Skip to content
CompliCloudHome

Privacy Policy

Last updated 3 July 2026

The short version

CompliCloud stores the documents you upload so it can warn you before they expire. Your documents are yours: we do not sell data, we do not run advertising, and nobody sees your files unless you share them.

What we store

  • Your account: email address, business name, and a securely hashed password.
  • The documents you upload, with the names, categories, people names, and expiry dates you attach to them.
  • Optional settings you provide, such as extra alert recipients and a phone number.
  • A record of which reminder emails we sent, so we do not send them twice.

What we do with it

Exactly one thing: run the service. We use your email to send the expiry reminders and account emails you asked for, and we show your compliance status to people you explicitly share a link with.

Share links show document names and validity status. They are status-only by default— the files themselves are not included. You can switch on file downloads for an individual link if you want a client or auditor to be able to open the actual documents on it; that is off unless you turn it on, applies only to the link you enabled it for, and you can revoke any link at any time.

Reading your documents with AI

When you add a document, CompliCloud can read it to pre-fill the name, category and expiry date so you don’t have to type them. To do that, the file is sent to our AI processor, OpenAI, which returns the extracted fields. OpenAI acts as a processor on our behalf and does not use your documents to train its models. The extracted values are only ever suggestions — you confirm or correct them before anything is saved.

This happens only for files you actually add to your account. If you would rather no document ever leave the platform this way, tell us at info@compli-cloud.com and we will disable the scanner for your account.

Payments

Subscriptions are processed by Stripe. Your card number goes directly to Stripe and never touches our servers; we only learn whether your subscription is active.

Cookies and advertising

One essential cookie keeps you logged in. We don’t use analytics cookies, and our own usage stats are counted on our servers without profiling you.

The one exception is advertising attribution: if you arrive by clicking one of our ads, we store the ad’s click identifier in a cookie so we can tell that the ad led to a sign-up. It contains no information about you beyond that identifier, and visitors who didn’t come from an ad never receive it.

If you reach CompliCloud by clicking one of our ads on Facebook or Instagram, Meta’s advertising pixel loads so we can measure whether the ad led to a sign-up. This runs only for visitors who arrived from our ads— never for organic visitors — and sends Meta only the minimum needed to attribute the ad (a one-way-hashed email plus Meta’s own ad identifiers). You can opt out anytime through your Meta ad preferences or your browser settings.

Your rights

Wherever you live, you can ask for a copy of your data, ask us to correct it, or ask us to delete it. We do not sell personal information and we do not share it for cross-context behavioral advertising. Deleting a document removes its file from storage, and deleting your account removes everything — you can do both yourself, at any time, without asking us.

If you are in California, those are the rights the CCPA/CPRA gives you (access, deletion, correction, and to opt out of sale or sharing — there is nothing to opt out of, because we do neither). If you are in the UK or EU, they are your GDPR rights. We will never charge you for a request or treat you differently for making one. For anything at all, write to info@compli-cloud.com. You also have the right to complain to your local data protection authority.

Changes

If this policy changes in a way that matters, we tell you by email before the change takes effect.