Parallax
Memo Log in
← Legal

Private beta

Privacy Policy

Last updated 3 August 2026

Contents
01Introduction and Scope02Our Roles03How the Platform Works, and Model Training04Personal Data We Collect05How and Why We Use Personal Data06Sharing Personal Data07International Transfers08Retention09Your Rights10Cookies and Similar Technologies11Security12Children13External Services14Changes to this Privacy Policy15Contact and Complaints

This Privacy Policy explains how Parallax ("we", "us" or "our") collects, uses, discloses and protects personal data in connection with the Platform, the Website and related communications, where we act as a controller of that data. It forms part of, and is incorporated into, our Terms of Use.

Capitalised terms used but not defined in this Privacy Policy have the meanings given in the Terms of Use.

  1. Introduction and Scope

    1. Who this Privacy Policy is for. The Services are made available for business and professional use only. This Privacy Policy nonetheless applies to the individuals whose personal data we process as controller in that context, including Account holders, Authorised Users, prospective customers and other business contacts. It is also relevant to individuals whose personal data appears within Customer Data — see Clauses 2.2 and 9.4.

    2. Related documents. This Privacy Policy should be read together with our Terms of Use, available at https://useparallax.ai/legal/terms-of-use/, and our Data Processing Addendum, available at https://useparallax.ai/legal/data-processing-addendum/, which governs our processing of personal data contained in Customer Data.

  2. Our Roles

    1. When we act as controller. We act as controller of the personal data we collect about you in connection with your Account, registration, billing, support, marketing and your use of the Platform and the Website — for example your name, business email address, job title, organisation, log and device data, and your communications with us. This Privacy Policy governs that processing.

    2. When we act as processor. Customer Data uploaded to the Platform for the purpose of conducting a due diligence exercise may contain personal data about third parties, including directors, officers, employees, shareholders and counterparties of a company under review. In respect of that personal data we act as a processor (or, where you are yourself acting on behalf of another person, as a sub-processor), processing it only on your instructions. That processing is governed by the DPA and the Terms of Use, not by this Privacy Policy. We do not determine the purposes for which Customer Data is processed.

    3. Notice to individuals named in Customer Data. Where you upload Customer Data containing personal data about individuals, you are responsible for providing any notice, and for establishing any legal basis, required under applicable Data Protection Laws in respect of those individuals. We are not in a position to give notice to individuals with whom we have no relationship and whose contact details we may not hold.

    4. Requests about Customer Data. If you are an individual whose personal data appears in Customer Data and you wish to exercise a right in respect of it, please see Clause 9.4.

  3. How the Platform Works, and Model Training

    1. We do not own or operate artificial intelligence models. The Platform is an application layer. We do not own, operate, host or train foundation models. In order to generate Outputs, the Platform transmits Customer Data and your instructions to third-party artificial intelligence model providers through their application programming interfaces, and returns the result to you through the Platform.

    2. We do not train on or sell Customer Data. Accordingly:

      1. we do not use Customer Data or Outputs to train, fine-tune, develop or otherwise improve any artificial intelligence or machine learning model of our own, and we have no model of our own on which to do so; and

      2. we do not sell, license or otherwise make Customer Data or Outputs available to any third party for the purpose of model development,

provided that during the Beta Period, Outputs are generated using third-party model providers and routing configurations which we may vary from time to time, and we do not represent or warrant that every such provider excludes Customer Data from its own model training or development, or applies zero data retention; each provider's processing is governed by the terms on which we engage it. A commitment (if any) concerning model training, provider retention or zero data retention after the Beta Period applies only to the extent expressly agreed in a customer agreement or Order Form entered into after that period.

    1. Retention by model providers. Model providers may retain Customer Data transmitted to them in accordance with their own retention practices, which vary between providers and which, during the Beta Period, we do not warrant to be limited to any particular period, for the purposes of, among others, abuse monitoring, security and compliance with their own legal obligations, in accordance with their terms.

    2. Improving the Services. We may use Service Metadata (as defined at Clause 4.2), Feedback, and de-identified or aggregated data to analyse, maintain, secure, develop and improve the Services, including our prompts, templates, question banks and retrieval logic. That activity does not involve training any model, and does not involve the use of Customer Data or Outputs for model development. We will not seek to re-identify data we have de-identified.

