Legal · v0.1
Effective date: 11 July 2026 · Last updated: 31 July 2026
ComplyEdge (“we”, “us”) operates the Service at complyedge.io, api.complyedge.io, dashboard.complyedge.io, trust.complyedge.io, and related properties. For privacy and support requests contact support@complyedge.io.
Depending on the processing activity, we act as an independent controller (account administration, website and product analytics, billing) or as a processor (evaluating content you submit through the API on your instructions). Processor terms may be set out in a Data Processing Agreement for enterprise customers. Where a DPA is required, it is executed offline (email countersign), not as an in-product clickwrap.
text_hash only in standard production DynamoDB audit rows — we do not persist raw prompts/outputs in those rows unless a separate written agreement says otherwise. Application / debug logs may briefly include truncated request text for operational troubleshootingWhere GDPR applies, legal bases include contract performance, legitimate interests (security, product improvement, B2B communications with opt-out), consent where required, and legal obligation.
We do not sell personal data. We use infrastructure and vendors to run the Service, including:
use_semantic_fallback is true on the request. The API and SDK default is false (OPA-only path; no content sent to an LLM)Vendors process data under contract and only on our instructions (or as independent controllers for their own console accounts, e.g. if you pay Stripe directly).
Which of these are DPA sub-processors. AWS, OpenAI, Brevo and Stripe may process customer personal data submitted through the Service, so they appear in the sub-processor table of the DPA and carry its notice and objection rights. Cloudflare, GitHub and api.ada-tool.com do not process data you submit through the API evaluation path as sub-processors under that DPA. They relate to frontend hosting, source-code hosting, and analytics on our own properties, where we act as an independent controller, which is why they are named here and not in the DPA table.
Infrastructure may process data in the United States and other countries where our vendors operate. Where required, we use appropriate safeguards (e.g. Standard Contractual Clauses) for transfers from the EEA/UK.
We use industry-standard controls appropriate to a cloud API product (TLS in transit, access controls, secret management, auditability). No method of transmission or storage is perfectly secure; please protect your API keys and rotate them if you believe they are compromised.
Depending on your location, you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent. Contact support@complyedge.io. You may also lodge a complaint with your local supervisory authority.
If we process data as your processor, we will assist you in responding to data-subject requests as required by your DPA and applicable law.
Strictly necessary. We use cookies or local storage for authentication and session continuity on the dashboard. These are required for the Service to function and are set without a separate analytics consent step.
Analytics preference. On marketing pages we also store your analytics Accept/Decline choice in local storage so we can honour it. Remembering a refusal is necessary to honour it.
Marketing analytics, consent required. On our marketing pages (complyedge.io) we use an analytics service operated on our behalf at api.ada-tool.com to measure which pages are read. It stores a randomly generated session_id and user_id in your browser's local storage and sends the page URL, path and timestamp to that domain. It does not load, and nothing for that pixel is stored, unless you accept it when first asked. Declining is remembered and you are not asked again on that browser (except on local development hosts used for product testing). Because the data is transmitted to a domain other than complyedge.io we describe it as a third-party recipient under this Policy.
Dashboard product analytics. On the authenticated dashboard we send product-funnel events (for example sign-in and first dashboard view) to the same api.ada-tool.com operator so we can operate and improve onboarding. Those events use the same session/user identifiers and page URL/path/timestamp fields. They are not the marketing-page consent banner; they run when you use the logged-in product.
To change a marketing-page choice, clear this site's local storage in your browser and reload; you will be asked again. We do not use advertising trackers, and we do not perform cross-site ad retargeting anywhere. Marketing pages may load fonts or CSS from third-party CDNs (for example Google Fonts) for presentation only.
The Service is built for professional / organizational use and is not directed to children under 16. We do not knowingly collect their personal data.
We may update this Policy. Material changes will be posted with a new “Last updated” date. Continued use after the effective date constitutes acceptance where permitted by law.
Use of the Service is also subject to our Terms of Service. Where we act as your processor, see the Data Processing Agreement.