Where we stand — including what we have not done yet.
Compliance pages are easy to inflate. This one sets out our data-protection roles, the arrangements we have with service providers, the documentation available for vendor reviews, and the certifications we do not hold.
Last updated: August 2026
UK company
10x Galaxy Ltd, United Kingdom
Controller & processor
Role depends on the data
DPA available
On request
No certifications held
Stated only when obtained
Our compliance position, stated plainly
This page describes where FixRank actually stands, so procurement teams can assess us without guessing. It is deliberately conservative: if something is not in place, it is listed as not in place.
FixRank AI is operated by 10x Galaxy Ltd, a company registered in the United Kingdom. Our practices are designed with UK and EU data-protection obligations in mind.
No certifications claimed
FixRank does not hold SOC 2, ISO 27001, PCI DSS, or HIPAA certification, and is not “GDPR certified” — GDPR is a legal framework rather than a certification scheme. Any certification we obtain in future will be published here with its scope and date.
Controller and processor roles
The role we hold depends on the data. This distinction matters for your own records of processing.
Controller
For account details, workspace membership, billing records, and marketing preferences, we determine the purposes and means of processing.
Processor
For the website content and connected-account data you submit for analysis, we process on your documented instructions in order to provide the service.
Data-protection practices
We operate with UK GDPR, the UK Data Protection Act 2018, and EU GDPR in mind where they apply to our processing. That means having a lawful basis for processing, limiting collection to what the service needs, honouring data subject requests, and contracting with our service providers on written terms.
We do not make an absolute guarantee of legal compliance. Compliance depends on how the service is used, and part of it sits with you as the customer.
Documented purposes and lawful bases, set out in our privacy policy.
Data subject requests handled within statutory response periods.
Written terms with the service providers who process data on our behalf.
Transfer mechanisms applied where data moves outside the UK or EEA.
Data minimisation and retention periods aligned to purpose and legal obligation.
Sub-processors and vendor due diligence
FixRank relies on third-party infrastructure and AI providers to deliver the service. We assess providers before onboarding them and contract with them on terms that limit their use of data to providing services to us.
The current list of sub-processors, including their processing purpose, is available on request for customers and prospective customers under review.
Data processing agreement
A data processing agreement covering our processing of customer data is available on request. It sets out the subject matter and duration of processing, the categories of data and data subjects, confidentiality obligations, sub-processor arrangements, assistance with data subject requests, and deletion or return of data at the end of the engagement.
Customer responsibilities
You are responsible for having a lawful basis to submit the websites and data you connect, for authorisation to analyse and modify those sites, and for the configuration of access within your workspace.
Documentation for vendor reviews
For procurement and security reviews we can provide the following. Where a document does not exist yet, we will say so rather than send an approximation.
Data processing agreement.
Current sub-processor list.
Written responses to security questionnaires covering our current setup.
A summary of our incident handling and disclosure process.
Confirmation of our data-protection roles and retention approach.
Accessibility
We build the FixRank interface with accessible practice in mind, including keyboard navigation, semantic structure, and readable contrast. We do not currently publish a formal conformance claim against a specific WCAG level.
If you encounter an accessibility barrier in the product, report it to us and we will treat it as a product defect.
What is planned, and clearly labelled as planned
As the platform and customer base grow, formalising our control set and pursuing external assurance is part of our direction. Until an assessment is completed and its scope confirmed, none of it is presented here as an existing control.
The same applies to product capability: planned autonomous features are roadmap items, not compliance controls.
Common questions
We operate with UK and EU data-protection obligations in mind and describe our practices in our privacy policy. There is no such thing as GDPR certification, so we do not claim one, and we do not offer an absolute legal guarantee — compliance also depends on how you use the service.
We can provide our standard data processing agreement, and we are willing to review a customer paper where the terms are workable for a company of our size.
No. FixRank is not designed for protected health information or cardholder data, and you should not submit that data to the platform.
Email us and we will send the current list, including each provider's processing purpose.
Not today. We will publish the scope and date here if and when an assessment is completed.
Questions about this page?
Compliance, DPA, and vendor review requests are handled by our team. Privacy-specific requests can go directly to our privacy contact.