top of page

One ONYX - ONYX Solutions Privacy Policy

Last Updated/Reviewed:  15 June 2026.

Introduction

This is the Privacy Notice of ONYX Solutions Limited, a company incorporated under the laws of Guernsey with registration number 73826. Our registered office is at First Floor Premises, Cirrus House, Garenne Park, Rue de la Cache, St Sampson, Guernsey GY2 4AF.

This Notice informs our customers, website visitors, and those whose personal data we process about how we collect, use, store and protect personal information. Your privacy is of the highest importance to us.

 

As Data Controllers for the information you provide to us, and Data Processors where we process personal data on behalf of our clients, we are committed to protecting your privacy. This Notice provides transparency on how data is collected and used in order to meet our data protection obligations in accordance with The Data Protection (Bailiwick of Guernsey) Law, 2017 (the “Law”).

This Notice will be reviewed annually, or following any revision of the Law, and you will be notified of any material changes. It is important that the information we hold about you is accurate and up to date; should your circumstances change, please notify us promptly using the contact details below.

Our Data Protection Lead

Our Data Protection Lead (DPL) is Lindsay Fox, who can be contacted as follows:

  • Telephone: 07781146626

  • Email: lindsay@onyxsolutions.gg

  • In writing: First Floor Premises, Cirrus House, Garenne Park, Rue de la Cache, St Sampson, Guernsey GY2 4AF

 

The DPL is responsible for overseeing our data protection practices, including the use of artificial intelligence in our platforms. Any queries about the use of your personal data may be directed to the DPL using the contact details above.

Data Controller and Data Processor

ONYX Solutions Limited operates in different capacities depending on the context in which personal data is processed:

  • Data Controller: Where we collect and process personal data directly from individuals, or example, in connection with enquiries, newsletter subscriptions, recruitment, or website usage, ONYX Solutions Limited acts as the Data Controller and this Notice applies directly to you.

  • Data Processor: Where our platforms (including ONYX-SOS) are used by regulated firms (our clients) to process the personal data of their own customers and beneficial owners for purposes such as Customer Due Diligence (CDD) and risk assessment, ONYX Solutions Limited acts as a Data Processor on behalf of those regulated firms. In those circumstances, the regulated firm is the Data Controller and is responsible for providing its own privacy notice to the individuals whose data is being processed. Our processing in this capacity is governed by a Data Processing Agreement with the relevant client.

 

If you are uncertain which capacity applies to your situation, please contact our Data Protection Officer.

When Personal Data is collected and the Lawful Basis for Processing

General processing — legal obligation

We process personal data where this is necessary to exercise any right or power or perform or comply with any duty conferred or imposed on us. Personal data collected for this purpose is processed in accordance with the Law.

Any information supplied to us by email will be processed using standard website and email applications such as Wix.com, Microsoft Outlook and Exchange. We may also maintain a record within our Microsoft Office 365 database.

CDD and risk assessment processing via ONYX-SOS

Where personal data is processed through our ONYX-SOS platform in connection with Customer Due Diligence (CDD), risk assessment, or onboarding of clients of regulated firms, the lawful basis for processing is legal obligation — specifically, the obligations imposed on regulated firms under:

  • The Proceeds of Crime (Bailiwick of Guernsey) Law 2018;

  • The GFSC Handbook for Financial Crime Business (and any applicable sector-specific Handbooks);

  • Any other applicable anti-money laundering or counter-terrorist financing legislation or regulation applicable to the relevant regulated firm.

Processing of personal data for these purposes is necessary and proportionate to the performance of those obligations. It does not rely on consent and cannot be withdrawn on the basis that a data subject objects to such processing.

Newsletter Subscriptions

Where personal data is collected as part of our newsletter subscription process, it is processed solely for the purpose of sending you that information. The lawful basis is consent. You may withdraw your consent at any time by clicking the unsubscribe link included in each newsletter.

Enquiries by phone or in person

We process personal data by maintaining records within Microsoft Office 365 when enquiries are made by phone or in person, as necessary for us to exercise any right or power, or perform or comply with any duty, conferred or imposed on us as controller.

Use of Artificial Intelligence

ONYX Solutions Limited uses artificial intelligence (AI) technology within its ONYX-SOS platform to assist with the presentation and explanation of Customer Due Diligence and risk assessment outcomes for regulated firm clients.

How the AI layer works

Our AI layer operates on the following principles:

  • Human in the loop: The AI does not make any CDD-level, risk, or onboarding decisions. It presents and explains outcomes produced by our deterministic compliance rules engine, and cites the rules and regulatory guidance on which those outcomes are based. Every outcome is reviewed and confirmed by a qualified human reviewer before any action is taken. No decision affecting individuals is taken solely by automated means.

