MERIXA PRACTITIONER'S GUIDE PRIVACY POLICY
This Privacy Policy explains how Merixa Limited handles personal information
MERIXA PRACTITIONER’S GUIDE PRIVACY POLICY
Effective date: 1 September 2026
This Privacy Policy explains how Merixa Limited (“Merixa”, “we”, “us” or “our”) handles personal information in connection with the Merixa Practitioner’s Guide mobile application (“Practitioner’s Guide” or the “Application”).
Practitioner’s Guide combines locally available professional-learning and reference functionality with an AI-assisted Tutor powered through the OpenAI API.
The privacy model therefore differs depending on the functionality you use.
Information such as locally stored reference activity, saved material and preferences can remain on your device. When you actively use the AI Tutor, information necessary to provide the AI interaction is transmitted off your device for processing.
This Privacy Policy applies only to Merixa Practitioner’s Guide. Other Merixa applications, the Merixa website and Merixa professional services may be governed by separate privacy notices.
1. Who we are
For personal information for which Merixa determines the purposes and means of processing:
Data Controller: Merixa Limited
Country of establishment: United Kingdom
Privacy contact: contact@merixa.co.uk
Questions about this Privacy Policy or applicable privacy rights may be sent to that address.
2. Privacy at a glance
Practitioner’s Guide is designed so that:
no Merixa user account or profile is required;
the professional Library and Paths functionality is principally available within the Application;
locally saved Application information is designed to remain on your device unless a feature expressly requires transmission;
the AI Tutor uses the OpenAI API;
AI prompts and relevant context must leave your device when an OpenAI-powered Tutor request is made;
OpenAI does not use API customer inputs and outputs to train its models by default under its current business-data terms;
Merixa does not use AI conversations to create advertising profiles;
Merixa does not sell Application-user personal information;
Practitioner’s Guide does not use behavioural advertising;
Practitioner’s Guide is not designed to track your precise real-time location; and
AI-generated responses should not be treated as verified professional advice or as a sole source of truth.
3. Information processed locally
Depending on the functions you use, information retained locally within Practitioner’s Guide may include:
Library activity;
learning progress;
Paths activity;
saved reference cards;
locally saved examples;
saved Tutor conversations where the Application provides this function;
preferences;
accessibility or narration preferences;
Application settings; and
other information deliberately saved within the Application.
Information that remains exclusively on your device is not received by Merixa merely because you view, save or use it locally.
4. The professional Library
Practitioner’s Guide contains professional and educational reference material covering areas such as:
accounting;
financial reporting;
management accounting;
financial analysis;
risk;
internal control;
audit;
governance;
ESG; and
related professional topics.
Using or viewing a Library card does not by itself require that your personal information be sent to OpenAI.
If you choose an AI-assisted action from a Library card, relevant Library context may be supplied to the AI Tutor so that it can respond to your request.
5. Learning Paths
Practitioner’s Guide may provide structured learning Paths that organise related professional topics into sequences.
Progress through a Path may be stored locally.
If you choose to continue a Path through the AI Tutor, contextual information necessary to identify the subject or stage of the Path may be included in the AI request.
6. AI Tutor
Practitioner’s Guide contains an AI-assisted Tutor.
The Tutor may provide functionality such as:
answering professional-learning questions;
explaining concepts;
developing examples;
exploring workplace applications;
deepening a Library topic;
supporting structured learning Paths;
Workplace Coach interactions;
Exam Coach interactions; and
related educational conversations.
AI responses are generated using artificial intelligence through the OpenAI API.
The Tutor is not a human adviser.
7. First-use AI transparency and permission
Before the first AI interaction, Practitioner’s Guide should inform you clearly that:
the feature uses artificial intelligence;
relevant input will be transmitted from your device;
OpenAI processes the request on Merixa’s behalf;
AI responses may be inaccurate or incomplete; and
you should avoid including unnecessary personal, confidential or sensitive information.
Where platform rules or applicable law require explicit permission before personal information is transmitted to a third-party AI provider, the Application will request that permission before the relevant processing occurs.
Declining AI processing should prevent the relevant AI feature from operating but should not, where technically practicable, prevent use of non-AI Library or Path functionality.
8. What is transmitted when you use the AI Tutor
When you actively use the AI Tutor, information necessary to process the interaction is transmitted off your device.
Depending on the request, this may include:
your typed question;
your instruction or prompt;
a transcript created from a voice request where voice input is used;
the Library concept being discussed;
the relevant Path context;
earlier conversation context required to continue the interaction;
Tutor mode, such as Workplace Coach or Exam Coach;
technical instructions used to control the Tutor;
information necessary to enforce safety controls; and
information necessary to generate and return the response.
Only information reasonably necessary for the requested AI functionality should be transmitted.
