Terms of Use
Please read these terms carefully before using Endaxi Brief.
Last updated: June 2026
Plain language summary: Endaxi Scribe is a speech-to-text service operated by IOLIS Ltd. By using it, you agree to use it lawfully, only record people where you have the right to do so, and accept the limits of our liability. The full legal terms are below.
1. About these terms
These Terms of Service (“Terms”) govern your use of the Endaxi Scribe platform (“Service”), operated by IOLIS Ltd, a company registered in Wales (company number 11968202), with its registered office at C5 Business Centre, C5 North Road, Bridgend Industrial Estate, Bridgend, Wales, CF31 3TP (“we”, “us”, “our”).
By creating an account, recording or uploading audio, or otherwise using the Service, you agree to be bound by these Terms. If you do not agree, you must not use the Service.
2. The service
Endaxi Scribe provides a platform for recording audio and producing transcripts using automated speech recognition. Key characteristics of the Service include:
- Live in-browser recording and file upload
- Automated transcription with timestamps
- Automatic speaker diarisation
- Bookmarks and inline editing of transcripts
- Configurable retention by plan
- Two-factor authentication on every account
We reserve the right to modify, suspend, or discontinue any aspect of the Service at any time, with reasonable notice where practicable.
3. Eligibility
You must be at least 18 years of age to create an account or use the Service. By using the Service, you represent and warrant that you meet this requirement.
If you are using the Service on behalf of an organisation, you represent that you have the authority to bind that organisation to these Terms.
4. Account responsibilities
If you create an account, you are responsible for:
- Maintaining the confidentiality of your login credentials
- All activity that occurs under your account
- Notifying us immediately if you believe your account has been compromised
You must provide accurate and complete information when registering. We reserve the right to suspend or terminate accounts that contain false or misleading information.
5. Recording consent and acceptable use
You are responsible for ensuring that you have the right to record any audio you submit to the Service. In particular:
- You must obtain any consent required by law from every identifiable person whose voice is recorded
- You must not record people covertly where doing so would be unlawful in the relevant jurisdiction
- You must comply with all applicable laws relating to privacy, data protection and interception of communications
You agree not to use Endaxi Scribe to:
- Record, transcribe or process content that is unlawful, defamatory, harassing, or that infringes the rights of others
- Attempt to bypass usage limits, security features or authentication
- Reverse-engineer, scrape or interfere with the operation of the Service
- Resell or sublicense the Service without our written agreement
We may suspend or terminate accounts that breach these rules.
6. Plans, minutes and top-ups
The Service is offered on Free, Solo, Team and Business plans, each with a monthly allowance of transcription minutes. Unused monthly allowance does not roll over to the following month.
One-off top-up minute packs may be purchased separately. Top-up minutes do not expire and are consumed only after your monthly allowance for that month has been used. On Team and Business plans, top-ups are added to the shared team pool.
7. Billing
Subscriptions and top-ups are billed by IOLIS Ltd. Subscription fees are charged in advance for the period selected (monthly or annual). Top-up purchases are charged at the time of purchase.
Unless required by law, fees are non-refundable once a billing period has begun. You can cancel a subscription at any time; cancellation takes effect at the end of the current billing period.
We may change pricing from time to time. We will give existing subscribers reasonable notice of any price change before it applies to their next billing period.
8. Your content
You retain all rights in the audio you record or upload, and in the transcripts produced from it.
You grant us a limited, non-exclusive licence to store, process and transmit your content solely to the extent necessary to provide the Service to you. We do not use your content to train AI models, and we do not share it with third parties except sub-processors strictly required to deliver the Service.
9. Retention and deletion
Audio files are retained for the storage window applicable to your plan (see the Privacy Policy for current windows). After the window expires they are deleted from our active systems.
Transcripts and summaries are retained until you delete them or your account is deleted.
You can delete your own recordings and transcripts at any time from within the application. If you close your account, your audio and transcripts will be deleted in accordance with our retention schedule.
10. Availability
We aim to make the Service available continuously but we do not guarantee uninterrupted availability. Maintenance, upgrades, third-party outages or events outside our control may cause downtime.
11. Disclaimers
Automated transcription is inherently imperfect. While we use current-generation speech recognition technology, transcripts may contain errors, particularly in cases of poor audio quality, strong accents, overlapping speech or specialist terminology. You are responsible for reviewing transcripts before relying on them for any purpose where accuracy matters.
