MERIXA MOBILE APPLICATIONS PRIVACY POLICY
This Privacy Policy explains how Merixa Limited handles personal information
Effective date: 9 August 2026
1. Scope of this Privacy Policy
This Privacy Policy explains how Merixa Limited (“Merixa”, “we”, “us” or “our”) handles personal information in connection with:
Merixa Management Micro; and
Merixa Practitioner's Guide.
Together, these are referred to as the “Merixa Applications” and individually as an “Application”.
The Applications are made available for compatible mobile and tablet devices, including through Google Play and the Apple App Store.
Where the two Applications handle information differently, this Privacy Policy identifies the relevant Application specifically.
This Privacy Policy applies only to the Merixa Applications. Merixa's corporate website and professional consultancy activities are governed by the separate Merixa corporate Privacy Notice.
2. Data controller and privacy contact
For personal information for which Merixa determines the purposes and means of processing:
Data Controller: Merixa Limited
Privacy contact: contact@merixa.co.uk
Country of establishment: United Kingdom
You may contact us at this address regarding this Privacy Policy or the exercise of applicable data-protection rights.
European Union representative
Merixa is established outside the European Union. Where Article 27 EU GDPR requires Merixa to appoint a representative in the European Union, the representative's identity and contact information will be published in this Privacy Policy and made available to relevant users and supervisory authorities.
Implementation requirement: this must be resolved before we treat EU distribution as fully signed-off. Article 27 generally requires a representative where Article 3(2) applies, subject to its limited exception for processing that is occasional, low-risk and does not involve large-scale sensitive/criminal data.
3. Our privacy approach
The Merixa Applications are designed around data minimisation and local device storage.
You do not need to create a Merixa account or profile to use the Applications.
Merixa does not operate a central database containing the financial information, calculations, working information, saved examples, preferences or other content that users create and retain solely within the Applications.
Information that remains solely on your device is not received by Merixa merely because you enter, calculate, edit, view or save it within an Application.
Apple likewise distinguishes information processed solely on-device from information collected off-device for its App Privacy disclosures.
4. Merixa Management Micro
Merixa Management Micro does not use OpenAI or generative AI processing.
Information that you enter, create, calculate or save within Merixa Management Micro is designed to remain locally within the Application environment on your device.
Depending on the functions you use, this may include financial information, assumptions, calculations, scenarios, tables, management information, saved analysis and application settings.
Merixa does not operate a central user-content repository containing this information.
5. Merixa Practitioner's Guide
Merixa Practitioner's Guide contains locally available professional reference and application functionality and also provides an AI-assisted feature using the OpenAI API.
Information that you save locally outside the AI interaction remains subject to the local-storage model described in this Privacy Policy.
When you actively use the AI feature, information needed to process the request is transmitted off your device.
This may include:
- the question, prompt or instruction you enter;
- contextual information supplied to the AI feature for that request; and
- information necessary to generate and return an AI response.
This information is processed for the purpose of providing the AI-assisted functionality requested by you.
6. OpenAI processing
The AI functionality within Merixa Practitioner's Guide only uses services provided through the OpenAI API.
OpenAI's current API documentation states that data submitted through standard API services is not used to train OpenAI models by default. Retention depends on the API endpoint and configuration used: for example, current Chat Completions and Responses API abuse-monitoring retention is generally 30 days, while certain stateful API resources may persist until deleted.
Accordingly, this Privacy Policy does not promise that every OpenAI interaction is deleted after exactly 30 days. The retention applicable to an AI request depends on the technical OpenAI service and configuration used by the Application.
Merixa does not use AI prompts submitted through Practitioner's Guide to create advertising profiles or for Merixa marketing.
Merixa does not maintain a separate corporate archive of AI conversations merely because an AI request has been made, unless information is separately submitted to Merixa for support, investigation or another stated purpose.
OpenAI's current Data Processing Addendum contains processor obligations, subprocessor provisions and international-transfer arrangements applicable to customer data processed under covered business services.
7. Do not use the AI feature as a client-data repository
Merixa Practitioner's Guide is not designed as a client personal-data management, document-management or confidential-records platform.
Where possible, you should anonymise or remove identifying information before submitting material to the AI feature.
You should not submit:
- special-category or highly sensitive personal information;
- criminal-offence information;
- confidential client records;
- legally privileged material;
- passwords, access credentials or security secrets;
- payment-card or banking credentials; or
- personal information relating to another individual,
unless it is genuinely necessary, you have appropriate authority and lawful grounds to do so, and your own professional, contractual and regulatory obligations permit that processing.
