Privacy Policy

Version 1.1 | Last updated: August 2026

Complydo Solutions GmbH (“ComplyDo”, “we”, or “us”) respects your privacy and is committed to protecting the information we hold about you. This policy (the “Privacy Policy”) explains how we collect, use, share, and process personal data. It applies to ComplyDo’s website at complydo.io (the “Website”), to the ComplyDo platform at platform.complydo.io and its related products and features (together, the “Services”; the platform itself, the “Platform”), to any other digital service that links to this Privacy Policy, and to our sales and marketing interactions. It also describes your rights and how to exercise them.

For how we use cookies and similar technologies on our Website, see our Cookie Policy.

“Personal data” means any information relating to an identified or identifiable individual, such as your name, email address, business contact details, or job title.

1. Scope

This Privacy Policy applies where ComplyDo is the data controller responsible for processing personal data of:

  • visitors and users of the Website and any other digital service that links to this Privacy Policy;
  • individuals who book a demo or otherwise contact our sales or support teams;
  • Customers (defined below), prospective customers, and their representatives;
  • users of the Services, to the extent we process their account and usage data for our own purposes (for example billing, security, account administration, and service improvement); and
  • suppliers, service providers, business partners, and their representatives.

This Privacy Policy does not apply to Customer Data, except as set out below. Customer Data is everything we process in the Platform for our Customers (the organizations that hold a contract with us for the Platform): the documents, prompts, and evidence files they submit, and the account, usage, and configuration data of the Customer’s employees and other authorized users (Platform users). We process Customer Data only on the Customer’s instructions under our Data Processing Addendum (the DPA). Where we use account and usage data for our own purposes (for example billing, security, account administration, and service improvement), we act as controller, and this Privacy Policy applies to that use.

Requests about Customer Data go to the relevant Customer; if you (a Platform user) send one to us, we forward it. Two exceptions we handle ourselves, after verifying your identity: correcting your account or profile data, and deactivating or deleting your account.

2. What we collect

Your personal data may come directly from you, from your employer, or from the sources described below. We collect only the data we need for the purposes in Section 3.

We do not knowingly collect sensitive data, and the Website and Services are not directed to children under 18.

2.1 Data you give us

User account information. Accounts exist only under a Customer contract; there is no self-service sign-up. When your employer creates your account, we receive your name and email address. You sign in through your employer’s single sign-on or with a Platform password. For our own purposes, we use this information for security and for managing our contractual relationship with your employer (Section 3). Beyond these purposes, your data in the Platform is Customer Data, handled on your employer’s instructions under the DPA (Section 1).

Communication information. When you contact us or our sales or support teams, we collect your name, contact details, and whatever else you include, so that we can respond.

Billing information. To invoice Customers we process billing contact details and payment information; online payments are processed by Stripe.

Demo booking information. Demo scheduling on our Website is provided by Calendly and loads only after you click to enable it. Calendly processes the booking details you enter (name, email, anything you add) on our behalf; we use them as described in Section 3, so we can prepare for and hold the meeting. For its own website and services, Calendly’s own privacy notice applies.

Social media information. We are present on LinkedIn and YouTube. If you interact with us there (comments, messages, reactions), we process what you share, such as your username and profile. The platforms also give us aggregated page statistics (“page insights”); for LinkedIn insights, we and LinkedIn Ireland Unlimited Company are joint controllers based on the LinkedIn Page Insights Joint Controller Addendum, with LinkedIn Ireland primarily responsible for enabling your rights; you can also contact us (Section 10). The platforms’ own policies apply to their processing.

2.2 Data we collect automatically

When you visit or use the Website or Services, we collect certain technical information (“Technical Information”):

Log data. Your browser automatically transmits your IP address, browser type and settings, and the date and time of your request. We use this to deliver the Website and Services and keep them secure.

Usage data. When you use the Services, we collect your session and user ID and interaction metadata (for example timestamps). We also use usage data, in pseudonymized form, to maintain and improve the performance, availability, and reliability of the Services. Personal data in Customer Data is collected and stored only as the agreement with the Customer and our DPA permit.

