1. Who we are
ComplyEasy (“ComplyEasy”, “we”, “us”) operates the ComplyEasy web application at complyeasy.net. For the purposes of the EU/UK GDPR and equivalent laws (Nigeria’s NDPA, Canada’s PIPEDA), ComplyEasy is the data controller for account and billing data, and a processor for the policy documents you upload for analysis.
Questions about this policy or your data? Email privacy@complyeasy.net.
2. What we collect and why
| Data | Why we collect it | Lawful basis (EU/UK) |
|---|---|---|
| Name, email | Create and secure your account, send account & product emails | Contract (Art. 6(1)(b)) |
| Password (stored hashed, never in plaintext) | Authenticate you | Contract |
| Uploaded policy documents (PDF / DOCX) | Extract text and send it to an AI model to generate a gap analysis | Contract |
| AI-generated analysis results and findings | Show you your compliance score and findings; let you track resolutions | Contract |
| Subscription & payment status (plan, renewal date, last-4 via Stripe) | Bill you, gate features by plan, contact you about failed payments | Contract / Legal obligation (tax records) |
| Basic product usage (pages, feature interactions) via Google Analytics | Understand how the product is used and improve it | Consent (Art. 6(1)(a)) — only after you accept cookies |
| Server logs (IP, user agent, timestamps) | Security, abuse prevention, debugging | Legitimate interests (Art. 6(1)(f)) |
3. How your uploaded documents are used
This is the part that matters most, so we’ll be direct:
- When you upload a policy document, we extract its text and send that text to the Lovable AI Gateway, which forwards it to a large language model (currently Google’s Gemini family) to generate your gap analysis.
- The AI provider processes the text solely to return an analysis. Per Lovable’s and Google’s API terms, uploaded content is not used to train foundation models.
- The original file is stored in our database so you can re-open the analysis. The extracted text is transmitted over TLS, not persisted by the AI provider beyond the request lifecycle.
- Please do not upload documents containing information you would not want stored in a US-hosted database (e.g. raw customer PII, payment card data, health records). ComplyEasy is designed for policy documents.
4. Who we share data with
We use a small, deliberate set of subprocessors:
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account, uploaded documents, analysis results | United States |
| Stripe | Payment processing & subscription billing | Name, email, billing address, card details (handled by Stripe) | United States / Ireland |
| Lovable AI Gateway (Google Gemini) | Generate compliance analysis from your document text | Extracted document text, chosen framework | United States |
| Google Analytics 4 | Anonymized product analytics — only if you accept cookies | Pseudonymous usage events, IP truncated by Google | United States / EU |
| Cloudflare | Application hosting & DDoS protection | Request metadata, IP | Global edge |
| Resend (via ComplyEasy) | Transactional email (waitlist, subscription, receipts) | Name, email | United States |
We do not sell your data, and we don’t share it with advertisers.
5. International transfers
Because Supabase, Stripe, our AI provider, and our email provider are US-based, your personal data — including the text of uploaded documents — is transferred to and processed in the United States. If you are in the EU/UK, Nigeria, or Canada, this means your data leaves your jurisdiction. We rely on the following safeguards:
- EU/UK → US: Standard Contractual Clauses with each subprocessor, plus, where applicable, the EU-US Data Privacy Framework.
- Nigeria (NDPA): transfer to jurisdictions with adequate protection, or on the basis of your contract with us for the service you requested.
- Canada (PIPEDA): contractual protections requiring subprocessors to provide a comparable level of protection to Canadian standards.
6. How long we keep your data
| Data | Retention |
|---|---|
| Account (name, email, hashed password) | For the life of your account. Deleted within 30 days of account deletion. |
| Uploaded documents & analysis results | Until you delete them, or 30 days after account deletion, whichever is sooner. |
| Subscription & invoice records | 7 years after the last transaction (tax & accounting obligations). |
| Server & security logs | 90 days, then aggregated or deleted. |
| Google Analytics events | 14 months (GA4 default retention). |
| Waitlist entries (pre-launch signups) | Until launch or unsubscribe, whichever comes first. |
7. Your rights
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate.
- Deletion — ask us to delete your account and associated data.
- Portability — receive your data (documents and analyses) in a machine-readable format.
- Objection / restriction — object to or limit certain processing.
- Withdraw consent — for analytics cookies, at any time.
- Lodge a complaint — with your local supervisory authority (e.g. the Irish DPC, UK ICO, Nigeria’s NDPC, or Canada’s OPC).
To exercise any of these, email privacy@complyeasy.net from the address on your account. We’ll respond within 30 days (as required under GDPR and PIPEDA).
8. Security
Passwords are hashed (bcrypt-family) by our authentication provider — we never see them. All traffic is served over HTTPS/TLS. Access to production data is restricted to the small number of ComplyEasy staff who need it, and reviewed periodically. We do not have a formal third-party certification yet; the product itself is intended to help you get there.
9. Cookies
We use a minimal set of cookies. See our Cookie Policy for the details, including how to change your consent choice.
10. Children
ComplyEasy is a B2B product intended for adults acting on behalf of an organisation. We do not knowingly collect data from children under 16.
11. Changes
We’ll update this policy as the product evolves. Material changes (new subprocessors, new data categories) will be announced by email to signed-up users before they take effect.
12. Contact
Privacy inquiries: privacy@complyeasy.net. General support: support@complyeasy.net.