Terms of Business
Platform 5 Ltd | IntegrityAI platform | Frank AI compliance reviewer
These Terms of Business set out the basis on which Platform 5 Ltd, a private limited company registered in England and Wales with company number 17283441 and registered office at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, supplies access to the IntegrityAI platform, including the Frank AI compliance reviewer. Platform 5 Ltd is registered with the Information Commissioner’s Office under registration number ZC177327.
1.About IntegrityAI and Frank
IntegrityAI is a software platform operated by Platform 5 Ltd. Frank is the AI compliance reviewer available within the IntegrityAI platform. Frank supports compliance teams by reading uploaded client file documents, checking them against selected compliance criteria, and producing a written review report for human consideration. Frank does not make final compliance decisions, approve advice, provide regulated financial advice, or replace the customer’s own professional judgement, supervisory controls, compliance procedures, or regulatory responsibilities.
2.Services
The services comprise access to the IntegrityAI platform, file upload functionality, AI-assisted file review by Frank, OCR processing where applicable, generation of RAG-rated review outputs, prioritised remedial findings, audit trail functionality, and downloadable reports in Word or PDF format where available.
3.Subscription, cancellation and usage credits
Subscriptions are provided on a monthly rolling basis with no minimum tie-in period unless otherwise agreed. Payment is collected in advance by Direct Debit at the start of each monthly billing cycle. The first billing cycle starts on the day the free trial period ends, or on the day the customer sets up payment if the free trial has already ended. The subscription fee is a flat monthly charge based on the customer’s pricing tier and is payable regardless of the number of review credits consumed, up to the agreed credit allowance for that tier. The customer may cancel before the next billing date to stop renewal for the following subscription period.
Each successfully processed file review will use one review credit. If a customer completes a review and later reprocesses the file because additional documents or files have been added, the reprocessed review will count as a separate review and will use a further review credit. If a review fails due to a platform processing failure and no usable review output is produced, no review credit will be used.
A firm may start a free trial of the platform without providing any payment details. The trial runs for the free trial period stated on the pricing page, beginning on the day the customer sets a password on the account. During it the customer may run up to ten file reviews and up to ten DB Deep Reviews. No subscription plan or DB Deep Review module is required for either, and no payment is collected during the trial period.
One free trial is available per email address. Email addresses are compared exactly, ignoring only leading and trailing spaces and the use of capitals. Where an email address has already been used for a free trial, a further trial is not available on it.
To continue after the free trial the customer chooses a subscription plan and sets up a Direct Debit within the platform, which the firm’s primary contact may do at any time during the trial. Choosing a plan ends the free trial at that point: the first monthly payment is collected then, the full monthly allowances apply from that date, and any remaining free trial days end. Until a plan is chosen nothing is collected, and the ten file reviews and ten DB Deep Reviews remain the applicable allowances.
4.Customer responsibilities
The customer is responsible for ensuring that it has lawful authority to upload documents and personal data, that uploaded material is accurate and complete, that suitably qualified personnel review outputs, and that all regulatory and compliance decisions are made by the customer.
5.Security and hosting
Platform 5 Ltd applies reasonable technical and organisational measures to protect customer data. All client data is stored and processed exclusively within the UK, in the AWS Europe (London) region (eu-west-2). No client data is transferred to or processed in any other geographic region for hosting purposes. Uploaded document content is processed by Anthropic’s Claude models hosted on Amazon Bedrock within the AWS Europe (London) region (eu-west-2) for AI-assisted analysis on an inference-only basis; it is not used to train or improve any AI model and is not retained beyond the time needed to process the request.
6.Confidentiality
Each party agrees to keep confidential all non-public information disclosed by the other party in connection with these Terms, including uploaded client documents, review outputs, and pricing terms, and to use such information only for the purposes of performing its obligations under these Terms. This obligation does not apply to information that is or becomes public other than through breach of this clause, or that a party is required to disclose by law or regulatory authority.
7.Intellectual property
The customer owns the content of the documents it uploads and retains ownership of the specific review reports generated for its files. Platform 5 Ltd retains all intellectual property rights in the IntegrityAI platform, the Frank AI compliance reviewer, and its underlying software, methodology and rule sets.
Platform 5 Ltd may use anonymised and aggregated data derived from review outputs, stripped of any information capable of identifying a customer, adviser, or client, to improve its products and services, including refining Frank’s review methodology and developing new features. Platform 5 Ltd will not use any customer’s uploaded documents or identifiable review content for this purpose.
8.Limitation of liability
Nothing in these Terms excludes or limits either party’s liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be excluded or limited.
Subject to the above, Platform 5 Ltd’s total aggregate liability to the customer arising out of or in connection with these Terms, whether in contract, tort (including negligence), breach of statutory duty or otherwise, shall not exceed the total fees paid by the customer to Platform 5 Ltd in the 12 months immediately preceding the event giving rise to the claim.
Subject to the first paragraph of this clause, Platform 5 Ltd shall not be liable for any indirect or consequential loss, or for any loss of profit, revenue, business, goodwill, or anticipated savings, in each case whether direct or indirect.
