Privacy Policy

Last updated: 27 July 2026

1. Data Controller and Representatives

Simple Use Software, LLC d/b/a AI COMPLY HQ™ ("we", "us", "our") is the data controller for personal data processed through the AI Comply HQ platform at aicomplyhq.com.

Contact: privacy@aicomplyhq.com

Postal address: Simple Use Software, LLC, 1314 E Las Olas Blvd, #2085, Fort Lauderdale, FL 33301, United States.

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

  • United Kingdom (UK) — UK GDPR Article 27: Prighter Ltd, 20 Mortlake High Street, London SW14 8JN, United Kingdom.
  • European Union (EU) — GDPR Article 27: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria.

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit app.prighter.com/portal/12051303668 or write to the representative addresses above.

Data Protection Officer: We have assessed our processing and are not currently required to appoint a Data Protection Officer under GDPR Article 37. You may direct all privacy questions to privacy@aicomplyhq.com.

2. What Personal Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Email address (required for authentication)
  • Full name (if provided)
  • Organization name

2.2 Interview Data

When you use our compliance interview, we collect:

  • Your responses to interview questions
  • AI-generated follow-up questions and analysis
  • Specificity scores for your answers
  • Auto-filled form field values extracted by AI from your responses
  • Your edits and approvals of auto-filled fields
  • Interview session metadata (start time, completion time, mode, sections completed)

2.3 Voice Data (Voice Mode Only)

If you use voice mode, we additionally process:

  • Audio recordings of your speech (processed in real-time for transcription)
  • Transcriptions of your spoken responses

Important: Voice audio is processed by Cartesia (our speech processing provider) for transcription and text-to-speech. Audio is processed in real time and is not retained after transcription. See Section 6 for details. Please do not speak special categories of personal data (such as health information) during a voice interview, as it is not required for the assessment.

2.4 Payment Data

Payment information (credit card numbers, billing address) is collected and processed directly by Stripe, our payment processor. We do not store your payment card details. From Stripe we receive: your purchase email, billing country (for tax purposes), subscription status and plan tier (for subscriptions), or transaction confirmation (for one-time downloads), and a Stripe customer identifier.

2.5 One-Time Download Data

If you purchase a one-time download (such as the Annex IV Bundle), we additionally process:

  • Purchase email — used to send your magic-link access token after Stripe confirms payment. This is the only authentication factor for one-time purchases (no password is created).
  • Onboarding wizard responses — the structured answers you provide to generate your bundle PDF (system name, intended purpose, deployment context, etc.).
  • Generated PDF — the bundle document we produce from your inputs, stored briefly for retrieval via your magic link.
  • Magic-link session metadata — token issue time, link click time, IP address of access (for security and abuse prevention), and expiry time.

One-time downloads do not create a long-lived user account. The 7-day workspace closes after the magic link expires, and the data is retained per Section 8.

2.6 Analytics Data (With Your Consent)

If you accept analytics cookies, we collect anonymized usage data via Google Analytics, including: pages visited, features used, session duration, and general geographic region. Analytics data is only collected after you explicitly consent via our cookie banner.

2.7 Automatically Collected Data

  • Authentication session tokens (strictly necessary cookies)
  • Audit logs of significant actions (for security and compliance)

2.8 Document Scanning (Optional)

If you upload a business document to help pre-fill an interview, the file is processed in memory and deleted immediately. The document itself is never stored. Only the field values you review and confirm are saved to your assessment. We do not use your documents to train AI models.

2.9 Onboarding Assistant (Concierge)

We are introducing an AI onboarding assistant (Concierge) that will help you get set up. When it becomes available to you, you will see a clear notice that you are interacting with AI before it begins. When you use it, we collect:

  • The messages you send the assistant (typed or spoken)
  • The details extracted from that conversation, such as the type of AI system you want to make compliant, your role, company size, and timeline
  • Conversation metadata (start time and completion status)

We use these details to personalize your onboarding, guide you to the right next step, and pre-fill parts of your compliance interview so you are not asked the same thing twice. AI-written content is marked as AI-generated, and we do not use your onboarding conversations to train AI models. The assistant carries out a setup and routing task; it does not make automated decisions that produce legal or similarly significant effects.

