ComplyEdge ComplyEdge
Home Terms Get Started

Legal · v0.1

Privacy Policy

Effective date: 11 July 2026 · Last updated: 31 July 2026

Draft for counsel review. This Policy describes current ComplyEdge data practices. Controller/operator entity details may be updated after formal legal review.

1. Who we are

ComplyEdge (“we”, “us”) operates the Service at complyedge.io, api.complyedge.io, dashboard.complyedge.io, trust.complyedge.io, and related properties. For privacy and support requests contact support@complyedge.io.

Depending on the processing activity, we act as an independent controller (account administration, website and product analytics, billing) or as a processor (evaluating content you submit through the API on your instructions). Processor terms may be set out in a Data Processing Agreement for enterprise customers. Where a DPA is required, it is executed offline (email countersign), not as an in-product clickwrap.

2. What we collect

Account and authentication

  • Email address
  • One-time passcodes and related auth metadata (delivery status, timestamps). OTP codes are stored hashed and expire after about five minutes
  • Tenant / organization identifiers and plan tier
  • API keys — stored so the authenticated dashboard can Show/Copy them; treat keys as secrets and rotate if exposed. A hash of the key is also stored for lookup

Service usage

  • API request metadata written to the compliance audit log: timestamps, jurisdiction / rule-bundle selection, latency, decision outcome (allow/block/flag), rule IDs, and legal citation text on violations (stored as rule description), plus related engine fields (for example engine path)
  • Evaluated text as SHA-256 text_hash only in standard production DynamoDB audit rows — we do not persist raw prompts/outputs in those rows unless a separate written agreement says otherwise. Application / debug logs may briefly include truncated request text for operational troubleshooting
  • Dashboard activity needed to operate the product

Website and communications

  • Lead-form fields you submit (name, email, optional company, message)
  • Analytics events (page views / funnel steps) sent to our analytics operator when analytics is active — see section 9. Event payloads are not designed to include intentional PII
  • Support emails you send us

Billing (paid plans)

  • Payment and invoicing data processed by our payment provider (we do not store full card numbers)

3. Why we process data

  • Provide, secure, and improve the Service
  • Authenticate users and prevent abuse
  • Produce compliance audit trails you request (hash-based records with rule citations)
  • Communicate service notices and respond to support
  • Meet legal obligations and enforce our Terms

Where GDPR applies, legal bases include contract performance, legitimate interests (security, product improvement, B2B communications with opt-out), consent where required, and legal obligation.

4. Retention

  • Audit events: default 180 days (DynamoDB TTL). That duration matches the common six-month floor often discussed for deployers of high-risk AI systems under EU AI Act Art 26(6); your own obligations may require longer retention. Plan-level overrides may be available where configured
  • Account data: for the life of the account plus a short wind-down period after deletion/closure
  • Auth OTP codes: short-lived (~5 minutes); expired codes are discarded
  • Backups: limited rolling windows (including point-in-time recovery where enabled), then overwritten

5. Sharing and subprocessors

We do not sell personal data. We use infrastructure and vendors to run the Service, including:

  • Amazon Web Services (AWS) — hosting, storage, compute (primary region: us-west-2)
  • Cloudflare — hosts the customer dashboard and trust portal (Cloudflare Pages)
  • OpenAI — LLM evaluation for the opt-in Layer 2 semantic fallback; receives evaluated text only when use_semantic_fallback is true on the request. The API and SDK default is false (OPA-only path; no content sent to an LLM)
  • Brevo — transactional email (OTP / notices)
  • Stripe — payment processing for paid plans (when enabled)
  • GitHub — public OSS distribution and related source hosting; not a live “connect your private repo” product surface today
  • api.ada-tool.com — analytics operator for marketing pages (consent-gated) and authenticated dashboard funnel events (see section 9)

Vendors process data under contract and only on our instructions (or as independent controllers for their own console accounts, e.g. if you pay Stripe directly).

Which of these are DPA sub-processors. AWS, OpenAI, Brevo and Stripe may process customer personal data submitted through the Service, so they appear in the sub-processor table of the DPA and carry its notice and objection rights. Cloudflare, GitHub and api.ada-tool.com do not process data you submit through the API evaluation path as sub-processors under that DPA. They relate to frontend hosting, source-code hosting, and analytics on our own properties, where we act as an independent controller, which is why they are named here and not in the DPA table.

6. International transfers

Infrastructure may process data in the United States and other countries where our vendors operate. Where required, we use appropriate safeguards (e.g. Standard Contractual Clauses) for transfers from the EEA/UK.

7. Security

We use industry-standard controls appropriate to a cloud API product (TLS in transit, access controls, secret management, auditability). No method of transmission or storage is perfectly secure; please protect your API keys and rotate them if you believe they are compromised.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent. Contact support@complyedge.io. You may also lodge a complaint with your local supervisory authority.

If we process data as your processor, we will assist you in responding to data-subject requests as required by your DPA and applicable law.

9. Cookies and similar technologies

Strictly necessary. We use cookies or local storage for authentication and session continuity on the dashboard. These are required for the Service to function and are set without a separate analytics consent step.

Analytics preference. On marketing pages we also store your analytics Accept/Decline choice in local storage so we can honour it. Remembering a refusal is necessary to honour it.

Marketing analytics, consent required. On our marketing pages (complyedge.io) we use an analytics service operated on our behalf at api.ada-tool.com to measure which pages are read. It stores a randomly generated session_id and user_id in your browser's local storage and sends the page URL, path and timestamp to that domain. It does not load, and nothing for that pixel is stored, unless you accept it when first asked. Declining is remembered and you are not asked again on that browser (except on local development hosts used for product testing). Because the data is transmitted to a domain other than complyedge.io we describe it as a third-party recipient under this Policy.

Dashboard product analytics. On the authenticated dashboard we send product-funnel events (for example sign-in and first dashboard view) to the same api.ada-tool.com operator so we can operate and improve onboarding. Those events use the same session/user identifiers and page URL/path/timestamp fields. They are not the marketing-page consent banner; they run when you use the logged-in product.

To change a marketing-page choice, clear this site's local storage in your browser and reload; you will be asked again. We do not use advertising trackers, and we do not perform cross-site ad retargeting anywhere. Marketing pages may load fonts or CSS from third-party CDNs (for example Google Fonts) for presentation only.

10. Children

The Service is built for professional / organizational use and is not directed to children under 16. We do not knowingly collect their personal data.

11. Changes

We may update this Policy. Material changes will be posted with a new “Last updated” date. Continued use after the effective date constitutes acceptance where permitted by law.

12. Related terms

Use of the Service is also subject to our Terms of Service. Where we act as your processor, see the Data Processing Agreement.

ComplyEdge ComplyEdge
GitHub Blog Terms Privacy DPA SaaS Contact

Disclaimer: ComplyEdge provides compliance tooling, not legal advice. Always consult legal counsel for specific regulatory requirements.