Template notice — not legal advice. This Privacy Policy is a template and starting point generated to accelerate ComplyWise's launch. It is not legal advice and does not create an attorney-client relationship. It contains placeholders in square brackets and assumptions about your operations that may not be accurate. It must be reviewed, completed, and adapted by qualified privacy and legal counsel — and validated against your actual data flows, subprocessors, and the laws of every jurisdiction in which you operate — before it is published or relied upon.
ComplyWise Privacy Policy
Effective date: [e.g., 2026-08-01] | Last updated: [e.g., 2026-08-01]
This Privacy Policy explains how ComplyWise, Inc. ("ComplyWise," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the ComplyWise compliance-training platform (the "Service") — a multi-tenant SaaS learning management system for regulated pharmaceutical and life-sciences (GxP) workforces. It also describes the rights available to individuals under the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"), and comparable laws.
Please read this Policy together with our Cookie Policy, our Sub-processors page, and — for customers — the Data Processing Addendum ("DPA") that forms part of our customer agreement. If any term of the DPA conflicts with this Policy with respect to Customer Training Data (defined below), the DPA controls.
1. Who we are & our roles (controller vs. processor)
ComplyWise, Inc. is the entity responsible for the Service.
- Registered entity: ComplyWise, Inc.
- Registered address: [registered address]
- Privacy / DPO contact: [DPO / privacy contact email]
- EU / UK representative (if applicable under Art. 27 GDPR): [EU/UK Art. 27 representative name and address, if required]
Our role under data-protection law depends on the category of data:
- ComplyWise acts as a processor (a "service provider" under CCPA/CPRA) for Customer Training Data. When an organization ("Customer" — typically an employer) subscribes to the Service and uploads or generates training data about its own workforce, the Customer is the controller and determines the purposes and means of processing. ComplyWise processes that data only on the Customer's documented instructions, as set out in the customer agreement and DPA. "Customer Training Data" includes learner identities, role-based training assignments, course completions, quiz scores, 21 CFR Part 11 electronic signatures, completion certificates, and the related tamper-evident audit records.
- ComplyWise acts as a controller (a "business" under CCPA/CPRA) for Account and Billing Data and for data we use to operate, secure, and improve the Service. This includes the Customer's account and subscription information, the contact details of administrators and other account contacts, billing records, and our own security, operational, and diagnostic logs. For this data, ComplyWise determines the purposes and means and is directly responsible to the individuals concerned.
End users (learners), please note: if you use ComplyWise because your employer or another organization gave you access, that organization — not ComplyWise — is the controller of your training records. Questions about how your employer uses your data, and most requests to access or delete training records, should be directed to that organization. See Section 9 (Your rights).
2. What data we collect
2.1 Account data (ComplyWise as controller)
- Organization / tenant details: organization name, subscription plan and tier, and configuration settings.
- Administrator and account-contact details: full name, work email address, and role.
2.2 User personal data (as processor for Customers; as controller for admins/contacts we deal with directly)
- Full name, work email address, and optional employee ID.
- Assigned RBAC role (tenant admin, author, manager, or learner) and manager/reporting relationships.
- Authentication data: hashed passwords (bcrypt), multi-factor authentication (TOTP) secrets and backup codes, and — where enabled — SSO/SCIM identifiers. Secrets are stored using envelope encryption (AES-256-GCM) under a versioned, rotatable application key held in the deployment environment and never stored in the database; we do not store passwords in plain text.
2.3 Training records (Customer Training Data — ComplyWise as processor)
- Course and curriculum assignments, due dates, and recertification schedules.
- SCORM course progress, quiz attempts and scores, and completion status.
- 21 CFR Part 11 electronic signatures (signer identity, meaning of signature, timestamp) and generated PDF/A completion certificates.
2.4 Billing data (ComplyWise as controller)
- Subscription plan, billing cycle, invoices, and payment status. Payment card details are collected and processed directly by Stripe, Inc.; ComplyWise does not store full card numbers.
2.5 Audit, security, and technical data (ComplyWise as controller for security/operations; reflected into Customer audit trails as processor)
- Tamper-evident, hash-chained audit-log entries recording security- and compliance-relevant events.
- IP address, user-agent/browser information, timestamps, session activity, and rate-limiting counters.
- Diagnostic and error data (for example, via Sentry, if enabled by the operator).
We do not intentionally collect special-category (sensitive) personal data through the Service. Please do not upload health, biometric, or other sensitive data into free-text fields unless expressly agreed with us in writing.
