Legal
Security & Data-Handling Brief
Last updated: 11 July 2026 · Version 1.0
Vera · Marco · Lilly · Atlas
This brief provides a plain-language overview of how Pennix intends to handle firm and client data. It is not a certification, audit report, legal opinion, or substitute for the final Data Processing Agreement, Terms, Privacy Policy, or firm-specific review.
Contents
- Access and permissions
- Hosting, storage & data location
- Encryption and transmission
- Retention, export & deletion
- AI processing & model providers
- Subprocessors
- Logging, monitoring & auditability
- Security incidents
- Business continuity & backups
- Customer responsibilities
- Client communication controls
- Product & professional boundaries
- Certifications & security claims
- Privacy & data-processing terms
- Requesting additional information
01Access and permissions
Access to firm and client data should be limited to authorised people, systems, and service providers that require access to operate, support, secure, or maintain the Pennix service.
Our production environment applies controls including:
- User roles and permissions
- Administrative-access rules
- Internal support access
- Authentication requirements
- Password requirements
- Session controls
- Account deactivation procedures
- Access-review frequency
- Logging of privileged actions
- Emergency-access procedures
Access is restricted to authorised Pennix personnel and systems on a least-privilege basis, with authentication, session controls, and logging of privileged actions. Specific role and access configurations are maintained internally and available to customers on request.
Pennix may prepare client-communication drafts within the purchased package capacity. No statement on this page should be interpreted as a promise that messages are sent automatically. Firm review, approval, and sending controls must match the verified product configuration.
02Hosting, storage, and data location
Pennix may use third-party infrastructure providers to host, store, transmit, and process firm and client data.
| Item | Current status |
|---|---|
| Primary cloud provider | Reputable third-party cloud infrastructure provider(s) |
| Primary hosting region | United States |
| Database provider | Managed database service within our cloud infrastructure |
| File-storage provider | Managed object storage within our cloud infrastructure |
| Backup location | Within our cloud provider’s United States infrastructure |
| Data-residency options | Processed and stored in the United States; other arrangements available on request |
Data is processed and stored in the United States. If regional data residency is required, contact us to discuss available options.
03Encryption and transmission
Pennix uses appropriate technical measures to protect data in transit and at rest, summarised below.
| Control | Current status |
|---|---|
| Encryption in transit | TLS (HTTPS) for data in transit, consistent with the Privacy Policy |
| Encryption at rest | Encryption at rest, as provided by our cloud infrastructure provider’s managed storage |
| Key-management provider | Managed key service provided by our cloud infrastructure provider |
| Backup encryption | Backups stored on encrypted cloud storage |
| File-transfer controls | Transfers occur over encrypted (TLS) connections |
These measures reflect our current configuration and the managed services we use; further technical detail is available to customers on request.
04Retention, export, and deletion
The table below summarises how long the main data categories are retained and how they are deleted.
| Data category | Retention period | Deletion process |
|---|---|---|
| Customer account information | Up to 24 months, or until deletion is requested, whichever is sooner (per the Privacy Policy) | Deleted on request or at end of retention; residual copies expire from backups on the normal rotation cycle |
| Uploaded client documents | Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) | Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle |
| Processed document output | Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) | Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle |
| Drafted client emails | Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) | Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle |
| Atlas query history | Returned or deleted within ~30 days of the activation/plan ending, or on written instruction (per the DPA) | Deleted from active systems at end of term or on written instruction; residual copies expire from backups on the normal rotation cycle |
| Activity and audit records | Retained for a limited period appropriate to security and record-keeping | Expire on the applicable log-retention cycle |
| Backups | Retained on a rolling basis | Overwritten or expired on the backup rotation cycle |
| Support records | Retained for a limited period after the matter is resolved | Deleted on the applicable schedule or on request |
The treatment of unused package capacity is governed by the Pennix purchase terms and is separate from the retention or deletion of customer data.
