Privacy Policy

Last updated: 8 July 2026

This Privacy Policy explains how Polis Consulting Limited, trading as Loxias AI (“Loxias AI”, “Loxias”, “Polis”, “we”, “our” or “us”), collects, uses, stores, shares and protects personal data when you visit https://loxias.ai, purchase or use our services, communicate with us, or otherwise interact with us.

Loxias AI provides B2B social, digital and market intelligence services, including reports, automated intelligence solutions, implementation, training, support, and access to selected third-party software, data and intelligence platforms.

This Privacy Policy applies to our website, customer account areas, sales and support interactions, marketing activities, and our own business operations. Where we process personal data strictly on behalf of a business customer as part of a specific customer project, we may act as a processor and the applicable customer agreement, data processing agreement or platform terms will also apply.

Our services are intended for business customers only. We do not intentionally target consumers or children.


1. Who we are

The controller responsible for this website and for the personal data described in this Privacy Policy is:

Polis Consulting Limited, trading under the Loxias brand
Unit 10, Argus House, Greenmount Office Park,
Harold’s Cross Road,
Dublin 6W, Ireland

Company number: 737553
VAT number: IE4153652OH
Email: [email protected]

Polis Consulting Limited operates the Loxias brand. Loxias is not currently a separate Irish legal entity.

For questions about this Privacy Policy or to exercise your data protection rights, please contact us using the contact details above.


2. Scope of this Privacy Policy

This Privacy Policy applies to personal data that we process in connection with:

  1. visits to and use of our website;
  2. account registration, purchases, orders and customer administration;
  3. requests for information, demos, proposals, support or training;
  4. B2B sales, marketing and relationship management;
  5. delivery of reports, dashboards, monitoring, implementation, training and related services;
  6. resale, implementation or support of third-party software and data platforms;
  7. use of third-party payment providers, business tools, analytics tools and service providers;
  8. compliance, security, fraud prevention, legal and accounting obligations.

3. Limited customer data processed by Polis Ireland / Loxias AI

Loxias AI provides B2B services and often acts as a reseller, implementation partner, training provider or first-level support provider for third-party software, data and intelligence platforms.

In that context, Polis Consulting Limited generally does not collect, store or control our customers’ own end-customer data. We normally process only the business contact, contractual, billing, account administration and support information necessary to manage the commercial relationship with our B2B customers.

This may include names, business email addresses, job titles, company details, billing details, VAT information, invoices, order history, support communications and related account records.

Where a customer contracts directly or indirectly for access to a third-party software platform, that platform provider may process personal data as an independent controller, joint controller or processor depending on the relevant product, configuration and terms. Those third-party providers are responsible for their own privacy notices, data processing terms, security measures, international transfer safeguards and compliance with applicable data protection law.

Where we assist with implementation, training, first-level support, reporting, dashboards or analysis, we may access limited data within those third-party tools or receive project information from the customer. In those cases, we process such data only as necessary to provide the agreed services and subject to the applicable contract, data processing agreement or platform terms.

We aim to minimise the personal data we access and to provide customers with aggregated, contextualised or derived intelligence rather than unnecessary individual-level personal data.


4. Personal data we collect

We may collect and process the following categories of personal data.

4.1 Contact and business identity data

This may include your name, business email address, business phone number, job title, employer, department, country, business address, LinkedIn profile or other professional identifiers.

4.2 Account and customer data

This may include usernames, passwords, account settings, communication preferences, customer ID, order details, subscription details, support history, invoice details, billing contact details and customer relationship notes.

4.3 Payment and transaction data

Where you purchase services through our website or otherwise make a payment, we may process order details, payment status, invoice information, billing address, VAT information and related transaction records.

Card payments and certain payment information may be processed directly by our payment provider, such as Stripe. We do not normally store full card numbers ourselves.

4.4 Communications data

This may include emails, messages, meeting notes, call notes, form submissions, proposal requests, support tickets, training communications, complaints and feedback.

4.5 Website, device and technical data

When you use our website, we may collect technical information such as IP address, browser type, device type, operating system, time zone, language, referring URL, pages visited, clickstream, session information, approximate location, cookie identifiers and similar online identifiers.

Some of this information is collected through cookies and similar technologies. Please see our Cookie Policy for more information.

4.6 Marketing and preference data

This may include newsletter subscriptions, event registrations, marketing consents, opt-outs, areas of professional interest, campaign interactions and engagement with our emails or website content.

