ComplyDo procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ We protect your personal data with appropriate technical and organizational measures in accordance with applicable data protection laws, including encryption of data at rest and in transit, strict access controls, network monitoring, and recurring penetration testing. Our information security management system is ISO/IEC 27001 certified. More on our Security Page; the measures for Customer Data are set out in our DPA.” | Captured 2026-09-24Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Where your personal data is processed depends on which part of ComplyDo you interact with. The Platform: EU by default. The Platform is hosted in the EU; no Platform data leaves the EU/EEA without the Customer's prior documented instruction. The details are in our DPA. The Website and our sales and marketing tools. Our Microsoft 365 workplace (email, calendar, and meetings) is hosted in EU data centers. Some of the other providers supporting our Website and our sales and marketing work may process personal data outside the EU/EEA, in particular in the United States: Webflow and Cloudflare (technical data such as IP addresses), HubSpot (CRM and email data), Stripe (billing and payment data), and, when you activate external content, Calendly and YouTube/Embedly. Transfer safeguards. Every third-country transfer relies on a recognized transfer mechanism: an adequacy decision (including the EU-U.S. Data Privacy Framework, verifiable at dataprivacyframework.gov ), the EU Standard Contractual Clauses (with the UK Addendum or Swiss adaptations where UK or Swiss data protection law applies), or your consent where you actively load external content (Art. 49(1)(a) GDPR), together with transfer impact assessments and supplementary measures where needed. You can request a copy of the safeguards via Section 10.” | Captured 2026-09-24Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ You have the following rights under applicable data protection laws, in particular the GDPR. If your local law grants you additional rights, contact us via Section 10 and we will handle your request as that law requires. If you are a Platform user, Section 1 explains who decides about your data in the Platform; the rights below apply to the data we process for our own purposes (for example billing, security, Website, and marketing data). Right to information and access. Ask whether we process your data and receive a copy, with information about the processing. Right to rectification. Have inaccurate or incomplete data corrected or completed. Please let us know if your details change so we can keep them accurate. Right to erasure. Have your data deleted, for example when it is no longer needed or you withdraw consent. Where a legal retention duty prevents deletion, we restrict the data and delete it once the duty ends. Right to restriction. Have processing restricted, for example while we check a rectification request or an objection. Right to data portability. For data processed under contract or consent: receive the data you gave us in a machine-readable format, or have it transmitted to another controller where technically feasible. Right to object. Object, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 6(1)(f) GDPR); we stop unless we demonstrate compelling overriding grounds. ” | Captured 2026-09-24Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Email: info@complydo.io Data Protection Officer: our external Data Protection Officer can be reached directly at mm@blueheads.de. Security matters and incident reports: security@complydo.io. Thank you for trusting ComplyDo with your data.” | Captured 2026-09-24Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Questions about this Privacy Policy or your rights: info@complydo.io. Controller: ” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ To administer our agreements with Customers, suppliers, and partners, handle billing, and send service-related communications. Providing the Platform itself happens under our DPA (Section 1). User account information; Communication information; Billing information; Log data; Usage data. Contract performance (Art. 6(1)(b) GDPR); where our contract partner is your employer, our legitimate interest in providing the contracted Services (Art. 6(1)(f) GDPR). Term of the agreement plus statutory periods. Data under the DPA: deleted within 30 days of termination.” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ To secure our IT systems and networks, verify identity, prevent fraud and misuse, and maintain and improve the performance, availability, and reliability of the Services. User account information; Log data; Usage data. Our legitimate interest in network and information security and in improving the Services (Art. 6(1)(f) GDPR). While you use the Services; longer only for incident investigation or by law. Usage data used for these purposes: pseudonymized, retained up to 12 months, then deleted or aggregated.” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ To operate the Website and protect it from automated abuse (Cloudflare Turnstile). Technical Information (including Log data). Our legitimate interest in a functioning, secure Website (Art. 6(1)(f) GDPR); strictly necessary cookies under applicable cookie laws implementing Art. 5(3) ePrivacy Directive. Session only; Turnstile tokens expire after 5 minutes. See our Cookie Policy .” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ To record your Cookie Settings choices so we can honor them and prove consent. Technical Information (the consent record fields listed in our Cookie Policy ). Legal obligation to demonstrate consent (Art. 6(1)(c) with Art. 7(1) GDPR). Browser: 6 months. Consent log: up to 3 years from your last choice. See our Cookie Policy .” