← Back to Pennix

Legal

Security & Data-Handling Brief

Last updated: 11 July 2026 · Version 1.0

Vera, Pennix intake agentMarco, Pennix intake agentLilly, Pennix intake agentAtlas, Pennix intake agent The Pennix Team
Vera · Marco · Lilly · Atlas
Plain-language summary — read with the full legal documents. This brief describes Pennix’s general data-handling posture. It is not a certification, audit report, legal opinion, or guaranteed service level, and it does not replace the Privacy Policy, Terms, Cookie Policy, or the applicable Data Processing Agreement. Specific configurations and the current named subprocessor list are available to customers on request.

This brief provides a plain-language overview of how Pennix intends to handle firm and client data. It is not a certification, audit report, legal opinion, or substitute for the final Data Processing Agreement, Terms, Privacy Policy, or firm-specific review.

Read this together with the other legal documents. This brief should be read alongside our Privacy Policy, Terms of Service, Cookie Policy, and the applicable Data Processing Agreement. Pennix should not be used with sensitive client information until your firm has reviewed and approved the applicable data-handling terms, subprocessors, storage locations, retention rules, access controls, and operational procedures.

01Access and permissions

Access to firm and client data should be limited to authorised people, systems, and service providers that require access to operate, support, secure, or maintain the Pennix service.

Our production environment applies controls including:

Access is restricted to authorised Pennix personnel and systems on a least-privilege basis, with authentication, session controls, and logging of privileged actions. Specific role and access configurations are maintained internally and available to customers on request.

Pennix may prepare client-communication drafts within the purchased package capacity. No statement on this page should be interpreted as a promise that messages are sent automatically. Firm review, approval, and sending controls must match the verified product configuration.

02Hosting, storage, and data location

Pennix may use third-party infrastructure providers to host, store, transmit, and process firm and client data.

Item Current status
Primary cloud provider Reputable third-party cloud infrastructure provider(s)
Primary hosting region United States
Database provider Managed database service within our cloud infrastructure
File-storage provider Managed object storage within our cloud infrastructure
Backup location Within our cloud provider’s United States infrastructure
Data-residency options Processed and stored in the United States; other arrangements available on request

Data is processed and stored in the United States. If regional data residency is required, contact us to discuss available options.

03Encryption and transmission

Pennix uses appropriate technical measures to protect data in transit and at rest, summarised below.

Control Current status
Encryption in transit TLS (HTTPS) for data in transit, consistent with the Privacy Policy
Encryption at rest Encryption at rest, as provided by our cloud infrastructure provider’s managed storage
Key-management provider Managed key service provided by our cloud infrastructure provider
Backup encryption Backups stored on encrypted cloud storage
File-transfer controls Transfers occur over encrypted (TLS) connections

These measures reflect our current configuration and the managed services we use; further technical detail is available to customers on request.

04Retention, export, and deletion

The table below summarises how long the main data categories are retained and how they are deleted.

Data category Retention period Deletion process
Customer account information Up to 24 months, or until deletion is requested, whichever is sooner (per the Privacy Policy) Deleted on request or at end of retention; residual copies expire from backups on the normal rotation cycle
Uploaded client documents Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle
Processed document output Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle
Drafted client emails Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle
Atlas query history Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle
Activity and audit records Retained for a limited period appropriate to security and record-keeping Expire on the applicable log-retention cycle
Backups Retained on a rolling basis Overwritten or expired on the backup rotation cycle
Support records Retained for a limited period after the matter is resolved Deleted on the applicable schedule or on request

The treatment of unused package capacity is governed by the Pennix purchase terms and is separate from the retention or deletion of customer data.

Customer export and deletion request procedures: requests may be made to info@getpennix.ai, and client-file data is returned or deleted in line with the applicable Data Processing Agreement, typically within ~30 days.

05AI processing and model providers

Pennix may use third-party AI, document-processing, storage, infrastructure, and communication services to perform parts of the Pennix workflow.

Processing category Provider Purpose Data location Retention or training terms
AI model provider Third-party AI / model provider(s) Generating drafts and processing intake content United States Configured so customer data is not used to train third-party foundation models (see Terms & DPA)
Document processing Third-party document-processing provider(s) Ingesting and extracting document content United States Not used to train third-party models (see Terms & DPA)
File storage Managed cloud storage Storing uploaded and processed files United States Not applicable
Email service Third-party email-delivery provider Delivering account and, where authorised, client communications United States Not applicable
Analytics or monitoring Operational monitoring only Service reliability and security United States Not used for advertising or model training

Where providers offer configuration options, Pennix configures them so customer data is not used to train third-party foundation models, consistent with our Terms and DPA. Applicable provider terms are available on request.

06Subprocessors

Subprocessors are third-party service providers that may process personal data on behalf of Pennix while supporting the operation of the service.

