Effective Date: January 1, 2025 Last Updated: January 1, 2025
Introduction
At Complyn (“we,” “our,” or “us”), we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our regulatory reporting and compliance platform (the “Service”).
This policy applies to all users of our Service, including visitors to our website, registered users, and customers. By using our Service, you agree to the collection and use of information in accordance with this policy.
We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
1. Information We Collect
1.1 Information You Provide to Us
Account Information:
- Full name
- Email address
- Phone number
- Company name and position
- Billing address
- Payment information (processed securely through third-party payment processors)
Profile Information:
- Professional credentials
- Department and role
- Preferences and settings
- Communication preferences
Content and Files:
- Questionnaire responses
- Uploaded documents and files
- Reports and submissions
- Comments and annotations
- Custom templates and configurations
Communications:
- Support requests and correspondence
- Feedback and survey responses
- Email communications with our team
1.2 Information We Collect Automatically
Usage Information:
- Pages visited and features used
- Time spent on the platform
- Actions taken (clicks, downloads, uploads)
- Search queries
- Session duration and frequency
Device and Technical Information:
- IP address
- Browser type and version
- Operating system
- Device type and identifiers
- Screen resolution
- Language preferences
- Referring URLs
Cookies and Similar Technologies:
- Session cookies (essential for platform functionality)
- Preference cookies (remember your settings)
- Analytics cookies (understand usage patterns)
- Marketing cookies (with your consent)
1.3 Information from Third Parties
Integration Data:
- Data imported from connected systems (with your authorization)
- Single Sign-On (SSO) authentication data
- Third-party service provider information
Business Information:
- Company data from public sources
- Industry and regulatory information
- Contact information from business partners
2. How We Use Your Information
We use your personal data for the following purposes:
2.1 Service Delivery
- Provide access to our platform and features
- Process and store your compliance data
- Generate reports and analytics
- Enable collaboration with team members
- Provide customer support
2.2 Service Improvement
- Analyze usage patterns to improve functionality
- Develop new features and services
- Conduct research and development
- Test and optimize platform performance
2.3 Communication
- Send service-related notifications
- Provide customer support responses
- Share product updates and announcements
- Send marketing communications (with consent)
- Conduct surveys and gather feedback
2.4 Security and Compliance
- Detect and prevent fraud and abuse
- Ensure platform security
- Comply with legal obligations
- Enforce our terms of service
- Protect our rights and property
2.5 Business Operations
- Process payments and billing
- Manage customer relationships
- Conduct business analytics
- Fulfill contractual obligations
3. Legal Basis for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our Service
- Legitimate Interests: Improving our Service, security, and business operations
- Legal Obligation: Compliance with applicable laws and regulations
- Consent: Marketing communications and optional features (you can withdraw consent anytime)
4. Data Sharing and Disclosure
4.1 We Do Not Sell Your Data
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
4.2 Service Providers
We share data with trusted third-party service providers who assist us in:
- Cloud hosting and infrastructure (AWS, Azure)
- Payment processing (Stripe, PayPal)
- Email delivery (SendGrid, Mailchimp)
- Analytics (Google Analytics, Mixpanel)
- Customer support (Zendesk, Intercom)
All service providers are contractually obligated to protect your data and use it only for specified purposes.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such change.
4.4 Legal Requirements
We may disclose your data when required by law, such as:
- Responding to legal process (subpoenas, court orders)
- Protecting our rights and property
- Preventing fraud or illegal activities
- Ensuring user safety
4.5 With Your Consent
We may share data with third parties when you explicitly authorize us to do so.
5. Data Security
We implement comprehensive security measures to protect your data:
Technical Measures
- Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
- Access Controls: Role-based access with multi-factor authentication
- Network Security: Firewalls, intrusion detection, and DDoS protection
- Secure Development: Regular security audits and penetration testing
Organizational Measures
- Staff Training: Regular security awareness training
- Access Restrictions: Principle of least privilege
- Incident Response: Documented procedures for security incidents
- Vendor Management: Due diligence on all service providers
Compliance Certifications
- SOC 2 Type II certified
- ISO 27001 certified
- GDPR compliant
- Regular third-party security assessments
6. Data Retention
We retain your personal data for as long as necessary to:
- Provide our Service to you
- Comply with legal obligations
- Resolve disputes
- Enforce our agreements
Specific Retention Periods:
- Account Data: Duration of account plus 90 days after closure
- Compliance Records: As required by applicable regulations (typically 7 years)
- Usage Logs: 12 months
- Marketing Data: Until consent is withdrawn
- Backup Data: 30 days
You can request deletion of your data at any time, subject to legal retention requirements.
7. Your Rights and Choices
7.1 GDPR Rights (EU/EEA Users)
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data (“right to be forgotten”)
- Restriction: Limit how we process your data
- Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for processing at any time
- Lodge a Complaint: File a complaint with your data protection authority
7.2 CCPA Rights (California Users)
You have the right to:
- Know what personal information we collect
- Know whether we sell or disclose your information
- Access your personal information
- Request deletion of your information
- Opt-out of the sale of your information (we don’t sell data)
- Non-discrimination for exercising your rights
7.3 How to Exercise Your Rights
To exercise any of these rights:
- Email: privacy@getcomplyn.com
- In-Platform: Use the privacy settings in your account
- Mail: Complyn Privacy Team, [Address]
We will respond to your request within 30 days (GDPR) or 45 days (CCPA).
8. Cookies and Tracking Technologies
8.1 Types of Cookies We Use
Essential Cookies (Required):
- Session management
- Authentication
- Security features
Functional Cookies (Optional):
- Remember preferences
- Language settings
- UI customization
Analytics Cookies (Optional):
- Usage statistics
- Performance monitoring
- Feature adoption
Marketing Cookies (Optional, with consent):
- Advertising effectiveness
- Retargeting campaigns
8.2 Managing Cookies
You can control cookies through:
- Browser settings (block or delete cookies)
- Our cookie consent banner
- Privacy settings in your account
Note: Disabling essential cookies may affect platform functionality.
9. International Data Transfers
We operate globally and may transfer your data to countries outside your residence, including the United States. We ensure appropriate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy Decisions for countries with adequate protection
- Binding Corporate Rules for intra-group transfers
- Your Explicit Consent when required
10. Children’s Privacy
Our Service is not intended for children under 16. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.
11. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by:
- Email notification
- In-platform notification
- Posting on our website
Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions or concerns:
Privacy Team:
- Email: privacy@getcomplyn.com
- Phone: +359 899 888 125
- Address: [Company Address]
Data Protection Officer:
- Email: dpo@getcomplyn.com
EU Representative:
- [EU Representative Details]
14. Supervisory Authority
If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection authority:
Last Updated: January 1, 2025
This Privacy Policy is effective as of the date stated above and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page.