Legal

Privacy Policy

Last updated: April 16, 2026Version 0.1-draft

Draft — pending attorney review

This document is a placeholder while Compli4nt finalizes its legal documentation with outside counsel. It is not yet binding. A versioned update will be published before this document takes effect, and all users will be prompted to review and re-accept.

1. Scope

This Privacy Policy describes how Compli4nt collects, uses, discloses, and safeguards information in connection with the Compli4nt platform. It applies to information collected through our website, web application, and related services.

2. Information We Collect

  • Account information: email address, practice name, contact details, and credentials provided during signup and profile completion.
  • Practice compliance data: information entered into risk assessments, policy intake forms, employee rosters, training records, and other compliance workflows.
  • Usage data: log entries, access timestamps, and technical metadata used to operate and secure the Service.

3. How We Use Information

We use information to provide and improve the Service, generate the documents and reports you request, communicate with account administrators, enforce our Terms, comply with law, and maintain platform security. Compli4nt does not sell customer information.

4. Protected Health Information (PHI)

To the extent the Service processes Protected Health Information as defined under HIPAA, Compli4nt acts as a Business Associate of the customer. The Business Associate Agreement governs the handling of PHI and takes precedence over this Privacy Policy with respect to PHI.

5. Subprocessors

We use the following subprocessors to operate the Service. Each is engaged under appropriate data protection terms, and where applicable, a Business Associate Agreement:

  • Supabase — database hosting and authentication (US region).
  • Vercel — application hosting.
  • Amazon Web Services (Bedrock) — AI inference provider for document generation. [Migration in progress; interim provider is Anthropic.]
  • Resend — transactional email delivery.
  • Stripe — payment processing. [Pending integration.]

A current list of subprocessors is maintained and available on request.

6. Data Retention

Customer account data is retained for the duration of the subscription and for a defined window thereafter to support deletion, export, and legal-hold obligations. HIPAA-related documentation is retained for a minimum of six years, consistent with 45 CFR § 164.530(j), unless the customer’s BAA specifies otherwise.

7. Your Rights

Depending on your state of residence, you may have the right to access, correct, delete, or export your personal information, and to opt out of certain processing. California residents have additional rights under the California Consumer Privacy Act (CCPA). Requests may be directed to privacy@compli4nt.com.

8. Security

We maintain administrative, physical, and technical safeguards designed to protect customer information, including encryption in transit and at rest, access controls, audit logging, and vendor due diligence. No method of electronic storage or transmission is perfectly secure.

9. International Transfers

Compli4nt currently operates its primary data stores and AI inference in US regions. Information is not routinely transferred outside the United States.

10. Changes to This Policy

Material changes will be communicated to account holders, who will be asked to review the updated version. The current version is identified at the top of this page.

11. Contact

Privacy questions may be directed to privacy@compli4nt.com.