Customer export and deletion request procedures: requests may be made to info@getpennix.ai, and client-file data is returned or deleted in line with the applicable Data Processing Agreement, typically within ~30 days.
05AI processing and model providers
Pennix may use third-party AI, document-processing, storage, infrastructure, and communication services to perform parts of the Pennix workflow.
| Processing category | Provider | Purpose | Data location | Retention or training terms |
|---|---|---|---|---|
| AI model provider | Third-party AI / model provider(s) | Generating drafts and processing intake content | United States | Configured so customer data is not used to train third-party foundation models (see Terms & DPA) |
| Document processing | Third-party document-processing provider(s) | Ingesting and extracting document content | United States | Not used to train third-party models (see Terms & DPA) |
| File storage | Managed cloud storage | Storing uploaded and processed files | United States | Not applicable |
| Email service | Third-party email-delivery provider | Delivering account and, where authorised, client communications | United States | Not applicable |
| Analytics or monitoring | Operational monitoring only | Service reliability and security | United States | Not used for advertising or model training |
Where providers offer configuration options, Pennix configures them so customer data is not used to train third-party foundation models, consistent with our Terms and DPA. Applicable provider terms are available on request.
06Subprocessors
Subprocessors are third-party service providers that may process personal data on behalf of Pennix while supporting the operation of the service.
For each subprocessor, Pennix maintains:
- Legal provider name
- Service provided
- Data categories processed
- Processing purpose
- Processing location
- Contractual role
- Link to the provider’s privacy or security information
- Whether the provider may appoint additional subprocessors
Pennix engages a limited set of vetted subprocessors — cloud infrastructure, storage, email delivery, document processing, and AI model processing — under written contract. The current named list, with roles and locations, is available to customers on request and in the applicable Data Processing Agreement.
Material changes to the subprocessor list are notified to customers with a reasonable opportunity to object, as set out in the Data Processing Agreement.
07Logging, monitoring, and auditability
Pennix should maintain appropriate records of account activity, processing events, permission changes, administrative access, and system actions where technically and legally appropriate.
| Control | Current status |
|---|---|
| User activity logging | Maintained for operational and security purposes |
| Administrative-access logging | Maintained |
| Communication-draft history | Retained within the account |
| Query history | Retained within the account |
| Log-retention period | A limited period appropriate to security and operational needs |
| Monitoring and alerting | Operational monitoring and alerting in place |
| Customer audit-log access | Available on request |
Specific log detail, retention, and availability are provided to customers on request.
08Security incidents
Pennix must maintain an internal process for assessing, containing, documenting, and responding to suspected security incidents involving the service or customer data.
Our incident-response process addresses:
- Incident-response owner
- Internal escalation procedure
- Technical containment process
- Customer notification process
- Notification timelines
- Regulator-notification responsibilities
- Evidence preservation
- Post-incident review
- Subprocessor incident escalation
Pennix maintains an internal process to assess, contain, document, and respond to suspected security incidents, including notifying affected customers without undue delay where required. Further detail is available on request and in the Data Processing Agreement.
09Business continuity and backups
Pennix must define how it protects service availability, restores systems, and recovers customer data following an outage, technical failure, or provider disruption.
| Item | Current status |
|---|---|
| Backup frequency | Regular automated backups |
| Backup retention | Retained on a rolling basis |
| Restore testing | Performed periodically |
| Recovery-time objective | Addressed on a commercially reasonable basis; not guaranteed unless stated in an agreement |
| Recovery-point objective | Addressed on a commercially reasonable basis; not guaranteed unless stated in an agreement |
| Business-continuity plan | Maintained internally |
| Disaster-recovery plan | Maintained internally |
Pennix does not guarantee specific uptime or recovery times unless those commitments are included in a signed service agreement.
10Customer responsibilities
Each customer remains responsible for determining whether Pennix is appropriate for its legal, professional, regulatory, contractual, and client-confidentiality obligations.
