Privacy Policy
Last updated: October 2026
Data controller
CompliantHQ is operated by Style4 Solutions AB (Org.nr 556910-5926), Lievägen 3, 599 31 Ödeshög, Sweden. Email: hello@complianthq.ai
What data we collect
When you create an account or use our scanning service, we collect:
- Email address — used for authentication (magic link login) and notifications.
- Website URLs — the sites you register for scanning.
- Billing details — company name, address, VAT number (if provided).
- Scan results — cookies, third-party requests, WCAG findings, and consent violations detected on your sites, plus the text content of policy and terms documents and form structure reviewed against GDPR.
We do not collect passwords (we use magic link authentication) and we do not use tracking cookies on complianthq.ai.
How we use your data and legal basis
Every processing activity is grounded in a specific legal basis under GDPR Art. 6:
- Magic-link login and account management — legal basis: contract (Art. 6.1.b).
- Scan notifications and product-related email — legal basis: contract (Art. 6.1.b).
- AI analysis in the scan and of scan results, for action plans, self-assessment and chat: legal basis contract (Art. 6.1.b).
- Billing and bookkeeping — legal basis: contract (Art. 6.1.b) and legal obligation under the Swedish Accounting Act (Bokföringslagen; Art. 6.1.c).
- Security logging and incident response — legal basis: legitimate interest (Art. 6.1.f).
We do not sell, share, or transfer your data to third parties except to the sub-processors described below.
Sub-processors
We use the following sub-processors to operate the service. All are bound by a data processing agreement and may only process your data on our behalf according to our instructions.
- Anthropic PBC (USA): AI analysis in the scan, for action plans and for the in-product chat. For each action plan and each chat reply we send a summary of the scan results (cookie names, script URLs, WCAG findings, page titles and HTML snippets from publicly reachable pages on your site) to Anthropic's Claude API. On paid plans, every scan additionally sends, automatically, the material from publicly reachable pages that the scan's checks and the per-criterion walkthrough need. That material may include text passages, headings and labels, screenshots of pages and individual elements, still frames from video, and text from documents. We never send login credentials, payment data, or content from authenticated areas of your site. If your public pages happen to contain personal data (for example a contact email), it may be included. What we keep of this ourselves, and for how long, is described under Data retention. Anthropic Privacy Policy.
- Mailjet (EU) — transactional email delivery. Your email address and email content pass through Mailjet's servers. Mailjet Privacy Policy.
- Sentry (EU, Frankfurt) — error monitoring and crash reporting. When an error occurs — on our server or in the visitor's browser — we send the error message, stack trace, runtime information (browser or Node version, environment), and a short trail of recent app actions (breadcrumbs). We have disabled performance and session tracking in the browser, so Sentry sends nothing on normal page views — only when an actual error occurs. We intentionally do not send request bodies, payment data, login credentials, or IP addresses. If an exception text happens to include an email address or other fragment of personal data, it can be included. Data is stored within the EU. Sentry Privacy Policy.
- Hetzner (Finland) — hosting for our application and database servers.
- Playwright/Chromium — automated browser running on our own servers to scan your sites. No data is sent to Google or other third parties from the scanning process itself.
International transfers
Anthropic PBC is based in the United States. The transfer is made under the European Commission's Standard Contractual Clauses (SCCs) as a safeguard under GDPR Art. 46. All other sub-processors are based within the EU/EEA.
Data storage and retention
Your data is stored in a MariaDB database on servers located in Finland. Retention by data category:
- Account and profile data — for the lifetime of your account; deleted within 30 days after you delete the account.
- Scan results and action plans — verdicts, summaries and action plans are kept for the lifetime of your account and deleted with it. The underlying material is removed sooner, because it ages: the stored copy of your pages (HTML) and the raw capture from the page load (cookies, requests, scripts and form structure) are kept for 180 days, and the per-page result (URL, title, counters and the findings on it) for 12 months. After that the scan remains as a verdict and an action plan, but no longer broken down page by page. Deleting your account deletes everything regardless of these periods.
- Element screenshots from accessibility scans — kept for at most 3 months and deleted when the account is deleted; for active customers they are refreshed on every monthly re-scan.
- Invoicing and bookkeeping records — retained for 7 years after the end of the financial year as required by the Swedish Accounting Act (Bokföringslagen 1999:1078), even if the account is deleted.
- Email delivery logs (Mailjet) — 30 days for delivery troubleshooting.
- AI prompt/response logs (Anthropic) — 90 days for quality monitoring and debugging.
- The scan's walkthrough texts and AI verdicts: the per-criterion walkthrough in the self-assessment and the AI verdicts that form part of the scan results follow the scan results' lifetime and are rewritten at every rescan. AI verdict caches are cleared after 3 months.
- Error-monitoring events (Sentry) — 90 days for debugging and regression analysis.
- Server and security logs — 90 days for incident response and access auditing.
Contact details for companies we contact
We also review websites of companies and organisations that are not our customers, for example in our industry studies, and then get in touch about what we found. If you have received such an email from us, this section applies to you.
- What data: the email address the message was sent to and, when we have them, your name and your role at the company, sometimes also a link to a public professional profile and short notes ahead of the contact. We keep the emails we have sent and the replies we have received, and we can see whether the link to the report has been used. We do not measure whether the email has been opened. If you open the report through the link, a temporary guest account without personal data is created; it is deleted after 30 days.
- Where the data comes from: the address info@ followed by the website's domain is added by us. Names, roles and personal work addresses come from the company's own website or other public sources, such as company registers.
- Why, and legal basis: to tell you what the review showed and to offer our service. The legal basis is legitimate interest (GDPR Article 6(1)(f)): our interest in reaching the companies the review concerns, weighed against the fact that the data relates to your professional role and that it is easy to say no.
- Who handles the data: Mailjet (EU) sends the emails, and replies are received in our mailbox at Google. The email drafts are written with the help of Anthropic's AI service (USA), which then receives the contact details and earlier emails in the thread. The data is stored on our servers at Hetzner in Finland.
- How long: the contact details and the emails are deleted 36 months after you last got in touch or used the link to the report. If you have never done so, the period runs from when we added the data. If you ask us to stop contacting you, we block the address right away, and the block remains for as long as we send such emails.
- Your rights: you can object to being contacted at any time. Reply to the email or write to hello@complianthq.ai, and we will stop. The rights under the heading Your rights also apply to you.
Your rights
Under GDPR, you have the right to:
- Access your personal data.
- Correct inaccurate data.
- Delete your account and all associated data (except bookkeeping data required by law).
- Export your data in a machine-readable format.
- Object to processing or request restriction.
To exercise any of these rights, email us at hello@complianthq.ai.
If you believe our processing violates GDPR, you have the right to lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY): imy.se.
Cookies
CompliantHQ uses no advertising or tracking cookies, so there's no cookie banner to click through. For anonymous visitor statistics we use Plausible Analytics — a cookieless, EU-hosted tool (servers in Germany) that sets no cookies and collects no personal data. Otherwise we use only essential and functional cookies: a session cookie for authentication, which is set only once you log in and lasts 30 days from when you last used the service, a locale cookie (NEXT_LOCALE) that remembers your language preference and is deleted when you close your browser, and a currency cookie (preferred_currency) that remembers your selected currency on the pricing page for 180 days.
Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the service after changes constitutes acceptance.