Complies

Privacy policy

LAST UPDATED: JULY 2026

This policy explains what Complies collects, why, how long we keep it, and the rights you have over it. It is written to be read, not skimmed past.

Who we are

Complies ("we", "us") operates complies.ai, compliance management software for companies preparing for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS. For data protection purposes we act as the controller for account and website data, and as a processor for the compliance program data a customer's team puts into the product. You can reach us at [email protected].

What we collect

  • Account data. Your email address when you sign up, confirm it, or contact us, plus the source of the signup and standard technical logs (IP address, browser type).
  • Compliance program data. What your team puts into the product: obligations, control descriptions and statuses, policies, evidence files and their metadata, owners, and due dates.
  • Usage data. Aggregate analytics about how pages are used, collected with minimal identifiers.

How compliance program data is handled

Your compliance program describes how your company protects itself, which makes it sensitive by nature. So:

  • It is your data. We process it only to operate the product for you, never to train models, build profiles, or market to anyone.
  • It is encrypted in transit and at rest, and access inside Complies is role-restricted and logged.
  • Evidence files are stored privately and served only to authenticated members of your team.
  • We never disclose one customer's program, controls, or evidence to another customer.

Why we process data (legal bases)

  • Contract: operating your account and delivering the tracking, mapping, evidence, and reporting features.
  • Legitimate interest: keeping the service secure, preventing abuse, and understanding aggregate product usage.
  • Consent: product emails you can withdraw from at any time.
  • Legal obligation: records we must keep, such as invoices.

Retention

DataKept for
Account email and signup recordUntil you ask us to delete it
Compliance program data and evidenceFor the life of the customer account, or until the customer deletes it
Server logs90 days
Contact messages24 months

Sharing

We do not sell personal data. We share it only with processors needed to run the service (hosting, email delivery), each bound by a data processing agreement, and where the law requires it. The current subprocessor list is published on the security page.

Your rights

Under the GDPR and similar laws you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. Email [email protected] and we will respond within 30 days. If a request concerns data your employer's team put into a customer account, we will route it with that customer, who controls the account. You can also complain to your supervisory authority.

Security

Data is encrypted in transit and at rest, access is role-restricted and logged, and production access requires multi-factor authentication. The full picture is on the security page. No system is perfectly secure; if an incident affects your data we will notify you as the law requires.

Changes

If this policy changes materially we will note it here with a new date, and for significant changes we will email account holders.