Cookies and similar technologies. Our Website uses only strictly necessary cookies, plus a record of your consent choices. We use no website analytics, Google Tag Manager, Google Ads, Meta Pixel, marketing automation, session replay, retargeting, or conversion tracking on our Website. External content (Calendly, YouTube/Embedly video) loads only after you click to enable it. Full details, providers (including Cloudflare Turnstile spam protection), and retention periods: see our Cookie Policy.

2.3 Data from other sources

We may receive personal data about you from third parties, in particular from your employer when they create your account or name you as a contact person.

For sales and marketing, we also process business contact information about representatives of Customers and prospective customers: name, employer, job title, business email and phone, and public professional profile (for example a LinkedIn URL). It comes from publicly accessible sources, in particular company websites and professional networks, or from business data providers. On request, we will tell you what we know about the source of your data.

3. How we use your data

The table below sets out everything we do with your personal data: each processing activity, its purpose, the data involved (Section 2), the legal basis, and how long we keep it (Section 8).

Activity
Purpose
Data involved (Section 2)
Legal basis (GDPR)
Retention period (Section 8)
Managing contractual and business relationships
To administer our agreements with Customers, suppliers, and partners, handle billing, and send service-related communications. Providing the Platform itself happens under our DPA (Section 1).
User account information; Communication information; Billing information; Log data; Usage data.
Contract performance (Art. 6(1)(b) GDPR); where our contract partner is your employer, our legitimate interest in providing the contracted Services (Art. 6(1)(f) GDPR).
Term of the agreement plus statutory periods. Data under the DPA: deleted within 30 days of termination.
Sales contact and demo bookings
To respond to inquiries, schedule and hold demos, and manage prospective customer relationships.
Communication information; Demo booking information.
Steps you asked for before a possible contract, such as a demo (Art. 6(1)(b) GDPR); for company representatives, our legitimate interest in building business relationships (Art. 6(1)(f) GDPR).
Until the inquiry is closed or the relationship ends; earlier if you object.
Website operation and protection against abuse
To operate the Website and protect it from automated abuse (Cloudflare Turnstile).
Technical Information (including Log data).
Our legitimate interest in a functioning, secure Website (Art. 6(1)(f) GDPR); strictly necessary cookies under applicable cookie laws implementing Art. 5(3) ePrivacy Directive.
Session only; Turnstile tokens expire after 5 minutes. See our Cookie Policy.
Documentation of cookie consent choices
To record your Cookie Settings choices so we can honor them and prove consent.
Technical Information (the consent record fields listed in our Cookie Policy).
Legal obligation to demonstrate consent (Art. 6(1)(c) with Art. 7(1) GDPR).
Browser: 6 months. Consent log: up to 3 years from your last choice. See our Cookie Policy.
External content you activate
To enable Calendly demo booking and YouTube (Embedly) video, only after you click to load it.
Demo booking information; Technical Information sent to the provider when you activate the content.
Your consent, given by clicking to load the content (Art. 6(1)(a) GDPR; applicable cookie laws implementing Art. 5(3) ePrivacy Directive); booking details: contract performance (Art. 6(1)(b) GDPR). Withdraw anytime via the Cookie Settings.
The providers’ own retention applies. See our Cookie Policy.
Securing our systems and Services
To secure our IT systems and networks, verify identity, prevent fraud and misuse, and maintain and improve the performance, availability, and reliability of the Services.
User account information; Log data; Usage data.
Our legitimate interest in network and information security and in improving the Services (Art. 6(1)(f) GDPR).
While you use the Services; longer only for incident investigation or by law. Usage data used for these purposes: pseudonymized, retained up to 12 months, then deleted or aggregated.
Direct marketing and prospect outreach (B2B)
To tell prospective customers about the Services, keep prospect records in our CRM, and measure engagement (replies, link clicks). Business contact data only; opt out via any message or Section 10.
Communication information; business contact information (Section 2.3); Technical Information relating to our messages.
Our legitimate interest in promoting the Services to business customers (Art. 6(1)(f) GDPR), using business contact data in a B2B context. Electronic marketing only as permitted by applicable e-marketing laws.
Up to 24 months after our last interaction; immediately when you object (we keep only your email on a suppression list).
Social media presence
To run our LinkedIn and YouTube pages, communicate with you there, and understand page use (insights).
Social media information (Section 2.1).
Our legitimate interest in public presence and communication (Art. 6(1)(f) GDPR); for LinkedIn insights see Section 2.1.
Until the interaction ends or you delete your contribution; the platforms set retention for insights data.
Compliance with legal obligations
To meet statutory obligations, such as commercial and tax retention duties.
Contractual and billing data covered by the obligation.
Legal obligation (Art. 6(1)(c) GDPR).
Statutory periods, generally six to ten years.
Defending legal claims
To establish, exercise, and defend legal claims.
Any Section 2 data relevant to the claim.
Our legitimate interest in defending claims and enforcing our rights (Art. 6(1)(f) GDPR).
For the limitation periods and any proceedings.

