Privacy policy
This is a starting template. Have it reviewed by your data protection adviser before you take paying customers — ComplyGood processes supplier contact data on behalf of its customers, which makes the controller/processor split worth getting right.
Who we are
ComplyGood is operated from Ireland. For questions about this policy or about the data we hold, contact hello@complygood.com.
What we collect
- Account data: name, work email, hashed password, organisation name.
- Supplier data your organisation enters: company name, contact name, email, phone and address.
- Product and packaging data: SKUs, materials, weights, recycled content and related compliance attributes.
- Documents you or your suppliers upload, and their metadata.
- Audit records: who did what and when, retained for compliance evidence.
- Technical data: IP address and timestamps recorded with audit events.
Why we process it
- To provide the service you have contracted for (performance of a contract).
- To send transactional email about document expiry, review outcomes and deadlines (legitimate interest in delivering the service; these are not marketing emails).
- To keep an audit trail you can produce for market surveillance (legal obligation).
- To take payment, via Stripe (performance of a contract).
Controller and processor
Where your organisation uploads supplier and product data, your organisation is the controller and ComplyGood is the processor. We process that data only on your documented instructions.
Sub-processors
- Render.com — application hosting and database (EU, Frankfurt region).
- Resend — transactional email delivery.
- Stripe — payment processing.
Retention
Compliance documents and audit records are retained for as long as your account is active, reflecting the ten-year technical documentation retention obligation under PPWR Article 38. After cancellation we retain your data for 30 days so you can export it, then delete it.
Your rights
Under GDPR you may request access, rectification, erasure, restriction, portability, or object to processing. Contact hello@complygood.com and we will respond within one month. You may also complain to the Irish Data Protection Commission.
Security
- Passwords are hashed with bcrypt; we never store them in plain text.
- Sessions use httpOnly cookies over TLS.
- All data access is scoped by organisation — tenants cannot see each other's data.
- Uploaded files are stored outside the web root and served only to authenticated users.