Privacy Policy.
Last updated · 2026-06-17
/01 What we collect
Identifying data: full name, email, country of residence. Optional: address, postal code, phone.
Payment data (only for paid roles): IBAN/SWIFT/PAN/crypto wallet — collected when you add a payment method. Stored encrypted with AES-256-GCM.
Operational data: applications you submit, payouts, chat messages, audit-log events, session metadata (user agent, IP, login times).
/02 Why we collect it
Identity and contact: to evaluate applications and reach you about payouts.
Payment data: to execute manual withdrawals through the rail you choose.
Audit log: to maintain an immutable trail of who did what, for safety and finance reconciliation.
/03 Data controller
The data controller is ISPLABS LIMITED (Company number 16958848), 128 City Road, London, United Kingdom, EC1V 2NX, operating the Phylex brand. Contact for all privacy matters: help@phylex.net.
We do not currently maintain an establishment in the EU; UK residents and EU residents may contact us at the same address. Where required we will appoint a representative and publish their details here.
/04 Legal bases for processing
Performance of a contract: operating your account, evaluating applications, and executing the payouts you request.
Legal obligation: anti-money-laundering, sanctions, tax, and accounting record-keeping.
Legitimate interests: platform security, fraud prevention, audit logging, and service improvement — balanced against your rights.
Consent: optional marketing emails only. You can withdraw consent at any time from Settings without affecting other processing.
/05 How it's stored
PII (address, postal code, phone) — encrypted at rest with AES-256-GCM (PII key).
Payment data — encrypted at rest with AES-256-GCM (separate PAYMENT key). Reveal requires a written reason that's logged with actor, timestamp, IP.
Passwords — argon2id, OWASP 2024 baseline parameters.
Refresh tokens — SHA-256 hashes only.
/06 Who can access what
Workers see their own data. Curators see chat threads for assigned workers and basic profile data. Finance can see payout-relevant data including masked payment-method details; reveal requires a reason.
Admins can see everything but every access to sensitive fields is logged with the reason given.
/07 Sharing & sub-processors
We do not sell, share, or trade personal data for marketing. We disclose data only when legally compelled (court order, regulator), and where possible we notify the affected user.
We use vetted sub-processors, by category: cloud hosting and database, transactional email delivery, security monitoring, accounting, and payment/payout execution rails. Each is bound by a data-processing agreement. A current list of named sub-processors is available on request at help@phylex.net.
/08 International transfers
Our infrastructure and some sub-processors may process data outside the UK and EEA. Where that happens we rely on an adequacy decision, the UK International Data Transfer Agreement (IDTA) / Addendum, or the EU Standard Contractual Clauses, together with technical safeguards (encryption in transit and at rest).
/09 How long we keep it
Account and profile data: for the life of the account, then deleted or anonymised within 30 days of closure.
Financial, payout, KYC and AML records: retained up to 6 years after the relevant transaction to meet legal and accounting obligations, even after account closure.
Audit logs and security events: retained up to 24 months for fraud investigation and reconciliation.
Backups: rotated on a rolling basis and overwritten within 35 days.
/10 Your rights
Under the UK GDPR and EU GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing, and the right to withdraw consent at any time.
To exercise any right, contact help@phylex.net. We verify the requester's identity before exporting or deleting data and respond within one month. Outstanding payouts must complete and legally-required records may be retained.
You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF — ico.org.uk. EU residents may complain to their local data protection authority.
/11 Cookies
We use first-party cookies for authentication (access token, refresh token), theme preference, and 2FA challenges. No third-party tracking or advertising cookies.
/12 Contact
Operator: ISPLABS LIMITED, Company number 16958848, 128 City Road, London, United Kingdom, EC1V 2NX.
Privacy questions: help@phylex.net. Security and abuse disclosures: abuse@phylex.net.