Privacy Policy
Your privacy is important to us. It is Complience.app's policy to respect your privacy regarding any information we may collect from you across our website, https://www.complience.app, and the related scanning, monitoring, and reporting services we operate.
This Privacy Policy was last updated on .
1. Who We Are and How to Contact Us
For the purposes of applicable data protection laws (including the EU General Data Protection Regulation, "GDPR"), the data controller of your personal data is:
Szara Sowa Software Development - Władysław KłaczkowOperating under the brand name "Complience.app".
Tax ID (NIP): 5272964677
Stefana Batorego 18/108
02-591 Warszawa
Poland
Email: wlad@wlad.me
Web: wlad.me
Product support is also available at support@complience.app.
2. Scope
This Privacy Policy applies to the Complience.app website and any related services provided by Szara Sowa Software Development - Władysław Kłaczkow, including public teaser scans, authenticated monitoring, scheduled scans, and client-ready PDF reports.
3. Data We Collect
- Account data: email address and, if you sign in with Google, your Google display name and avatar. We do not use passwords.
- Workspace data: sites you add, client labels, branding settings, team invitations, and notification preferences.
- Scan evidence: the public URL you submit, accessibility findings, cookies and third-party requests captured before consent clicks, HTTP headers, screenshots, scores, grades, and PDF artifacts. Public teaser scans expire. Authenticated scans stay in your workspace until you delete the site.
- Payment data: Stripe processes subscription payments. We do not store payment card data. We receive subscription status and invoice metadata from Stripe.
- Technical and usage data: limited server logs (IP address, browser type, pages visited) from our hosting provider, plus cookieless analytics as described below.
- Contact data: information you send us by email for support.
4. How We Use Your Data
- Provide, operate, and secure the website and scanning service
- Run scans you request and store the resulting evidence in your workspace
- Process subscriptions, trials, and invoices
- Send transactional email (magic links, invitations, scan and billing notices)
- Respond to support requests
- Comply with legal obligations (for example, tax and accounting records)
We do not certify legal compliance. Scan output is technical evidence, not legal advice.
We only retain collected information for as long as necessary to provide the service. What data we store, we protect within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use or modification.
5. Legal Bases for Processing (GDPR)
- Contract (Art. 6(1)(b) GDPR): creating an account, running scans, delivering reports, and processing subscriptions.
- Legitimate interests (Art. 6(1)(f) GDPR): securing the service, preventing abuse of public scans, producing aggregated statistics that do not identify you, and cookieless product analytics.
- Legal obligation (Art. 6(1)(c) GDPR): keeping payment and invoicing records for tax and accounting purposes.
- Consent (Art. 6(1)(a) GDPR): where we use non-essential cookies or send marketing communications, we will obtain your consent first.
6. Cookies
We use cookies and similar technologies for the following purposes:
- Essential cookies: authentication and session management (Supabase Auth). Without them, you cannot stay signed in.
- Abuse prevention: public scans may use Cloudflare Turnstile. That is an anti-bot check, not a marketing tracker.
EventDash analytics, described below, does not set cookies.
7. Third Parties
- Stripe: payment processing. We do not store payment card data.
- Supabase: authentication, database, and storage of workspace and scan data.
- Vercel: hosting. Vercel may collect technical data such as IP address and request logs.
- Resend: transactional email.
- Cloudflare Turnstile: bot protection on the public scan form.
- EventDash: cookieless product analytics. EventDash does not set cookies. It collects anonymous usage data such as pages viewed and conversion events so we can understand how the site is used. See eventda.sh/privacy.
These providers only process your data on our documented instructions where they act as processors, and are contractually required to implement appropriate technical and organizational measures.
8. Your Rights Under GDPR
If you are an EU resident, you have the right to request access to and deletion of your personal data at any time. Non-EU residents will also be granted these rights where applicable. Under GDPR, you have the right to access, rectify, erase, restrict, port, object to processing based on legitimate interests, and withdraw consent.
To exercise any right, contact us at wlad@wlad.me or via wlad.me. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). If you are located in another EU Member State, you may also contact your local data protection authority.
9. Data Sharing
We do not sell, trade, or rent your personal identification information to others. We may share generic aggregated demographic information not linked to any personal identification information. We may also disclose your personal data where required to do so by law or in response to valid requests by public authorities.
10. International Transfers
We use third-party processors that may involve transferring your personal data outside the European Economic Area. Where we do so, we rely on appropriate safeguards such as adequacy decisions (including the EU-US Data Privacy Framework), Standard Contractual Clauses, or other mechanisms approved by the European Commission.
11. Security
We implement appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect online, including encryption in transit (HTTPS) and access controls. No method of transmission or storage is completely secure.
12. Data Breach Notifications
In the event of a personal data breach, we will:
- Notify affected individuals and supervisory authorities without undue delay, and where feasible, within 72 hours of becoming aware of the breach
- Provide information about the nature of the breach, affected data categories, likely consequences, and remedial measures taken
- Document all breaches for regulatory verification
13. Age Restrictions
Our website and services are not directed to children under the age of 16. We do not knowingly collect personal information from children under the age of 16. If we become aware that we have collected such data, we will take reasonable steps to delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the updated date at the top of this page.
15. Contact
For privacy questions, contact wlad@wlad.me or wlad.me. For product support, use support@complience.app.
Szara Sowa Software Development - Władysław KłaczkowTax ID (NIP): 5272964677
Stefana Batorego 18/108
02-591 Warszawa
Poland
Email: wlad@wlad.me
Web: wlad.me