3. How and why we use data, and our legal bases
Where ComplyWise is a processor, we use Customer Training Data only to provide the Service on the Customer's instructions; the Customer is responsible for establishing the legal basis for its own processing (typically its legitimate interests in workforce training and its legal/regulatory obligations under GxP frameworks). Where ComplyWise is a controller, we rely on the following legal bases under GDPR/UK GDPR:
- To provide, administer, and secure the Service — including authentication, RBAC, MFA, tenant isolation, rate limiting, and audit logging. Legal basis: performance of a contract (Art. 6(1)(b)) with the Customer, and our legitimate interests (Art. 6(1)(f)) in operating a secure, reliable platform.
- To process billing and subscriptions — invoicing, payment reconciliation, and plan enforcement via Stripe. Legal basis: performance of a contract; compliance with legal obligations (Art. 6(1)(c)), e.g., tax and accounting; and legitimate interests in collecting amounts due.
- To secure the platform and prevent abuse — monitoring, intrusion detection, account-lockout, and integrity verification of the audit chain. Legal basis: legitimate interests in security and fraud prevention; compliance with legal obligations.
- To support customers and communicate service messages — responding to requests and sending operational notices (e.g., security or availability notifications). Legal basis: performance of a contract; legitimate interests.
- To improve and maintain the Service — aggregated diagnostics and troubleshooting. Legal basis: legitimate interests, balanced against your rights; we minimize and, where feasible, aggregate or de-identify.
- To meet our own legal, regulatory, and compliance obligations and to establish, exercise, or defend legal claims. Legal basis: legal obligation; legitimate interests.
- Optional analytics cookies and any marketing communications where applicable. Legal basis: consent (Art. 6(1)(a)), which you may withdraw at any time.
Under CCPA/CPRA, the "business or commercial purposes" for which we use personal information map to the uses above. ComplyWise does not "sell" personal information and does not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA. We do not use sensitive personal information for purposes requiring a right to limit.
4. Cookies and similar technologies
The Service uses a strictly necessary, essential session cookie — a stateless JWT stored in an httpOnly cookie — to keep you signed in, enforce idle timeout, and protect against cross-site request forgery. This cookie is required for the Service to function and is not used for advertising.
Where enabled, we may also use optional analytics to understand usage and improve the Service; these are set only with your consent where required. You can accept or decline non-essential cookies, and withdraw consent at any time, via our cookie controls. For the full list of cookies, their purposes, durations, and how to manage them, see our Cookie Policy.
5. Sharing and sub-processors
We do not sell personal data. We disclose personal data only as described here:
- To the relevant Customer (controller): a learner's training data is accessible to their own organization's administrators and managers within that tenant.
- To sub-processors that help us run the Service under written contracts imposing data-protection obligations at least as protective as this Policy and our DPA. Our current sub-processors include:
- Vercel Inc. — application hosting and delivery (serverless functions and edge network), the platform request and function logs that hosting generates, and — only where you accept non-essential cookies — Vercel Web Analytics; United States and Vercel’s global edge locations.
- Supabase, Inc. — managed PostgreSQL database and object storage for all Service data. Supabase itself runs on Amazon Web Services infrastructure, so AWS is engaged as a sub-processor by Supabase rather than directly by ComplyWise. The Supabase project — database and object storage — is in
us-east-1(N. Virginia, USA). - Stripe, Inc. — payment processing and subscription billing; United States.
- Resend — transactional email (optional, if enabled by the operator).
- Sentry — error monitoring (optional, if enabled by the operator).
- For legal and safety reasons: where required to comply with law, valid legal process, or a regulatory request, or to protect the rights, safety, and security of ComplyWise, our Customers, or others. Where a Customer's data is involved, we will, where legally permitted, notify the Customer.
- In a corporate transaction: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and applicable law.
6. International data transfers
The Service is hosted on Vercel, with the database and object storage provided by Supabase. We do not currently offer customer-selected hosting or data-residency regions. Application hosting runs in Vercel’s iad1 region (Washington, D.C., USA); the Supabase project — database and object storage — is in us-east-1 (N. Virginia, USA). Vercel’s global edge network serves static assets from locations worldwide, but the application functions that process personal data execute in iad1. If you access the Service from the European Economic Area, the United Kingdom, or another jurisdiction with cross-border transfer rules, your personal data may be transferred to and processed in the United States or other countries whose laws may differ from those of your jurisdiction.
Where we transfer personal data internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary technical and organizational measures (such as encryption in transit and at rest). A copy of the relevant transfer mechanism is available on request at [DPO / privacy contact email]. Our DPA sets out the transfer terms applicable to Customer Training Data.
7. Data retention
For Customer Training Data, ComplyWise retains data for as long as the Customer's subscription is active and as instructed by the Customer, so that the Customer can meet its own GxP recordkeeping obligations (training records, e-signatures, certificates, and audit trails often must be retained for extended periods under 21 CFR Part 11, EU Annex 11, and related requirements). On termination, we return or delete Customer Training Data in accordance with the DPA, subject to any legal retention requirements.