3. How We Use Your Data

PurposeData UsedLegal Basis (GDPR Art. 6)
Provide the compliance interview serviceAccount data, interview responsesContract (Art. 6(1)(b))
Generate AI-powered compliance assessmentsInterview responses sent to AI providerContract (Art. 6(1)(b))
Personalize onboarding and guide you through setup (Concierge)Onboarding conversation, extracted fieldsContract (Art. 6(1)(b)) and Legitimate interest (Art. 6(1)(f))
Process voice interviewsVoice audio, transcriptionsConsent (Art. 6(1)(a))
Process subscription paymentsEmail, subscription tier (via Stripe)Contract (Art. 6(1)(b))
Fulfill one-time download purchasesPurchase email, wizard responses, generated PDFContract (Art. 6(1)(b))
Authenticate one-time download access via magic linkEmail, magic-link token, access IPContract (Art. 6(1)(b)) and Legitimate interest (Art. 6(1)(f) — security)
Analytics and service improvementAnonymized usage dataConsent (Art. 6(1)(a))
Security and fraud preventionAudit logs, session dataLegitimate interest (Art. 6(1)(f))

4. AI System Disclosure (EU AI Act Article 50)

AI Comply HQ™ uses artificial intelligence to process your interview responses and generate compliance assessments. Specifically:

  • Interview responses are processed by Anthropic's Claude AI model to generate follow-up questions, evaluate answer specificity, and extract structured compliance data.
  • Onboarding conversations with our setup assistant (Concierge), a feature we are introducing, are processed by Anthropic's Claude AI to understand your goals and personalize your setup.
  • Voice audio (voice mode only) is processed by Cartesia's speech AI for transcription (speech-to-text) and spoken responses (text-to-speech).
  • Risk classifications and auto-filled form fields are AI-generated outputs that should be reviewed by a qualified professional before use in any regulatory submission.

No solely automated decisions with legal effect. Our AI outputs are advisory. You review, edit, and approve them, so they are not automated decisions that produce legal or similarly significant effects under GDPR Article 22. You may request meaningful information about the logic involved by contacting us.

5. How AI Providers Use Your Data (Model Training)

We do not use your interview responses, voice data, uploaded documents, or generated outputs to train our own AI models. Under our agreements with our AI providers, data submitted through their APIs is used only to return results to us and is not used to train their foundation models. If this ever changes, we will update this policy and, where required, ask for your consent.

6. Third-Party Data Processors

We share personal data with the following processors, each under a Data Processing Agreement. We remain responsible for personal data we entrust to them.

ProcessorPurposeLocation
Anthropic (Claude API)AI interview processingUnited States
CartesiaVoice processing (STT/TTS)United States
SupabaseDatabase and authenticationEuropean Union — Frankfurt, Germany (AWS eu-central-1)
StripePayment processingUnited States / EU
NetlifyApplication hostingVariable (CDN)
ResendTransactional email (verification, notifications)United States
Google (Analytics)Website analytics (consent-only)United States
CloudflareRuns the onboarding assistant (edge compute)Global edge
PostHogProduct analytics (onboarding)European Union
SentryError monitoring (onboarding assistant)European Union

We may add or replace processors as the Service evolves. We will update this list, and business customers may subscribe to advance notice of sub-processor changes by emailing privacy@aicomplyhq.com.

7. International Data Transfers

Some of our processors are located outside the European Economic Area (EEA). For transfers to the United States and other third countries, we rely on:

  • The EU-US Data Privacy Framework (and its UK and Swiss extensions) where the processor is certified, and
  • European Commission-approved Standard Contractual Clauses (SCCs) as a fallback and additional safeguard, together with
  • Supplementary technical and organizational measures, consistent with the CJEU Schrems II ruling.

You may request information about the safeguards applied to a specific transfer by contacting us.