9. OpenAI processing
Merixa uses services provided through the OpenAI API to provide AI-assisted functionality.
For this processing, OpenAI processes relevant customer data under its business/API contractual arrangements.
Under OpenAI’s current API terms:
API inputs and outputs are not used to train OpenAI models by default;
OpenAI acts as a processor for customer data covered by its Data Processing Addendum;
authorised subprocessors may support provision of the service;
international-transfer safeguards are provided for covered UK and EEA data; and
retention depends on the API endpoint and configuration being used.
Standard API processing may include temporary retention for abuse monitoring and service operation.
Merixa does not promise that every OpenAI request is deleted immediately after the response is returned.
10. AI retention
Merixa does not maintain a permanent central archive of every Tutor conversation merely because you interact with the Tutor.
OpenAI currently documents retention of certain API inputs and outputs for up to approximately 30 days for standard abuse-monitoring purposes, subject to the relevant endpoint, configuration, legal requirements and available retention controls.
Certain API features or stateful resources may have different retention behaviour.
Where Merixa materially changes the API configuration in a way that changes the privacy impact of Tutor interactions, this Privacy Policy will be reviewed.
11. Saved Tutor conversations
Where Practitioner’s Guide allows you to save a Tutor conversation, the saved Application copy is designed to be retained locally on your device unless the Application expressly informs you otherwise.
Saving a conversation locally is separate from the temporary processing required to generate an AI response through the OpenAI API.
Merixa cannot normally retrieve a locally saved conversation from your device.
12. Response caching
Practitioner’s Guide may use limited caching intended to:
avoid unnecessary repeated AI requests;
improve response speed;
reduce repeated network processing; and
control operating costs.
An approved exact-match response may be returned from a cache rather than making a new OpenAI request.
Caching should not be used to create advertising profiles or behavioural user profiles.
Where a cache contains information capable of being associated with a licence, device or user interaction, Merixa will apply appropriate access, isolation and retention controls.
13. Narration and audio caching
Practitioner’s Guide may provide narration functionality so that supported content can be listened to.
Where current Application caching functionality is enabled:
narration may be temporarily cached on the device to reduce repeated network requests; and
limited narration may also be temporarily cached within supporting infrastructure.
Caching exists to provide the requested narration efficiently and is not used for behavioural advertising.
Where a separate third-party voice or speech service receives personal information, that provider must be identified in the Application’s applicable privacy disclosure before or when that processing is introduced.
14. Voice input
Practitioner’s Guide may allow you to speak rather than type a Tutor request.
Voice functionality may require:
microphone permission;
speech-to-text processing;
creation of a temporary transcript; and
transmission of the resulting Tutor request for AI processing.
You should not speak confidential, sensitive or third-party personal information into the Tutor unless you are authorised to process and disclose that information.
The Application should request microphone access only when required for a voice feature.
15. Do not use the Tutor as a confidential-data repository
Practitioner’s Guide is a professional-learning application.
It is not designed as:
a client-record system;
an employee-record system;
a confidential document repository;
a medical-record system;
a legal case-management platform;
a regulated customer-data platform; or
a secure password or credential manager.
Where possible, remove or anonymise identifying information before submitting material to the Tutor.
16. Information you should not submit
You should not submit through the AI Tutor:
passwords;
authentication codes;
cryptographic secrets;
complete payment-card details;
banking credentials;
highly confidential client files;
legally privileged documents;
unpublished commercially sensitive documents;
special-category personal information;
medical information;
criminal-offence information;
identification documents;
private information about another person; or
other highly sensitive information,
unless doing so is genuinely necessary, lawful and authorised and your professional, contractual and regulatory obligations permit that processing.
17. Third-party personal information
If you include another individual’s personal information in a Tutor request, you are responsible for ensuring that you have appropriate authority and a lawful reason to do so.
Practitioner’s Guide should not be used to circumvent:
privacy obligations;
confidentiality obligations;
professional secrecy;
legal privilege;
employment confidentiality;
client confidentiality; or
another person’s rights.
18. No Merixa user account
Practitioner’s Guide does not require registration for a Merixa user account.
Merixa therefore does not ordinarily maintain:
Practitioner’s Guide usernames;
Application passwords;
a central user-profile database;
a user email database created through app registration; or
a Merixa cloud account containing your locally saved Library and Path information.
Your Apple or Google account is maintained by the relevant platform.
19. Purchases and subscriptions
Purchases and subscriptions are administered through the platform from which you obtain Practitioner’s Guide.
This may include:
Google Play and Google Play Billing; and
Apple App Store and StoreKit.
Apple and Google may independently process:
platform-account information;
payment information;
purchase information;
subscription information; and
transaction information
under their own privacy arrangements.
