1. Scope
This Privacy Policy describes how Compli4nt collects, uses, discloses, and safeguards information in connection with the Compli4nt platform. It applies to information collected through our website, web application, and related services.
2. Information We Collect
- Account information: email address, practice name, contact details, and credentials provided during signup and profile completion.
- Practice compliance data: information entered into risk assessments, policy intake forms, employee rosters, training records, and other compliance workflows.
- Usage data: log entries, access timestamps, and technical metadata used to operate and secure the Service.
3. How We Use Information
We use information to provide and improve the Service, generate the documents and reports you request, communicate with account administrators, enforce our Terms, comply with law, and maintain platform security. Compli4nt does not sell customer information.
4. Protected Health Information (PHI)
To the extent the Service processes Protected Health Information as defined under HIPAA, Compli4nt acts as a Business Associate of the customer. The Business Associate Agreement governs the handling of PHI and takes precedence over this Privacy Policy with respect to PHI.
5. Subprocessors
We use the following subprocessors to operate the Service. Each is engaged under appropriate data protection terms, and where applicable, a Business Associate Agreement:
- Supabase — database hosting and authentication (US region).
- Vercel — application hosting.
- Amazon Web Services (Bedrock) — AI inference provider for document generation. [Migration in progress; interim provider is Anthropic.]
- Resend — transactional email delivery.
- Stripe — payment processing. [Pending integration.]
A current list of subprocessors is maintained and available on request.
6. Data Retention
Customer account data is retained for the duration of the subscription and for a defined window thereafter to support deletion, export, and legal-hold obligations. HIPAA-related documentation is retained for a minimum of six years, consistent with 45 CFR § 164.530(j), unless the customer’s BAA specifies otherwise.
7. Your Rights
Depending on your state of residence, you may have the right to access, correct, delete, or export your personal information, and to opt out of certain processing. California residents have additional rights under the California Consumer Privacy Act (CCPA). Requests may be directed to privacy@compli4nt.com.
8. Security
We maintain administrative, physical, and technical safeguards designed to protect customer information, including encryption in transit and at rest, access controls, audit logging, and vendor due diligence. No method of electronic storage or transmission is perfectly secure.
9. International Transfers
Compli4nt currently operates its primary data stores and AI inference in US regions. Information is not routinely transferred outside the United States.
10. Changes to This Policy
Material changes will be communicated to account holders, who will be asked to review the updated version. The current version is identified at the top of this page.
11. Contact
Privacy questions may be directed to privacy@compli4nt.com.