Privacy Policy
Last updated: 28 July 2026 · Version 1.0
This Privacy Policy explains how Complylify Ltd collects, uses, stores, and protects personal data in connection with the Complylify. It is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Complylify Ltd ("Complylify", "we", "us", "our") is a private limited company registered in England and Wales (Company No. 14574112). Our registered office is at:
Complylify Ltd167–169 Great Portland Street, 5th Floor
London, W1W 5PF
England
We operate the Complylify, a software-as-a-service (SaaS) product that helps UK independent healthcare providers — particularly care homes — manage CQC compliance, governance records, audits, incidents, risks, policies, and staff training.
2. Our Role Under UK GDPR
Complylify operates in two distinct capacities depending on the type of data involved:
- Data Controller — for data we collect about our customers (account holders, billing contacts) when they register for and pay for the Platform.
- Data Processor — for compliance and governance records that your organisation uploads or creates within the Platform (audits, incidents, staff training, etc.). In this capacity we act on your instructions as the Data Controller. A Data Processing Agreement (DPA) is available on request and must be in place before using the Platform.
3. What Personal Data We Collect
As Data Controller (account & billing data):
- Name and email address of account holders and invited users
- Organisation name and registered office address
- Billing information (processed directly by Stripe — we never see raw card data)
- IP addresses (retained in security logs for up to 30 days)
- Login timestamps and session tokens
As Data Processor (compliance records on behalf of your organisation):
- Audit records, incident reports, risk entries, and policy documents
- Staff training records including names, courses, and expiry dates
- Feedback and complaints records
- Notices and acknowledgement records
- Any other data your organisation chooses to enter into the Platform
We do not collect special category data (health records, racial origin, etc.) about your service users. Care records are out of scope for this Platform. If your organisation enters special category data about staff members, you remain the Data Controller for that data.
4. Lawful Basis for Processing
| Purpose | Lawful Basis |
|---|---|
| Providing the Platform to registered customers | Contract (Article 6(1)(b)) |
| Processing subscription payments via Stripe | Contract (Article 6(1)(b)) |
| Security logging and fraud prevention | Legitimate Interests (Article 6(1)(f)) |
| Responding to support enquiries | Legitimate Interests (Article 6(1)(f)) |
| Processing compliance records on customer instruction | Contract / Legitimate Interests |
| Compliance with legal obligations (ICO, HMRC) | Legal Obligation (Article 6(1)(c)) |
5. How Long We Keep Your Data
- Active accounts: Data is retained for the duration of your subscription.
- After cancellation or termination: Account data and all compliance records are retained for 30 days to allow for data export, then permanently deleted.
- Security logs (IP addresses): Retained for a maximum of 30 days.
- Billing records: Retained for 7 years in accordance with UK tax law (HMRC requirements).
- Audit trail entries: Retained for the duration of the subscription. These are immutable (append-only) and cannot be individually deleted.
6. Who We Share Your Data With
We do not sell your data. We share it only with the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway (Railway Corp.) | PostgreSQL database hosting | United States |
| Netlify Inc. | Application hosting and CDN | United States |
| Stripe Inc. | Payment processing | United States |
| Amazon Web Services | File / document storage (S3) | United States / EU |
All US-based sub-processors are required to maintain appropriate safeguards for international data transfers in compliance with UK GDPR Chapter V. We rely on Standard Contractual Clauses (SCCs) and, where applicable, the UK–US Data Bridge.
7. Your Rights Under UK GDPR
As a data subject, you have the following rights:
- Right of access (Article 15): Request a copy of your personal data.
- Right to rectification (Article 16): Correct inaccurate data.
- Right to erasure (Article 17): Request deletion of your data where no legitimate grounds for retention exist. You can export your data first via Settings → Data Protection.
- Right to portability (Article 20): Export all your governance data in machine-readable JSON format via Settings → Data Protection → Export All Data.
- Right to restriction (Article 18): Restrict processing in certain circumstances.
- Right to object (Article 21): Object to processing based on legitimate interests.
To exercise any right, email legal@complylify.com. We will respond within 30 days. We may need to verify your identity before processing the request.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
8. Security Measures
We take the security of your data seriously and implement appropriate technical and organisational measures:
- All data is encrypted in transit using TLS 1.2 or higher (enforced by Netlify)
- Database storage is encrypted at rest (Railway PostgreSQL)
- Passwords are hashed using bcrypt (cost factor 12) — never stored in plaintext
- Role-based access control (RBAC) limits data access to authorised users within each organisation
- Every data modification is captured in an immutable audit log with before/after snapshots
- Rate limiting is applied to authentication endpoints to mitigate brute-force attacks
- Multi-tenant isolation: every database query is scoped to the authenticated organisation
- Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) applied on all responses
9. Cookies
We use the following cookies:
- Session cookie (next-auth.session-token): An HttpOnly, Secure, SameSite=Lax session cookie set by NextAuth to maintain your login state. It expires when you sign out or after 30 days of inactivity.
- CSRF protection cookie (next-auth.csrf-token): Used to prevent cross-site request forgery attacks. Essential for security.
We do not use advertising cookies, tracking pixels, or third-party analytics on the Platform. By using the Platform, you consent to these essential cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify account holders by email. Continued use of the Platform after changes constitutes acceptance of the updated policy.
11. Contact Us
For any questions about this Privacy Policy or your data rights, please contact:
Complylify Ltd — Data Enquiries
Email: legal@complylify.com
Post: 167–169 Great Portland Street, 5th Floor, London W1W 5PF
Website: complylify.com