Merixa does not receive your complete card number, bank credentials, Google password or Apple Account password.
The Application may receive limited purchase or entitlement information necessary to determine whether paid functionality is available.
20. Support enquiries
If you contact Merixa for support, we may receive information you choose to provide, including:
name;
email address;
Application version;
device type;
operating-system information;
screenshots;
description of the issue;
transaction reference where relevant; and
the contents of your communication.
You should not send complete AI conversations or confidential information unless it is necessary for us to investigate the issue and you are authorised to disclose it.
21. Reports of AI output
Practitioner’s Guide may provide a mechanism allowing users to report or flag:
inaccurate responses;
inappropriate responses;
offensive content;
unsafe content;
suspected policy violations; or
other problematic AI behaviour.
Where you submit a report, Merixa may process the relevant reported content and limited contextual information necessary to investigate the issue, improve safeguards, satisfy platform requirements or protect users.
Reported content may need to be retained longer than an ordinary Tutor interaction where reasonably necessary for investigation, security or legal purposes.
22. Safety processing
AI inputs and outputs may be processed using automated safety systems intended to detect or prevent prohibited, harmful or abusive activity.
Where appropriate, reported or flagged interactions may be subject to additional review.
Safety processing is intended to protect users, the Application and the AI service and is not used by Merixa to create advertising profiles.
23. Analytics, advertising and tracking
Under Practitioner’s Guide’s current operating model:
Merixa does not use behavioural advertising;
Merixa does not sell Application-user personal information;
Merixa does not use Tutor conversations for targeted advertising;
Merixa does not construct advertising profiles from Library or Tutor activity;
the Application is not designed to track precise real-time location; and
Merixa does not currently use Crashlytics or Sentry to collect crash logs, diagnostics or other app-performance information.
If analytics, advertising, diagnostics, telemetry or an additional third-party SDK is introduced in a future production release, the relevant disclosures will be reviewed before deployment.
24. Location
Practitioner’s Guide is not designed to collect or track your precise real-time location.
Ordinary platform or network services may process general technical information independently under their own arrangements.
25. Automated decisions and profiling
Merixa does not use Practitioner’s Guide to make automated decisions about whether you receive:
employment;
admission to education;
examination results;
credit;
insurance;
professional membership;
regulated services; or
another legal or similarly significant outcome.
The AI Tutor produces educational responses for the user.
It does not determine qualifications, grades or professional eligibility.
26. Legal bases for processing
Where UK GDPR, EU GDPR or comparable law applies, Merixa relies on an appropriate lawful basis for personal information that it actually processes.
Providing requested functionality
Processing necessary to deliver a Tutor response or another service requested by you may be undertaken where necessary for performance of the service or contractual relationship.
Platform and AI permission
Where applicable law or platform rules require express permission for third-party AI processing, Merixa will request that permission.
Such permission requirements do not necessarily mean that consent is the sole legal basis for every aspect of processing under every privacy law.
Legitimate interests
Merixa may rely on legitimate interests where appropriate for purposes including:
securing Practitioner’s Guide;
preventing misuse;
investigating AI reports;
resolving technical issues;
answering support enquiries;
protecting users;
enforcing intellectual-property rights; and
maintaining reasonable compliance records.
Legal obligations
Information may be processed or disclosed where required by applicable law, court order or regulatory obligation.
27. Who receives information
Depending on the feature used, recipients may include:
OpenAI
For AI Tutor processing and associated API functionality.
Apple
For App Store distribution, purchases, subscriptions and platform services.
Google
For Google Play distribution, purchases, subscriptions and platform services.
Service providers supporting Merixa
Where reasonably necessary for hosting, security, communications or Application operations.
Professional advisers, authorities or courts
Where legally necessary or permitted.
Information that never leaves your device is not disclosed by Merixa merely because it exists locally.
28. OpenAI subprocessors
OpenAI may engage authorised subprocessors to provide its API services.
The composition and location of those subprocessors can change over time.
OpenAI maintains its own current subprocessor information and contractual arrangements.
Merixa does not represent that every AI request will necessarily be processed in the United Kingdom.
29. International transfers
Merixa is established in the United Kingdom.
OpenAI processing may involve international processing.
OpenAI’s current Data Processing Addendum contains contractual mechanisms for covered international transfers, including:
European Standard Contractual Clauses for relevant EEA transfers; and
the UK Addendum for covered UK transfers.
Apple, Google and other independent platform providers may also process information internationally according to their own privacy arrangements.
Where another international-transfer mechanism is required by applicable law, Merixa will take appropriate measures.
30. Retention
Local information
Information existing only on your device remains under your control until deleted or otherwise removed, subject to independent device backups.
AI interactions
Retention associated with OpenAI API processing depends on the endpoint, configuration and applicable contractual controls.