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.” | Captured 2026-07-20Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ We retain personal data only as long as necessary for its purpose, or longer where the law requires. Per-activity retention periods are in the Section 3 table (cookie retention details in our Cookie Policy ); deletion of Customer Data is governed by our DPA. Where statutory retention duties apply, for example under German commercial and tax law, we keep the data for the statutory periods, generally six to ten years. We may keep data longer only for legal claims, and a duty to retain data never allows us to use it for anything else. When data is no longer needed, we delete or anonymize it; deleted data may persist in encrypted backups for a short period, until our routine backup cycles purge it.” | Captured 2026-09-24Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ To respond to inquiries, schedule and hold demos, and manage prospective customer relationships. Communication information; Demo booking information. Steps you asked for before a possible contract, such as a demo (Art. 6(1)(b) GDPR); for company representatives, our legitimate interest in building business relationships (Art. 6(1)(f) GDPR). Until the inquiry is closed or the relationship ends; earlier if you object.” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We share personal data only with the recipients described below. Providers acting as our processors handle it only on our instructions, under data processing agreements as required by applicable data protection laws. Platform hosting and infrastructure. The Platform runs on cloud hosting and AI infrastructure providers located in EU regions. The authorized sub-processors for the Platform are listed in Annex 2 of our DPA; that annex is the authoritative list and is updated per the DPA's notification process. Website providers. Webflow hosts the Website; Cloudflare provides Turnstile spam protection. Sales and marketing tools. HubSpot (customer relationship management and email) and lemlist (sales engagement) support our sales and marketing work. Scheduling and video. Calendly (demo booking) and YouTube via Embedly (video playback) receive data only when you activate that content on the Website. Email, calendar, and meetings. We use Microsoft 365 (Outlook, Teams) for our email, calendars, and video meetings; when you book a demo or meet with us, your booking details and meeting participation are processed there. Payments. Stripe processes online payments for us and receives the billing contact and payment details needed for this. For its payment services, Stripe also acts as its own controller under its own privacy policy, for example for fraud prevention and financial-regulation duties. Accounting and tax. ” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ The Company may use Personal Data for the following purposes: We may share Your personal information in the following situations: With Service Providers: We may share Your personal information with Service Providers to monitor and analyze the use of our Service, to contact You. For business transfers: We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company. With Affiliates: We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us. With business partners: We may share Your information with Our business partners to offer You certain products, services or promotions. With other users: when You share personal information or otherwise interact in the public areas with other users, such information may be viewed by all users and may be publicly distributed outside. With Your consent: We may disclose Your personal information for any other purpose with Your consent. To provide and maintain our Service, including to monitor the usage of our Service. To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user. ” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ To enable Calendly demo booking and YouTube (Embedly) video, only after you click to load it. Demo booking information; Technical Information sent to the provider when you activate the content. Your consent, given by clicking to load the content (Art. 6(1)(a) GDPR; applicable cookie laws implementing Art. 5(3) ePrivacy Directive); booking details: contract performance (Art. 6(1)(b) GDPR). Withdraw anytime via the Cookie Settings . The providers’ own retention applies. See our Cookie Policy .” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Prevent or investigate possible wrongdoing in connection with the Service Protect the personal safety of Users of the Service or the public” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.Your consent to this Privacy Policy followed by Your submission of such information represents Your agreement to that transfer.The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Policy and no transfer of Your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of Your data and other personal information.” | Captured 2026-07-20Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “The platforms’ own policies apply to their processing.” | Captured 2026-09-24Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “Our external tax and accounting advisors receive billing and accounting records as required for bookkeeping and statutory obligations. Business changes. In a merger, acquisition, financing, reorganization, or asset sale, personal data may be shared with the parties and advisors involved, under confidentiality, and transferred to a successor. Legal requirements. We may disclose personal data where the law requires it or a valid authority requests it. We may also disclose it to protect our rights or property, prevent fraud or misuse, protect someone’s safety in an emergency, or defend against a legal claim. Third-party websites. Links to sites we do not operate (for example our social media pages) are governed by those parties’ own privacy policies. We do not sell personal data or share it for third parties’ advertising. Processors are not permitted to use your data for their own purposes, including training machine-learning models. Independent controllers (for example YouTube/Embedly for activated external content, or Cloudflare for improving its bot-detection service) are governed by their own policies.” | Captured 2026-09-24Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.