Frank’s outputs are intended to assist human reviewers and may contain errors or omissions. Platform 5 Ltd does not guarantee that all compliance issues will be identified. The customer remains responsible for all regulatory compliance and decisions, and for exercising its own professional judgement in relation to every review before relying on it.
9.Warranties
Platform 5 Ltd warrants that it will provide the services with reasonable skill and care. Except as expressly set out in these Terms, all warranties, conditions and other terms implied by statute or common law are excluded to the fullest extent permitted by law.
10.Termination
Either party may terminate these Terms for convenience by giving notice in line with the cancellation provisions in clause 3.
Platform 5 Ltd may suspend or terminate the customer’s access immediately, without notice, if the customer fails to make payment when due and does not remedy this within 7 days of being notified, or if the customer becomes insolvent, enters administration, or ceases to trade.
Either party may terminate these Terms with immediate effect by written notice if the other party commits a material breach of these Terms that is capable of remedy and fails to remedy it within 30 days of being notified in writing, or commits a material breach that is not capable of remedy.
On termination, the customer’s right to access the platform ends. Completed review reports and audit logs already generated remain accessible in line with the retention terms of the data processing agreement, or will be provided to the customer on request within a reasonable period, after which Platform 5 Ltd may delete them.
Where a free trial ends and the customer does not take out a subscription, no further reviews may be started, but the customer keeps access to the reviews already completed for 90 days after the trial ends. At the end of that period the account is deactivated and can no longer be signed in to for normal use. Deactivation does not delete any of the customer’s completed reviews or audit logs, which are retained in line with section 6 of the Privacy Policy and may be restored if the customer later takes out a subscription. A deactivated account is reactivated by contacting Platform 5 Ltd.
11.Force majeure
Neither party shall be liable for any failure or delay in performing its obligations under these Terms to the extent caused by events beyond its reasonable control, including but not limited to acts of God, war, civil unrest, industrial action, failure of internet or telecommunications infrastructure, or failure of a third-party service provider.
12.Variation
Platform 5 Ltd may update these Terms from time to time to reflect changes in the service, legal or regulatory requirements. Where a change is material, Platform 5 Ltd will give the customer at least 30 days’ notice before it takes effect. Continued use of the platform after that date constitutes acceptance of the updated Terms.
13.Governing law and jurisdiction
These Terms are governed by the laws of England and Wales. Each party submits to the exclusive jurisdiction of the courts of England and Wales in relation to any dispute arising out of or in connection with these Terms.
14.Contact
Questions should be sent to: info@integrityai.uk
15.Data processing
To the extent Platform 5 Ltd processes personal data on behalf of the customer in connection with the Services, the terms of Schedule 1 (Data Processing Agreement) apply and are incorporated into, and form part of, these Terms of Business. In this context, “Controller” means the customer and “Processor” means Platform 5 Ltd.
Schedule 1: Data Processing Agreement
1.Definitions
In this Schedule:
“Data Protection Legislation” means the UK GDPR, the Data Protection Act 2018, and any other applicable law relating to the processing of personal data, each as amended or replaced from time to time.
“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject” and “Personal Data Breach” have the meanings given to them in the UK GDPR.
“Customer Personal Data” means any Personal Data contained in documents uploaded to the platform by or on behalf of the Controller, and any Personal Data generated in the resulting review outputs, which is Processed by the Processor on behalf of the Controller under this Schedule.
“Special Category Data” means Personal Data described in Article 9(1) of the UK GDPR, including data concerning health.
“Sub-processor” means any third party appointed by the Processor to Process Customer Personal Data on behalf of the Controller in connection with the Services.
2.Roles of the parties
The Controller is the controller of Customer Personal Data. The Processor Processes Customer Personal Data solely as a processor on behalf of the Controller, in accordance with this Schedule and the Controller’s documented instructions.
This Schedule does not apply to Personal Data that the Processor Processes as an independent controller, such as the Controller’s own business contact details, account data, and billing information used to administer the Services. That Processing is described in the Processor’s Privacy Notice.
3.Subject matter, duration, nature and purpose
Subject matter: the Processor’s provision of AI-assisted compliance file review services to the Controller.
Duration: for the term of these Terms of Business, and thereafter for the period during which the Processor retains Customer Personal Data in accordance with clause 10 of this Schedule.
Nature of processing: collection, storage, analysis, and generation of derived outputs, all by automated means, including transmission of document content to a third-party AI model for analysis and OCR of scanned documents.
Purpose of processing: to review uploaded client advice file documents against applicable FCA rules and Consumer Duty outcomes, identify gaps and remedial actions, and produce a graded review report for the Controller’s use.
Types of Personal Data: client names and contact details, financial and pension information, product and policy details, risk profiling data, advice history, and any other Personal Data the Controller includes in uploaded documents.
Special Category Data: the Controller may include Special Category Data in uploaded documents where necessary for the advice under review, for example health information relevant to an ill-health early retirement or enhanced annuity case. The Controller is responsible for ensuring it has an appropriate lawful basis and Article 9 condition for including such data, and for identifying an appropriate policy document where required by the Data Protection Act 2018, before uploading it.
