Privacy Policy

Last updated: January 2026

REGMATIX, a product of KREIOS SARL ("we", "us", or "our"), is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

1. Information We Collect

We collect information that you voluntarily provide to us when you contact us through our website.

Contact Form Data includes:
• First name and last name
• Business email address
• Organisation name
• Role or position (optional)
• Type of inquiry (e.g., demo request, pricing, technical questions)
• Message content

Automatically Collected Information includes:
• IP address and browser type
• Pages visited and time spent on our website
• Referring website addresses
• Device and operating system information

We do not use cookies for tracking or advertising purposes. Any cookies used are strictly necessary for website functionality.

2. How We Use Your Information

We use the information we collect to:
• Respond to your inquiries and demo requests
• Provide information about our regulatory oversight solutions
• Improve our website and user experience
• Comply with legal obligations

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not send marketing communications unless you explicitly request them.

3. Legal Basis for Processing (GDPR)

For individuals in the European Economic Area (EEA), we process personal data based on:
Consent: When you submit the contact form and agree to our privacy policy
Contractual Necessity: To respond to your inquiries and provide requested information
Legitimate Interests: To improve our services and maintain website security
Legal Obligation: To comply with applicable laws and regulations

You may withdraw consent at any time by contacting us.

4. Data Sharing and Disclosure

We may share your information with:
Service Providers: Trusted partners who assist with website hosting and email delivery (bound by confidentiality agreements)
Legal Requirements: When required by law, court order, or governmental authority
Business Transfers: In connection with any merger, acquisition, or sale of company assets

We ensure that any third parties with access to your data maintain appropriate security measures and comply with applicable data protection laws.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:
• Encryption of data in transit (TLS/SSL)
• Secure server infrastructure
• Access controls and authentication

While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but are committed to maintaining industry-standard protections.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
• Contact form submissions: Duration of business relationship plus 3 years
• Legal compliance: As required by applicable laws

After the retention period, data is securely deleted.

7. Your Rights

Under GDPR and applicable data protection laws, you have the right to:
Access: Request a copy of your personal data
Rectification: Correct inaccurate or incomplete data
Erasure: Request deletion of your personal data ("right to be forgotten")
Restriction: Limit how we process your data
Data Portability: Receive your data in a structured, machine-readable format
Objection: Object to processing based on legitimate interests
Withdraw Consent: Revoke previously given consent

To exercise these rights, contact us at privacy@regmatix.com.

8. Cookies

Our website uses only essential cookies required for basic website functionality. We do not use:
• Analytics or tracking cookies
• Advertising cookies
• Third-party tracking cookies

You can control cookies through your browser settings. Disabling cookies may affect website functionality.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence. When transferring data outside the EEA, we ensure appropriate safeguards are in place, such as:
• Standard Contractual Clauses approved by the European Commission
• Adequacy decisions for recipient countries

10. Children's Privacy

Our services are directed to businesses and professionals, not individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy regularly.

12. Contact Us

For questions about this Privacy Policy or to exercise your data protection rights, please contact:

KREIOS SARL
23 Rue du Cimetière
5214 Sandweiler
Luxembourg

Commercial Register: B118494

Email: privacy@regmatix.com

You also have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or where the alleged infringement occurred.