Security & data
Where your data goes, in plain English
Automation means touching your customer data. You should know exactly what that involves before you sign anything, so here it is, without the marketing language.
Our principles
Least access, by design
An automation only gets the permissions it actually needs. We do not take blanket admin access to your systems because it is convenient for us.
Your data does not train AI models
We use business API tiers from our AI providers, which do not train on your content. That is a contractual commitment, not a checkbox.
UK and EU only
Data we hold for you stays in UK and EU regions. Our own systems run in London. Nothing moves outside that without your agreement.
Minimise what the AI sees
Where a task can be done without showing an AI model your customer's personal data, we design it that way. The safest data is the data we never send.
A human where it matters
Anything with real consequences (a price, a commitment, a clinical or legal matter) goes to a person. Agents escalate rather than guess.
You own it, so you can leave
The automations, integrations and credentials are yours. If you want to take them to someone else, you can, and we will help you hand over.
The systems we use
These are the providers behind this website and the free audit tool. When we build for you, the stack is chosen around your requirements, and for regulated sectors that can include self-hosting so data never leaves infrastructure you control.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Hosts this website | EU / global edge |
| Supabase | Stores enquiries and site analytics | London, UK |
| Anthropic (Claude) | Analyses the website you submit to the audit | API, no training on our data |
| Resend | Sends the report and enquiry emails | EU / US |
| Meta Pixel | Ad measurement, only after you accept cookies | Blocked until consent |
UK GDPR
We handle personal data in line with UK GDPR. That means we only collect what we need, we tell you what we are doing with it, we do not keep it longer than we should, and you can ask us to show you what we hold or delete it.
Non-essential cookies and tracking on this site are switched off until you actively accept them, and you can withdraw that at any time from the cookie settings. Our privacy policy sets out exactly what we collect and why.
If you have a question about how we handle your data, email info@fixology.co.uk and a human will answer.
Questions
Does our data train AI models?
No. We use business API tiers, which do not use your content to train the underlying models. This is a contractual commitment from the providers, not a setting we tick. If you need this in writing for your own compliance file, ask and we will provide it.
Where is our data stored?
Data we hold for you is stored in UK and EU regions. Our own analytics and lead database runs in London. We will not move your data outside the UK/EU without telling you and agreeing it first.
Who at Fixology can see our data?
Only the people working on your build, and only for as long as they need to. We work on the principle of least access: an automation gets the narrowest permission that lets it do its job, not blanket admin rights to your systems.
Can we get a Data Processing Agreement?
Yes. Where we process personal data on your behalf we will sign a DPA. Just ask.
What happens if we stop working together?
You keep the automations, because you own them. We hand over the accounts and credentials, remove our access, and delete the data we hold for you on request.
What does the free website audit actually access?
Only the public pages of the website address you type in, the same as any search engine would. It does not log in, it does not access anything private, and it does not touch your internal systems.
Still have a security question?
Ask it before you commit to anything. If we cannot answer it properly, you should not work with us.