Legal

Privacy Policy

Learn how we collect, use, store, and protect your personal information while using our platform. Your privacy and data security are our top priorities.

On this page
01

Introduction

Regxion AI, Inc. ("Regxion," "Company," "we," "our," or "us") respects your privacy and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store, transfer, and otherwise process Personal Data when you:

  • Visit our websites
  • Create an account
  • Use the Regxion AI Platform
  • Purchase subscriptions
  • Contact customer support
  • Attend webinars or events
  • Participate in product research
  • Use our APIs
  • Interact with our Artificial Intelligence ("AI") services

This Privacy Policy applies globally unless a separate jurisdiction-specific notice or enterprise agreement governs your relationship with us.

02

Who We Are

Regxion AI is an enterprise software company providing AI-powered regulatory, quality, clinical, manufacturing, labeling, pharmacovigilance, and compliance solutions for the life sciences industry.

For purposes of applicable privacy laws, Regxion may act as:

  • Controller (when determining why and how personal data is processed, such as for our website or marketing), or
  • Processor/Service Provider (when processing customer data solely on behalf of enterprise customers under their instructions).
03

Scope

This Privacy Policy covers:

  • Website visitors
  • Trial users
  • Individual subscribers
  • Enterprise customers
  • Customer employees
  • API users
  • Mobile application users
  • Event attendees
  • Job applicants (unless a separate recruitment privacy notice applies)
  • Customer support interactions

It does not apply to third-party websites or services that are not controlled by Regxion.

04

Information We Collect

4.1 Information You Provide

Depending on your interactions with us, we may collect:

Identity Information

  • Name
  • Professional title
  • Employer
  • Department
  • Organization

Contact Information

  • Email address
  • Telephone number
  • Business mailing address

Account Information

  • Username
  • Password (stored using secure hashing techniques)
  • Authentication settings
  • Subscription details
  • Organization affiliation

Billing Information

  • Billing contact
  • Payment information (processed through PCI-compliant payment processors; Regxion does not generally store full payment card numbers)
  • Tax identifiers where required

Customer Communications

  • Support tickets
  • Emails
  • Chat messages
  • Survey responses
  • Product feedback

4.2 Customer Content

When customers use the Services, they may upload or create Customer Content, including:

  • Regulatory submissions (e.g., INDs, NDAs, BLAs, CTDs, eCTDs)
  • Clinical protocols and reports
  • Investigator Brochures
  • CMC documentation
  • Manufacturing records
  • Quality records (CAPAs, deviations, investigations, audits)
  • Labeling documents
  • SOPs
  • Scientific reports
  • Regulatory correspondence
  • AI prompts
  • AI conversation history
  • Files, images, and other documents

Customer Content remains the property of the customer, subject to the applicable agreement.

4.3 Automatically Collected Information

When you use our Services, we may automatically collect:

  • IP address
  • Device identifiers
  • Browser type and version
  • Operating system
  • Language preferences
  • Time zone
  • Referring URLs
  • Pages viewed
  • Features used
  • Session duration
  • Clickstream data
  • Error logs
  • Diagnostic information
  • Cookies and similar technologies

4.4 AI Interaction Data

To provide AI-powered features, we may process:

  • Prompts you submit
  • Context you provide to AI agents
  • Conversation history
  • Uploaded documents used for retrieval
  • Retrieval metadata
  • AI-generated responses
  • User ratings and feedback on AI outputs

This information is processed to deliver the requested functionality, improve service reliability, maintain security, and support troubleshooting.

Unless expressly authorized in writing, Customer Content is not used to train foundation models for the benefit of other customers.

05

How We Use Personal Data

We process Personal Data for the following purposes:

  • Provide and operate the Services
  • Authenticate users
  • Deliver AI-powered functionality
  • Process customer requests
  • Provide customer support
  • Manage subscriptions and billing
  • Maintain and improve the Services
  • Detect, prevent, and investigate fraud, abuse, and security incidents
  • Comply with legal obligations
  • Communicate product updates and service notices
  • Conduct analytics and product research
  • Personalize user experiences where appropriate and lawful

Where required by law, we rely on appropriate legal bases such as contract performance, legitimate interests, legal obligations, or consent.

06

How AI Processes Your Data

Regxion AI uses artificial intelligence technologies to support regulatory and quality workflows.