8. Data Retention

  • Account data: Retained for the duration of your account. Deleted within 30 days of account deletion request.
  • Interview data (answers, auto-filled forms, generated documents, feedback, AI-interaction logs): Retained per your organization's configured retention period (180 days by default) from creation, after which it is hidden from the app and permanently deleted 12 months later. You may request earlier deletion at any time.
  • Onboarding assistant (Concierge) data: Conversation transcripts and extracted fields are retained for 180 days (or your organization's configured retention period), then deleted. You may request earlier deletion at any time.
  • Voice recordings: Processed in real-time. Audio is not stored after transcription.
  • One-time download wizard responses and generated PDF: The 7-day workspace closes 7 days after purchase. The generated PDF and wizard responses are retained for 12 months from purchase for support and re-download requests, then deleted. You may request earlier deletion at any time.
  • Magic-link tokens: Hashed in storage, invalidated after first use or 7 days, whichever comes first. Token access logs are retained for 6 months for security review.
  • Payment data: Retained by Stripe per their data retention policy.
  • Analytics data: Retained by Google Analytics for 26 months.
  • Audit logs (append-only, keyed to a user ID): Kept as a tamper-evident security and accountability record for the life of your organization's account, and deleted when the organization is erased. We retain them despite an individual erasure request only to the extent GDPR Article 17(3) permits (for example, to establish or defend legal claims), and we delete or anonymize them where no such exception applies.

We may retain limited information for longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements. Backups are overwritten on a rolling basis.

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Correct inaccurate personal data.
  • Right to erasure (Art. 17): Request deletion of your personal data.
  • Right to restriction (Art. 18): Request that we limit processing of your data.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interest.
  • Right regarding automated decisions (Art. 22): Our AI outputs are advisory and subject to human review, not automated decision-making with legal effects. You may request meaningful information about the logic involved.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw at any time.

To exercise any of these rights, contact us at privacy@aicomplyhq.com. We may need to verify your identity before responding, and we will respond within 30 days. There is no fee unless your request is manifestly unfounded or excessive.

10. Your U.S. State Privacy Rights

If you are a resident of California or another U.S. state with a comprehensive privacy law (such as Virginia, Colorado, or Connecticut), you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the "sale" or "sharing" of personal information, and certain profiling.

  • No sale or sharing. We do not sell your personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under California law.
  • Opt-out preference signals. Where applicable, we honor recognized browser-based opt-out signals, such as Global Privacy Control (GPC).
  • How to exercise. Email privacy@aicomplyhq.com. We will not discriminate against you for exercising your rights.
  • Appeals. If we deny your request, you may appeal by replying to our decision; we will respond within the timeframe required by your state's law.

11. Cookies

  • Strictly necessary cookies: Authentication session tokens managed by Supabase. Cannot be disabled.
  • Analytics cookies: Google Analytics cookies, loaded only after explicit consent via our cookie banner.

You can change or withdraw your cookie choices at any time through the cookie banner. Where required, we treat a recognized opt-out signal such as Global Privacy Control as a request to decline non-essential cookies.

12. Data Security

We implement appropriate technical and organizational measures including:

  • Encryption in transit (TLS/HTTPS on all connections)
  • Encryption at rest (Supabase database encryption)
  • Row-Level Security (RLS) ensuring organization-level data isolation
  • Secure authentication via Supabase Auth
  • Stripe webhook signature verification
  • Append-only audit logging

No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data using measures appropriate to the risk.

13. Data Breach Notification

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also notify affected users without undue delay.

14. Business Transfers and Legal Disclosures

We may disclose personal data where we believe in good faith that doing so is necessary to comply with a legal obligation, respond to lawful requests from public authorities, enforce our agreements, or protect the rights, safety, or property of our users or others. If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Privacy Policy or a policy at least as protective, and we will notify you of any material change in how your data is handled.

15. Children

AI Comply HQ™ is a business-to-business service. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately.

16. Changes to This Policy

We may update this Privacy Policy at any time to reflect changes in our data practices, technology, or legal requirements. When we make changes, we will update the "Last updated" date above, and for material changes we will notify you by email or a prominent notice on our platform before they take effect. We encourage you to review this page periodically. Your continued use of the Service after an update takes effect means you acknowledge the revised policy.

17. Complaints

If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU/EEA supervisory authorities is available at edpb.europa.eu. UK users may complain to the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concerns first.

18. Contact

For privacy inquiries or data subject requests:
Email: privacy@aicomplyhq.com
General: hello@aicomplyhq.com