Privacy Policy

Last updated: June 26, 2026

This Privacy Policy explains how AI Aware Certified ("we", "us") collects, uses, and shares personal data when you use our website and platform at compliance-now.io (the "Service"). We act as a data controller for account data and as a data processor for the content you upload about your AI systems — see our DPA for processor terms.

1. Data we collect

Account data

  • Name and email address
  • Authentication identifiers (e.g. Google account ID if you sign in with Google)
  • Password hashes (we never store plaintext passwords)

Service data

  • AI systems you describe, assessment answers, and evidence files you upload
  • Documents generated by the Service on your behalf

Usage data

  • Log data: IP address, browser, pages viewed, timestamps
  • Limited cookies strictly required to keep you signed in

Billing data

If you subscribe to a paid plan, our payment processor (Stripe) collects your billing details. We receive only the last four digits of your card and a subscription identifier.

2. How we use your data

  • Provide and operate the Service (legal basis: contract)
  • Maintain security and prevent abuse (legitimate interests)
  • Send transactional and service emails (contract)
  • Comply with legal obligations (legal obligation)
  • Improve the Service in aggregate and de-identified form (legitimate interests)

We do not sell your personal data and we do not use your content to train AI models.

3. Subprocessors

We share data only with the following subprocessors, under contract:

  • Supabase — database, authentication, and file storage (EU region)
  • Cloudflare — hosting and CDN
  • Stripe — payment processing (when you subscribe)
  • Google Cloud and Anthropic — AI model inference for document generation
  • Resend — transactional email delivery

A current subprocessor list is available on request at privacy@compliance-now.io.

4. International transfers

Some subprocessors are located in the United States. Where personal data is transferred outside the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and equivalent UK addenda.

5. Retention

  • Account data: kept while your account is active, then deleted within 30 days of closure.
  • Service data and evidence files: deleted with your account or within 30 days of an export-and-delete request.
  • Billing records: retained for 7 years to meet tax and accounting obligations.
  • Log data: retained up to 12 months for security and debugging.

6. Your rights

Under the GDPR, UK GDPR, and similar laws, you have the right to access, rectify, delete, restrict, or port your personal data, and to object to processing. To exercise any right, email privacy@compliance-now.io. You also have the right to lodge a complaint with your local supervisory authority.

7. Security

We use encryption in transit (TLS 1.2+) and at rest, role-based access controls, row-level security on the database, and least-privilege storage access. No system is perfectly secure; you should also protect your credentials.

8. Children

The Service is not directed to children under 16, and we do not knowingly collect their data.

9. Changes

We will notify you of material changes by email or in-product notice at least 14 days before they take effect.

10. Contact

Data controller: AI Aware Certified. Email privacy@compliance-now.io.