4.7 Social, digital and public-source data used in our services

In delivering social media intelligence, digital intelligence, market intelligence, monitoring, reports and dashboards, we may process information from publicly available or licensed sources, including social networks, online media, blogs, forums, podcasts, video platforms, search data, public databases and third-party data providers.

Depending on the project, this may include usernames, public profile information, public posts, public comments, public engagement data, public media content, timestamps, URLs, inferred topics, sentiment, audience categories, trends, entities, keywords and other publicly available or licensed data relevant to the customer’s business question.

We generally aim to provide customers with aggregated, contextualised or derived intelligence rather than raw personal data, unless otherwise agreed and lawful.

4.8 Client-provided project data

Customers may provide us with project briefs, keywords, brand names, competitor names, campaign materials, target markets, audience definitions, analytics exports or other information needed to deliver services.

Where such information contains personal data, the customer is responsible for ensuring that it has the right to provide it to us, unless otherwise agreed in writing.

4.9 Recruitment and supplier data

If you apply to work with us, act as a freelancer, supplier or partner, we may process CVs, professional qualifications, contact details, payment details, tax information, contract information and related correspondence.


5. How we collect personal data

We collect personal data:

  1. directly from you when you complete forms, create an account, make a purchase, contact us, attend a meeting, subscribe to marketing, or use our services;
  2. from your employer or colleagues where they engage us or invite you to use our services;
  3. from customers who provide information for a project;
  4. from publicly available sources, including professional profiles, company websites, social media and online media;
  5. from third-party data providers, listening platforms, analytics tools, payment providers, CRM systems, marketing tools and business partners;
  6. automatically through cookies, server logs and similar technologies when you use our website.

6. Purposes and legal bases for processing

We process personal data only where we have a lawful basis under applicable data protection law.

6.1 To operate the website and provide requested functionality

We use website, device, technical and account data to operate the website, allow logins, process requests, maintain security and ensure the website functions correctly.

Legal basis: legitimate interests; contract where the functionality is necessary to provide requested services; legal obligation where security logging is required.

6.2 To create and administer accounts

We use contact, account and customer data to create accounts, manage access, provide account-related notices, administer orders and support customer use of our services.

Legal basis: contract; legitimate interests in managing customer relationships and providing requested B2B services.

6.3 To process orders, payments and invoices

We use contact, order, billing, VAT and transaction data to process purchases, issue invoices, receive payments, manage subscriptions and maintain accounting records.

Legal basis: contract; legal obligation; legitimate interests in receiving payment and maintaining business records.

6.4 To provide services, reports, dashboards, implementation, training and support

We use customer data, project data, communications data, platform data and relevant social, digital or public-source data to deliver agreed services, prepare reports, configure platforms, provide training, operate dashboards and respond to support requests.

Legal basis: contract with our customer; legitimate interests in delivering and improving B2B services; legal obligation where applicable. Where we process personal data on behalf of a customer, we may act as processor under the applicable data processing agreement.

6.5 To resell, implement and support third-party software

We may process business contact, order, billing, account administration and support data in order to resell, configure, implement, train users on, or provide support for third-party software, data or intelligence platforms.

Legal basis: contract; legitimate interests in managing customer relationships and delivering B2B software-related services; legal obligation for accounting, tax and compliance records.

Where the third-party software provider processes personal data within its own platform, its own privacy notice, data processing terms and security documentation may also apply.

6.6 To produce social, digital and market intelligence

We may process publicly available, licensed or customer-provided data to identify trends, topics, risks, market signals, brand reputation issues, campaign performance, audience insights and other intelligence requested by our customers.

Legal basis: legitimate interests of us and our business customers in obtaining B2B market, communication, reputation and business intelligence, provided those interests are not overridden by the rights and freedoms of individuals; contract where the processing is necessary to deliver customer services.

We apply safeguards such as data minimisation, access controls, aggregation where appropriate, and a focus on derived intelligence rather than unnecessary disclosure of individual-level personal data.

6.7 To communicate with you

We use contact and communications data to respond to enquiries, provide requested information, manage proposals, answer complaints, send service updates and maintain business records.

Legal basis: legitimate interests in responding to business communications and managing customer relationships; contract where the communication relates to a service or order; legal obligation where applicable.

6.8 For B2B marketing

We may use business contact details, preferences and interaction data to send newsletters, invitations, product updates, event information and other B2B marketing communications.

Legal basis: consent where required; legitimate interests in B2B marketing where permitted by applicable law; compliance with legal obligations relating to opt-outs.

