Back to Ropix

Legal

Privacy Policy

Last updated: 10 September 2026. Effective from the same date.

Jadvix LTD runs Ropix. This page sets out what personal data we handle, why we have it, and what you can ask us to do with it. It follows UK law: the UK GDPR and the Data Protection Act 2018.

Throughout, “we” means Jadvix LTD and “you” means whoever is reading, whether you run Ropix for a business or spoke to one of its AI representatives on a call.

1. Who we are

We are the data controller for most of the data described here. For some of it we act only as a processor, working to a customer’s instructions. Section 2 explains the split.

  • Jadvix LTD, registered in England and Wales, company number 16055823.
  • Registered office: College House, 2nd Floor, 17 King Edwards Road, Ruislip HA4 7AE.
  • Privacy contact: jadvix@jadvix.uk.

We’re registered with the Information Commissioner’s Office under registration number ZB930503.

Use that email or the address above for anything in this policy, including to exercise your rights.

2. Our two roles

There are two kinds of personal data on Ropix, and we stand in a different place to each one.

Controller: your account data

This is the data about you as a customer. Your name, the business email you sign in with, your billing details, and the record of what you did in the app. We decide what we collect and why. For this data we answer to you, and to the ICO, directly.

Processor: what your AI representatives handle

When your representatives take or place calls, they deal with call audio, transcripts, summaries, the phone numbers on the line, and any lead or contact records you loaded. That data is yours. You decide why it exists, how it is used, and how long it stays. We touch it only to run the service, and only in the ways you have told us to. Here your business is the controller and we are the processor working for you.

If you called a business and spoke to one of its representatives, that business is your controller, not us. Section 9 explains how to make a request.

3. What we collect

The full list, by category.

CategoryWhat it includes
Account dataYour name, the business email you sign in with, your password (kept only as a hash), and your workspace and user settings.
Billing dataWho to invoice, which plan you are on, and what has been paid. Card numbers go straight to our payment processor. We never see or store them.
Call dataRecordings and transcripts of calls your AI representatives handle, the phone numbers on each call, when it happened and how long it ran, why it ended, and the summary. We hold this as your processor.
Lead and contact recordsThe business and contact details you upload or generate for calling, and where each one sits in your pipeline. Also held as your processor.
Usage and diagnostic dataWhat happens in the app: actions taken, features and credits used, error reports, and basic technical details such as browser type and IP address. We use it to run the service and keep it secure.
Cookies and local storageA short list of items your browser needs. See section 11.

4. Why we process personal data, and our lawful basis

Every use of your data has a legal basis under UK GDPR. Here is which basis covers what.

  • Running the service. Setting up your workspace, signing users in, placing and handling calls, counting usage.
    Lawful basis: performing our contract with your organisation, and acting on your request before that contract starts.
  • Billing. Invoicing you, taking payment, and keeping the records.
    Lawful basis: performing our contract, plus a legal obligation to keep tax records.
  • Security. Spotting and investigating fraud, break-in attempts and misuse, and enforcing our limits and terms.
    Lawful basis: our legitimate interest in protecting the service, our customers, and the people they call.
  • Support. Answering questions, fixing faults, and handling rights requests.
    Lawful basis: performing our contract, and our legitimate interest where the person asking is not a customer.
  • Keeping the service working and making it better. Diagnosing faults, seeing which features get used, and planning changes. We work with aggregated or de-identified data where we can.
    Lawful basis: our legitimate interest in running and improving something our customers depend on.
  • Meeting legal duties. Responding to lawful requests from authorities, and following the law that applies to us.
    Lawful basis: legal obligation.
  • Anything we ask you to opt into. We ask first, and you can change your mind later without it affecting what came before.
    Lawful basis: consent.

For the call and lead data we hold as processor, our customer sets the lawful basis, not us.

Where we rely on legitimate interests, we have weighed that against your rights and think it is fair. Ask us and we will show you our reasoning.

5. Call recording

Calls that an AI representative handles are recorded and transcribed. The service needs this. It uses the recording and the transcript to run the call, write the summary, and let the business that owns the representative look back at what was said.

Telling callers that the call is recorded, and having a lawful reason to record it, is the operating business’s job. Not ours. We do not write the script or the words a representative uses on any given call.

If you are a caller and you do not want to be recorded, say so on the call, or contact the business you were dealing with. You can also email us at jadvix@jadvix.uk, and we will pass that to the business and help them deal with it.

