Privacy Policy

Compliance Colleague

Last Updated: September 21, 2026

1. Overview

This Privacy Policy explains how Compliance Colleague Limited Liability Company, an Arizona limited liability company doing business as “Compliance Colleague” (“Company,” “we,” “us,” or “our”), collects, uses, discloses, and protects personal data in connection with the Compliance Colleague website, application, and related services (collectively, the “Service”). This Policy is incorporated by reference into, and should be read together with, our Terms of Service.

This Policy describes our practices as a business. If your organization has its own Data Processing Agreement with us covering personal data your organization submits through the Service, that agreement governs our processing of that data as your processor, and this Policy supplements it by describing our practices as a business generally.

2. Scope

This Policy applies to personal data we collect through the Service, our website, and related communications (such as support emails). It does not apply to third-party websites, applications, or services that we do not control, even if you access them through the Service or a link we provide — including the separate services described in Section 6 below, each of which has its own privacy practices.

The Service is intended for business and professional use and is not directed to consumers or to individuals under 18. See Section 13 (Children's Privacy).

3. Information We Collect

3.1 Account information

When you create an account, we collect your email address (used for magic-link sign-in through our authentication provider, Supabase) and the subscription tier and compliance standards you select.

3.2 Content you submit

We collect the questions you ask, the compliance standards you select for a query or comparison, and any documents you upload for AI-assisted review against a standard. Documents and questions may contain personal data at your discretion — for example, if an uploaded policy document names individual employees. We do not control what you choose to include in content you submit, and you should avoid submitting personal data that isn't necessary for your query.

3.3 Usage and billing data

We collect records of your usage of the Service (which standards you queried, token/compute usage, and computed cost) to enforce your plan's allowance and calculate any opted-in overage. Payment card and billing details are collected and processed directly by our payment processor and merchant of record, Paddle — see Section 6.3. We receive only your subscription and payment status from Paddle, not your full payment card number. When you sign up, we also record how you reached us: a campaign tag in the link you followed (for example, ?ref=linkedin), or, if there is none, the domain of the website that sent you. This is read from the link itself, not from cookies or third-party tools, is stored with your account, and is used only to understand which channels bring people to the Service.

3.4 Device and session data

To enforce the single-user license described in Terms of Service Section 5 (account-sharing prohibition), we collect a device identifier (stored in a first-party cookie), multi-factor authentication enrollment status, and records of concurrent active sessions across devices. This is used only for the anti-sharing and account-security purposes described in Section 4 below.

3.5 Communications

If you contact us (for example, by email), we collect the content of that communication and any information you choose to provide in it.

3.6 Information we do not intentionally collect

We do not use analytics or advertising trackers, and we do not sell personal data. See Section 12 (Cookies) for the specific cookies the Service uses.

4. How We Use Information

We do not use your account information, questions, or uploaded documents to train AI models. Section 5 below explains how content you submit is handled by our AI model provider specifically.

5. AI Processing and Our Model Provider

The Service uses Anthropic's Claude models, accessed through Anthropic's commercial API, to generate responses to your questions and to review documents you upload. This section describes how that processing works and is intended to mirror Terms of Service Section 11 (Confidentiality of Your Data) so the two documents stay consistent — if you notice any inconsistency between them, this Policy and Section 11 should be read together, and please let us know.

5.1 What we send to Anthropic

Your question, the text of the compliance standard(s) you selected (via Anthropic's Agent Skills feature), and, if you upload one, the content of your document (sent as a native PDF, or as extracted text for a Word document) are sent to Anthropic's API to generate a response. We do not send your account email address, payment information, or device/session data to Anthropic — only the content needed to answer your question.

5.2 Anthropic does not train on this data by default

By Anthropic's own published policy for commercial/API customers (which governs our use of Claude): “By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.” We have not opted in to any Anthropic program (such as its Development Partner Program) that would change this, and the Service does not expose any “thumbs up/down” feedback mechanism to Anthropic. Source: Anthropic Privacy Center, “Is my data used for model training?”, privacy.claude.com.

5.3 How long Anthropic retains this data

Anthropic's stated default policy for its commercial API is to “automatically delete inputs and outputs on our backend within 30 days of receipt or generation,” subject to limited exceptions (for example, active investigations of a Usage Policy violation, or a separate zero data retention agreement). The Service sends documents inline as part of each API request rather than through Anthropic's separate Files API, so the longer, user-controlled retention available through that product does not apply here — the standard 30-day (or shorter) deletion window governs. Source: Anthropic Privacy Center, “How long do you store my organization's data?”, privacy.claude.com.

5.4 Anthropic's own data processing terms

Anthropic's Data Processing Addendum, including Standard Contractual Clauses for international transfers, is automatically incorporated when a business accepts Anthropic's Commercial Terms of Service — which we have done as an Anthropic API customer. This means Anthropic's processing of the content described in Section 5.1 is already governed by a data processing agreement with SCCs in place, one link in the transfer chain described in Section 8 below. Source: Anthropic Privacy Center, “How do I view and sign your Data Processing Addendum (DPA)?”, privacy.claude.com.

6. Other Service Providers

6.1 Sub-processors acting on our instructions

We use the following service providers to operate the Service. Each processes personal data only on our instructions, for the purposes described below, and is bound by a data processing agreement with us.