About legitimate interest. Several activities in the table rely on our legitimate interest (Art. 6(1)(f) GDPR). For each of them, we have carefully weighed our interest against your interests, rights, and freedoms, taking into account what you would reasonably expect and the safeguards we apply, such as using business contact data only and maintaining suppression lists. We only proceed where the processing is necessary and our interest is not outweighed. You can object at any time (Section 6) and ask us how we weighed these interests (Section 10).

Do you have to give us your data? Only if you want something from us. Using the Platform requires an account, and we need billing details from Customers for invoicing. Everything else is optional, though without contact details we cannot, for example, book you a demo or answer your message.

4. Sharing

We share personal data only with the recipients described below. Providers acting as our processors handle it only on our instructions, under data processing agreements as required by applicable data protection laws.

Platform hosting and infrastructure. The Platform runs on cloud hosting and AI infrastructure providers located in EU regions. The authorized sub-processors for the Platform are listed in Annex 2 of our DPA; that annex is the authoritative list and is updated per the DPA's notification process.

Website providers. Webflow hosts the Website; Cloudflare provides Turnstile spam protection.

Sales and marketing tools. HubSpot (customer relationship management and email) and lemlist (sales engagement) support our sales and marketing work.

Scheduling and video. Calendly (demo booking) and YouTube via Embedly (video playback) receive data only when you activate that content on the Website.

Email, calendar, and meetings. We use Microsoft 365 (Outlook, Teams) for our email, calendars, and video meetings; when you book a demo or meet with us, your booking details and meeting participation are processed there.

Payments. Stripe processes online payments for us and receives the billing contact and payment details needed for this. For its payment services, Stripe also acts as its own controller under its own privacy policy, for example for fraud prevention and financial-regulation duties.

Accounting and tax. Our external tax and accounting advisors receive billing and accounting records as required for bookkeeping and statutory obligations.

Business changes. In a merger, acquisition, financing, reorganization, or asset sale, personal data may be shared with the parties and advisors involved, under confidentiality, and transferred to a successor.

Legal requirements. We may disclose personal data where the law requires it or a valid authority requests it. We may also disclose it to protect our rights or property, prevent fraud or misuse, protect someone’s safety in an emergency, or defend against a legal claim.

Third-party websites. Links to sites we do not operate (for example our social media pages) are governed by those parties’ own privacy policies.

We do not sell personal data or share it for third parties’ advertising. Processors are not permitted to use your data for their own purposes, including training machine-learning models. Independent controllers (for example YouTube/Embedly for activated external content, or Cloudflare for improving its bot-detection service) are governed by their own policies.

5. Where your data is processed

Where your personal data is processed depends on which part of ComplyDo you interact with.

The Platform: EU by default. The Platform is hosted in the EU; no Platform data leaves the EU/EEA without the Customer's prior documented instruction. The details are in our DPA.

The Website and our sales and marketing tools. Our Microsoft 365 workplace (email, calendar, and meetings) is hosted in EU data centers. Some of the other providers supporting our Website and our sales and marketing work may process personal data outside the EU/EEA, in particular in the United States: Webflow and Cloudflare (technical data such as IP addresses), HubSpot (CRM and email data), Stripe (billing and payment data), and, when you activate external content, Calendly and YouTube/Embedly.

