SCANLEX
  • Services
    • KYC / ODD OutsourcingEU-based analyst teams live in 2 weeks. Monthly fixed rate per analyst, no placement fees.
      →
    • Compliance Officer SupportInterim, fractional and licence-stage provision. Gap cover, licence applications, resilience.
      →
    • AML Audit and AdvisoryIndependent AML audit and programme design. Fixed fee agreed before engagement starts.
      →
    • MiCA / CASP AML ComplianceMiCA AML programme build, KYC teams, Travel Rule and AMLCO support for crypto CASPs.
      →
    • AI Compliance for Regulated FirmsClassification, FRIA and cross-regulatory advisory for credit, insurance and HR screening AI.
      →
  • ← Back to main site
contact@scanlex.eu Book Free Call →

GDPR Notice

Last updated: March 2026  ·  Scanlex Ltd  ·  contact@scanlex.eu

This notice fulfils our transparency obligations under Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR). It describes how we process personal data in connection with our website and compliance advisory services.

1. Data Controller

The data controller for personal data processed through this website and in connection with our advisory engagements is:

Scanlex Ltd
Registration number: 14232412
Registered address: Tornimäe tn 5, Kesklinna linnaosa, Tallinn, Harju maakond, 10145, Estonia, EU
Email: contact@scanlex.eu
Website: scanlex.eu

2. What Personal Data We Process

Data categoryExamplesSource
Contact and identification dataName, email, company, job titleProvided by you via contact forms
Professional context dataIndustry sector, service interest, compliance situationProvided by you via contact forms
Engagement dataCorrespondence, deliverables, meeting notesGenerated during service delivery
Technical dataIP address, browser type (server logs only)Automatically collected on site visit

3. Purposes and Legal Bases

PurposeLegal basis (GDPR Art. 6)
Responding to enquiries and arranging scoping callsArt. 6(1)(b) — pre-contractual steps
Delivering compliance advisory servicesArt. 6(1)(b) — performance of contract
Sending regulatory updates relevant to your stated interestsArt. 6(1)(f) — legitimate interests
Maintaining records for legal and professional obligationsArt. 6(1)(c) — legal obligation
Improving our services based on engagement experienceArt. 6(1)(f) — legitimate interests

4. Retention Periods

Data typeRetention period
Enquiry data where no engagement proceeds12 months from initial contact
Engagement data (correspondence, deliverables)Duration of engagement + 6 years
Financial records (invoices, payments)7 years (legal obligation)
Server log technical data30 days (automatic deletion)

5. Your Rights

Right of Access (Art. 15)

Request a copy of all personal data we hold about you, including the purposes and recipients.

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data without undue delay.

Right to Erasure (Art. 17)

Request deletion of your data where it is no longer necessary or processing is unlawful.

Right to Restriction (Art. 18)

Request that we limit processing of your data in certain defined circumstances.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format where technically feasible.

Right to Object (Art. 21)

Object to processing based on legitimate interests, including direct marketing.

To exercise any right, contact us at contact@scanlex.eu. We will respond within 30 days. We may ask you to verify your identity before processing your request. There is no fee for exercising your rights.

6. Automated Decision-Making

We do not subject any individual to automated decision-making or profiling as defined under GDPR Article 22. All decisions made in connection with our services involve human review.

7. International Transfers

We do not transfer personal data to countries outside the European Economic Area (EEA) except where adequate safeguards are in place (such as EU Standard Contractual Clauses) and we have assessed transfer impact appropriately. Where we use service providers based outside the EEA, we ensure GDPR-compliant data processing agreements are in place.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against accidental loss, destruction, alteration, unauthorised disclosure, or access. These include encrypted communication channels, access controls, and secure data storage. We review our security measures regularly.

9. Right to Lodge a Complaint

If you believe we have processed your personal data unlawfully or in breach of your rights, you have the right to lodge a complaint with your national data protection supervisory authority. A full list of EU supervisory authorities is available at edpb.europa.eu.

We encourage you to contact us first at contact@scanlex.eu so we can attempt to resolve any concern directly.

10. Updates to This Notice

We review and update this GDPR Notice regularly. The date of the most recent update is shown at the top of this page. Material changes will be communicated to existing clients by email where appropriate.

SCANLEX

Scanlex is a regulated-sector compliance firm providing KYC/ODD team outsourcing, compliance officer support, AML audit, MiCA CASP advisory and AI compliance advisory to regulated financial institutions across the European Union.

Services
  • KYC / ODD Outsourcing
  • Compliance Officer Outsourcing
  • AML Audit & Advisory
  • MiCA / CASP AML
  • AI Compliance
Company
  • About Us
  • Contact
  • Sitemap
Legal
  • Privacy Policy
  • Terms of Engagement
  • Cookie Policy
  • GDPR Notice

© 2026 Scanlex. All rights reserved.

Scanlex Ltd · Tornimäe tn 5, Tallinn, Estonia, EU · contact@scanlex.eu

AML Compliance Outsourcing · KYC/ODD Outsourcing · Compliance Officer Support · AML Audit · MiCA AML · AI Compliance

We use analytics cookies. We use Google Analytics (GA4) to understand how visitors use this site. No advertising or tracking cookies are used. You can accept or decline. See our Cookie Policy and Privacy Policy.