You can opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us.

6.9 For analytics and website improvement

We use website, device, technical and usage data to understand how visitors use our website, improve content, measure performance, diagnose errors and improve user experience.

Legal basis: consent for non-essential analytics cookies or similar technologies where required; legitimate interests for essential technical analytics and security.

6.10 For advertising and remarketing

Where enabled, we may use cookies or similar technologies to measure advertising effectiveness, build audiences or show relevant advertising.

Legal basis: consent where required.

6.11 For security, fraud prevention and misuse detection

We use account, technical, usage and communications data to detect, prevent and investigate fraud, cyber incidents, misuse, unauthorised access, breaches of terms and other harmful activity.

Legal basis: legitimate interests in protecting our business, customers, website and systems; legal obligation where applicable.

6.12 For legal, regulatory, tax and accounting compliance

We use relevant personal data to comply with company law, tax law, accounting obligations, regulatory requests, legal claims, audits and record-keeping requirements.

Legal basis: legal obligation; legitimate interests in managing legal risk and defending our rights.

6.13 For business restructuring or corporate transactions

If we reorganise, sell, merge, transfer or finance part of our business, personal data may be reviewed or transferred as part of that transaction.

Legal basis: legitimate interests in managing corporate transactions and business continuity; legal obligation where applicable.


7. Third-party software and data platforms

Some services sold or supported by Loxias AI are provided through third-party software, data, analytics, social listening, media intelligence, payment, hosting or infrastructure platforms.

We select business partners and providers that are expected to maintain appropriate contractual, technical and organisational safeguards. However, each third-party provider remains responsible for the services, systems, privacy documentation, data processing terms and compliance obligations that apply to its own platform.

Customers should review the relevant third-party terms, privacy notices and data processing agreements before using those platforms.

Where we support a customer’s use of a third-party platform, our access is normally limited to what is necessary for implementation, configuration, training, first-level support, account administration, reporting or agreed analysis.


8. Special category data

We do not intentionally seek to collect special category data, such as health data, political opinions, religious beliefs, trade union membership, biometric data, sexual orientation or similar sensitive information, unless this is strictly necessary for a specific lawful purpose and appropriate safeguards are in place.

Because social, digital and public-source data may occasionally contain sensitive information, we use reasonable measures to limit unnecessary processing and disclosure of such information in our services.


9. AI, automation and profiling

We may use software, automation and artificial intelligence tools to support data collection, classification, summarisation, translation, trend detection, clustering, topic analysis, reporting and workflow automation.

We do not use automated processing to make decisions about individuals that produce legal effects or similarly significant effects on them.

Where AI tools are used, we aim to apply appropriate safeguards, including human review where appropriate, data minimisation, access controls, contractual restrictions and restrictions on unauthorised training or reuse of customer data.


10. Recipients of personal data

We may share personal data with the following categories of recipients where necessary and lawful:

  1. Group companies and affiliated businesses, including Polis group entities involved in service delivery, administration, support, finance, technology or business operations.
  2. Freelancers, consultants and subcontractors who support analysis, reporting, implementation, training, customer success, engineering, support or administration.
  3. Technology and hosting providers, including cloud hosting, website hosting, data storage, security, workflow automation, analytics and software providers.
  4. CRM, marketing and communication providers, including email, newsletter, webinar, sales and customer relationship tools.
  5. Payment providers, including Stripe or other payment processors.
  6. Third-party software, data and intelligence platform providers, where needed for account creation, licensing, access administration, implementation, support, reporting or customer service.
  7. Professional advisers, including lawyers, accountants, auditors, insurers and tax advisers.
  8. Authorities, courts, regulators and law enforcement bodies, where required by law or necessary to protect our rights.
  9. Potential purchasers, investors, lenders or corporate transaction parties, where relevant to a restructuring, investment, financing, sale or merger.

We require service providers and processors to protect personal data and to process it only in accordance with applicable law and our instructions where they act as processors.


11. International transfers

We are based in Ireland, but our group, service providers, customers, suppliers and technology partners may be located in other countries. This means personal data may be transferred to or accessed from countries outside Ireland and the European Economic Area.

Where personal data is transferred outside the EEA, we use appropriate safeguards as required by law. These may include:

  1. an adequacy decision by the European Commission;
  2. the EU Standard Contractual Clauses;
  3. the EU-US Data Privacy Framework for eligible certified US recipients;
  4. transfer impact assessments and supplementary measures where required;
  5. contractual, organisational and technical safeguards.