  1. Personal Data We Collect

    1. Data you provide to us. This includes: your name, business email address, job title, organisation name, Account Credentials (stored in hashed form) and other profile details you choose to provide; billing information; the content of support requests and other correspondence with us; Feedback; and your marketing preferences.

    2. Data we collect automatically. This includes: log data such as IP address, timestamps, and the pages and features you access; device and browser data; approximate location derived from your IP address; cookies and similar technologies as described at Clause 10; and metadata relating to your use of the Services, including usage data, diagnostic information and error logs ("Service Metadata"). Service Metadata is distinct from the content of any prompt, instruction or document you submit, which constitutes Customer Data and is addressed at Clause 2.2.

    3. Data we receive from others. Where an Account is held by an organisation, that organisation may provide your name, email address and role in order to allocate you a seat as an Authorised User. We may also receive data from our payment processor. We reserve the right to conduct sanctions and compliance screening using third-party screening providers where required or appropriate; as at the date of this Privacy Policy we do not engage any such provider.

    4. Visibility within an organisation’s Account. Where an Account is held by an organisation, that organisation controls which individuals are Authorised Users under the Account and their access to it. Customer Data and Outputs created under that Account may be accessible to the organisation and to other Authorised Users in accordance with the Account’s configuration. This follows from the Account structure described in the Terms of Use and is not something we are able to restrict on an individual Authorised User’s behalf.

    5. Sensitive data. We do not seek to collect special-category, sensitive or criminal-offence data about you. Clause 7.5.3 of the Terms of Use prohibits the submission of such data through the Services except as expressly agreed with us in writing in advance.

  2. How and Why We Use Personal Data

    1. Purposes and legal bases. The table below summarises the purposes for which we process personal data as controller, and the legal basis on which we rely where Data Protection Laws require one. Where you are located in a jurisdiction that does not use a legal basis framework, the purposes remain the same.

Purpose

Data used

Legal basis

Providing and operating your Account and the Services

Account, profile, log data

Performance of a contract

Authentication, security, fraud and abuse prevention, enforcing the Terms of Use

Account, log, device data

Legitimate interests; legal obligation

Billing and payment

Billing data

Performance of a contract; legal obligation

Service communications, including notice of changes

Account data

Performance of a contract; legitimate interests

Support

Account and correspondence data

Performance of a contract; legitimate interests

Analysing, maintaining, developing and improving the Services (Clause 3.4)

Service Metadata; Feedback; de-identified data

Legitimate interests

Marketing communications (Clause 5.5)

Account and marketing preference data

Legitimate interests or consent, as applicable

Compliance, lawful requests and legal claims

Account data; screening results if used

Legal obligation; legitimate interests

Corporate transactions involving us

Account and billing data

Legitimate interests

    1. Improvement of the Services. We rely on our legitimate interests in analysing, maintaining, securing, developing and improving the Services to process Account data, log and device data, Service Metadata, Feedback and de-identified or aggregated data for those purposes, as described at Clause 3.4. We have concluded that this processing does not override your interests or fundamental rights, having regard to the limited and largely technical nature of the data involved and the safeguards described in this Privacy Policy. You may object to processing carried out on the basis of legitimate interests — see Clause 9.

    2. Assessments and inferences about individuals named in Customer Data. You should be aware that the Services may generate Outputs that describe, assess or draw inferences about individuals named in Customer Data — for example by summarising a director’s appointments, flagging that a shareholder may be a politically exposed person, or identifying adverse media or litigation associated with an officer of a company under review. In respect of that processing:

      1. it is carried out on the instructions of the customer who uploaded the Customer Data, and that customer is the controller of it and is responsible for its lawfulness, including under any applicable rules on profiling, automated decision-making, credit, employment, tenancy, insurance or anti-discrimination;

      2. Clause 6.1 of the Terms of Use prohibits the use of the Services to profile, screen, score, investigate or make decisions about individuals in a manner that breaches those laws; and

      3. any such Output is indicative only, is generated by a probabilistic system, may be inaccurate or incomplete, and is subject to the verification obligation at Clause 9.5 of the Terms of Use. It must not be treated as a finding about any individual.

    3. No automated decision-making about you. We do not use your personal data to make solely automated decisions producing legal or similarly significant effects concerning you as a user of the Services. Clause 5.3 addresses processing concerning individuals named in Customer Data.