Provider

Role & Data

Location & Safeguards

Anthropic, PBC

AI model provider. Processes your questions, selected standards, and uploaded document content to generate responses. See Section 5.

United States. Anthropic's Commercial DPA with Standard Contractual Clauses applies automatically (Section 5.4). Anthropic's current sub-processor list is published at trust.anthropic.com.

Supabase, Inc.

Database, authentication, and (if used) file storage. Hosts your account record, usage logs, and device/session records.

United States (East US, Ohio). Supabase offers a Data Processing Addendum; see supabase.com/legal/customer-resources/data-processing-addendum.

6.2 Sub-processor changes

We may add or replace sub-processors as our business needs evolve. Any new sub-processor will be held to data protection obligations materially equivalent to those described in this Policy and in our Data Processing Agreement.

6.3 Paddle — not our sub-processor

Payment processing works differently. We use Paddle.com Market Limited (“Paddle”) as our merchant of record for billing, consistent with Terms of Service Section 6. Because Paddle is the merchant of record, Paddle itself — not us — is the party you transact with for payment, and Paddle acts as an independent data controller (not our sub-processor) for the billing and payment data it collects directly from you at checkout. Paddle's handling of that data is governed by Paddle's own privacy policy, available at paddle.com/legal/privacy, not by this Policy. We receive from Paddle only your subscription status and the identifiers needed to link your subscription to your account — we do not receive or store your full payment card number.

7. Legal Bases for Processing (EEA/UK Users)

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction that requires a stated legal basis for processing, we process personal data on the following bases:

8. International Data Transfers

Compliance Colleague is based in the United States, and our service providers described in Section 6 process data primarily in the United States. If you are located outside the United States, your information will be transferred to, and processed in, the United States and potentially other countries.

Where required by applicable data protection law (including the GDPR and UK GDPR), we rely on Standard Contractual Clauses or another valid transfer mechanism for these transfers. As described in Section 5.4, Anthropic's own Commercial DPA with Standard Contractual Clauses applies automatically to our use of its API. We are evaluating the equivalent transfer mechanism available through Supabase's Data Processing Addendum for account and usage data.

9. Data Retention

9.1 Account and usage data

We retain your account information (email, tier, allowed standards) and usage records for as long as your account is active, and for [24 months] after cancellation or termination — to allow reactivation, resolve billing disputes, and comply with our legal and accounting obligations — after which we delete or anonymize it, except where a longer period is required by law (for example, tax recordkeeping).

9.2 Questions and uploaded documents

We do not separately store the content of your questions or uploaded documents once a response has been generated and returned to you, beyond what is transiently necessary to process the request. As described in Section 5.3, Anthropic separately retains the inputs and outputs it processes for up to 30 days by default under its own policy, independent of our own systems.

9.3 Device and session records

Device and concurrent-session records described in Section 3.4 are retained on a rolling basis (see Terms of Service Section 5.4) to support account-sharing detection, and are not kept longer than necessary for that purpose.

10. Data Security

We use technical and organizational measures designed to protect personal data, including:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and any required regulator as described in Section 14.

11. Your Privacy Rights

11.1 EEA, UK, and similar jurisdictions

If applicable data protection law gives you these rights, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; receive a portable copy of data you provided; and lodge a complaint with your local data protection authority. To exercise any of these rights, contact us using the details in Section 16.

11.2 India

If you are located in India, India's Digital Personal Data Protection Act 2023 (DPDP Act) may give you rights over your personal data, including the right to access, correction, and erasure, and the right to grievance redressal. We will honor applicable DPDP Act rights requests.

11.3 Australia

If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles may apply to our handling of your personal data. We will honor applicable access and correction requests consistent with that Act.

11.4 United States

Depending on your state of residence, you may have rights under a state privacy law (such as the right to know, delete, or correct your personal information). Because the Service is a business/professional tool and we do not sell personal data or use it for cross-context behavioral advertising, several state-law obligations that apply to consumer-facing, ad-supported services may not apply to our processing — we will still honor a verifiable rights request consistent with applicable law.

11.5 How to exercise your rights

Contact us at the email address in Section 16. We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law.

12. Cookies and Similar Technologies

We use a small number of first-party cookies necessary for the Service to function: an authentication session cookie (so you stay signed in) and a device identifier cookie used for the account-sharing detection described in Section 3.4. We do not use third-party advertising or cross-site tracking cookies. Because these cookies are strictly necessary for the Service to operate, we do not currently display a cookie consent banner; if that changes (for example, if we add analytics), we will update this Policy and add appropriate consent controls.

13. Children's Privacy

The Service is intended for business and professional use by individuals at least 18 years old, consistent with Terms of Service Section 1, and is not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact us using the details in Section 16 and we will delete it.

14. Data Breach Notification

If we become aware of a security incident that compromises the confidentiality, integrity, or availability of your personal data, we will notify affected users and, where required by applicable law, the relevant regulator(s), without undue delay and consistent with the timelines applicable law requires.

15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (such as by email or an in-product notice) before the changes take effect. The “Last Updated” date at the top of this Policy reflects the most recent revision.

16. Contact Us

Questions about this Privacy Policy, or requests to exercise a privacy right described in Section 11, can be sent to support@compliancecolleague.ai or 6556 North Burro Creek Lane, Tucson, Arizona 85718.