How AZComply handles your data — designed for GDPR compliance from day one.
Last updated: March 2026
AZComply is a detection tool, not a data warehouse. We process the minimum data necessary to generate your compliance analysis and discard the rest immediately.
For paid workspaces, you act as data controller and AZComply as data processor within the meaning of Articles 4(7)–(8) GDPR: we process account and compliance data only on your documented instructions under our Article 28 Data Processing Agreement. For the public free questionnaire, AZComply is the controller. Payment processing is performed by Lemon Squeezy as Merchant of Record.
Your uploaded documents — parsed in memory, never written to disk or database.
Raw document text — deleted immediately after LLM extraction (GDPR Art. 5 data minimisation).
LLM prompts and raw responses — only structured reasoning summaries are retained.
Personal data from your documents — we extract regulatory facts only.
| Data | Where | Retention | Legal Basis |
|---|---|---|---|
| Generated PDF report | Supabase Storage (eu-central-1, Frankfurt DE) | 30 days — auto-deleted | Contract performance |
| Report metadata (system name, risk level) | Supabase PostgreSQL (eu-central-1) | Account lifetime | Contract performance |
| Advisor traces (LLM reasoning summaries — EU AI Act Art. 12) | Supabase PostgreSQL (eu-central-1) | Account lifetime | EU AI Act Art. 12 |
| Classification audit log | Supabase PostgreSQL (eu-central-1) | 12 months | Legitimate interest |
| Account data (email, credit balance) | Supabase Auth (eu-central-1) | Account lifetime | Contract performance |
| Payment records | Lemon Squeezy (Merchant of Record — US processor, EU DPA) | 7 years | Legal obligation |
Generated PDF report
Supabase Storage (eu-central-1, Frankfurt DE)
Report metadata (system name, risk level)
Supabase PostgreSQL (eu-central-1)
Advisor traces (LLM reasoning summaries — EU AI Act Art. 12)
Supabase PostgreSQL (eu-central-1)
Classification audit log
Supabase PostgreSQL (eu-central-1)
Account data (email, credit balance)
Supabase Auth (eu-central-1)
Payment records
Lemon Squeezy (Merchant of Record — US processor, EU DPA)
All data is processed and stored within the European Union. No US data transfer, no fallback regions.
Supabase
eu-central-1 (Frankfurt, Germany)
Database, auth, storage
Google Vertex AI
europe-west4 (Netherlands)
LLM processing — Zero Data Retention (ZDR) enabled
Lemon Squeezy
Merchant of Record — US processor, EU DPA
Payment processing
No US data transfer except payment processing via our Merchant of Record.
We apply encryption in transit (TLS 1.2+) and at rest, role-based access control with least privilege, tenant isolation between workspaces, audit logging of administrative actions, and EU-only backups. Infrastructure runs on Supabase (eu-central-1, Frankfurt) with Google Cloud (europe-west4, Netherlands) for AI processing under Zero Data Retention.
You have the right to access, erase, port, rectify, and object to processing of your personal data.
Request a copy of all data we hold about you (GDPR Art. 15).
Delete your account and all associated data — PDF reports, traces, audit logs (GDPR Art. 17).
Export your assessment history in a machine-readable format (GDPR Art. 20).
Correct inaccurate account data (GDPR Art. 16).
Object to processing based on legitimate interest (GDPR Art. 21).
For HIGH_RISK classifications, advisor traces are retained to provide the audit trail required by Article 12. These contain reasoning summaries only — no personal data from submitted documents.
Our Data Processing Agreement incorporating the Article 28 GDPR terms is available on request to all customers at [email protected]. It covers subject matter and duration of processing, confidentiality obligations, sub-processor flow-down, assistance with data subject requests, breach notification, and deletion or return of data on termination.
Request DPA — [email protected]