Depending on the subscribed service, AI processing may include:

  • Natural language processing
  • Large Language Models (LLMs)
  • Retrieval-Augmented Generation (RAG)
  • Semantic search
  • Vector embeddings
  • Knowledge graph retrieval
  • AI agent orchestration
  • Document summarization
  • Draft generation
  • Intelligent review
  • Regulatory intelligence

AI-generated content is produced algorithmically and may contain inaccuracies, omissions, or outdated information. Customers remain responsible for reviewing and validating AI-generated outputs before relying upon them.

07

Customer Data Ownership

Customer retains ownership of all Customer Content.

Regxion does not claim ownership of:

  • Customer documents
  • Regulatory submissions
  • Scientific content
  • Manufacturing records
  • Quality documentation
  • Customer prompts
  • AI conversations

Regxion receives only the limited rights necessary to provide, secure, maintain, and improve the Services as described in the applicable agreement.

08

AI Model Training

Unless expressly authorized by the customer in writing:

  • Customer Content is not used to train foundation models for the benefit of other customers.
  • Customer prompts remain confidential.
  • Uploaded regulatory documentation remains confidential.
  • AI interactions are processed only to provide the requested Services and maintain platform operations.

Where de-identified and aggregated operational telemetry is used to improve the Services, it will not be used in a manner that reasonably identifies a customer or discloses Customer Confidential Information.

09

How We Share Information

We may share Personal Data with:

  • Cloud infrastructure providers
  • Identity and authentication providers
  • Payment processors
  • Customer support vendors
  • Email and communications providers
  • Analytics providers
  • Professional advisors (e.g., legal, audit, accounting)
  • Government authorities where required by law
  • Successors in connection with mergers, acquisitions, or similar corporate transactions

We do not sell Personal Data in exchange for monetary consideration.

Where applicable privacy laws define "sale" or "sharing" broadly (such as under the CPRA), we provide mechanisms for users to exercise available rights.

10

International Data Transfers

Personal Data may be transferred to and processed in countries other than the country in which it was collected.

Where required, Regxion implements appropriate safeguards, which may include:

  • Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Addendum
  • Other lawful transfer mechanisms recognized under applicable law

Enterprise customers may request additional information regarding international data transfers as part of procurement or due diligence.

11

Data Security

Regxion maintains a comprehensive information security program designed to protect Personal Data and Customer Content.

Security measures may include:

  • Encryption in transit (TLS)
  • Encryption at rest (AES-256 or equivalent)
  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • Single Sign-On (SSO)
  • Continuous monitoring
  • Security logging
  • Vulnerability management
  • Penetration testing
  • Backup and disaster recovery
  • Secure software development lifecycle (SSDLC)
  • Personnel security and confidentiality obligations

No method of transmission or storage is completely secure. Accordingly, while we strive to protect information using commercially reasonable safeguards, we cannot guarantee absolute security.

12

Data Retention

We retain Personal Data only for as long as necessary to:

  • Provide the Services
  • Fulfill contractual obligations
  • Comply with legal and regulatory requirements
  • Resolve disputes
  • Enforce agreements

Retention periods may vary depending on the nature of the data, customer instructions, and applicable legal obligations.

Upon termination of applicable services, Customer Content will be returned or deleted in accordance with the governing agreement and documented retention schedules, subject to legal or operational requirements.

13

Your Privacy Rights

Depending on your jurisdiction, you may have rights to:

  • Access Personal Data
  • Correct inaccurate Personal Data
  • Delete Personal Data
  • Restrict or object to certain processing
  • Receive a portable copy of your Personal Data
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with an applicable supervisory authority

Enterprise customers should generally submit requests concerning Customer Content through their organization's designated administrator, as Regxion may process such information solely on behalf of the customer.

14

Children's Privacy

The Services are intended for business and professional use and are not directed to children.

Regxion does not knowingly collect Personal Data from children below the age required by applicable law. If we become aware that such information has been collected without appropriate authorization, we will take reasonable steps to delete it.

15

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or business practices.

Material changes will be communicated through the Services, our website, email, or other appropriate means. The "Last Updated" date at the top of this Privacy Policy indicates when the latest revision became effective.

16

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact:

Regxion AI, Inc.

Privacy Office / Data Protection Officer (if appointed)

Additional contact information may be provided on our website or in applicable customer agreements.

Read our Terms of Service

Last updated July 18, 2026