Last updated: 27 July 2026
Simple Use Software, LLC d/b/a AI COMPLY HQ™ ("we", "us", "our") is the data controller for personal data processed through the AI Comply HQ platform at aicomplyhq.com.
Contact: privacy@aicomplyhq.com
Postal address: Simple Use Software, LLC, 1314 E Las Olas Blvd, #2085, Fort Lauderdale, FL 33301, United States.
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit app.prighter.com/portal/12051303668 or write to the representative addresses above.
Data Protection Officer: We have assessed our processing and are not currently required to appoint a Data Protection Officer under GDPR Article 37. You may direct all privacy questions to privacy@aicomplyhq.com.
When you create an account, we collect:
When you use our compliance interview, we collect:
If you use voice mode, we additionally process:
Important: Voice audio is processed by Cartesia (our speech processing provider) for transcription and text-to-speech. Audio is processed in real time and is not retained after transcription. See Section 6 for details. Please do not speak special categories of personal data (such as health information) during a voice interview, as it is not required for the assessment.
Payment information (credit card numbers, billing address) is collected and processed directly by Stripe, our payment processor. We do not store your payment card details. From Stripe we receive: your purchase email, billing country (for tax purposes), subscription status and plan tier (for subscriptions), or transaction confirmation (for one-time downloads), and a Stripe customer identifier.
If you purchase a one-time download (such as the Annex IV Bundle), we additionally process:
One-time downloads do not create a long-lived user account. The 7-day workspace closes after the magic link expires, and the data is retained per Section 8.
If you accept analytics cookies, we collect anonymized usage data via Google Analytics, including: pages visited, features used, session duration, and general geographic region. Analytics data is only collected after you explicitly consent via our cookie banner.
If you upload a business document to help pre-fill an interview, the file is processed in memory and deleted immediately. The document itself is never stored. Only the field values you review and confirm are saved to your assessment. We do not use your documents to train AI models.
We are introducing an AI onboarding assistant (Concierge) that will help you get set up. When it becomes available to you, you will see a clear notice that you are interacting with AI before it begins. When you use it, we collect:
We use these details to personalize your onboarding, guide you to the right next step, and pre-fill parts of your compliance interview so you are not asked the same thing twice. AI-written content is marked as AI-generated, and we do not use your onboarding conversations to train AI models. The assistant carries out a setup and routing task; it does not make automated decisions that produce legal or similarly significant effects.
| Purpose | Data Used | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Provide the compliance interview service | Account data, interview responses | Contract (Art. 6(1)(b)) |
| Generate AI-powered compliance assessments | Interview responses sent to AI provider | Contract (Art. 6(1)(b)) |
| Personalize onboarding and guide you through setup (Concierge) | Onboarding conversation, extracted fields | Contract (Art. 6(1)(b)) and Legitimate interest (Art. 6(1)(f)) |
| Process voice interviews | Voice audio, transcriptions | Consent (Art. 6(1)(a)) |
| Process subscription payments | Email, subscription tier (via Stripe) | Contract (Art. 6(1)(b)) |
| Fulfill one-time download purchases | Purchase email, wizard responses, generated PDF | Contract (Art. 6(1)(b)) |
| Authenticate one-time download access via magic link | Email, magic-link token, access IP | Contract (Art. 6(1)(b)) and Legitimate interest (Art. 6(1)(f) — security) |
| Analytics and service improvement | Anonymized usage data | Consent (Art. 6(1)(a)) |
| Security and fraud prevention | Audit logs, session data | Legitimate interest (Art. 6(1)(f)) |
AI Comply HQ™ uses artificial intelligence to process your interview responses and generate compliance assessments. Specifically:
No solely automated decisions with legal effect. Our AI outputs are advisory. You review, edit, and approve them, so they are not automated decisions that produce legal or similarly significant effects under GDPR Article 22. You may request meaningful information about the logic involved by contacting us.
We do not use your interview responses, voice data, uploaded documents, or generated outputs to train our own AI models. Under our agreements with our AI providers, data submitted through their APIs is used only to return results to us and is not used to train their foundation models. If this ever changes, we will update this policy and, where required, ask for your consent.
We share personal data with the following processors, each under a Data Processing Agreement. We remain responsible for personal data we entrust to them.
| Processor | Purpose | Location |
|---|---|---|
| Anthropic (Claude API) | AI interview processing | United States |
| Cartesia | Voice processing (STT/TTS) | United States |
| Supabase | Database and authentication | European Union — Frankfurt, Germany (AWS eu-central-1) |
| Stripe | Payment processing | United States / EU |
| Netlify | Application hosting | Variable (CDN) |
| Resend | Transactional email (verification, notifications) | United States |
| Google (Analytics) | Website analytics (consent-only) | United States |
| Cloudflare | Runs the onboarding assistant (edge compute) | Global edge |
| PostHog | Product analytics (onboarding) | European Union |
| Sentry | Error monitoring (onboarding assistant) | European Union |
We may add or replace processors as the Service evolves. We will update this list, and business customers may subscribe to advance notice of sub-processor changes by emailing privacy@aicomplyhq.com.
Some of our processors are located outside the European Economic Area (EEA). For transfers to the United States and other third countries, we rely on:
You may request information about the safeguards applied to a specific transfer by contacting us.
We may retain limited information for longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements. Backups are overwritten on a rolling basis.
You have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@aicomplyhq.com. We may need to verify your identity before responding, and we will respond within 30 days. There is no fee unless your request is manifestly unfounded or excessive.
If you are a resident of California or another U.S. state with a comprehensive privacy law (such as Virginia, Colorado, or Connecticut), you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the "sale" or "sharing" of personal information, and certain profiling.
You can change or withdraw your cookie choices at any time through the cookie banner. Where required, we treat a recognized opt-out signal such as Global Privacy Control as a request to decline non-essential cookies.
We implement appropriate technical and organizational measures including:
No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data using measures appropriate to the risk.
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also notify affected users without undue delay.
We may disclose personal data where we believe in good faith that doing so is necessary to comply with a legal obligation, respond to lawful requests from public authorities, enforce our agreements, or protect the rights, safety, or property of our users or others. If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Privacy Policy or a policy at least as protective, and we will notify you of any material change in how your data is handled.
AI Comply HQ™ is a business-to-business service. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately.
We may update this Privacy Policy at any time to reflect changes in our data practices, technology, or legal requirements. When we make changes, we will update the "Last updated" date above, and for material changes we will notify you by email or a prominent notice on our platform before they take effect. We encourage you to review this page periodically. Your continued use of the Service after an update takes effect means you acknowledge the revised policy.
If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU/EEA supervisory authorities is available at edpb.europa.eu. UK users may complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concerns first.
For privacy inquiries or data subject requests:
Email: privacy@aicomplyhq.com
General: hello@aicomplyhq.com