6. Who we share personal data with

We do not sell personal data, and we do not share it for anyone else’s advertising. The only people who get it are the suppliers that keep Ropix running, and each one gets only the part it needs:

  • Cloud hosting and infrastructure. The data centres and platform services that store the data and run the app.
  • Telephony and voice network providers. The networks that carry calls between Ropix and the public phone system.
  • Speech and AI model providers. The services that turn speech into text, work out replies, and write summaries.
  • Payment processing. The provider that takes card payments and runs subscriptions.
  • Email delivery. The service that sends account and billing email.

Every one of them is under a written contract that ties it to our instructions, or to our customer’s instructions passed through us for the call and lead data, and to keeping the data safe.

Want the actual names? Email jadvix@jadvix.uk for the current list of sub-processors.

We also disclose personal data when the law requires it, or when we need it to bring or defend a legal claim.

7. International transfers

Most of the data stays in the UK. Some suppliers, or the infrastructure they run on, sit outside it, mostly in the United States.

When data goes abroad, we rely on one of two things. Either the destination is covered by UK adequacy regulations, or the transfer runs under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, with extra safeguards where they are needed. Ask us if you want the detail for a transfer that affects you.

8. How long we keep personal data

How long we hold something depends on what it is. Account data and call data stay while your account is open, and we delete them when you ask. Tax records are the exception: the law makes us keep those for six years.

  • Account data (your name, the business email, login records). We keep this while your account is open. Close the account, or write to jadvix@jadvix.uk, and we delete it within 30 days.
  • Call recordings, transcripts and summaries. We keep these while your account is open, so you can go back through your own call history. You can ask us to delete specific recordings, or all of them, at any time by emailing jadvix@jadvix.uk. We action that within 30 days.
  • Lead and contact records. Same as call data. You control them, and you can have them deleted whenever you want.
  • Billing and transaction records. We keep these for six years after the end of the financial year they relate to, because UK tax law requires it. We cannot delete these early, even if you ask.
  • Usage and diagnostic logs. We keep these only as long as we need them for security monitoring and fault-finding, and clear them down on a regular cycle.

Ropix does not have a “delete my account” button, or a per-record delete, yet. We are building that. Until it is live, deletion is a manual job we do at the email above.

9. Your rights under UK GDPR

UK GDPR gives you rights over your own data. You can ask us to:

  • give you a copy of what we hold about you;
  • correct anything that is wrong or missing;
  • delete your data, in the situations where that applies;
  • pause using it while a dispute is sorted out;
  • hand you certain data in a portable format, or send it straight to another provider;
  • stop any processing we do on the basis of legitimate interests;
  • treat consent you gave as withdrawn, from the moment you say so.

To use any of these, email jadvix@jadvix.uk. We reply within a month. If the request is complicated, or you have sent several, we can take up to two months more, and we will tell you if we do. There is no fee, unless the request is clearly unfounded or excessive.

For the call and lead data we hold as a processor, the customer is the controller, not us. If you were called by a business, or you are a contact in its records, send your request to that business. If it reaches us instead, we pass it on quickly and help them answer.

10. Security

Some of what we do to keep data safe:

  • traffic is encrypted with HTTPS/TLS, and stored credentials and sensitive settings are encrypted at rest;
  • people and systems only reach the data they actually need;
  • each customer’s data is walled off from every other customer’s;
  • session tokens live in httpOnly cookies, so page scripts cannot read them;
  • we log security events and rate-limit the API to slow down abuse.

No system is perfectly safe. If there is a breach that puts people at real risk, we tell the ICO, and the affected controllers or individuals, within the time limits UK GDPR sets.

11. Cookies and local storage

Ropix keeps this light. There are no advertising cookies and nothing that follows you across other sites. There is no analytics cookie either.

  • Session cookies: ropix_access and ropix_refresh. They appear when you sign in and keep you signed in. They are httpOnly, so page scripts cannot read them, sent only over HTTPS in production, and locked to this site. The service will not work without them.
  • Local storage: a few preferences saved in your browser and never sent to us. Your light or dark theme, whether the side rail is collapsed, and which one-off prompts you have dismissed. Clear them from your browser whenever you like.

There is no cookie banner, because everything here is either strictly necessary or never leaves your browser. Block the session cookies and you will not be able to sign in.

12. Complaints

If something about how we handle your data is wrong, tell us first at jadvix@jadvix.uk so we can put it right.

You can also complain to the Information Commissioner’s Office, the UK’s data protection regulator:

Complaining to us does not take away your right to go to the ICO.

13. Changes to this policy

We will change this page when the way we handle data changes. The date at the top moves when we do, and for anything significant we will tell affected customers directly. This version applies from 10 September 2026.

← Back to Ropix

Ropix is a product of Jadvix LTD.