The Service is provided “as is” and “as available”. To the maximum extent permitted by law, we disclaim all warranties not expressly set out in these Terms.
12. Limitation of liability
Nothing in these Terms excludes or limits our liability for death or personal injury caused by our negligence, for fraud, or for any other liability that cannot lawfully be excluded.
Subject to that, our total liability to you arising out of or in connection with the Service is limited to the greater of (a) the fees you have paid to us in the 12 months immediately before the event giving rise to the claim, and (b) £100.
We are not liable for indirect, incidental, consequential, special or exemplary damages, including loss of profits, revenue, business or data, even if advised of the possibility.
13. Termination
You may close your account at any time. We may suspend or terminate your account if you breach these Terms, if continued provision of the Service would expose us to legal risk, or if you have not used the Service for an extended period.
14. Changes to these terms
We may update these Terms from time to time. Material changes will be notified to account holders by email or via the application, and will take effect after a reasonable notice period.
15. Governing law
These Terms are governed by the laws of England and Wales. Any disputes arising out of or in connection with them are subject to the exclusive jurisdiction of the courts of England and Wales.
16. Contact
Questions about these Terms? Email us at [email protected].
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the Endaxi Scribe Terms of Service. By accepting the Terms of Service, you agree to the terms of this DPA. No separate signature is required. Data protection queries: [email protected]
1. Parties and Roles
Data Processor: IOLIS Ltd, operator of the Endaxi Scribe platform.
Data Controller: The Customer — the individual or organisation that has accepted these Terms and uses the Services.
IOLIS Ltd acts solely as a Processor in respect of audio files, transcripts, and any personal data contained therein that are uploaded, live-streamed, or otherwise submitted to the platform by or on behalf of the Customer. The Customer is the Controller and determines the purposes and means of that processing.
2. Definitions
“UK GDPR” means the UK General Data Protection Regulation as retained in UK law by the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018. “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in the UK GDPR. “Services” means the Endaxi Scribe text-to-speech and transcription platform. “ICO” means the Information Commissioner’s Office. “Sub-processor” means any third party engaged by IOLIS Ltd to Process Personal Data on behalf of the Customer.
3. Description of Processing
| Subject matter | Provision of text-to-speech and audio transcription services via the Endaxi Scribe platform. |
| Nature & purpose | Collection, storage, transmission, transcription, and deletion of audio files and transcripts to provide the Services as requested by the Customer. |
| Categories of personal data | Audio recordings; transcripts; any personal data contained within audio or transcript content submitted by the Customer; account and billing data. |
| Data subjects | The Customer’s authorised users; any individuals whose voice or personal data appears in audio files or transcripts submitted by the Customer. |
| Special category data | IOLIS Ltd does not knowingly process special category data. Customers must not submit special category data (Article 9 UK GDPR) without a valid legal basis. |
| Duration | For the duration of the Customer’s active subscription, subject to clause 8 below. |
4. Processing Instructions & Controller Obligations
IOLIS Ltd shall Process Personal Data only on the documented instructions of the Customer, as set out in this DPA and the Terms of Service, unless required otherwise by applicable law (in which case IOLIS Ltd shall notify the Customer where permitted). If IOLIS Ltd considers any instruction to infringe the UK GDPR, it shall notify the Customer and may suspend the relevant Processing pending resolution.
The Customer warrants that: (a) it has a valid lawful basis for processing the Personal Data it submits; (b) it has provided all required notices to, and obtained all required consents from, data subjects; (c) its instructions comply with applicable law; and (d) it is responsible for the accuracy and legality of Personal Data submitted.
5. Confidentiality & Security
IOLIS Ltd shall ensure that all personnel authorised to Process Personal Data are subject to binding confidentiality obligations and that access is limited to those who need it to perform the Services.
IOLIS Ltd implements and maintains the following technical and organisational security measures in accordance with Article 32 UK GDPR:
- Dedicated infrastructure: All Customer data is hosted on a dedicated server operated exclusively by IOLIS Ltd, not shared with any other organisation.
- Encryption in transit: All data transmitted to and from the platform is protected by SSL/TLS.
- Encryption at rest: All audio files and transcripts are encrypted at rest.
- Authentication: Two-factor authentication (2FA) is available to all users and is strongly recommended.
- Access controls: Role-based, need-to-know access to Personal Data is enforced internally.
