
Loading CompliClear

Loading CompliClear
Effective 15 July 2026. This notice separates CompliClear's controller activities from customer-directed workspace processing and explains practical privacy controls.
CompliClear is the controller for its public site, account administration, direct billing records, security, support, optional analytics, reviews, and its own legal records. For personal data a business customer places in a workspace solely for its compliance work, that customer is normally the controller and CompliClear acts as processor under its instructions.
Service operator and privacy contact: CompliClear, Varanasi, Uttar Pradesh, India 221005; founder@compliclear.com and support@compliclear.com. CompliClear is currently founder-operated. The legal seller of a paid order and applicable tax identity must be shown at hosted checkout and on the order confirmation. Do not complete an order if that identity is absent.
We receive identity and contact data; Clerk authentication identifiers; company and team-invitation data; assessment answers; generated documents and notes; uploaded evidence; system/vendor registers; audit events; plan, invoice, tax, and payment-status metadata; support and privacy messages; CompliClear Practice early-access interest; security logs; and optional analytics or chat data.
Sources include you, your employer or workspace administrator, invited team members, configured authentication/payment/support providers, service telemetry, and public regulatory sources used for research. We do not intentionally collect full card numbers or card security codes.
| Purpose | Data | Basis / role |
|---|---|---|
| Provide accounts and workspaces | Identity, profile, company, assessment, document, evidence, and audit data | Contract; steps requested before contract; processor instructions for customer content |
| AI-assisted features | Selected answers, prompts, document excerpts, and company context | Contract and customer instructions; explicit action acknowledgement is separate from privacy consent |
| Billing and fraud prevention | Contact, plan, order, invoice, payment-status, device, and risk metadata | Contract, legal obligations, and legitimate interests; hosted providers handle card details |
| Security and reliability | Authentication, IP/network, device, error, event, and audit information | Legitimate interests and legal obligations |
| Optional analytics and support chat | Usage events or chat content after the relevant choice | Consent where required; consent can be withdrawn |
| Support, privacy, and legal requests | Messages, request evidence, identity-verification results, and correspondence | Contract, legal obligations, and legitimate interests |
| Practice early-access intake | Name, work email, firm, country, role, team size, workflow, current tools, and non-confidential context you choose to provide | Steps requested before a possible workflow evaluation; legitimate interests in qualification and service improvement; contact permission acknowledged in the form |
Where we rely on legitimate interests, the interests are service security, fraud prevention, customer support, product reliability, and establishing or defending legal claims. You may object where applicable. We do not treat acceptance of this notice as consent.
When you request an AI feature, selected inputs and relevant excerpts may be sent to the configured provider, such as AWS Bedrock, Anthropic, or OpenAI. Do not submit secrets or unnecessary special-category, health, biometric, child, financial-account, identity-document, or payment-card data. Customer content is not intentionally used by CompliClear to train a general-purpose model.
CompliClear produces AI-assisted drafts and risk indicators; it does not make a solely automated decision intended to create legal or similarly significant effects about an individual. Human review is required. See the AI Disclaimer.
Data may be available to authorized workspace members and to vendors needed for hosting, authentication, storage, email, security, optional analytics/support, AI generation, and hosted payment processing. The current functional register is on the Subprocessors page. Payment providers may act as independent controller or merchant of record for their transaction duties.
We may disclose information where lawfully required, to protect users and the service, in a corporate transaction subject to safeguards, or with your direction. We do not sell personal data.
CompliClear operates from India and vendors may process data in India, the United States, the European Economic Area, or other documented regions. Where EU/UK transfer law applies and no adequacy decision covers the destination, the relevant controller should use an appropriate mechanism such as applicable Standard Contractual Clauses, together with transfer-risk and supplementary-measure review. Contract status and hosting region depend on the deployed vendor configuration; contact privacy support for the current evidence package.
| Record | Default criterion |
|---|---|
| Account and active workspace records | While the account is active and needed to provide the service. |
| Customer content after verified closure/erasure | Target deletion from active systems within 30 days; encrypted backup cycles may take up to 90 additional days unless legal hold or customer instructions require otherwise. |
| Billing, tax, consent, and transaction evidence | Up to 8 years where accounting, tax, dispute, fraud, or contract law requires it. Card numbers and security codes are not stored by CompliClear. |
| Security and audit events | Normally 12 months; selected fraud, access, consent, dispute, and legal evidence may be retained up to 7 years. |
| Support and privacy-request records | Normally 24 months for support and 3 years after privacy-request completion, unless a longer dispute or legal-hold period applies. |
| Practice early-access interest | Normally 24 months from submission or last meaningful contact; earlier deletion is available through the Privacy Center unless an evaluation agreement or legal obligation requires a different period. |
| Optional cookie choice | Up to 6 months, then the site asks again. Provider storage may have separate durations listed in the Cookie Policy. |
These are default criteria, not permission to keep every record for the maximum. A shorter customer instruction, legal hold, unresolved dispute, statutory duty, or technically unavoidable backup cycle may change a specific record's date and will be documented.
Depending on location, rights may include access, correction, erasure, portability, restriction, objection, consent withdrawal, grievance, and a complaint to a competent data-protection authority. Withdrawal does not invalidate earlier lawful processing. Submit a tracked request through the Privacy Center. Workspace admins can also download a machine-readable workspace export from Settings.
We normally respond within one month where GDPR applies and publish a one-month grievance target for current Indian SPDI requests. We verify identity and may extend, refuse, or retain limited records only where law permits and with an explanation. If customer workspace data is involved, we assist the customer controller.
EU/EEA users may complain to the supervisory authority in their habitual residence, workplace, or the place of an alleged infringement. CompliClear's Article 27 EU-representative assessment and appointment, if required, is an operational requirement that cannot be replaced by this notice; representative details will be added here when appointed.
India's current SPDI framework applies until the relevant DPDP operational provisions commence. CompliClear's Privacy and Grievance Officer is the founder-operated privacy role at founder@compliclear.com. The individual's public name and complete service address still require formal operator confirmation; use the tracked request route in the meantime.
We use access controls, private object references, authenticated downloads, transport encryption, audit events, environment-managed secrets, and vendor safeguards. No system is risk-free. Where an incident triggers notification duties, CompliClear assesses its controller/processor role and applicable regulator, customer, and individual timelines.
The service is designed for business users aged 18 or older and is not directed to children. Do not upload children's personal data unless a customer has a documented lawful basis, appropriate safeguards, and written authorization from CompliClear.
Optional analytics and support chat remain off until enabled through the Cookie Policy controls. We will update the effective date and, where appropriate, provide an in-product or email notice before a material change.
Privacy and grievance: founder@compliclear.com. General support: support@compliclear.com. Postal contact: Varanasi, Uttar Pradesh, India 221005.