← Complian
Draft — pending solicitor review

Privacy Policy

Last updated: 6 July 2026  ·  Version 0.2 (Draft)

This privacy policy is a draft for internal review only and has not been reviewed by a solicitor or data protection officer. It will be replaced with a solicitor-drafted policy before Complian is made available to the public. Do not rely on this document as a final legal statement.

1. Who We Are

Complian is a regulatory gap-analysis engine operated by COMPLIAN AI LTD (Company No. 17181330), registered in England and Wales. It produces compliance reports in which every claim is cited to primary legislation, and monitors regulatory change against your declared profile. References to "we", "us", or "Complian" refer to COMPLIAN AI LTD.

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: email address, organisation name, and password hash
  • Compliance profile data: your firm's name, type, size band, regulatory roles, building and activity details, jurisdictions, and the contact name and email you provide
  • Declared evidence: descriptions of the compliance evidence you say you hold
  • Uploaded evidence documents: the policies, registers, contracts and procedures you choose to upload, and the text we extract from them. These documents may themselves contain personal data about your staff or customers — see section 4a
  • Generated reports: the gap-analysis reports produced for your profiles
  • Waitlist data: email, industry, jurisdiction and role if you join the build queue

3. How We Use Your Data

We use your data to:

  • Produce your compliance gap-analysis reports and re-runs
  • Match your uploaded documents against the statutory obligations that apply to your profile
  • Send you a periodic regulatory-horizon digest filtered to your declared profiles (you can opt out at any time by emailing us)
  • Operate, secure and support the platform

We do not use your data to train AI models, and we do not sell it.

4. AI Processing

To classify your compliance position, excerpts of the statutory text, your declared evidence descriptions, and short excerpts of your uploaded documents are sent to Anthropic PBC via the Claude API. Document embeddings and, where configured, the same classification excerpts are processed by OpenAI. Both act as sub-processors under their respective commercial terms and data processing addenda.

  • No training on your data: Anthropic does not train its models on inputs or outputs submitted through the commercial Claude API by default.
  • Retention for abuse monitoring: Anthropic retains API inputs and outputs for up to 30 days for trust-and-safety and abuse monitoring, after which they are deleted in the ordinary course. Content flagged by automated safety systems may be retained for up to 2 years (and classifications for up to 7 years) as described in Anthropic's usage policies.
  • International transfers: Anthropic processes data in the United States. Transfers of personal data from the UK/EU are protected by the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as incorporated into Anthropic's DPA.
  • Please avoid sensitive personal data: do not enter special category personal data (health, biometric, political, etc.) or identifiable information about individuals into profile fields or evidence descriptions unless strictly necessary for the compliance assessment.

Anthropic's terms are available at anthropic.com/legal/commercial-terms and their DPA at anthropic.com/legal/dpa. OpenAI's API data-usage terms are at openai.com/policies.

4a. Your Uploaded Documents — Our Role as Processor

Where an evidence document you upload contains personal data about your staff, residents or customers, you remain the controller of that data and we process it only to produce your compliance analysis. Specifically: documents are stored in a private storage bucket accessible only to our service layer; they are never made publicly downloadable through the product; only short relevant excerpts are sent for AI classification; and every quotation from a document that appears on a report is mechanically verified against the document's extracted text. You can delete an uploaded document at any time from your account, which removes both the original file and the extracted text. Do not upload documents containing special category personal data (health, biometric, etc.) unless strictly necessary for the compliance assessment.

5. Data Retention

We retain your account data for as long as your account is active. Assessment history, generated documents, and audit events are retained for a minimum of 7 years to support compliance and regulatory recordkeeping obligations. You may request deletion of your account and associated data subject to applicable legal retention requirements.

6. Data Sharing

We do not sell your personal data. We share data only with:

  • Supabase (database, file storage and authentication infrastructure)
  • Anthropic (AI classification processing)
  • OpenAI (text embeddings and, where configured, AI classification)
  • Resend (transactional and digest email delivery)
  • Vercel and Railway (hosting infrastructure)

All sub-processors are required to maintain appropriate data protection standards.

7. Your Rights and Complaints

Under UK GDPR and applicable data protection law, you have the right to access, correct, or delete your personal data, to object to processing, and to data portability. You also have the right to complain to us directly — we will acknowledge your complaint within 30 days — and to the Information Commissioner's Office (ico.org.uk). To exercise these rights, contact us at hello@complianai.com.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security reviews. No system is completely secure; we will notify you promptly in the event of a data breach that affects your personal data.

9. Governing Law

This privacy policy is governed by the laws of England and Wales and we operate in compliance with UK GDPR and the Data Protection Act 2018.

10. Contact

For privacy-related enquiries, contact us at hello@complianai.com.

Terms of ServiceComplian