IAP Exchange
Legal

Privacy notice

How Inter-Agent Protocol Ltd handles personal data under the UK GDPR and the Data Protection Act 2018.

Last updated: 21 August 2026

1. Who we are

Inter-Agent Protocol Ltd (“IAP Exchange”, “we”) is the data controller for the personal data described in this notice. We are registered in England and Wales and operate from the United Kingdom.

We have not appointed a statutory Data Protection Officer; privacy questions are handled by the address above.

2. Where we get personal data

Directly from you when you complete an enquiry form, request data-room access or use the control centre; automatically from your device when you browse the site; and occasionally from your employer when they nominate you as a user or accountable person.

IAP Exchange is infrastructure for agent-to-agent transactions between institutions. Transaction and agent records processed through the platform are institutional data, but may contain limited personal data such as the named accountable person and the operator who approved an exception.

3. What we collect, why, and on what legal basis

PurposeDataLegal basisRetention
Responding to technical briefing, design partner and investor enquiriesName, work email, job title, institution, fund name, message contentLegitimate interests (Art. 6(1)(f)) — responding to a business enquiry you initiated24 months from last contact, then deleted
Granting and administering access to the IAP Exchange control centreAccount email, authentication identifiers, role and approval status, institution affiliationContract (Art. 6(1)(b)) — providing the platform you or your employer have signed up forDuration of the account plus 12 months
Security, fraud prevention and tamper-evident audit logging of platform actionsUser identifier, timestamps, IP address, action performed, hash-chained audit recordsLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) — platform integrity6 years, in line with UK financial-services record-keeping expectations
Operating and securing the website (essential cookies, error and abuse monitoring)IP address, browser and device information, session identifiers, error diagnosticsLegitimate interests (Art. 6(1)(f)) — keeping the site available and secureUp to 13 months
Sending occasional product or funding updates where you have asked for themName, email, preferencesConsent (Art. 6(1)(a)) — withdrawable at any timeUntil you withdraw consent, then suppression-list only

We do not carry out automated decision-making producing legal effects about you, and we do not knowingly collect special category data. Please do not include it in enquiry forms.

4. Who we share it with

We share personal data only with processors acting on our instructions, and with professional advisers or regulators where we are legally required to.

  • Hosting and application platform — Lovable / Cloudflare, for serving the website and running application logic.
  • Database, authentication and storage — Supabase, for accounts, platform records and audit logs.
  • Email delivery — used to send transactional messages such as sign-in and approval notifications.
  • Professional advisers — legal, accounting and audit firms, under duties of confidentiality.

We do not sell personal data and we do not share it with advertising networks.

5. International transfers

Our primary hosting and database infrastructure is located in the United Kingdom and the European Economic Area. Some suppliers process data in the United States or other third countries.

Where personal data leaves the UK to a country without UK adequacy regulations, we rely on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, supported by a transfer risk assessment and technical measures including encryption in transit and at rest. You can request a copy of the safeguards in place by emailing privacy@iapexchange.com.

6. How long we keep it

Retention periods are set out in the table above. Where a period has expired we delete or irreversibly anonymise the data, except where we must retain it to comply with a legal obligation, establish or defend legal claims, or preserve the integrity of the tamper-evident audit chain — in which case the record is retained in restricted form for the period required.

7. Security

Access to platform data is restricted by role-based access control and row-level security, all traffic is served over TLS with HSTS, administrative actions are written to a hash-chained audit ledger, and signing keys are rotated on a fixed schedule.

8. Your rights

Under the UK GDPR you have the right to:

  • access a copy of your personal data;
  • have inaccurate data corrected;
  • have data erased where we have no continuing basis to hold it;
  • restrict or object to processing based on legitimate interests;
  • data portability where processing is by consent or contract and automated;
  • withdraw consent at any time, without affecting prior processing.

To exercise any of these, email privacy@iapexchange.com. We respond within one month. If you are unhappy with our response you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.

9. Cookies

Our use of cookies and similar technologies, including the full vendor list and how to change your preferences, is described in our cookie policy.

10. Changes

We update this notice when our processing changes. Material changes will be flagged on this page, and the “last updated” date above will change.