Standard API abuse-monitoring retention may currently be up to approximately 30 days.
Local caches
Temporary local caches may remain for the period configured by the Application and may be removed automatically or through normal device/Application management.
Infrastructure caches
Where temporary server-side caching is used to provide Application functionality, information should be retained only for the limited operational period for which the cache is required.
Support information
Routine support correspondence may normally be retained for up to two years after the last meaningful contact, unless longer retention is reasonably necessary for legal, security, dispute or compliance purposes.
AI reports
AI safety or content reports may be retained for the period reasonably necessary to investigate and resolve the reported issue and satisfy applicable safety, legal or platform obligations.
31. Deletion
Information stored solely on your device must normally be managed by you through Practitioner’s Guide or your device.
Depending on Application functionality, this may include:
deleting saved conversations;
deleting saved Library material;
clearing local data;
managing caches;
managing backups; or
uninstalling the Application.
Merixa cannot remotely erase information it never possessed.
Deleting Practitioner’s Guide does not necessarily:
cancel a subscription;
delete platform purchase records;
delete device backups; or
immediately erase temporary OpenAI API processing records.
32. Your privacy rights
Depending on where you live and the processing involved, applicable law may give you rights concerning personal information held by Merixa.
These may include:
access;
correction;
deletion;
restriction;
objection;
portability;
withdrawal of consent where processing relies on consent; and
complaint to a supervisory authority.
Where information exists only on your device, Merixa generally cannot retrieve it in order to respond to a remote data request.
Where Merixa actually holds your personal information, you can contact:
UK users may have the right to complain to the Information Commissioner’s Office.
EEA users may have the right to complain to the competent data-protection authority in their country.
Residents of other jurisdictions may have additional mandatory rights where applicable law applies to Merixa.
33. Users in the European Economic Area
Merixa is established in the United Kingdom and not in the European Union.
Where the EU GDPR applies to Merixa’s offering of Practitioner’s Guide in the EEA, applicable EU GDPR requirements will apply.
Where Article 27 EU GDPR requires appointment of an EU representative, Merixa must maintain the required representative arrangements and make the appropriate contact information available.
34. AI transparency in the European Union
Practitioner’s Guide is designed to make clear that Tutor interactions are generated using artificial intelligence.
Where the EU Artificial Intelligence Act applies, AI interaction information will be provided clearly and distinguishably no later than the user’s first interaction with the AI system.
Practitioner’s Guide does not represent AI Tutor responses as responses from a human tutor or Merixa professional adviser.
35. Age and children
Practitioner’s Guide is currently intended for users aged 18 or over.
It is not directed to children.
Merixa does not knowingly operate Practitioner’s Guide as a service intended for children under 18.
If Merixa later decides intentionally to offer Practitioner’s Guide to users under 18, the relevant:
parental or guardian permissions;
age-assurance processes;
privacy requirements;
platform requirements;
AI safety controls;
content safeguards; and
OpenAI requirements
will be assessed and implemented before that change is introduced.
36. Academic integrity
AI processing is provided to support learning.
Practitioner’s Guide is not intended to enable academic dishonesty.
You should not submit assessment material or use Tutor output where doing so would violate:
examination rules;
university or college policies;
professional-body requirements;
employer policies;
course rules; or
another applicable integrity requirement.
Academic-integrity restrictions are addressed further in the Practitioner’s Guide Terms & Conditions.
37. External websites
Practitioner’s Guide may link to:
professional bodies;
regulators;
standard setters;
government organisations;
educational resources; or
other independent websites.
Those services operate under their own terms and privacy arrangements.
A reference or link does not automatically mean that the organisation sponsors, endorses or is affiliated with Merixa.
38. Security
Merixa uses a data-minimising architecture intended to reduce unnecessary central collection.
Security also depends on:
your device security;
your network;
operating-system protections;
third-party platform security;
OpenAI’s applicable security measures; and
the information you choose to submit.
No electronic system can guarantee absolute security.
39. No sale of personal information
Merixa does not sell personal information collected through Practitioner’s Guide.
Merixa does not share Practitioner’s Guide user information for cross-context behavioural advertising.
40. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to:
Practitioner’s Guide;
OpenAI services;
AI models;
caching arrangements;
voice functionality;
service providers;
privacy law;
AI regulation;
platform rules; or
security practices.
Where a change materially affects personal-information processing, Merixa will provide any additional notice or permission required by applicable law or platform requirements.
The effective date identifies the current version.
41. Contact
For privacy enquiries relating to Merixa Practitioner’s Guide:
Merixa Limited
United Kingdom
Email: contact@merixa.co.uk
Merixa Practitioner’s Guide Privacy Policy
Merixa Limited