Transfer safeguards. Every third-country transfer relies on a recognized transfer mechanism: an adequacy decision (including the EU-U.S. Data Privacy Framework, verifiable at dataprivacyframework.gov), the EU Standard Contractual Clauses (with the UK Addendum or Swiss adaptations where UK or Swiss data protection law applies), or your consent where you actively load external content (Art. 49(1)(a) GDPR), together with transfer impact assessments and supplementary measures where needed. You can request a copy of the safeguards via Section 10.

6. Your rights

You have the following rights under applicable data protection laws, in particular the GDPR. If your local law grants you additional rights, contact us via Section 10 and we will handle your request as that law requires.

If you are a Platform user, Section 1 explains who decides about your data in the Platform; the rights below apply to the data we process for our own purposes (for example billing, security, Website, and marketing data).

Right to information and access. Ask whether we process your data and receive a copy, with information about the processing.

Right to rectification. Have inaccurate or incomplete data corrected or completed. Please let us know if your details change so we can keep them accurate.

Right to erasure. Have your data deleted, for example when it is no longer needed or you withdraw consent. Where a legal retention duty prevents deletion, we restrict the data and delete it once the duty ends.

Right to restriction. Have processing restricted, for example while we check a rectification request or an objection.

Right to data portability. For data processed under contract or consent: receive the data you gave us in a machine-readable format, or have it transmitted to another controller where technically feasible.

Right to object. Object, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 6(1)(f) GDPR); we stop unless we demonstrate compelling overriding grounds. Objection to direct marketing is absolute: we always stop.

Right to withdraw consent. Withdraw consent at any time with effect for the future; for cookies and external content, use the Cookie Settings link in the Website footer. Withdrawal does not affect prior processing.

Right to lodge a complaint. Where your local law provides for it, complain to a data protection supervisory authority, in particular where you live or work, or where the alleged infringement occurred.

To exercise your rights, contact us via Section 10; this is free of charge. To protect your data from unauthorized access or deletion, we may first verify your identity. Residual copies may remain in backups for a limited period (see Section 8).

7. Security

We protect your personal data with appropriate technical and organizational measures in accordance with applicable data protection laws, including encryption of data at rest and in transit, strict access controls, network monitoring, and recurring penetration testing. Our information security management system is ISO/IEC 27001 certified.

More on our Security Page; the measures for Customer Data are set out in our DPA.

8. Retention

We retain personal data only as long as necessary for its purpose, or longer where the law requires. Per-activity retention periods are in the Section 3 table (cookie retention details in our Cookie Policy); deletion of Customer Data is governed by our DPA.

Where statutory retention duties apply, for example under German commercial and tax law, we keep the data for the statutory periods, generally six to ten years. We may keep data longer only for legal claims, and a duty to retain data never allows us to use it for anything else. When data is no longer needed, we delete or anonymize it; deleted data may persist in encrypted backups for a short period, until our routine backup cycles purge it.

9. Updates

We may update this Privacy Policy, for example when our Services, providers, or the law change. Updates are posted here with a new “Last updated” date; for material changes, we give additional notice where the law requires, for example by email or on the Website.

10. Contact

Questions about this Privacy Policy or your rights: info@complydo.io.

Controller:

Complydo Solutions GmbH

c/o hubraum, Winterfeldtstraße 21

10781 Berlin, Germany

Commercial register: Amtsgericht Charlottenburg, HRB 275112

Email: info@complydo.io

Data Protection Officer: our external Data Protection Officer can be reached directly at mm@blueheads.de.

Security matters and incident reports: security@complydo.io.

Thank you for trusting ComplyDo with your data.

Address:
Complydo Solutions GmbH
c/o hubraum, Winterfeldtstraße 21, 10781
Berlin, Germany.
Contact:
info@complydo.io

Enterprise Level Security • Hosted where you need it
Supported by Y Combinator and Telekom hubraum
2026 Complydo Solutions GmbH