  • Grounded outputs: AI outputs are grounded in the GFSC Handbook and applicable regulatory rules. Every AI output carries a citation and a confidence indicator. Where confidence falls below our defined threshold, the output is escalated for human review rather than presented to the reviewer.

  • Data minimisation: Personal data is minimised and redacted before being passed to AI models. Raw personal data such as identity document numbers, full names, and addresses is not transmitted directly to AI models. The AI operates primarily on the compliance engine’s structured output and regulatory handbook text.

 

AI technology and sub-processors

We use the following Microsoft Azure AI services in connection with the ONYX-SOS AI layer. All AI processing is hosted within the EU/EEA. These services are listed in our sub-processor register and are subject to the Microsoft Data Processing Addendum:

  • Azure OpenAI Service — large language model inference (presenting and explaining compliance engine outputs)

  • Azure AI Search — vector search and retrieval of GFSC Handbook citations

  • Azure AI Document Intelligence — document parsing and analysis

  • Azure Blob Storage — secure document storage (passports, proof of address, source of funds evidence and other identity documents) retained for seven years in tenant-scoped containers with versioning and soft-delete protection

  • SharePoint — CDD pack synchronisation on Signature and Elite subscription tiers, providing regulated firm clients with a directly accessible copy of completed CDD records on their dedicated SharePoint site

 

Microsoft does not train its models on data processed through these services under our agreement. No processing under ONYX-SOS is transferred outside the EU/EEA.

Audit and accountability

Every AI-assisted step in ONYX-SOS is logged, recording the model and version used, the sources retrieved, the confidence level, and the decision made by the human reviewer. This log is retained for audit purposes in accordance with our retention policy and the requirements of applicable regulators.

Sharing of Information

Your data will only be shared with trusted service providers where a contract is in place with us. Our current service providers include:

  • Microsoft Corporation — Microsoft Office 365, Azure OpenAI Service, Azure AI Search, Azure AI Document Intelligence, Azure Blob Storage, SharePoint

  • Professional advisors

  • IT Consultants

  • Wix.com — website hosting and analytics

  • Software provider for ONYXTrack

  • Software provider for ONYXTrain

  • Software provider for ONYX-SOS (Compliance Intelligence platform)

  • Software provider for ONYX-Owls / Owlexa

 

Microsoft Office 365 (general business use)

Data processed by Microsoft Office 365 on our behalf for general business purposes (email, document management) may be transferred to, and stored and processed in, the United States or any other country in which Microsoft or its sub-processors operate, subject to appropriate safeguards under the Law.

ONYX-SOS AI processing (Azure AI services)

All processing undertaken through the ONYX-SOS platform using Azure OpenAI Service, Azure AI Search, Azure AI Document Intelligence, Azure Blob Storage, and SharePoint is pinned to an EU/EEA Azure region. This processing is not transferred outside the EU/EEA. These services are governed by the Microsoft Data Processing Addendum (version recorded in our sub-processor register, reviewed annually).

 

We will notify clients of any material changes to our sub-processors in accordance with our Data Processing Agreements. Any change to the Azure AI services used, or their data residency, will be communicated to affected clients in advance.

Any request for data made by a financial services regulator or public authority or governmental body with jurisdiction over us shall be complied with.

We shall only use sub-processors that offer at least the same level of protection for data as required by the Law.

Event Photography

We may take photographs and/or video footage at our events in which you may appear. We use these images for purposes such as documenting the event and promoting our services (for example on our website, social media, or in marketing materials). We retain event images only for as long as they are needed for these purposes and in line with our data retention practices. You have the right to request access to images that identify you, to object to our use of them, and in some circumstances to request their deletion. To exercise your rights, please contact us.

 

Data Retention

All personal data obtained will be retained securely and only used for the purposes set out in this Notice and the Law.

ONYX-SOS as system of record

ONYX-SOS retains all Client Data, including customer documents, structured CDD records, and AI-generated outputs, for seven years from the date of collection. This satisfies the GFSC Handbook minimum of five years from end of the business relationship and the Proceeds of Crime (Bailiwick of Guernsey) Law 2018 requirement. ONYX-SOS is the primary system of record for this data throughout that period. Longer retention may apply where required by law, regulation, or the Client’s written instructions.

