Legal
Privacy Policy
Last updated 17 September 2026.
Privacy Policy · Terms of Service
This Privacy Policy explains how PRIME AX LTD (“Prime”, “we”, “us”) processes personal data when you use our marketing site (https://prime.ax), customer portal (https://portal.prime.ax), and related products and apps (including Prime and Safety mobile apps).
We are a company registered in England and Wales (company number 16992174). For privacy requests email .
1. Who this applies to
This policy covers personal data we process when you:
- browse or contact us via prime.ax;
- create or use a Prime account on the portal;
- use hosted mail, domains, websites, phone, Workspace/CRM, billing, eSign, Identity, eSIM, or support tickets;
- use the Prime or Safety mobile apps, including Safety features when your account is entitled to them.
2. Data we collect
We collect only what is needed to provide the services you use. Categories include:
Account and authentication
- Name, email address, phone number (if provided), password (stored as a hash), role and organisation/tenant association.
- Session and sign-in records needed to keep you logged in and secure the account.
- Optional multi-factor authentication secrets where MFA is enabled.
Portal, Workspace and CRM
- Business and customer records you or your organisation store (for example companies, contacts, deals and related activity).
- Support tickets and messages you send to us or within your organisation.
- Operational notifications shown in the portal or apps.
Billing and payments
- Invoice and billing details tied to your account or organisation.
- Payment processing via payment processors (for example customer and payment references used to complete a charge). Card details are handled by the payment processor; we do not store full card numbers on Prime servers.
Mail, hosting and domains
- Mailbox configuration and, when you use Prime Webmail or mail products, message content required to deliver those services.
- Domain and hosting configuration needed to provision and manage services (including integration with hosting, DNS and infrastructure providers where those services are configured for your account).
Phone
- Where you use Prime Phone, call and SMS metadata and numbers provisioned through our communications providers, as needed to operate the service.
Identity (KYC) and eSign
- Where you use Prime Identity: identity document images, extracted document data, and selfie / liveness evidence required to complete verification. Optional biometric / identity-verification providers are used only when configured for that check.
- Where you use eSign: documents, signer details, and signature evidence for the signing workflow.
eSIM and shop orders
- Order, fulfilment and install details for products purchased through the public shop or portal catalogue.
Safety features (when entitled)
Safety capabilities (live location, location history, SOS / medical alerts, check-ins, journeys, trusted contacts, and related desk tools) are available only when your organisation or account is entitled. When those features are used we may process:
- Device registration details and push notification tokens (including Critical Alerts on supported devices where permitted).
- Live and historical location coordinates, timestamps, and reverse-geocoded address labels (via map / geocoding services).
- SOS and medical alert records, desk communications, check-ins and journey status.
- Emergency / trusted contact details you configure.
- Optional care-profile fields you choose to provide (for example medical conditions, medications, allergies, blood type and related notes). Sensitive care fields are encrypted at rest when encryption is configured on the server.
Mobile apps and notifications
- App and device identifiers needed to deliver push notifications and Safety features.
- Permission states you grant on the device (for example location, notifications, Critical Alerts).
Marketing site contact
- Name, email, phone and message content you submit via the contact or registration forms on prime.ax.
Technical logs
- Server and security logs (for example IP address, user agent, timestamps and error diagnostics) used to operate, secure and troubleshoot the service.
3. How we use personal data
- To create and manage accounts, authenticate users and provide the products you subscribe to.
- To process payments, issue invoices and manage billing.
- To deliver mail, hosting, domains, phone, Workspace, eSign, Identity, eSIM and support.
- To operate Safety features you are entitled to use, including alerting trusted people or the Safety desk when you trigger SOS or medical alerts.
- To send service messages (for example billing, security and product notices). Marketing messages are only sent where permitted.
- To maintain security, prevent abuse, comply with law and improve reliability.
Under UK GDPR, we typically rely on: performance of a contract; legitimate interests (securing and operating the platform); legal obligation; and consent where required (for example certain device permissions or optional marketing).
4. Sharing and processors
We do not sell personal data. We share data with processors and partners only as needed to run Prime, including:
- Payment processors — payments and related billing events.
- Communications providers — phone numbers, voice and SMS where Phone is used.
- Device push notification services — delivery of push notifications (and Critical Alerts where enabled on supported devices).
- Hosting, DNS and infrastructure providers — where those services are configured for your account.
- Map and geocoding services — reverse geocoding of Safety coordinates into address labels.
- Email delivery — sending transactional mail from Prime.
- Identity verification providers — only when Identity checks are configured to use an external biometric provider.
Organisation administrators and authorised staff in your tenant may access data belonging to that organisation (including Safety desk tools where enabled). We may disclose data if required by law or to protect rights, safety and security.
5. International transfers
Our primary systems are operated for UK customers. Some processors (for example payment processors, communications providers, device push notification services, or an optional Identity biometric provider) may process data outside the UK. Where that happens we use appropriate safeguards required by UK data protection law.
6. Retention
We keep personal data for as long as needed to provide the service, meet legal and accounting duties, resolve disputes and enforce agreements. Examples:
- Account and billing records are retained while the account is active and for a reasonable period afterwards for legal and financial records.
- Mail, ticket and CRM content follows product settings and operational need.
- Safety location history and related records are retained to operate monitoring and incident response, then deleted or anonymised when no longer required.
- Safety in-app direct messages are subject to short soft retention (approximately 30 days); SOS and incident records are managed separately.
7. Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict or object to certain processing, and to data portability. You may also complain to the UK Information Commissioner’s Office (ICO).
To exercise rights, email . For Safety account deletion, the Safety app / portal flow can raise a deletion request ticket; staff complete erasure after review (self-service purge is not available).
8. Children
Prime services are aimed at businesses and adult users. We do not knowingly offer accounts to children for these products.
9. Cookies and similar technologies
The marketing site (prime.ax) does not use non-essential analytics or advertising cookies. The portal and apps use cookies or local storage that are necessary for sign-in, security and core functionality. Payment pages may involve cookies set by our payment processor on their domains. Because we do not set non-essential tracking cookies on the public marketing site, we do not show a separate cookie banner there.
10. Security
We use technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, access controls, and encryption at rest for certain sensitive Safety care-profile fields when server encryption is configured. No method of transmission or storage is perfectly secure.
11. Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the services after an update means you should review the revised policy.
12. Contact
PRIME AX LTD
Privacy / support:
Portal: https://portal.prime.ax
Website: https://prime.ax
Related: Terms of Service.