Complyance is the trading name of Securely Technology Limited, a company registered in England and Wales, and its subsidiary, Complyance US Inc. In this notice, "Complyance," "we," and "us" refer to both entities.
Where we act as a controller. We decide how and why personal data is processed when we operate our website, run marketing and sales activities, respond to enquiries, administer customer accounts, and manage our own business. This notice describes that processing.
Where we act as a processor. Customers use the Complyance platform to run governance, risk, and compliance workflows. Personal data that a customer or its users load into their Complyance environment is processed on that customer's instructions, under a data processing agreement. The customer is the controller for that data and decides why it is processed and how long it is kept. This notice does not govern that processing.
We only retain data for the minimum amount of time required either by contract, law, or if neither apply, for the minimum amount of time needed for the business use case.
Data you give us. We collect the minimal amount of data. Name, business email address, telephone number, job title, employer, and the contents of enquiries, support requests, and other correspondence.
Data we collect automatically. When you visit our website or use the platform, our systems record IP address, browser and device type, operating system, pages viewed, referring and exit pages, and timestamps. Platform activity logs record actions taken by named users, which is a security and audit requirement of the product.
Data we obtain from other sources. We obtain business contact details from data enrichment and sales intelligence providers, professional networking platforms, publicly available sources such as company websites, event organizers and co-marketing partners, and referrals. This data is limited to professional information: name, job title, employer, business email, and business phone number.
The Complyance platform uses AI agents to execute GRC workflows inside customer environments.
We do not use customer data to train or fine-tune AI models. Personal data and business data in a customer's Complyance environment is used to deliver the service to that customer and for no other purpose. It is not used to train, fine-tune, or improve any model, and it is not used to benefit other customers. All AI Agents can be turned off in the platform for each customer.
Model providers do not train on customer data. Where we use third-party model providers to deliver platform functionality, we contract on terms that prohibit them from retaining or training on data we send them.
Agents operate inside configured, auditable workflows. Where an agent produces a recommendation or an output that a customer acts on, a person in the customer's organization reviews and decides. We do not make automated decisions that produce legal or similarly significant effects on individuals.
Our website uses strictly necessary cookies only.
Our application uses technologies necessary to keep you signed in, maintain session security, and record product usage. These are required for the service to function
We use third parties for hosting, security, communications, customer relationship management, analytics, payment processing, and professional services. They act on our instructions, are bound by written contracts, and may use the data only to provide their service to us. Our sub-processors for the Complyance platform are listed here, and customers are notified of changes under their data processing agreement.
We disclose personal data where we are legally required to, where necessary to establish or defend legal claims, or where necessary to protect the rights or safety of Complyance, our customers, or others. Where a law enforcement or government request relates to customer data, we notify the customer unless legally prohibited from doing so.
We do not sell personal data, and we do not share it for cross-context behavioral advertising as those terms are defined under US state privacy laws.
Security is central to what we sell, and we hold ourselves to the standard we ask customers to meet. We maintain an information security program covering access control, encryption in transit and at rest, logging and monitoring, vulnerability management, secure development, vendor management, and incident response. We annually undergo a SOC 2 Type II examination, and maintain robust security controls consistent with industry standards.
Depending on where you live, you may have the right to access the personal data we hold about you, receive it in a portable format, correct it, delete it, restrict or object to how we use it, withdraw consent where we rely on it, and opt out of direct marketing. Residents of certain US states also have the right not to be discriminated against for exercising these rights, and may use an authorized agent to submit a request.
To exercise any of these rights, email privacy@complyance.com. We will respond within the period required by applicable law and may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
You can opt out of marketing at any time using the unsubscribe link in any marketing email or by emailing privacy@complyance.com.
If you are unhappy with how we have handled your personal data, you can complain to a regulator: the Information Commissioner's Office in the United Kingdom, your supervisory authority in the EEA, or your state attorney general in the United States.
Complyance is a business product sold to organizations. It is not directed at children and we do not knowingly collect personal data from anyone under 16. If we learn that we hold personal data from a child, we will delete it.
We update this notice as our business and the law change. The current version and its date appear at the top. Where a change materially affects how we use personal data, we will give notice by email or in the product before it takes effect.
Questions about this notice, or about how we handle personal data:
Additional information
Our InfoSec sheet is available here.
Our DPA is available here.
Our SLA’s are available here.