Last updated: 7/24/2026
Complyanz ("Complyanz", "we", "us"), operated by [LEGAL ENTITY], provides a governance, risk, and compliance (GRC) platform that helps organizations build and manage an Information Security Management System. This policy explains what personal data we process, why, and the rights you have. For data you upload about your own organization and employees, you are the data controller and we act as your processor.
Where GDPR applies, we process personal data to perform our contract with you, to pursue our legitimate interests in operating and securing the service, to comply with legal obligations, and on the basis of consent where required.
We share data with service providers that operate the platform on our behalf — including cloud hosting and database (DigitalOcean), transactional email (Resend), and AI providers (OpenAI / DeepSeek) — under contractual confidentiality and security obligations. We disclose data when required by law. We do not sell personal data.
We retain customer content for the life of your account and delete or anonymize it within 30 days of account deletion, except where longer retention is required by law. Audit logs are retained to support security and compliance obligations.
Subject to applicable law, you may request access, correction, deletion (erasure), portability of your data, or restriction/objection to processing. Account owners can export their organization's data and request deletion from within the app, or by contacting us. We do not discriminate against you for exercising these rights.
We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies.
We take reasonable technical and organizational measures to protect personal data, including encryption in transit, hashed credentials, multi-factor authentication, and access controls. No method of transmission or storage is 100% secure.
For privacy questions or to exercise your rights, contact us at support@complyanz.app or at [LEGAL ENTITY], [ADDRESS].