Customers are responsible for:
- Having a lawful basis to upload and process client information
- Providing required client notices
- Obtaining any required client consents
- Limiting user access to authorised personnel
- Protecting login credentials
- Reviewing Pennix-assisted output
- Reviewing client-email drafts before sending
- Maintaining professional judgment and responsibility
- Following applicable tax, accounting, privacy, and professional rules
- Removing data that should not be processed through Pennix
- Promptly reporting suspected unauthorised access
Pennix does not replace the customer’s professional review, tax judgment, legal obligations, or responsibility to clients.
11Client communication controls
Pennix packages include capacity for drafting client emails. Drafting is not the same as sending.
Unless the live product and account configuration have been separately verified to support automatic sending, all Pennix-generated client communication must be treated as a draft for firm review and approval.
Current sending and approval controls: Pennix generates client communications as drafts that are held for firm review. Outbound sending is controlled by the firm’s designated authorised approver, and automatic sending is not promised.
12Product and professional boundaries
Pennix is an AI-assisted intake-processing tool for tax and accounting firms.
Pennix does not:
- Prepare tax returns
- Provide tax advice
- Provide legal advice
- Replace professional review
- Replace professional judgment
- Guarantee document accuracy
- Guarantee file readiness
- Guarantee client responses
- Guarantee time or cost savings
- Guarantee regulatory compliance
- Guarantee uninterrupted availability
- Automatically approve client communication
All Pennix-assisted output should be reviewed under the firm’s normal professional and quality-control procedures.
13Certifications, attestations, and security claims
Pennix does not currently claim any certification, audit result, regulatory approval, or formal security attestation unless it is specifically identified below with its scope, date, and issuing body.
| Certification or attestation | Status |
|---|---|
| SOC 2 | Not claimed |
| ISO 27001 | Not claimed |
| HIPAA compliance | Not claimed |
| IRS approval | Not claimed |
| PCI DSS certification | Not claimed unless separately verified |
| Independent penetration test | Not claimed |
| External vulnerability assessment | Not claimed |
Pennix does not use “bank-grade,” “military-grade,” or similar promotional security language.
If a certification, audit, or attestation is obtained later, this page must identify the exact scope, date, issuing body, and any limitations.
14Privacy and data-processing terms
The final Privacy Policy, Terms, Data Processing Agreement, and any customer-specific data-handling commitments must be read together.
Pennix’s legal and data-processing framework covers:
- Pennix legal entity
- Registered address
- Privacy contact
- Security contact
- Data-protection contact, if applicable
- Governing law
- Contracting jurisdiction
- Data-controller and data-processor roles
- International-transfer mechanism
- Data-subject request process
- Complaint process
Current legal and privacy details:
| Legal entity | Pennix LLC, a Wyoming limited liability company |
| Operating address | 308 N Fairfield Rd, Devon, PA 19333, USA |
| Group | Part of the Peregrine X group |
| Privacy, security & data-protection contact | info@getpennix.ai |
| Governing law | State of Wyoming, USA, and applicable US federal law |
| Contracting jurisdiction / venue | State and federal courts located in the State of Wyoming and the Commonwealth of Pennsylvania, USA |
| Controller / processor roles | Controller for website and application data; processor for client-file data under a Data Processing Agreement |
| International-transfer mechanism | Standard Contractual Clauses, the UK International Data Transfer Agreement, or adequacy decisions |
| Data-subject requests & complaints | Via info@getpennix.ai; see the Privacy Policy |
15Requesting additional information
Before using Pennix with sensitive client information, request and review the current:
- Security and Data-Handling Brief
- Privacy Policy
- Terms
- Data Processing Agreement
- Subprocessor list
- Retention and deletion schedule
- Incident-notification terms
- Hosting and data-location information
Privacy contact: info@getpennix.ai
Security contact: info@getpennix.ai