Privacy policy
LAST UPDATED: JULY 2026
This policy explains what Complies collects, why, how long we keep it, and the rights you have over it. It is written to be read, not skimmed past.
Who we are
Complies ("we", "us") operates complies.ai, compliance management software for companies preparing for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS. For data protection purposes we act as the controller for account and website data, and as a processor for the compliance program data a customer's team puts into the product. You can reach us at [email protected].
What we collect
- Account data. Your email address when you sign up, confirm it, or contact us, plus the source of the signup and standard technical logs (IP address, browser type).
- Compliance program data. What your team puts into the product: obligations, control descriptions and statuses, policies, evidence files and their metadata, owners, and due dates.
- Usage data. Aggregate analytics about how pages are used, collected with minimal identifiers.
How compliance program data is handled
Your compliance program describes how your company protects itself, which makes it sensitive by nature. So:
- It is your data. We process it only to operate the product for you, never to train models, build profiles, or market to anyone.
- It is encrypted in transit and at rest, and access inside Complies is role-restricted and logged.
- Evidence files are stored privately and served only to authenticated members of your team.
- We never disclose one customer's program, controls, or evidence to another customer.
Why we process data (legal bases)
- Contract: operating your account and delivering the tracking, mapping, evidence, and reporting features.
- Legitimate interest: keeping the service secure, preventing abuse, and understanding aggregate product usage.
- Consent: product emails you can withdraw from at any time.
- Legal obligation: records we must keep, such as invoices.
Retention
| Data | Kept for |
|---|---|
| Account email and signup record | Until you ask us to delete it |
| Compliance program data and evidence | For the life of the customer account, or until the customer deletes it |
| Server logs | 90 days |
| Contact messages | 24 months |
Sharing
We do not sell personal data. We share it only with processors needed to run the service (hosting, email delivery), each bound by a data processing agreement, and where the law requires it. The current subprocessor list is published on the security page.
Your rights
Under the GDPR and similar laws you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. Email [email protected] and we will respond within 30 days. If a request concerns data your employer's team put into a customer account, we will route it with that customer, who controls the account. You can also complain to your supervisory authority.
Security
Data is encrypted in transit and at rest, access is role-restricted and logged, and production access requires multi-factor authentication. The full picture is on the security page. No system is perfectly secure; if an incident affects your data we will notify you as the law requires.
Changes
If this policy changes materially we will note it here with a new date, and for significant changes we will email account holders.