Back to home

Privacy Policy

Last updated: July 2026

Draft — pending legal review. This is a template for evaluation and is not legal advice. It will be reviewed and finalized by counsel before it is relied upon.

This Privacy Policy explains how Compliance HQ (“we,” “us”) collects, uses, and shares information when you use our application and website. By using the service, you agree to the practices described here.

1. Information we collect

We collect the following categories of information:

  • Account information: your username, hashed password, organization, and role.
  • Content you submit: documents, text, and policies you upload for review.
  • Review data: decisions, reviewer notes, and timestamps generated during use.
  • Usage and technical data: log data such as IP address and request metadata, used for security and operations.

2. How we use information

We use the information we collect to:

  • Provide, operate, and secure the service.
  • Perform document compliance reviews you request.
  • Maintain records of reviews and decisions for your organization.
  • Monitor for abuse, troubleshoot issues, and improve reliability.
  • Communicate with you about your account and the service.

3. AI processing and sub-processors

To perform reviews, document text is processed by our AI sub-processor, OpenAI, via its API (GPT-4o and embedding models). OpenAI does not use data submitted through its API to train its models, per OpenAI’s API data-usage policy.

We also rely on infrastructure sub-processors to host and operate the service: Neon (database), Render (application hosting), and Vercel (frontend hosting). A current list of sub-processors is available on request.

4. How we share information

We do not sell your personal information. We share information only as follows:

  • With sub-processors that provide the infrastructure and AI services described above, under contractual confidentiality and security obligations.
  • When required by law, regulation, legal process, or enforceable governmental request.
  • In connection with a merger, acquisition, or sale of assets, subject to this policy.

5. Data retention

We retain account and review data for as long as your organization maintains an account, and as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion of your data as described below. [Confirm specific retention periods with counsel.]

6. Data security

We use technical and organizational measures to protect your data, including encryption in transit and at rest, hashed credentials, and database-level tenant isolation. See our Security page for details. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing (for example under GDPR or CCPA/CPRA). To exercise these rights, contact us at the address below. We will respond within the timeframe required by applicable law.

8. International data transfers

Your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers. [Confirm mechanisms (e.g., Standard Contractual Clauses) with counsel.]

9. Children’s privacy

The service is intended for business use and is not directed to children. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, provide additional notice.

Questions about this privacy policy? Contact privacy@compliancehq.ai.