If your organisation requires Merixa to act formally as a processor of client personal data under a dedicated data-processing agreement or other regulated arrangement, the consumer Application Terms do not themselves create such an arrangement.
8. No Merixa user accounts
The Applications do not require registration with Merixa.
Merixa therefore does not ordinarily maintain:
- Application usernames or passwords;
- user identity profiles;
- an app-user email database;
- an app-user contact database; or
- a central account containing your locally stored Application content.
Your Apple or Google account is maintained by the relevant platform, not by Merixa.
9. Purchases and subscriptions
Purchases, subscriptions and store membership arrangements are administered through the platform from which you obtain the Application, including:
Google Play / Google Play Billing for Android; and
Apple App Store / StoreKit for Apple devices.
Apple and Google may process account, payment, billing, transaction and subscription information under their own privacy arrangements.
Merixa does not receive or store your complete payment-card number, bank-account credentials or Apple/Google account password.
The Applications may receive limited purchase or entitlement information necessary to determine whether paid functionality is available to you.
Apple's current App Privacy guidance expressly distinguishes payment information entered through an external payment service where the developer never receives the payment information.
10. Local storage and device backups
Content stored locally within the Applications remains under the control of your device.
Depending on your operating system and settings, locally stored information may also be included within device, Apple, Google or other backup services that you have enabled.
Those backup services are controlled through the relevant provider and your own platform settings.
Merixa does not control copies independently maintained through your personal device-backup arrangements.
11. Support enquiries
If you voluntarily contact Merixa for technical support or another Application-related enquiry, Merixa may receive information you choose to provide, such as:
- your name, if provided;
- email address;
- Application name;
- device or operating-system information you voluntarily provide;
- screenshots or diagnostic information you choose to send; and
- the content of your enquiry.
We use that information to respond to you, investigate the matter and maintain reasonable business records.
This is separate from locally stored Application information that Merixa cannot access.
12. Advertising, analytics and tracking
Under the current Application design:
Merixa does not use the Applications for behavioural advertising.
Merixa does not sell Application-user personal information to advertisers or data brokers.
Merixa does not use locally entered financial or professional information to construct advertising profiles.
The Applications are not intended to use location tracking for advertising or behavioural profiling.
If an advertising, analytics, telemetry or additional third-party SDK is introduced in a future production release, Merixa will review the applicable privacy disclosures before deployment.
Google requires developers to disclose data handling by both the app and third-party SDKs and to keep each application's Data Safety disclosure accurate.
13. Location
The Applications are not designed to collect or track your precise real-time geographic location.
14. Automated decisions and profiling
Merixa does not use the Applications to make automated decisions about you that determine whether you receive employment, credit, insurance, professional services or another legal or similarly significant outcome.
The AI function in Merixa Practitioner's Guide generates informational responses to user requests. It is not used by Merixa to make legal or similarly significant decisions about the user.
15. External professional and official websites
The Applications may contain links to websites operated by professional bodies, regulators, standard setters, government organisations or other third parties.
These are ordinary external references provided for convenience or professional reference.
If you choose to open an external website, that organisation may process information associated with your visit under its own privacy policy.
Merixa does not control those websites or their independent privacy practices.
A hyperlink does not make the linked organisation a Merixa data processor or imply sponsorship, approval or affiliation unless expressly stated.
Apple's App Privacy guidance similarly distinguishes navigation to the open web from embedded collection occurring within an app.
16. Why we process personal information
Where UK GDPR, EU GDPR or comparable data-protection law applies, Merixa processes personal information only where there is an applicable legal basis.
Providing requested Application functionality
Where processing is necessary to provide functionality requested by you, including processing necessary to provide the AI feature in Merixa Practitioner's Guide, Merixa may process the relevant information for performance of the service requested by you.
Legitimate interests
Where appropriate, Merixa may process limited personal information where necessary for legitimate interests including:
- providing and securing the Applications;
- responding to support requests;
- preventing misuse;
- protecting Merixa's legal and intellectual-property rights;
- investigating technical or security issues; and
- maintaining appropriate records,
provided those interests are not overridden by applicable individual rights.
Legal obligations
Merixa may process or disclose information where necessary to comply with applicable law, court orders, regulatory obligations or other legally binding requirements.
17. Who receives information
Depending on the Application and the functionality used, relevant recipients may include:
OpenAI — AI processing for Merixa Practitioner's Guide only.
Apple — App Store distribution, purchase, subscription and platform services.
