Privacy Policy

Last updated: July 2026

This Privacy Policy explains how ComplyPS ("we", "us") collects, uses and protects personal data when you use our website at complyps.com and the ComplyCRA application, and describes your rights under the EU General Data Protection Regulation (GDPR).

1. Who we are

ComplyPS (Comply Product Security) is the data controller for the personal data described in this policy. You can contact us about privacy at complyps@outlook.com.

2. What data we collect

We do not use advertising or tracking cookies. The application stores a login token in your browser's local storage; this is strictly necessary to keep you signed in.

3. Why we use your data, and our legal basis

4. How your document content is handled

The ComplyCRA application is designed to keep your data private: the analysis logic, storage and the AI used by the gap assessment run on our own local infrastructure. Document text you upload is not sent to third-party AI providers.

5. Sharing and processors

We do not sell your personal data. Our public website is hosted using GitHub Pages and delivered via Cloudflare, which may process technical data (such as IP addresses) as part of serving and protecting the site. We only share personal data with such providers to the extent necessary to run the service, or where required by law.

6. Retention

We keep form submissions for as long as needed to handle your request and for a reasonable follow-up period, and account data for as long as your account is active. You can ask us to delete your data at any time (see your rights below).

7. Your rights under the GDPR

Subject to the conditions in the GDPR, you have the right to: access your data; have it corrected; have it erased; restrict or object to its processing; data portability; and to withdraw consent at any time (without affecting processing already carried out). You also have the right to lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, email complyps@outlook.com.

8. International transfers

Where data is processed by providers outside the European Economic Area (for example, hosting/CDN providers), we rely on appropriate safeguards such as the providers' standard contractual clauses.

9. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top shows when it last changed.

10. Contact

Questions about this policy or your data: complyps@outlook.com.