What is retained and how

The seven-year retention applies across three categories:

  • Customer documents (passports, proof of address, source of funds evidence and other identity documents uploaded during onboarding) stored in secure Azure Blob Storage with tenant-scoped containers, versioning, and soft-delete protection;

  • Structured CDD data (risk assessments, questionnaire responses, compliance engine decisions, screening results, and periodic review records);

  • AI artifacts (prompts, retrieved text, AI outputs, citations, confidence scores, and human reviewer decisions) retained as an immutable audit log for the full seven-year period.

 

SharePoint synchronisation

On Signature and Elite subscription tiers, the complete CDD pack, including documents, risk assessment, AI outputs, and audit log is synchronised automatically to the regulated firm’s dedicated SharePoint site on completion of the CDD review. This provides the regulated firm with a directly accessible copy of their client’s CDD record. SharePoint synchronisation is a secondary access mechanism; ONYX-SOS remains the primary system of record.

Analytics

When using www.onyxsolutions.gg, we use Visitor Analytics through Wix.com. Visitor Analytics is a website analytics service which measures website traffic and visitors’ general details. We collect these statistics to enhance your experience (for example, which pages are visited and when, where visitors are approximately located, and where a user first lands on the site) and to improve our services.

We use cookies to collect data about visitors’ device type and screen size, approximate location, browser, operating system, IP address, page visits, bounce rate, conversions, and popular content. All data is pseudonymised and Visitor Analytics will not use it to identify individual users or match it with additional information on an individual. Each visitor has control over the placement of cookies. You can control and/or delete cookies via your browser settings — for details see aboutcookies.org.

Your Rights

You have a number of legal rights in relation to your personal data under the Law. These rights are summarised below. Full information can be found within the Law. Please write directly to us to make any request.

Right to information

You have the right to be given various information about the data we hold about you, including a statement as to whether your provision of personal data is a statutory or contractual requirement, whether you are obliged to provide it, and the possible consequences of failing to do so.

Right to data portability

You may ask us to move, or ‘port’, your personal information to another organisation electronically. We will only port personal information you have provided to us, that we have processed based on your consent or performance of a contract, or that has been processed automatically. We will port your personal information without charge and within one month where technically feasible.

Right of access

You have the right to request a copy of the information we hold about you by submitting a Subject Access Request.

Right to object

You have the right to require us to cease processing your data for direct marketing purposes, on grounds of public interest, or for historical or scientific purposes.

Right to rectification

You may ask us to correct, update or remove information you think is inaccurate or incomplete. We ask that you inform us promptly of any changes to your circumstances.

Right to erasure

You may ask us to erase your personal information from our systems in certain circumstances. There are specific circumstances where the right to erasure does not apply and we are permitted to retain your data; we will explain the reason at the time if this occurs.

Where personal data has been processed through the ONYX-SOS AI layer, erasure requests will include the removal of personal data from AI vector search indexes and any embeddings generated in connection with that data. We re-index our AI search index upon deletion to ensure no personal data persists in the system. This process is tested periodically to verify that re-identification from residual data is not possible.

Right to restriction of processing

You have the right to request that we restrict the processing of your data in certain circumstances. We will inform third parties to whom we have disclosed your data that they must also restrict processing, and we will inform you when the restriction ends.

Right not to be subject to solely automated decisions

You have the right not to be subject to a decision based solely on automated processing that produces a legal effect or similarly significantly affects you.

 

Where our ONYX-SOS platform uses AI-assisted processing in connection with CDD or risk assessment, no decision is taken solely by automated means. The AI layer presents and explains outcomes produced by our deterministic compliance rules engine; a qualified human reviewer reviews and confirms every outcome before any action is taken. The lawful basis for such processing is legal obligation (AML/CFT obligations) not consent.

If you believe a decision has been made about you using automated processing and you wish to request human review of that decision, or to understand the basis on which it was reached, please contact our Data Protection Lead.

 

Complaints

Should you wish to complain about our handling of your personal data, please do so in writing to the address stated in the Contact Us section below.

Section 67 of the Law provides a right for you to complain directly to the Office of the Data Protection Authority for the Bailiwick of Guernsey (ODPA). Sections 82 and 83 of the Law provide for rights of appeal.

 

Specific procedures can be found at www.odpa.gg.

ODPA contact details: Tel: 01481 742074 | Email: info@odpa.gg | Address: Block A, Lefebvre Court, Lefebvre Street, St Peter Port, Guernsey GY1 2JP.

Contact us

ONYX Solutions Limited can be contacted as follows:

Telephone: 07781146626

Email: enquiries@onyxsolutions.gg

Data Protection Lead: lindsay@onyxsolutions.gg

Registered Office Address:

First Floor Premises, Cirrus House, Garenne Park, Rue de la Cache, St Sampson,  Guernsey GY2 4AF

bottom of page