- Incident response: Documented procedures are maintained for detecting, reporting, and responding to Personal Data Breaches.
6. Sub-processor
IOLIS Ltd engages the following single Sub-processor in connection with the Services:
| Name | Mistral AI SAS |
| Address | 15 Rue des Halles, 75001 Paris, France |
| Purpose | AI language model processing for transcription and text-to-speech functionality |
| Data transferred | Audio content and transcript data submitted by the Customer to the Services |
| Transfer basis | France is within the EEA; transfers from the UK to France are covered by UK adequacy regulations under the Data Protection Act 2018. Any further transfers by Mistral AI to third countries are governed by the Mistral AI DPA, which incorporates Standard Contractual Clauses where required. |
| DPA in place | Yes — IOLIS Ltd has entered into the Mistral AI Data Processing Addendum. See also the Mistral AI Trust Centre. |
IOLIS Ltd shall provide the Customer with at least 14 days’ prior notice of any intended change to its Sub-processor arrangements, by email or in-platform notification. The Customer may object in writing within 14 days on reasonable data protection grounds. If the parties cannot resolve the objection, either party may terminate the affected Services without penalty.
7. Data Subject Rights
The Customer, as Controller, is responsible for responding to data subject rights requests under the UK GDPR. IOLIS Ltd shall provide reasonable assistance to enable the Customer to respond to such requests, including by providing access to or deletion of Personal Data held on the platform upon written request. If IOLIS Ltd receives a data subject rights request directly, it will not respond without the Customer’s prior written consent (unless required by law) and will promptly forward the request to the Customer.
8. Retention & Deletion
IOLIS Ltd shall retain Personal Data only for as long as necessary to provide the Services. Upon termination or expiry of the Customer’s subscription, IOLIS Ltd shall, at the Customer’s election, securely delete or return all Personal Data processed on the Customer’s behalf within 30 days of termination. IOLIS Ltd may retain Personal Data beyond this period only to the extent required by applicable law and shall notify the Customer accordingly.
9. Personal Data Breaches
IOLIS Ltd shall notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting data processed under this DPA. Notification shall include, to the extent available: the nature of the breach; categories and approximate number of data subjects and records affected; likely consequences; and measures taken or proposed. Information may be provided in phases where not all details are immediately available. IOLIS Ltd shall provide reasonable assistance to the Customer in meeting its obligations to notify the ICO and affected data subjects where required. Notification of a breach does not constitute an admission of fault or liability.
10. Audit Rights
Upon reasonable written request, IOLIS Ltd shall make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality obligations. The Customer may, no more than once per calendar year and with at least 30 days’ prior written notice, conduct or commission an audit of IOLIS Ltd’s relevant data processing activities. Any audit shall be conducted during normal business hours, in a manner that minimises disruption, and at the Customer’s cost.
11. General
Precedence: In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail in respect of the Processing of Personal Data.
Governing law: This DPA is governed by the laws of England and Wales. Disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Amendments: IOLIS Ltd may update this DPA to reflect changes in applicable law or processing activities. Material changes will be notified by email or in-platform notice. Continued use of the Services following such notice constitutes acceptance.
Liability: Each party’s liability under this DPA is subject to the limitations set out in the Terms of Service, except where prohibited by applicable data protection law.
Contact: For all data protection queries, contact [email protected]. a company registered in Wales (Company No. 11968202), with registered address at C5 Business Centre, C5 North Road, Bridgend Industrial Estate, Bridgend, Wales, CF31 3TP (“IOLIS”, “we”, “us”).
By accessing or using the Service, you and the organisation on whose behalf you act (“Customer”, “you”) agree to be bound by these Terms. If you do not agree, you must not use the Service.
2. Access and Accounts
Access to Brief is provided on an invitation-only basis during the current supervised rollout phase. Each organisation using Brief (“Customer”) must have a valid account. User accounts are created by an organisation administrator and are personal to the individual named on the account.
You are responsible for maintaining the confidentiality of your login credentials. You must notify us immediately at [email protected] if you believe your account has been compromised. You are responsible for all activity conducted through your account.
3. Permitted Use
Brief is licensed to you for the purpose of managing investigation cases and preparing papers for disciplinary or regulatory hearings within your organisation. The Service may only be used for lawful purposes and in accordance with these Terms.
