Privacy · GDPR
Privacy notice, in plain language
ComplyAI processes little data, keeps it in the EU and gives you the button to delete it yourself. This page explains that without pointless legalese — but it is a real notice under Articles 13–14 GDPR. If something looks wrong, report it: fixing this page is an obligation, not a courtesy.
Who is the data controller
Giacomo Fedeli, who develops ComplyAI as an open, non-commercial personal project. Contacts at the bottom of this page (LinkedIn or GitHub): I answer personally, not an office.
What data we process
- Account (only if you sign up): email and password. The password is managed and encrypted by Supabase Auth: we never see it in clear text.
- Content you choose to save: AI Act assessments, deadlines, control matrices, contract review memos. If you do not save, it stays in your browser and never reaches us.
- Uploaded contracts: they are read IN YOUR BROWSER. The text reaches our servers only if you choose AI analysis; in any case we store the review memo, never the original file.
- Audit log: who (your ID), what (created/updated/deleted) and when, for every action on your data. It is append-only: nobody can alter it — an integrity guarantee.
- Minimal technical data from hosting providers (service delivery logs). We install no analytics tools or tracking pixels.
What we do NOT do
- No advertising, no profiling, no selling or sharing of data.
- No tracking cookies: only technical cookies/storage to keep you signed in.
- No AI model training on your data: the AI provider is configured with training opt-out.
- No marketing emails (in beta we send no emails at all).
Where the data lives and who processes it for us
- Supabase (database and authentication) — data stored in the EU region, Frankfurt. Data processor.
- Vercel (application hosting) — server functions are configured in the Frankfurt region; the CDN serving static pages is global. Data processor.
- Mistral AI (AI analysis, only at your explicit request) — an EU company; submitted texts are not used to train models (opt-out enabled) and are subject to the provider's technical retention.
- Nobody else: the code is public on GitHub and anyone can verify it.
Legal basis and retention
- Performance of the service you request (Art. 6(1)(b) GDPR) for account and saved content.
- Your explicit action for AI analysis: text is sent only when you press the button.
- Retention: as long as you keep the account. If you delete it, linked data is erased immediately; providers' technical backups expire in their ordinary cycles.
- The audit log survives account deletion, pseudonymised: the identifier is no longer attributable to a person.
Your rights (Arts. 15–22 GDPR)
Access, rectification, erasure, restriction, portability, objection: they all apply. Two are already in your hands without asking: you can export your data (PDF, CSV, JSON, .ics from every module) and you can delete your account and all data yourself, instantly, from the “My assessments” page. For everything else, write to me; you also have the right to complain to your data protection authority.
Delete your account from “My assessments” →
Contacts
For any request about this notice or your data (it is a personal project: I answer directly):
Version: v1.0 — 8 luglio 2026