Categories of Data Subjects: the Controller’s clients, and where relevant, the Controller’s advisers and staff named in uploaded documents.
4.Processor obligations
The Processor shall:
(a) Process Customer Personal Data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do otherwise by law, in which case the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits this;
(b) ensure that persons authorised to Process Customer Personal Data are subject to a duty of confidentiality;
(c) implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in clause 8 of this Schedule;
(d) not engage a Sub-processor without the Controller’s general written authorisation as set out in clause 6 of this Schedule;
(e) taking into account the nature of the Processing, assist the Controller by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling the Controller’s obligations to respond to requests from Data Subjects exercising their rights under Data Protection Legislation;
(f) assist the Controller in ensuring compliance with its obligations relating to the security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor;
(g) at the choice of the Controller, delete or return all Customer Personal Data to the Controller after the end of the provision of the Services relating to Processing, and delete existing copies, in accordance with clause 10 of this Schedule;
(h) make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in this Schedule, and allow for and contribute to audits in accordance with clause 9 of this Schedule.
5.Controller obligations
The Controller shall:
(a) ensure it has a lawful basis, and where relevant an Article 9 condition, for Processing Customer Personal Data and for its collection and disclosure to the Processor;
(b) ensure that its instructions to the Processor comply with Data Protection Legislation;
(c) be responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it was acquired;
(d) ensure that only authorised, suitably trained personnel access the platform and review outputs.
6.Sub-processors
The Controller authorises the Processor to engage the Sub-processors listed in the Processor’s Privacy Notice for the purposes described there. The Processor shall:
(a) maintain an up-to-date list of Sub-processors and make it available to the Controller on request or via the Privacy Notice;
(b) give the Controller at least 14 days’ notice before appointing a new Sub-processor, during which the Controller may object on reasonable data protection grounds. If the Parties cannot resolve the objection, the Controller may terminate the affected Services;
(c) impose data protection obligations on each Sub-processor that are no less protective than those set out in this Schedule;
(d) remain fully liable to the Controller for the performance of a Sub-processor’s obligations.
7.International transfers
The Processor stores and processes Customer Personal Data exclusively within the United Kingdom, in the AWS Europe (London) region (eu-west-2). Uploaded document content is processed by Anthropic’s Claude models hosted on Amazon Bedrock within the AWS Europe (London) region (eu-west-2) for AI-assisted analysis on an inference-only basis; it is not used to train or improve any AI model and is not retained beyond the time needed to process the request. Where this or any other Processing involves a transfer of Customer Personal Data outside the United Kingdom, the Processor shall ensure an appropriate transfer mechanism recognised under Data Protection Legislation is in place, such as the UK’s International Data Transfer Addendum to the EU Standard Contractual Clauses, before the transfer takes place.
8.Security measures
The Processor shall implement and maintain appropriate technical and organisational measures, including:
(a) encryption of Customer Personal Data at rest and in transit;
(b) access controls restricting access to Customer Personal Data to personnel who need it to perform the Services;
(c) network and infrastructure security measures provided through the Processor’s UK hosting environment;
(d) regular review of security measures in light of the risk presented by the Processing;
(e) the ability to restore availability and access to Customer Personal Data in a timely manner in the event of a technical or physical incident.
9.Audit
On reasonable prior written request, the Processor shall provide the Controller with the information reasonably necessary to demonstrate compliance with this Schedule, which may include a written security questionnaire response, a summary of technical and organisational measures, and, once obtained, any relevant third-party security certification (such as ISO 27001 or SOC 2) then held by the Processor.
Where the Processor holds a current, relevant third-party certification covering the Services, provision of that certification and any related audit summary shall satisfy the Processor’s obligations under this clause, and the Controller shall not be entitled to require a further on-site or remote audit covering the same scope and period.
Where no such certification is held, or the certification does not cover the matter in question, the Controller may request an on-site or remote audit, no more than once in any 12-month period (save where required following a Personal Data Breach or by a supervisory authority), on reasonable notice and subject to a reasonable scope, timing, and confidentiality basis agreed between the Parties, at the Controller’s cost, save where the audit identifies a material breach of this Schedule, in which case the Processor shall bear its own reasonable costs of participation.
10.Deletion and return of data
Uploaded documents are automatically deleted from the platform once the relevant review is complete and the report has been generated; they are not retained beyond this point. On termination of the Services, the Processor shall, at the Controller’s written request made within 30 days of termination, provide the Controller with a copy of its completed review reports and audit logs in a common format, after which the Processor shall delete all remaining Customer Personal Data from its systems within a further 30 days, except to the extent applicable law requires continued retention.
11.Personal Data Breach notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting Customer Personal Data. The notification shall include, to the extent known at the time: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. The Processor shall cooperate with the Controller and take reasonable steps to assist the Controller in meeting its own breach notification obligations under Data Protection Legislation.
12.Liability
Each Party’s liability arising out of or in connection with this Schedule is subject to the limitations and exclusions of liability set out in clause 8 of these Terms of Business.
13.Survival
Clauses 9, 10, 11 and 12 of this Schedule survive termination of these Terms of Business.