You may not:
- use the Service for any purpose that is unlawful or prohibited by these Terms
- attempt to gain unauthorised access to any part of the Service or its infrastructure
- use the Service to store or transmit any material that is defamatory, unlawful or infringes any third-party rights
- reverse engineer, decompile or attempt to extract source code from the Service
- resell or sublicense access to the Service to any third party without our prior written consent
- upload content to the AI analysis features that includes unnecessary personal data unrelated to the analytical task being performed
4. Data and Privacy
Our collection and use of personal data in connection with the Service is governed by our Privacy Policy. Where IOLIS processes personal data on your behalf as data processor, the terms of the Data Processing Addendum below also apply and form part of these Terms.
You are the data controller for case and investigation data uploaded to Brief. You are responsible for ensuring you have an appropriate lawful basis for processing any personal data held within Brief, and that such processing is disclosed in your own privacy notices.
5. AI Features
The AI analysis features within Brief are provided to assist with document review and hearing preparation. AI outputs are provided as an aid to professional judgement and must be reviewed carefully before being relied upon. IOLIS does not warrant the accuracy or completeness of any AI-generated output, and you remain solely responsible for all decisions made in connection with your cases.
AI processing is performed by Mistral AI SAS, a French company operating within the European Union. By using the AI features, you consent to relevant document text being transmitted to Mistral AI for the purpose of generating analysis. Please refer to the Data Processing Addendum for details of this sub-processor arrangement.
6. Intellectual Property
The Service, including all software, design, text and documentation, is owned by IOLIS Ltd and protected by copyright and other intellectual property laws. Nothing in these Terms transfers any ownership of intellectual property to you.
Data and documents uploaded by your organisation remain your property. You grant IOLIS a limited, non-exclusive licence to store, process and transmit that data solely as necessary to provide the Service.
7. Availability and Support
We aim to keep Brief available and operating normally, but we do not warrant that the Service will be uninterrupted or error-free. Planned maintenance will be communicated to administrators in advance where possible. We provide support by email at [email protected] and aim to respond within one business day.
8. Limitation of Liability
To the fullest extent permitted by applicable law, IOLIS shall not be liable for any indirect, incidental, special, consequential or punitive damages, or loss of profits, data or business opportunities, arising out of or in connection with your use of the Service, even if we have been advised of the possibility of such damages.
Our total aggregate liability to you in connection with the Service, whether in contract, tort (including negligence) or otherwise, shall not exceed the total fees paid by your organisation in the twelve months preceding the event giving rise to the claim, or £500, whichever is greater.
Nothing in these Terms limits or excludes our liability for death or personal injury caused by our negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be excluded by law.
9. Indemnification
You agree to indemnify and hold harmless IOLIS Ltd and its officers, employees and contractors from and against any claims, losses, damages, costs and expenses (including reasonable legal fees) arising out of your use of the Service in violation of these Terms or applicable law.
10. Termination
Either party may terminate access to the Service on written notice. We reserve the right to suspend or terminate access immediately if you breach these Terms, fail to pay applicable fees, or if we are required to do so by law. On termination, your organisation’s data will be deleted in accordance with our Privacy Policy and the Data Processing Addendum.
11. Changes to these Terms
We may update these Terms from time to time. We will notify you of material changes by email at least 14 days before they take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised Terms.
12. Governing Law
These Terms are governed by the laws of England and Wales. Any disputes arising under or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales, except where mandatory consumer protection law in your jurisdiction requires otherwise.
13. Contact
For questions about these Terms, contact us at [email protected] or write to IOLIS Ltd at the address above.
Data Processing Addendum
This Addendum forms part of the Terms of Use and governs the processing of personal data by IOLIS Ltd on behalf of the Customer.
1. Definitions
In this Addendum, the following definitions apply in addition to those in the main Terms:
- “Controller” means the Customer organisation that determines the purposes and means of processing Personal Data uploaded to Brief.
- “Processor” means IOLIS Ltd, which processes Personal Data on behalf of the Controller.
- “Personal Data” has the meaning given in UK GDPR / EU GDPR.
- “Processing” has the meaning given in UK GDPR / EU GDPR.
- “Data Protection Law” means UK GDPR, the Data Protection Act 2018, and (where applicable) EU GDPR and other applicable data protection legislation.
- “Sub-processor” means any third party engaged by IOLIS to process Personal Data under this Addendum.