    4. Marketing. We will send you transactional and service-related communications regardless of your marketing preferences, as these are necessary to provide the Services. We may also send you marketing communications about our products, features and offers, either on the basis of our legitimate interests in marketing similar products and services to an existing customer where applicable law permits, or on the basis of your consent where consent is required. Every marketing communication contains a means of opting out, and you may update your preferences at any time by contacting [email protected].

  1. Sharing Personal Data

    1. Service providers and model providers. We engage service providers to help us operate the Services, including providers of cloud hosting and infrastructure, artificial intelligence model providers, analytics, email delivery, support tooling and payment processing. The identity of the model providers we engage, and the locations in which they process data, may vary over time and according to which models are used. During the Beta Period we may change model providers and routing configurations at any time and without prior notice.

    2. Within your organisation. Where an Account is held by an organisation, personal data and any Customer Data and Outputs may be visible to that organisation and to other Authorised Users, as described at Clause 4.4.

    3. Affiliates. We may share personal data with our Affiliates for the purposes described in this Privacy Policy.

    4. Professional advisers and insurers. We may share personal data with our professional advisers, auditors and insurers where necessary for the purposes described in this Privacy Policy.

    5. Legal and regulatory disclosures. We may disclose personal data where required by law, regulation, court order or a competent authority, or where we consider disclosure necessary to protect our rights or the rights, safety or property of any person, consistent with Clause 8.4 of the Terms of Use.

    6. Corporate transactions. If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be disclosed to actual or prospective counterparties under appropriate confidentiality protections.

    7. No sale of personal data. We do not sell personal data, and we do not share personal data for cross-context behavioural advertising or targeted third-party advertising, as those terms are used under United States state privacy laws.

  2. International Transfers

    1. Where personal data is processed. Personal data may be hosted, stored and processed in a jurisdiction other than where we are incorporated and in the jurisdictions in which our service providers and sub-processors operate. Because the Platform relies on third-party model providers, Customer Data may be transmitted to and processed in the jurisdictions in which those providers operate, which may vary according to which models are used and may change over time.

    2. Safeguards. Where a transfer of personal data is subject to restrictions under Data Protection Laws, we will ensure that an appropriate transfer mechanism is in place before the transfer occurs, applying in order: (a) reliance on a finding of adequacy or equivalent recognition, where available; (b) for transfers subject to the GDPR, the European Commission’s standard contractual clauses; (c) for transfers subject to the UK GDPR, the UK International Data Transfer Addendum or Agreement; and (d) for transfers subject to any other Data Protection Laws, any other mechanism recognised by those laws, in each case together with any supplementary measures required in the circumstances.

    3. Copies of safeguards. You may request further information about, or a copy of, the safeguards applicable to a particular transfer by contacting [email protected].

    4. Relationship with the DPA. Where we process personal data contained in Customer Data as a processor, the transfer mechanisms applicable to that processing are those set out in the DPA, which prevails over this Clause 7 in respect of that data.

  3. Retention

    1. General approach. We retain personal data for as long as necessary for the purposes described in this Privacy Policy.

    2. Inactive Accounts. Where an Account has been inactive for a continuous period of twelve (12) months, we may delete, deactivate or suspend the Account and delete or remove Customer Data associated with it, in accordance with Clause 3.4 of the Terms of Use. We will use reasonable efforts to give prior notice to the email address associated with the Account before doing so.

    3. Customer Data and Outputs. Customer Data and Outputs are not retained under this Clause 8. During the Beta Period, on termination or expiry of the Terms of Use and on request at any time, we will remove Customer Data and Outputs from active views within the Platform, after which they are not used in generating further Outputs, and will action requests to export or delete them manually, on a reasonable-efforts basis and subject to applicable technical and legal constraints, as provided in Clause 3.6 of the Terms of Use and in the DPA and subject to the exceptions set out there. We do not during the Beta Period commit to a fixed export window, to the export of Customer Data or Outputs in any particular format or in complete form, to a fixed deletion period, to hard or irreversible deletion, to the deletion of copies contained in routine backups or in application, operational or security logs, or to self-service export or deletion functionality. De-identified and aggregated data derived from your use of the Services, which does not identify you, any Authorised User or any individual named in Customer Data, may be retained after deletion.

  4. Your Rights

    1. Rights available to you. Subject to Data Protection Laws, you may have the right to access the personal data we hold about you; to have inaccurate or incomplete data corrected; to have your personal data deleted in certain circumstances; to restrict or object to our processing, including processing based on legitimate interests and processing for marketing purposes; to receive a copy of your personal data in a portable format; to withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing; and to complain to your supervisory or data protection authority.