Transfers may include, where relevant, transfers to the United Kingdom, Switzerland, Brazil, the United States and other countries where our group companies, suppliers, platforms, cloud providers or professional advisers operate.

You may contact us for more information about the safeguards used for international transfers.


12. Data retention

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

The retention period depends on the nature of the data, the purpose of processing, the sensitivity of the data, legal limitation periods, tax and accounting obligations, contractual obligations, customer requirements and the need to resolve disputes or enforce rights.

As a general guide:

  1. Customer account and order data is retained for the duration of the customer relationship and thereafter as needed for legal, accounting and contractual purposes.
  2. Invoice, accounting and tax records are retained for the period required by applicable tax and accounting law.
  3. Marketing data is retained until you unsubscribe, object or your details are no longer reasonably relevant for B2B marketing.
  4. Website analytics data is retained in accordance with our cookie settings and analytics provider configurations.
  5. Support and communications data is retained for as long as necessary to handle the matter and maintain business records.
  6. Project data is retained according to the customer contract, data processing agreement or project requirements.
  7. Security logs are retained for a limited period unless needed to investigate incidents or comply with legal obligations.
  8. Legal claims data is retained for the period needed to establish, exercise or defend legal claims.

Where possible and appropriate, we anonymise or aggregate data so that it no longer identifies individuals.


13. Cookies and similar technologies

Our website uses cookies and similar technologies. Some cookies are necessary for the website to function. Others, such as analytics or marketing cookies, are used only where permitted by law and where any required consent has been obtained.

You can manage your cookie preferences through the cookie banner or consent management tool on our website.

For more information, please see our Cookie Policy.


14. Your data protection rights

Subject to applicable law and certain limitations, you may have the following rights:

  1. Right of access — to request a copy of personal data we hold about you.
  2. Right to rectification — to ask us to correct inaccurate or incomplete personal data.
  3. Right to erasure — to ask us to delete personal data in certain circumstances.
  4. Right to restriction — to ask us to restrict processing in certain circumstances.
  5. Right to data portability — to receive certain personal data in a structured, commonly used and machine-readable format.
  6. Right to object — to object to processing based on legitimate interests, including profiling based on legitimate interests.
  7. Right to object to direct marketing — to stop receiving direct marketing at any time.
  8. Right to withdraw consent — where processing is based on consent, to withdraw consent at any time. This does not affect processing carried out before withdrawal.
  9. Right to complain — to lodge a complaint with a data protection authority.

To exercise your rights, please contact us using the contact details in Section 1.

We may need to verify your identity before responding. Some rights are not absolute and may be subject to legal exemptions.


15. Right to complain to the Irish Data Protection Commission

If you are unhappy with how we process your personal data, we encourage you to contact us first so that we can try to resolve the issue.

You also have the right to lodge a complaint with the Irish Data Protection Commission:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland

Website: https://www.dataprotection.ie

You may also contact your local supervisory authority if you are based elsewhere in the EEA.


16. Security

We use appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

These measures may include access controls, authentication, encryption, secure hosting, logging, backup procedures, confidentiality obligations, staff and contractor access restrictions, and security reviews.

No online service can be guaranteed to be completely secure. You are responsible for keeping your account credentials confidential and for notifying us of any suspected unauthorised access.


17. Third-party websites

Our website and services may contain links to third-party websites, platforms, social networks, payment providers, data providers or business partners.

Those third parties have their own privacy policies and practices. We are not responsible for their privacy practices, and you should review their privacy notices before providing personal data to them.


18. Customer responsibilities

Where a business customer provides personal data to us or instructs us to process personal data as part of a project, the customer is responsible for ensuring that it has a lawful basis to do so and that any required notices, consents or other legal requirements have been satisfied.

Where required, we will enter into a data processing agreement with the customer.

Where the customer uses a third-party software platform supplied, resold, implemented or supported by us, the customer is also responsible for reviewing the relevant platform terms, privacy notice and data processing agreement and for configuring and using the platform in compliance with applicable law.


19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “last updated” date and, where appropriate, provide additional notice.

The version published on our website is the current version.


20. Contact us

For privacy questions, data protection requests or complaints, please contact:

Polis Consulting Limited, trading under the Loxias brand
Unit 10, Argus House, Greenmount Office Park,
Harold’s Cross Road,
Dublin 6W, Ireland

Email: [email protected]
Company number: 737553
VAT number: IE4153652OH