Skip to content

Trust

What we do with your data

You are about to give a compliance company your compliance data. Eight questions, eight straight answers, each linking to the page that documents it in full.

What do you collect?
What you give us so the product can do its job: your account details, the sites and systems you ask us to assess, the answers you type into assessments and generators, and the documents and evidence you upload. Plus ordinary service logs — the kind any web application keeps to stay up and to investigate abuse. The full privacy policy.
Do you sell it, or train on it?
No — not sold, not shared for anyone else’s marketing, not anonymized and sold, not aggregated and sold. We do not train models on your compliance data. There are no third-party tracking scripts and no advertising pixels on this site. The never-sold pledge.
Who else can reach it?
The infrastructure and service providers the product runs on, each named publicly with what it does — hosting, database, email, payments. Nobody else. If that list changes, the list changes with it. Every sub-processor, named.
Where does it physically live?
Named regions, published, so a buyer with a data-residency requirement can check against it rather than ask us and hope. Data residency.
How is it protected?
Encryption in transit and at rest, access scoped per organisation and enforced server-side rather than in the browser, and the security practices we hold ourselves to written down rather than asserted. Security.
Can I get it back, or have it deleted?
Yes, whenever you want, without asking us: export everything you have given us in one click, or delete it in one click. Deleting means deleting — not flagging a row as hidden. If you cancel, you keep access to the end of the period you paid for and can export on your way out. Export or delete, in your account.
I need a DPA before I can sign.
It is published, not negotiated per customer — read it before you buy rather than after. If you are a controller and we are your processor, that is the document that says so. Data Processing Addendum.
Somebody has made a request about their own data to me. Can you help?
That is a product, not a favour: the data-subject request portal handles intake, identity verification before anything is disclosed, and the SLA clock per jurisdiction. The DSR portal.

Something here not answered, or answered in a way you cannot verify? Ask us — we reply within 4 working days, and if the honest answer changes what this page says, this page changes.