Google — Google Play distribution, purchase, subscription and platform services.
Professional advisers, authorities or other recipients — where disclosure is required by law, necessary to establish or defend legal rights, or otherwise permitted under applicable law.
Merixa does not disclose locally stored Application information that Merixa has never received.
18. International processing
Locally stored information is not transferred internationally by Merixa merely because it exists within your Application on your device.
Information transmitted through the OpenAI functionality may be processed internationally through OpenAI and its approved subprocessors.
OpenAI's Data Processing Addendum provides contractual mechanisms addressing international transfers, including applicable European Standard Contractual Clauses and UK transfer provisions.
Apple and Google may independently process their own store and account information internationally according to their respective privacy arrangements.
19. Retention
Local Application information
Merixa does not impose a server-side retention period on information that exists solely on your device.
It remains under your device control until you delete it, clear the Application's local information, uninstall the Application or otherwise manage it through your operating system, subject to independent backups.
AI processing
Merixa does not maintain a separate permanent corporate archive merely because you use the AI feature.
OpenAI retention is governed by the API endpoint, configuration and contractual controls applicable to the AI processing. OpenAI currently documents different retention characteristics for different API endpoints, including 30-day abuse-monitoring periods for various standard endpoints and longer state retention for certain stateful resources.
Support information
Routine support correspondence may normally be retained for up to two years following the last meaningful contact, unless a longer period is reasonably necessary for legal, contractual, security or dispute-related purposes.
Store records
Information held independently by Apple or Google is retained according to those platforms' own policies and legal obligations.
20. Deletion
Information stored solely on your device must ordinarily be deleted or managed by you through the relevant Application or device.
Depending on the operating system and Application functionality, this may involve:
- deleting an individual saved item;
- clearing local Application information;
- managing backups; or
- uninstalling the Application.
Merixa cannot remotely erase information it has never possessed.
Deleting an Application does not necessarily delete information held independently in your Apple or Google account, device backup or subscription records.
21. Security
Merixa uses a data-minimising Application model intended to reduce unnecessary central collection of user information.
You are responsible for maintaining reasonable security over your own device, including device access controls, operating-system updates and backup settings.
Where information is transmitted to a third-party service, the relevant provider's technical and contractual security measures also apply.
No electronic system can guarantee absolute security.
22. Your privacy rights
Depending on the law applicable to you and the particular processing involved, you may have rights relating to access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaints to an appropriate supervisory authority. EU GDPR contains these core data-subject rights, and the ICO provides corresponding UK guidance.
Because Merixa does not operate a user account or central database containing locally stored Application content, we generally cannot locate, provide or erase information that exists only on your device.
Where Merixa does possess personal information about you — for example because you contacted us for support — you may contact:
contact@merixa.co.uk
UK users may have the right to complain to the Information Commissioner's Office.
Users in the EEA may have rights to complain to the competent supervisory authority under applicable EU or national law.
Other jurisdictions may provide additional mandatory privacy rights, which will apply where Merixa is legally subject to them.
23. No sale or targeted advertising
Merixa does not sell personal information collected through the Applications.
Merixa does not share Application-user personal information for cross-context behavioural advertising or equivalent targeted advertising arrangements.
If this practice changes, this Privacy Policy and applicable store declarations will be updated before such processing is introduced.
24. Age and children's privacy
The Merixa Applications are intended for users aged 18 or over and are not directed to children.
Merixa does not knowingly operate the Applications as services intended for children.
This age position is particularly relevant to Merixa Practitioner's Guide because OpenAI's current API guidance requires additional safeguards where developers deliberately serve users under 18.
If Merixa later decides to make either Application intentionally available to children or minors, the relevant privacy, safety, age-assurance and platform controls will be reviewed before doing so.
25. Global availability
The Applications may be made available in multiple countries.
Availability through an app store does not mean that every feature, professional reference, accounting treatment or other Application output is appropriate for every jurisdiction.
Privacy and consumer laws may provide mandatory rights in the country where you live. Nothing in this Privacy Policy is intended to remove rights that apply mandatorily under applicable law.
26. Changes to this Privacy Policy
Merixa may update this Privacy Policy where the Applications, service providers, data-processing arrangements, legal requirements or platform requirements change.
The current version will display its effective date.
Where applicable law requires additional notice or consent for a material change, Merixa will provide such notice or obtain such consent as required.
27. Contact
For privacy enquiries relating to the Merixa Applications:
Merixa Limited
Email: contact@merixa.co.uk
