Privacy Policy
Last updated: [Date]
This Privacy Policy explains what data [Company Legal Name] ("we," "us") collects through ComplyScan (the "Service"), why, and what rights you have over it.
1. Information We Collect
- Account data: email address and a hashed password.
- Scan data: URLs you submit for scanning, and the resulting technical results (violation details, page HTML snippets relevant to each issue found).
- Billing data: handled directly by Stripe — we store your Stripe customer and subscription IDs and plan status, not your card details.
- Technical/log data: IP address, retained briefly to enforce rate limits on the free scanning tool and prevent abuse.
- Prospect data (B2B outbound only): if you receive an outbound email from us, we processed your business domain and a role-based contact address (e.g. hello@yourcompany.com) derived from it — never a scraped personal email address. See Section 6 for how to opt out.
2. How We Use It
- To run the scans you request and show you the results
- To generate AI explanations and suggested fixes for issues found (sent to Anthropic for processing — see Section 3)
- To send account, billing, and scan-digest emails (via Resend)
- To process subscription payments (via Stripe)
- To prevent abuse of the free scanning tool (IP-based rate limiting)
3. Who We Share Data With
We use the following processors to run the Service. Each only receives the data it needs to perform its function:
- Anthropic — processes scan violation data (rule descriptions and page HTML snippets) to generate explanations and suggested fixes.
- Stripe — processes payment and billing data.
- Resend — sends transactional, digest, and outbound email on our behalf.
- [Database/hosting provider] — stores application data.
We do not sell your data, and we do not share it with anyone else except where required by law.
4. Data Retention
Account and scan data is retained for as long as your account is active, plus [retention period] afterward for legal/accounting purposes. Rate-limit IP logs are retained briefly (a matter of minutes) and not linked to your account. You can request deletion at any time — see Section 6.
5. Cookies
We use one essential session cookie to keep you signed in. It is not used for advertising or cross-site tracking, and isn't set until you log in.
6. Your Rights
If you're in the EU/EEA or UK, you have rights under GDPR to access, correct, delete, or export your data, and to object to or restrict certain processing. To exercise any of these, or to opt out of outbound emails (reply STOP to any outbound email, or contact us directly), email [Contact Email]. [EU Representative, if required under Art. 27 GDPR: Name / Address.]
7. Security
Passwords are hashed (never stored in plain text). Data is transmitted over encrypted connections. No system is perfectly secure, and we can't guarantee absolute security.
8. International Transfers
Our processors (Section 3) may process data outside your country, including in the United States. Where that involves transferring EU/EEA personal data outside the EU/EEA, we rely on those providers' standard contractual clauses or equivalent safeguards.
9. Children's Privacy
The Service is intended for business use and not directed at children. We do not knowingly collect data from anyone under 16.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by email or an in-app notice before they take effect.
11. Contact
[Company Legal Name], [Registered Address]. Questions or requests: [Contact Email].