For each subprocessor, Pennix maintains:

Pennix engages a limited set of vetted subprocessors — cloud infrastructure, storage, email delivery, document processing, and AI model processing — under written contract. The current named list, with roles and locations, is available to customers on request and in the applicable Data Processing Agreement.

Material changes to the subprocessor list are notified to customers with a reasonable opportunity to object, as set out in the Data Processing Agreement.

07Logging, monitoring, and auditability

Pennix should maintain appropriate records of account activity, processing events, permission changes, administrative access, and system actions where technically and legally appropriate.

Control Current status
User activity logging Maintained for operational and security purposes
Administrative-access logging Maintained
Communication-draft history Retained within the account
Query history Retained within the account
Log-retention period A limited period appropriate to security and operational needs
Monitoring and alerting Operational monitoring and alerting in place
Customer audit-log access Available on request

Specific log detail, retention, and availability are provided to customers on request.

08Security incidents

Pennix must maintain an internal process for assessing, containing, documenting, and responding to suspected security incidents involving the service or customer data.

Our incident-response process addresses:

Pennix maintains an internal process to assess, contain, document, and respond to suspected security incidents, including notifying affected customers without undue delay where required. Further detail is available on request and in the Data Processing Agreement.

09Business continuity and backups

Pennix must define how it protects service availability, restores systems, and recovers customer data following an outage, technical failure, or provider disruption.

Item Current status
Backup frequency Regular automated backups
Backup retention Retained on a rolling basis
Restore testing Performed periodically
Recovery-time objective Addressed on a commercially reasonable basis; not guaranteed unless stated in an agreement
Recovery-point objective Addressed on a commercially reasonable basis; not guaranteed unless stated in an agreement
Business-continuity plan Maintained internally
Disaster-recovery plan Maintained internally

Pennix does not guarantee specific uptime or recovery times unless those commitments are included in a signed service agreement.

10Customer responsibilities

Each customer remains responsible for determining whether Pennix is appropriate for its legal, professional, regulatory, contractual, and client-confidentiality obligations.

Customers are responsible for:

Pennix does not replace the customer’s professional review, tax judgment, legal obligations, or responsibility to clients.

11Client communication controls

Pennix packages include capacity for drafting client emails. Drafting is not the same as sending.

Unless the live product and account configuration have been separately verified to support automatic sending, all Pennix-generated client communication must be treated as a draft for firm review and approval.

Current sending and approval controls: Pennix generates client communications as drafts that are held for firm review. Outbound sending is controlled by the firm’s designated authorised approver, and automatic sending is not promised.

12Product and professional boundaries

Pennix is an AI-assisted intake-processing tool for tax and accounting firms.

Pennix does not:

All Pennix-assisted output should be reviewed under the firm’s normal professional and quality-control procedures.

13Certifications, attestations, and security claims

Pennix does not currently claim any certification, audit result, regulatory approval, or formal security attestation unless it is specifically identified below with its scope, date, and issuing body.

Certification or attestation Status
SOC 2 Not claimed
ISO 27001 Not claimed
HIPAA compliance Not claimed
IRS approval Not claimed
PCI DSS certification Not claimed unless separately verified
Independent penetration test Not claimed
External vulnerability assessment Not claimed

Pennix does not use “bank-grade,” “military-grade,” or similar promotional security language.

If a certification, audit, or attestation is obtained later, this page must identify the exact scope, date, issuing body, and any limitations.

14Privacy and data-processing terms

The final Privacy Policy, Terms, Data Processing Agreement, and any customer-specific data-handling commitments must be read together.

Pennix’s legal and data-processing framework covers:

Current legal and privacy details:

Legal entityPennix LLC, a Wyoming limited liability company
Operating address308 N Fairfield Rd, Devon, PA 19333, USA
GroupPart of the Peregrine X group
Privacy, security & data-protection contactinfo@getpennix.ai
Governing lawState of Wyoming, USA, and applicable US federal law
Contracting jurisdiction / venueState and federal courts located in the State of Wyoming and the Commonwealth of Pennsylvania, USA
Controller / processor rolesController for website and application data; processor for client-file data under a Data Processing Agreement
International-transfer mechanismStandard Contractual Clauses, the UK International Data Transfer Agreement, or adequacy decisions
Data-subject requests & complaintsVia info@getpennix.ai; see the Privacy Policy

15Requesting additional information

Before using Pennix with sensitive client information, request and review the current:

Privacy contact: info@getpennix.ai

Security contact: info@getpennix.ai

Summary only. This brief describes Pennix’s general data-handling posture and is not a certification, audit result, or guaranteed service level. The current named subprocessor list, specific configurations, and the applicable Data Processing Agreement are available to customers on request before onboarding sensitive client information.
← Return to the Pennix site