1. Regulatory Standing & Sovereign Data Controller
ReguLex.uk ("ReguLex", "the Platform", "we") operates as an institutional statutory risk bureau and automated compliance platform for UK chartered accountants and corporate service providers. ReguLex is owned and operated by The Quite Good Project. For the purposes of the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR), we act as an independent data controller in respect of public registry intelligence, and as a data processor on behalf of appointed accountancy practices utilizing the Practice Sentinel Suite.
2. Lawful Basis for Processing Companies House Data
ReguLex indexes, normalizes, and monitors records officially published by the Registrar of Companies for England & Wales, Scotland, and Northern Ireland under the Crown Open Government Licence (OGL v3.0). Our processing of corporate statutory filings, officer appointments, registered office addresses, and London Gazette strike-off notices is conducted under:
- Article 6(1)(f) UK GDPR (Legitimate Interests): The vital public and commercial interest in assisting regulated accountancy practices and corporate directors to maintain statutory compliance under the Economic Crime and Corporate Transparency Act 2023 (ECCTA), preventing fraudulent registered office appointments, and averting irreparable corporate bank account freezes under CA 2006 s.1000.
- Article 6(1)(c) UK GDPR (Legal Obligation): Assisting authorized practice occupiers in fulfilling their mandatory statutory duties under ECCTA 2023 s.28 and executing Form RP07 address eviction procedures.
3. Business-to-Business Communications (PECR Compliance)
Outbound notifications dispatched by ReguLex Sentinel regarding impending First Gazette strike-off notices, director IDV deadlines, or registered office address misuse are strictly directed to corporate subscribers (UK limited companies, LLPs, and professional accountancy partnerships) pursuant to Regulation 22 of the Privacy and Electronic Communications Regulations 2003 (PECR). Every statutory notice includes a direct, single-click opt-out mechanism and the contact credentials of the data governance team.
4. Sovereign Data Residency & Sub-Processors
To ensure complete compliance with UK data sovereignty mandates and professional body standards (ICAEW, ACCA, ICAS), all customer data and platform operations reside strictly within verified UK and European Union infrastructure:
| Sub-Processor | Purpose | Sovereign Jurisdiction | Security Standard |
|---|---|---|---|
| DigitalOcean LON1 | Production Node Compute & API Engine | London, United Kingdom | ISO 27001 / SOC 2 Type II |
| Cloudflare LHR | Edge Reverse Proxy, DDoS & SSL Termination | London, United Kingdom | ISO 27001 / SOC 2 / PCI-DSS |
| Supabase EU West 1 | Encrypted Relational Data Store | Dublin, European Union | SOC 2 Type II / HIPAA / AES-256 |
| Mailgun EU | Statutory Notice Dispatch Gateway | European Union (EU-Only Transit) | ISO 27001 / GDPR Binding Corporate Rules |
5. Practitioner Rights & Contact Point
Under UK GDPR Articles 15 through 21, practitioners and directors hold the right to request access to, rectification of, or erasure of their personal information held outside the public statutory record. Direct all privacy inquiries and statutory representations to our appointed Data Governance Officer at [email protected].