Security & data protection
Your business data is precious.
Here’s exactly how we keep it safe — in plain English, no marketing puffery.
AES-256 encryption
Encrypted in transit (TLS 1.2+) and at rest at the storage layer (AES-256, provided by Supabase managed Postgres). Passwords are hashed with bcrypt — we cannot read them, even in an emergency.
Row-Level Security
Database access is gated at the row level. Every user-scoped query also carries an explicit user-id filter on top of RLS, so a policy misconfiguration cannot leak another user’s data — you get zero rows, not the wrong rows.
Read-only AI assistant
The calendar assistant can only read your own records — invoices, clients, deadlines. It cannot send emails, delete data, edit records, browse the web, or reach any other user. Every query is logged.
Bank details masked by default
Your account number and sort code are hidden by default in Settings and on the public payment page. Only the last few digits show — the rest is revealed only when you (or your customer) tap to show.
EU-hosted infrastructure
Data stored in EU regions on Supabase managed Postgres, with automatic daily backups and 30-day point-in-time recovery.
UK GDPR compliant
Full UK GDPR compliance. You own your data. Export or permanently delete it any time from Settings.
We never sell data
No ads, no data resale, no analytics partnerships that share customer data. You pay £15/month — we provide software. That’s it.
Vulnerability disclosure
Acknowledged within 24 hours; initial assessment within 72. ICO + HMRC notified within 72 hours of any confirmed personal-data breach.
What we store
We hold only what’s necessary to run the app:
- · Your business details (name, address, bank details for invoices)
- · Your customers’ details (names, addresses, emails)
- · Invoice data (job descriptions, amounts, dates)
- · Your email and a hashed password (we can’t see your password)
Card details are handled directly by Stripe — we never see them. Bank details for invoice payment are masked by default in the app and on the public payment page.
When you use the AI assistant, your question and the relevant records it reads are sent to Anthropic (the makers of Claude) for processing. Anthropic’s commercial API terms apply — your data is not used to train their models.
Your rights
Under UK GDPR you have the right to:
- · Access — download everything we hold on you
- · Rectification — correct incorrect data
- · Erasure — permanently delete your account and data
- · Portability — export in a common machine-readable format
All four are available instantly from Settings › Account.
Reporting a security incident
Found a vulnerability? Tell us immediately.
If you discover a vulnerability, suspect unauthorised access to your account, or believe your data has been compromised, contact us straight away.
- Email: v.l.hawley@hotmail.com
- Or via: our contact form
Reports acknowledged within 24 hours; initial assessment within 72. If a personal-data breach is confirmed, we notify the Information Commissioner’s Office and HMRC within 72 hours, and email every affected customer directly with what happened, what data was involved, and the steps to take.
Full Security Incident & Data Breach Response Policy available on request.
Questions about security?
Email goes straight to Vix. No support tickets, no offshore call centres.
Contact us