    2. Exercising your rights. You may exercise these rights by contacting us at [email protected]. We may need to verify your identity before responding, and we will respond within the period required by applicable law. We do not charge a fee unless applicable law permits it, for example where a request is manifestly unfounded or excessive. Where applicable law permits, you may authorise an agent to submit a request on your behalf, and we may require verification of that agent’s authority.

    3. No discrimination. We will not discriminate against you for exercising any of the rights described in this Clause 9.

    4. If your personal data appears in Customer Data. If you believe your personal data has been uploaded to the Platform by one of our customers as part of a due diligence exercise (for example because you are or were a director, officer, employee, shareholder or counterparty of a company under review) we act as a processor in respect of that data and our customer, not us, is the controller. We will refer your request to the relevant customer and assist them in accordance with the DPA. In order to protect the confidentiality of our customers’ due diligence activities, we will not confirm to you whether any particular customer holds data about you, or whether any such data exists on the Platform.

    5. Additional rights under local law. Some jurisdictions confer additional or differently-framed rights. Without limiting Clause 9.1: if you are in the European Economic Area or the United Kingdom you may lodge a complaint with your supervisory authority, which in the United Kingdom is the Information Commissioner’s Office; if you are a resident of California or another United States state with a comprehensive privacy law, you have the rights to know, delete, correct and opt out described in Clause 9.1, we do not sell or share your personal information as described at Clause 6.7, and we honour Global Privacy Control where technically feasible; and if you are in Hong Kong, you may request access to and correction of your personal data under the Personal Data (Privacy) Ordinance by contacting [email protected]. Where the law of your jurisdiction provides rights beyond those set out in this Privacy Policy, we will honour those rights on request.

  5. Cookies and Similar Technologies

    1. What we use. We use cookies and similar technologies, including local storage and pixels, falling into three categories: strictly necessary cookies, required for the Platform to function, including for authentication and session management, which cannot be disabled; functional cookies, which remember your preferences and settings; and analytics cookies, which help us understand how the Services are used. We do not use cookies for third-party advertising purposes.

    2. Consent and controls. Where applicable law requires it, including for users in the European Economic Area and the United Kingdom, we will obtain your consent before setting non-essential cookies. You may also control cookies through your browser settings, although blocking strictly necessary cookies may affect the functioning of the Services.

  6. Security

    1. Our measures. We implement and maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Those measures are described at Clause 8.5 of the Terms of Use and in Annex 2 to the DPA, and include encryption of data in transit and at rest, role-based access controls applying least-privilege principles, basic application and operational logging, logical segregation of Customer Data between Accounts, and confidentiality obligations for personnel with access.

    2. Limits. No method of transmission or storage is completely secure and we cannot guarantee absolute security. Where we become aware of a personal data breach affecting your personal data we will notify you and, where required, the relevant authority, in accordance with Data Protection Laws and, in respect of Customer Data, the DPA.

  7. Children

    1. Age. The Services are intended for business and professional use by individuals aged 18 or over, as provided in Clause 2.3 of the Terms of Use. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete it.

  8. External Services

    1. Third-party privacy practices. The Services may link to or integrate with External Services, as described at Clause 10.3 of the Terms of Use. Those third parties have their own privacy practices, which are not covered by this Privacy Policy. We encourage you to review the privacy policy of any External Service before connecting it to the Platform or otherwise using it.

  9. Changes to this Privacy Policy

    1. Amendments. We may update this Privacy Policy from time to time. We will publish the updated version and update the date at the top of it. Where a change is material and adverse to you, we will give you at least thirty (30) days’ prior notice by email to the address associated with your Account or by in-Platform notification, consistent with the amendment mechanics at Clause 13.1 of the Terms of Use.

  10. Contact and Complaints

    1. Contacting us. If you have any question, concern or complaint about this Privacy Policy or our handling of your personal data, please contact us at [email protected].

Parallax

See how Parallax helps investment teams pressure-test the case.

Company

Home Memo

Legal

Terms of Use Privacy Policy Data Processing Addendum
© 2026 Parallax AI. All rights reserved.

Request Demo

Tell us where live diligence gets hardest to track. We will follow up if there is a strong fit.

We'll be in touch.

Thank you for requesting a demo of Parallax.