Privacy notice
How Inter-Agent Protocol Ltd handles personal data under the UK GDPR and the Data Protection Act 2018.
Last updated: 21 August 2026
1. Who we are
Inter-Agent Protocol Ltd (“IAP Exchange”, “we”) is the data controller for the personal data described in this notice. We are registered in England and Wales and operate from the United Kingdom.
- Controller: Inter-Agent Protocol Ltd
- Registered office: United Kingdom
- Privacy contact: privacy@iapexchange.com
We have not appointed a statutory Data Protection Officer; privacy questions are handled by the address above.
2. Where we get personal data
Directly from you when you complete an enquiry form, request data-room access or use the control centre; automatically from your device when you browse the site; and occasionally from your employer when they nominate you as a user or accountable person.
IAP Exchange is infrastructure for agent-to-agent transactions between institutions. Transaction and agent records processed through the platform are institutional data, but may contain limited personal data such as the named accountable person and the operator who approved an exception.
3. What we collect, why, and on what legal basis
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Responding to technical briefing, design partner and investor enquiries | Name, work email, job title, institution, fund name, message content | Legitimate interests (Art. 6(1)(f)) — responding to a business enquiry you initiated | 24 months from last contact, then deleted |
| Granting and administering access to the IAP Exchange control centre | Account email, authentication identifiers, role and approval status, institution affiliation | Contract (Art. 6(1)(b)) — providing the platform you or your employer have signed up for | Duration of the account plus 12 months |
| Security, fraud prevention and tamper-evident audit logging of platform actions | User identifier, timestamps, IP address, action performed, hash-chained audit records | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) — platform integrity | 6 years, in line with UK financial-services record-keeping expectations |
| Operating and securing the website (essential cookies, error and abuse monitoring) | IP address, browser and device information, session identifiers, error diagnostics | Legitimate interests (Art. 6(1)(f)) — keeping the site available and secure | Up to 13 months |
| Sending occasional product or funding updates where you have asked for them | Name, email, preferences | Consent (Art. 6(1)(a)) — withdrawable at any time | Until you withdraw consent, then suppression-list only |
We do not carry out automated decision-making producing legal effects about you, and we do not knowingly collect special category data. Please do not include it in enquiry forms.
4. Who we share it with
We share personal data only with processors acting on our instructions, and with professional advisers or regulators where we are legally required to.
- Hosting and application platform — Lovable / Cloudflare, for serving the website and running application logic.
- Database, authentication and storage — Supabase, for accounts, platform records and audit logs.
- Email delivery — used to send transactional messages such as sign-in and approval notifications.
- Professional advisers — legal, accounting and audit firms, under duties of confidentiality.
We do not sell personal data and we do not share it with advertising networks.
5. International transfers
Our primary hosting and database infrastructure is located in the United Kingdom and the European Economic Area. Some suppliers process data in the United States or other third countries.
Where personal data leaves the UK to a country without UK adequacy regulations, we rely on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, supported by a transfer risk assessment and technical measures including encryption in transit and at rest. You can request a copy of the safeguards in place by emailing privacy@iapexchange.com.
6. How long we keep it
Retention periods are set out in the table above. Where a period has expired we delete or irreversibly anonymise the data, except where we must retain it to comply with a legal obligation, establish or defend legal claims, or preserve the integrity of the tamper-evident audit chain — in which case the record is retained in restricted form for the period required.
7. Security
Access to platform data is restricted by role-based access control and row-level security, all traffic is served over TLS with HSTS, administrative actions are written to a hash-chained audit ledger, and signing keys are rotated on a fixed schedule.
8. Your rights
Under the UK GDPR you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have data erased where we have no continuing basis to hold it;
- restrict or object to processing based on legitimate interests;
- data portability where processing is by consent or contract and automated;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these, email privacy@iapexchange.com. We respond within one month. If you are unhappy with our response you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
9. Cookies
Our use of cookies and similar technologies, including the full vendor list and how to change your preferences, is described in our cookie policy.
10. Changes
We update this notice when our processing changes. Material changes will be flagged on this page, and the “last updated” date above will change.
