← Back to Pennix

Legal

Privacy Policy

Last updated: 11 July 2026 · Version 1.0

Vera, Pennix intake agentMarco, Pennix intake agentLilly, Pennix intake agentAtlas, Pennix intake agent The Pennix Team
Vera · Marco · Lilly · Atlas

This Privacy Policy explains how Pennix collects, uses, shares, and protects personal data through the Pennix website and our monthly and annual processing-capacity plans (Solo and Firm), the lawful bases we rely on, how long we keep data, who we share it with, and the rights you have under the EU/UK General Data Protection Regulation (GDPR), US state privacy laws, Canada’s PIPEDA, and other applicable laws.

Plain-language summary (not a substitute for the policy below). Pennix is a business service for tax and accounting firms. For your website enquiries and applications we act as a controller; for the client files you put through Pennix we act as a processor on your firm’s instructions. We do not sell your personal data. You can access, correct, or delete your data, and control cookies and marketing, at any time by contacting info@getpennix.ai.

01Who we are & scope

The controller of personal data collected through the Pennix website and application form is Pennix LLC (“Pennix”, “we”, “us”, “our”), a Wyoming limited liability company, operating from 308 N Fairfield Rd, Devon, PA 19333, USA, and part of the Peregrine X group. For any privacy question, to exercise your rights, or to reach the person responsible for data protection at Pennix, contact info@getpennix.ai.

This policy covers the website and the monthly and annual processing-capacity plans (Solo and Firm). It should be read together with our Terms of Service, Cookie Policy, and Security & Data-Handling Brief. If we are ever required to appoint an EU or UK representative or a Data Protection Officer, their contact details will be published here.

02Our two roles

As a controller — for information you submit through the website (for example the application form) and for operating, securing, and improving the site, we determine the purposes and means of processing.

As a processor — during a paid plan, we process the client-file data you provide (client contact details in the list you supply and documents your clients upload) on your firm’s behalf and on your documented instructions. Your firm is the controller of that data, and a Data Processing Agreement (DPA) governs it. This policy focuses on our controller processing; the DPA and the Security & Data-Handling Brief govern the processor processing.

03What personal data we collect

We do not intentionally collect special-category data through the website and ask that you do not submit it.

04How we use it & lawful bases

PurposeLawful basis (GDPR Art. 6)
Respond to your application, assess fit, and communicate with youConsent (6(1)(a)) and pre-contract steps taken at your request (6(1)(b))
Provide, administer, and support the Solo and Firm plans, and process paymentsPerformance of a contract (6(1)(b))
Secure the service, prevent misuse and fraud, keep business records, and improve the serviceLegitimate interests (6(1)(f)); legal obligation (6(1)(c))
Send service and transactional messages about your accountPerformance of a contract (6(1)(b)); legitimate interests (6(1)(f))
Optional analytics or marketing (only if you enable it)Consent (6(1)(a)) — you may withdraw at any time

Where we rely on legitimate interests, we balance them against your rights and freedoms; contact us if you would like our assessment.

05Cookies & similar technologies

By default the website uses only strictly necessary storage. Analytics or marketing technologies load only with your consent, where consent is required. You can accept, reject, or change your choices at any time via the consent banner or “Manage cookies” in the footer. Full details are in the Cookie Policy.

06Marketing & communications

We send service and transactional messages about your account and packages. Marketing messages are sent only where permitted — on the basis required by applicable law, for example prior consent under Canada’s CASL and, where relevant, the EU/UK; or the opt-out and sender-identification requirements of the US CAN-SPAM Act. You can unsubscribe at any time using the link in the message or by contacting info@getpennix.ai.

07Sharing & subprocessors

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only with service providers who help us run Pennix under written contract — for example hosting and cloud infrastructure, email delivery, payment processing, and AI document processing. The current list, with roles and locations, is described in the Security & Data-Handling Brief and is available on request. We may also disclose data where required by law, to protect rights and safety, or in connection with a merger, financing, or sale of assets (with continued protection for your data).

08International data transfers

Pennix is based in the United States. Where personal data is transferred across borders — including from the EEA, the UK, or other regions to the US — we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement (or Addendum), or an adequacy decision, together with additional measures where needed. Details are available on request.

09How long we keep data

We keep personal data only as long as necessary for the purposes above. Application and marketing data is retained for up to 24 months, or until you ask us to delete it, whichever is sooner. Billing and tax records are kept for as long as the law requires. Installation (client-file) data is returned or deleted in line with the DPA, typically within 30 days of the plan ending or on your written instruction.

10Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and least-privilege access. See the Security & Data-Handling Brief for specifics and our conservative stance on certifications. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11Your rights (GDPR / UK)

Subject to conditions in the GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent at any time (without affecting processing already carried out). To exercise a right, contact info@getpennix.ai; we will respond within the period the law requires (generally one month under the GDPR). You also have the right to complain to your supervisory authority — in the EU, your local Data Protection Authority; in the UK, the Information Commissioner’s Office (ICO).

12US state privacy rights

Depending on your US state (for example California, Virginia, Colorado, Connecticut, Utah, Texas and others), you may have the right to know about and access, delete, and correct your personal information, to obtain a portable copy, and to opt out of any “sale” or “sharing” and certain targeted advertising or profiling. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We do not discriminate against you for exercising these rights. To exercise them, contact info@getpennix.ai; we will verify your request as the law requires, and you may use an authorised agent where permitted. California residents may also request information about disclosures under the “Shine the Light” law.

13Canada (PIPEDA)

For individuals in Canada, we handle personal information consistent with PIPEDA and applicable provincial laws, obtain consent where required, and honour access and correction requests. Commercial electronic messages follow CASL. You may complain to the Office of the Privacy Commissioner of Canada.

14GCC, MENA & other regions

Where local data-protection laws apply to you — for example the UAE PDPL, the KSA PDPL, and free-zone regimes such as those of the DIFC and ADGM — we process personal data consistent with those laws, and you may have rights of access, correction, and deletion under them. You remain responsible for your own compliance and licensing obligations. Where local law requires data residency or local dispute resolution, that mandatory law applies.

15Automated processing & AI

The Service uses artificial intelligence to process intake data and generate drafts. We do not make solely automated decisions that produce legal or similarly significant effects about individuals — your firm reviews and approves client communications. We may use aggregated, de-identified data to maintain and improve the Service, and we do not use your client-file data to train third-party foundation models except as permitted by your Order and the DPA. See the Terms for more.

16Children’s data

Pennix is a business service and is not directed to children. We do not knowingly collect personal data from anyone under 18 (or under the applicable age of digital consent in the EEA/UK). If you believe a child has provided us data, contact us and we will delete it.

17Third-party links & services

The website may link to or integrate third-party services (for example a payment processor or scheduling tool) that are governed by their own privacy policies. We are not responsible for the privacy practices of third parties; please review their policies before providing personal data.

18Exercising rights & complaints

Contact info@getpennix.ai for any request or question about your data. We may need to verify your identity before acting on a request. If you are not satisfied with our response, you may contact your supervisory authority or privacy regulator (for example your EU Data Protection Authority, the UK ICO, or the Office of the Privacy Commissioner of Canada).

19Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the “last updated” date and, where required by law or reasonable in the circumstances, give additional notice. Your continued use of the Service after changes take effect means you accept the updated policy.

20Contact us

Pennix LLC
308 N Fairfield Rd, Devon, PA 19333, USA
Email: info@getpennix.ai — for all privacy and data-protection matters.

← Return to the Pennix site