Last updated: February 2026
Welcome to ComplyGuard. We are an EU-based company operating from Croatia, providing AI-powered compliance scanning services for businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website complyguard.eu and use our services.
We are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
ComplyGuard is the data controller responsible for your personal data. Our contact details are:
ComplyGuard
Company Registration Number: [Company Registration Number]
VAT Number: [VAT Number]
Location: Croatia, European Union
Email: info@complyguard.eu
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details above.
When you create an account with ComplyGuard, we collect:
When you use our service, we automatically collect:
We automatically collect certain technical information:
When you contact us, we collect:
If you subscribe to our newsletter, we collect:
When you submit a website for compliance scanning, we process the URL and publicly available information from that website. This is business data used to generate your compliance reports. We do not collect personal data of third parties from scanned websites.
Under Article 6 of the GDPR, we process your personal data based on the following legal grounds:
| Data Type | Legal Basis | Explanation |
|---|---|---|
| Account Data | Contract Performance | Necessary to provide you with our services |
| Usage Data | Legitimate Interest | To improve our platform and user experience |
| Technical Data | Legitimate Interest | For security, fraud prevention, and analytics |
| Communication Data | Contract Performance / Legitimate Interest | To respond to your inquiries and provide support |
| Newsletter Data | Consent | You actively subscribe and can unsubscribe anytime |
| Scanned Website Data | Contract Performance | Necessary to deliver the compliance scanning service |
We use your personal data to:
We do not sell your personal data. We only share your data with third parties when necessary to provide our services or as required by law.
We work with the following categories of service providers:
All our service providers are bound by data processing agreements and are required to protect your data in accordance with GDPR.
We may disclose your data if required by law, court order, or governmental authority.
Your personal data is primarily processed and stored within the European Union/European Economic Area (EU/EEA).
If any data transfer outside the EEA is necessary (for example, using a service provider based outside the EU), we ensure appropriate safeguards are in place, including:
We retain your personal data only for as long as necessary:
| Data Type | Retention Period |
|---|---|
| Account Data | While your account is active + 30 days after deletion |
| Compliance Scan Results | 12 months from the date of the scan |
| Newsletter Data | Until you unsubscribe |
| Technical Logs | 90 days |
| Communication Data | 2 years from last communication |
Under the GDPR (Articles 15-22), you have the following rights:
To exercise any of these rights, please contact us at info@complyguard.eu. We will respond within 30 days.
Right to Lodge a Complaint: If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Croatian Data Protection Authority:
AZOP (Agencija za zaštitu osobnih podataka)
Website: azop.hr
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority (AZOP — Croatian Data Protection Authority) within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay via email to the address associated with your account, as required by GDPR Article 34.
Our breach notification will include:
We maintain internal breach detection, investigation, and reporting procedures to ensure timely identification and appropriate response to any personal data breaches.
We implement appropriate technical and organizational measures to protect your data:
While we strive to protect your personal data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security but are committed to maintaining industry-standard protections.
ComplyGuard is a business service not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe we have inadvertently collected data from a child, please contact us immediately, and we will delete it.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:
We aim to respond to all inquiries within 30 days.