

This privacy policy explains how Exec X AI Ltd (DIFC commercial licence 10474), of Dubai International Financial Centre, Dubai, United Arab Emirates (“we”, “us”, the “controller”), collects, uses, discloses and protects personal data through regulation10.com and its platform (the “service”). It is issued in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679 (the “GDPR”).

Where the service supports duties that arise under the EU AI Act, Regulation (EU) 2024/1689, those duties sit with you as the operator of the AI system. This policy covers the personal data we process about you as a user of regulation10.com.

1. Privacy contact

For any privacy matter, or to exercise your rights, contact our data protection contact:

Khaled Shivji, Data Protection Officer. Email Khaled@execxai.com, telephone +971 55 853 2913, or write to Exec X AI Ltd, Dubai International Financial Centre, Dubai, United Arab Emirates. You can also email privacy@regulation10.com.

2. Personal data we process

  • Account and identity data: name, work email, role, organisation, and authentication data (one-time codes, authenticator enrolment, recovery codes).
  • Contact and enquiry data: information you submit through sign-up, support and complaint forms.
  • Usage and technical data: IP address, device and browser information, pages visited, and access logs used for security and to operate the service.
  • Compliance and assessment data: information you enter into assessments and compliance modules, and the documents you generate. You are responsible for the lawful basis of any third-party personal data you input.
  • Billing data: subscription tier, and payment metadata processed by our payment provider. We do not store full card numbers.

3. Purposes and legal bases (Article 6 of the GDPR)

PurposeLegal basis
Provide, authenticate and secure the servicePerformance of a contract; our legitimate interests in security
Respond to enquiries and provide supportOur legitimate interests; steps prior to a contract
Billing and subscription managementPerformance of a contract; compliance with legal obligations
Analytics to improve the serviceConsent (see the cookie policy)
Comply with law and respond to lawful requestsCompliance with a legal obligation

4. Recipients and processors

We share personal data only with service providers who process it on our instructions under written contracts, including hosting and cloud infrastructure, payment processing, invoicing and transactional email. The current list is published at sub-processors. We do not sell personal data.

5. Residency and international transfers (Chapter V of the GDPR, Articles 44 to 49)

Tenant data is resident in the Azure Sweden Central region, inside the EU data boundary. AI inference for the platform runs in the same region.

Where personal data is transferred to a jurisdiction that is not the subject of an adequacy decision, we rely on the European Commission standard contractual clauses under Article 46 of the GDPR, supported by a transfer impact assessment. The mechanism relied on for each provider is listed on the sub-processors page.

6. Retention

We retain personal data only for as long as necessary for the purposes above, to meet legal, audit and evidentiary obligations, and to resolve disputes. Compliance artefacts and audit records may be retained for the period required for regulatory evidence. On cancellation, account data is retained read-only before deletion as described in your service terms.

7. Security (Article 32 of the GDPR)

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, multi-factor authentication, tamper-evident (WORM) audit logging, and Sweden Central (EU data boundary) data residency for tenant data.

8. Automated processing (Article 22 of the GDPR)

The service produces AI-assisted compliance outputs, for example draft assessments and notices. These are decision-support outputs that remain subject to human review by your organisation. We do not use them to make decisions producing legal effects about you without human involvement.

9. Your rights (Articles 15 to 22 of the GDPR)

Subject to the GDPR, you have the right to:

  • Access, a copy of your personal data and information about how it is processed (Article 15).
  • Rectification, correct inaccurate or incomplete data (Article 16).
  • Erasure, deletion in the circumstances the GDPR allows (Article 17).
  • Restriction, limit processing while a matter is resolved (Article 18).
  • Portability, receive data you provided in a machine-readable form (Article 20).
  • Objection, to processing based on legitimate interests, and to direct marketing (Article 21).
  • Withdraw consent, at any time, without affecting prior lawful processing (Article 7(3)).
  • Not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22).

To exercise any right, use the data request channel or contact us at privacy@regulation10.com. We respond within the timeframes set by the GDPR. You also have the right to lodge a complaint with the supervisory authority of the EU or EEA member state where you live, work, or where you believe the infringement took place (Article 77 of the GDPR), see the EDPB list of national supervisory authorities.

10. Children

The service is intended for business users and is not directed to children. We do not knowingly collect personal data from children.

11. Changes

We may update this privacy policy from time to time. Material changes will be reflected by the effective date shown above.

Privacy policy | regulation10.com