cComplyEU

Privacy Policy

Last updated: 30 May 2026

This Privacy Policy explains how ComplyEU(“ComplyEU,” “we,” “us”) processes personal data when you use our website and the ComplyEU compliance platform (the “Service”). We comply with Regulation (EU) 2016/679 (the “GDPR”) and applicable EU and Member-State data-protection law.

1. Who we are

The data controller for personal data collected through our marketing website is ComplyEU. For data you submit while using the Service in connection with your employer's ComplyEU account, your employer is the controller and we act as a processor under the Data Processing Agreement (DPA) available at /dpa.

Contact: [email protected]

2. Categories of personal data we process

2.1 Account data

Name, email address, hashed password, organisation name, role, profile picture (if provided).

2.2 Authentication data

OAuth identifiers from Google or Microsoft when you choose to sign in with those providers.

2.3 Workspace integration data

When you connect Google Workspace or Microsoft 365, we read the inventory of OAuth applications installed in your tenant. We do not access user mailboxes, documents, or other content. Access tokens are encrypted at rest with AES-256-GCM.

2.4 Usage data

Pages visited, actions taken, IP address, browser user-agent, audit log entries.

2.5 Billing data

Billing email, VAT number, subscription tier, payment status. Card data is processed by Stripe and never touches our servers.

3. Legal bases (GDPR Article 6)

  • Contractual necessity (Art. 6(1)(b)) — to provide the Service.
  • Legitimate interest (Art. 6(1)(f)) — security, fraud prevention, product analytics.
  • Legal obligation (Art. 6(1)(c)) — VAT, accounting, lawful requests.
  • Consent (Art. 6(1)(a)) — non-essential cookies and marketing emails.

4. How long we retain data

  • Account & workspace data — until you delete your account or 90 days after subscription end.
  • Audit logs — 24 months.
  • Billing records — 10 years (statutory accounting period).
  • Marketing-website analytics — 14 months.

5. Sub-processors

We use the sub-processors listed at /trust. All sub-processors are bound by GDPR-compliant data-processing terms and, where data leaves the EEA, by Standard Contractual Clauses.

6. International transfers

All ComplyEU production data is stored within the EU (Frankfurt region). Some sub-processors (e.g. Anthropic for AI classification) process data in the United States under SCCs and supplementary measures. No personal data of your employees is sent to Anthropic — only metadata about the AI tools your organisation uses.

7. Your rights

You have the right to access, rectify, erase, restrict processing, port, and object to the processing of your personal data. To exercise these rights, contact [email protected]. You may also lodge a complaint with your national supervisory authority — for example, the Swedish IMY (Integritetsskyddsmyndigheten) or any other EU DPA.

8. Security

We use TLS 1.3 for all transport, AES-256-GCM for token encryption at rest, JWT authentication, role-based access control, and continuous audit logging. See /trust for the full security posture.

9. Cookies

We use strictly necessary cookies (session, CSRF) and, with your consent, anonymous analytics. We do not use advertising cookies.

10. Changes

We will notify customers by email of material changes at least 30 days before they take effect.