Skip to main content

Privacy & Data Protection

How AZComply handles your data — designed for GDPR compliance from day one.

Last updated: March 2026

Our Philosophy

AZComply is a detection tool, not a data warehouse. We process the minimum data necessary to generate your compliance analysis and discard the rest immediately.

Data Protection Roles

For paid workspaces, you act as data controller and AZComply as data processor within the meaning of Articles 4(7)–(8) GDPR: we process account and compliance data only on your documented instructions under our Article 28 Data Processing Agreement. For the public free questionnaire, AZComply is the controller. Payment processing is performed by Lemon Squeezy as Merchant of Record.

What We Do Not Store

Your uploaded documents — parsed in memory, never written to disk or database.

Raw document text — deleted immediately after LLM extraction (GDPR Art. 5 data minimisation).

LLM prompts and raw responses — only structured reasoning summaries are retained.

Personal data from your documents — we extract regulatory facts only.

What We Do Store

Generated PDF report

Supabase Storage (eu-central-1, Frankfurt DE)

30 days — auto-deletedContract performance

Report metadata (system name, risk level)

Supabase PostgreSQL (eu-central-1)

Account lifetimeContract performance

Advisor traces (LLM reasoning summaries — EU AI Act Art. 12)

Supabase PostgreSQL (eu-central-1)

Account lifetimeEU AI Act Art. 12

Classification audit log

Supabase PostgreSQL (eu-central-1)

12 monthsLegitimate interest

Account data (email, credit balance)

Supabase Auth (eu-central-1)

Account lifetimeContract performance

Payment records

Lemon Squeezy (Merchant of Record — US processor, EU DPA)

7 yearsLegal obligation

Data Residency — 100% European Union

All data is processed and stored within the European Union. No US data transfer, no fallback regions.

Supabase

eu-central-1 (Frankfurt, Germany)

Database, auth, storage

Google Vertex AI

europe-west4 (Netherlands)

LLM processing — Zero Data Retention (ZDR) enabled

Lemon Squeezy

Merchant of Record — US processor, EU DPA

Payment processing

No US data transfer except payment processing via our Merchant of Record.

Technical & Organizational Measures

We apply encryption in transit (TLS 1.2+) and at rest, role-based access control with least privilege, tenant isolation between workspaces, audit logging of administrative actions, and EU-only backups. Infrastructure runs on Supabase (eu-central-1, Frankfurt) with Google Cloud (europe-west4, Netherlands) for AI processing under Zero Data Retention.

Your Rights Under GDPR

You have the right to access, erase, port, rectify, and object to processing of your personal data.

Access

Request a copy of all data we hold about you (GDPR Art. 15).

Erasure

Delete your account and all associated data — PDF reports, traces, audit logs (GDPR Art. 17).

Portability

Export your assessment history in a machine-readable format (GDPR Art. 20).

Rectification

Correct inaccurate account data (GDPR Art. 16).

Object

Object to processing based on legitimate interest (GDPR Art. 21).

Contact us at [email protected] to exercise any of these rights.

EU AI Act Compliance (Art. 12)

For HIGH_RISK classifications, advisor traces are retained to provide the audit trail required by Article 12. These contain reasoning summaries only — no personal data from submitted documents.

Data Processing Agreement (DPA)

Our Data Processing Agreement incorporating the Article 28 GDPR terms is available on request to all customers at [email protected]. It covers subject matter and duration of processing, confidentiality obligations, sub-processor flow-down, assistance with data subject requests, breach notification, and deletion or return of data on termination.

Request DPA — [email protected]
Privacy & Data Protection | AZComply