For Account, Billing, and security data where we are the controller, we retain data for the duration of the customer relationship and thereafter only as long as necessary for the purposes described in this Policy — for example, to meet tax, accounting, audit, and legal-defense obligations, and to preserve the integrity of the tamper-evident audit chain. Specific retention periods: [insert retention schedule, e.g., billing records 7 years; security logs 12–24 months].
8. How we protect data (security measures)
ComplyWise applies technical and organizational measures designed to protect personal data, including:
- Hard tenant isolation using PostgreSQL row-level security (RLS) enforced through a non-superuser application role, so one Customer's data cannot be read by another.
- Encryption in transit (TLS) and at rest, including SSE-encrypted S3 storage and an encrypted RDS database.
- Strong authentication: multi-factor authentication (TOTP with backup codes), bcrypt password hashing with configurable complexity, password history, and account lockout on repeated failures.
- Secrets protection: envelope encryption (AES-256-GCM) under a versioned, rotatable application key held in the deployment environment and never stored in the database, for stored MFA and SSO secrets.
- Access control: role-based access control (tenant admin, author, manager, learner) and, on eligible tiers, SAML SSO with SCIM provisioning.
- Session and abuse controls: stateless JWT sessions in
httpOnlycookies with idle timeout, plus per-tenant and per-user rate limiting. - Integrity and accountability: a tamper-evident, hash-chained audit log and 21 CFR Part 11-compliant electronic signatures.
No system can be guaranteed perfectly secure. We maintain incident-response procedures and will notify affected Customers and, where required, supervisory authorities and data subjects of a personal-data breach in accordance with applicable law and the DPA.
9. Your rights
Subject to applicable law, individuals have rights over their personal data, which may include:
- Access — to obtain confirmation of, and a copy of, the personal data we hold about you.
- Rectification — to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — to have data deleted in certain circumstances.
- Portability — to receive certain data in a structured, commonly used, machine-readable format.
- Restriction and objection — to limit or object to certain processing, including processing based on legitimate interests.
- Withdraw consent — where processing relies on consent (e.g., optional analytics), at any time, without affecting prior processing.
- CCPA/CPRA rights — to know, delete, and correct personal information, and to non-discrimination for exercising these rights. Because we do not sell or share personal information for cross-context behavioral advertising, and do not use sensitive personal information for purposes requiring it, the rights to opt out of sale/sharing and to limit sensitive-data use do not apply; a request will be honored as such if that ever changes. You may use an authorized agent, and we will verify requests as required by law.
End-user (learner) requests are typically routed through your employer/Customer. For training data, your organization is the controller. If you are a learner and want to exercise rights over your training records, please contact your organization's administrator; if you contact ComplyWise directly, we will refer or forward your request to the relevant Customer and assist them in responding, as required under our processor obligations. We do not decide the outcome of such requests on the Customer's behalf.
10. How to exercise your rights (including in-app export and deletion)
Where ComplyWise is the controller (Account, Billing, and admin/contact data), you may exercise your rights by contacting us at [DPO / privacy contact email]. We will respond within the timeframes required by applicable law (generally one month under GDPR/UK GDPR and 45 days under CCPA/CPRA, extendable where permitted). We may need to verify your identity before acting, and will not discriminate against you for exercising your rights.
The Service also provides self-service tools that Customers and, where enabled, their users can use directly:
- In-app data export: tenant administrators can export training records and audit data (for example, via the Service's data-export and evidence-package features) in machine-readable formats to support access and portability requests.
- Account deletion: administrators can deactivate or delete users and can request deletion of tenant data on termination, subject to the retention rules in Section 7 and the DPA.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data-protection authority) or, in California, to contact the California Privacy Protection Agency or Attorney General. We would appreciate the chance to address your concerns first.
11. Children's data
The Service is a workforce compliance-training tool intended for use by organizations and their personnel. It is not directed to children and is not intended for anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data through the Service, please contact us at [DPO / privacy contact email] and we will take appropriate steps, together with the relevant Customer, to delete it.
12. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or the Service. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify Customers through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, except where additional consent is required by law.
13. Contact us
For any questions, requests, or complaints about this Policy or our handling of personal data:
- ComplyWise, Inc.
- Privacy / Data Protection contact: [DPO / privacy contact email]
- Postal address: [registered address]
- Governing law: [Governing law: e.g., State of Delaware, USA]
- EU / UK representative (if applicable): [EU/UK Art. 27 representative name and address, if required]
Reminder: bracketed placeholders must be completed and this Policy reviewed by qualified legal counsel before publication.