2. Scope and Nature of Processing
IOLIS processes Personal Data on behalf of the Controller solely for the purpose of providing the Brief service as described in these Terms. The categories of data subjects and types of personal data processed are those uploaded to the Brief platform by the Controller’s users, which may include: names, contact details, statements, interview records and other information relating to individuals involved in investigations or disciplinary proceedings.
The duration of processing is for the term of the Customer’s access to Brief, plus any retention period agreed in writing or required by applicable law.
3. Controller Obligations
The Controller is responsible for:
- ensuring it has an appropriate lawful basis for processing any Personal Data uploaded to Brief
- ensuring its own privacy notices accurately describe the processing carried out via Brief
- providing accurate and complete information to data subjects about the processing of their data
- ensuring that only necessary and proportionate Personal Data is uploaded to the Service
- responding to data subject rights requests in relation to Personal Data for which it is Controller
4. Processor Obligations
IOLIS Ltd, as Processor, undertakes to:
- process Personal Data only on documented instructions from the Controller (namely, to provide the Service), except where required to do so by applicable law
- ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations
- implement appropriate technical and organisational security measures as described in Clause 7 below
- assist the Controller in responding to data subject rights requests, to the extent technically practicable
- notify the Controller without undue delay on becoming aware of a Personal Data breach affecting the Controller’s data
- on termination, delete or return all Personal Data (at the Controller’s election) within 30 days, unless a longer retention period is required by law
- make available to the Controller all information reasonably necessary to demonstrate compliance with this Addendum
5. Sub-processors
The Controller hereby grants general authorisation to IOLIS to engage sub-processors, subject to the conditions in this Clause. IOLIS will notify the Controller of any intended changes to sub-processor arrangements, giving the Controller a reasonable opportunity to object before the change takes effect.
Current approved sub-processors are:
- Mistral AI SAS — 15 rue des Halles, 75001 Paris, France. Purpose: AI analysis of case documents submitted via the AI Analysis feature. Processing location: European Union. Data submitted to Mistral AI is not retained beyond the scope of the individual request and is not used for model training.
IOLIS will ensure that sub-processor agreements impose data protection obligations equivalent to those in this Addendum.
6. International Transfers
IOLIS will not transfer Personal Data outside the UK or EEA without ensuring that appropriate safeguards are in place. Mistral AI processes data within the European Union. Where any transfer to a third country is necessary, IOLIS will rely on an adequacy decision, Standard Contractual Clauses or another approved transfer mechanism under applicable Data Protection Law.
7. Security Measures
IOLIS implements and maintains the following technical and organisational measures:
- AES-256-GCM encryption of all documents at rest, using a three-tier key hierarchy (system, organisation and case level)
- Argon2id password hashing for all user credentials
- Two-factor authentication (email-based OTP) for all application logins
- Database-backed opaque session tokens with CSRF protection
- Comprehensive audit logging of all case actions with user identity, timestamp and IP address
- Strict data segregation between organisations at the application layer
- Access controls limiting data access to authorised users within the relevant organisation
8. Personal Data Breaches
IOLIS will notify the Controller without undue delay (and in any event within 72 hours where feasible) upon becoming aware of a Personal Data breach affecting the Controller’s data. The notification will include: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.
9. Data Subject Rights
Where IOLIS receives a request directly from a data subject in relation to Personal Data for which the Controller is the data controller, IOLIS will promptly refer that request to the Controller. IOLIS will provide reasonable assistance to the Controller in fulfilling data subject rights requests, including access, rectification, erasure and portability, to the extent technically practicable.
10. Deletion and Return
On termination of the Customer’s access to Brief (for any reason), IOLIS will delete all Personal Data processed on behalf of the Controller within 30 days, unless retention is required by applicable law. IOLIS will confirm deletion in writing upon request. Where the Controller requests return of data prior to deletion, IOLIS will provide a data export in a portable format within 14 days of that request.
11. Audits
IOLIS will, upon reasonable written notice (not less than 14 days), provide the Controller with all information reasonably necessary to demonstrate compliance with this Addendum. Audits by the Controller or its appointed auditor may be requested no more than once per year and must be conducted during normal business hours, at the Controller’s expense, and in a manner that minimises disruption to IOLIS’s operations.
12. Governing Law
This Addendum is governed by the laws of England and Wales and is subject to the same jurisdiction clause as the main Terms of Use.
