Privacy policy
Last updated 3 August 2026
1. Who we are
ConnexOS is operated by ConnexOS Solutions Limited, a Private Company Limited by Shares registered in the Isle of Man under company number 139160C, and a Chapel Tech Limited company. Our registered office is Ports of Call Offices, Bay View Road, Port St. Mary, IM9 5AE, Isle of Man. Our data protection registration number is R557686.
Our Data Protection Officer is Nathan Bradley, contactable at dpo@connexos.com. To report a security concern, contact dev@connexos.com.
2. Controller and processor
When you browse this site or send us an enquiry, we decide why and how your data is handled. We are the controller.
A membership organisation using ConnexOS to run its community decides why and how its members’ data is handled. They are the controller. We act as their processor, under a written agreement, and only on their instructions. If you are a member of an organisation that uses ConnexOS and you want to exercise your rights over your data, approach that organisation first, and we will support their response.
3. Data we handle as a controller
When you contact us
Our demo request form collects your name, work email address, organisation, optionally your role and an approximate community size, and whatever you tell us about the problem you want to solve. We use it to answer you and to prepare for a conversation. The lawful basis is our legitimate interest in responding to business enquiries.
We keep enquiries for up to 24 months from our last exchange. Ask us to delete yours sooner and we will.
Cookies and tracking on this site
This site sets no tracking cookies, no advertising cookies and no analytics cookies. We run no third-party analytics, no advertising pixels, no session recording and no fingerprinting. Nothing on these pages is loaded from a third-party host. That is why you have not been shown a cookie banner: there is nothing to consent to.
Our hosting provider processes standard server request logs, including IP address, for security and reliability. They are retained briefly and are not used to profile visitors.
4. Data we handle as a processor
Inside the ConnexOS platform we handle, on our customers’ instructions, the categories of personal data a membership organisation needs to run its community. Depending on which parts of the platform a customer uses, this can include:
- Identity and contact details for members and their representatives
- Membership records: tier, status, joining and renewal history, roles held
- Business information about member organisations, including public registry details
- Transaction records: invoices, payments, points balances and redemptions
- Event records: registrations, attendance and accessibility requirements
- Identity and business verification records, where the customer’s scheme requires them
- Communications and activity records within the platform
We do not use this data for our own purposes. We do not sell it, and we do not use it to train machine learning models for other customers.
5. Connected accounts on other platforms
A member can choose to connect an account they administer on another platform, so that their own business profile in ConnexOS can be filled in from it rather than typed out again. Connecting is always the member’s decision, always made through that platform’s own authorisation flow, and can be undone at any time.
The same rules apply to every connection, whichever platform it is:
- We access business profile information only, for the organisation whose account is connected. We do not build profiles about individual people from it.
- We use it for one purpose: to populate and keep current that organisation’s own business profile inside ConnexOS.
- Everything retrieved is stored as a suggestion, attributed to the platform it came from, and is applied only when the profile owner explicitly approves it. Nothing overwrites a record automatically.
- We do not sell it, license it, transfer it to any third party, use it for advertising, or use it to train machine learning models.
- We keep it only while the connection exists. Disconnect and we delete what we retrieved, other than fields already approved into the member’s own profile, which are from that point their own content. See deleting your data.
Where a member connects a Google Business Profile they own or manage, we request the business.manage scope and access the business listing information held on that profile, such as the business name, description, categories, address and service areas, contact details and opening hours.
We use it solely to populate that organisation’s business profile in ConnexOS, subject to the member’s approval of each field as described above. We store only what the member approves, plus a reference to the connected profile so we can keep it current. Nothing else is retained. ConnexOS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and we do not transfer Google user data to third parties, use it for advertising, or use it to train generalised models.
Meta
Where a member connects a Facebook Page they administer, we access the Page’s public business information, such as its about text, category, contact details, opening hours and published posts, together with the linked Instagram business account where one exists. The same single purpose, approval step, and deletion-on-disconnect rules apply.
LinkedIn Page data is handled under a separate and narrower set of commitments, set out in full on our LinkedIn data use page.
Which connections are available today
These connections are being introduced progressively, and each one requires approval from the platform concerned before it can be offered. A connection is only ever available to members once that approval is in place. This section describes how each works when it is offered, so that you can see the commitments before you decide whether to connect anything.
6. Who else is involved
We use a small number of service providers to operate ConnexOS, for example for hosting, transactional email, and the specialist services a customer has chosen to enable. Each is bound by contract and may act only on our instructions.
Our current list of sub-processors is provided to customers on request and forms part of the data processing agreement. We notify customers of changes to it in accordance with that agreement.
7. Where data is held
Personal data within ConnexOS is hosted in the European Union. Where a service provider needs to handle data outside the UK, EU or Isle of Man, we put appropriate safeguards in place, such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses.
8. How long we keep things
As a processor, we retain customer data for the term of the customer’s agreement and delete or return it afterwards in line with that agreement. Some records, such as invoices, are kept longer to satisfy accounting and tax obligations.
As a controller, we keep enquiry correspondence for up to 24 months, and business records for as long as the law requires.
9. Your rights
Depending on where you are, you may have the right to access your personal data, to have it corrected or erased, to restrict or object to how it is handled, and to receive it in a portable form. You can also complain to a supervisory authority: in the Isle of Man that is the Information Commissioner, and in the UK the Information Commissioner’s Office.
Send requests to dpo@connexos.com. If your data sits inside a customer’s ConnexOS instance, we will pass your request to them promptly and support their response.
10. Changes to this policy
We update this policy when what we do changes. The date at the top reflects the current version. Material changes affecting customers are notified under their agreement.