Legal

Privacy Policy

Effective Date: April 16, 2026 · Last updated: April 16, 2026

1. Introduction and Scope

This Privacy Policy ("Policy") describes how ComplyFormAI Corp, doing business as ComplyFormAI ("ComplyFormAI," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you access or use our platform, websites, applications, and related services (collectively, the "Services").

ComplyFormAI is a business-to-business (B2B) software-as-a-service (SaaS) platform designed for government contracting (GovCon) professionals. Our Services enable organizations to manage work orders, candidate submissions, proposals, compliance documentation, and government form generation. This Policy applies to all users of our Services, including organizational administrators, team members, and individual account holders.

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you are using the Services on behalf of an organization, you represent that you have the authority to bind that organization to this Policy.

This Policy does not apply to third-party websites, services, or applications that may be linked to or integrated with our Services. We encourage you to review the privacy policies of any third-party services you access through our platform.

2. Information We Collect

We collect information necessary to provide, maintain, improve, and secure our Services. The types of information we collect depend on how you interact with our platform.

2.1 Account and Identity Data

When you create an account or are added to an organization, we collect:

  • Full name, email address, and professional title
  • Organization name, business address, and contact information
  • Authentication credentials and tokens from identity providers (Microsoft Entra ID, Google Workspace, or email/password)
  • Role assignments and permissions within your organization
  • Subscription tier and billing information (processed through Stripe)

2.2 Content and Business Data

In the course of using our Services, you and your organization may upload or generate content, including:

  • Work order details, position descriptions, and staffing requirements
  • Candidate information, including resumes, qualifications, certifications, and employment history
  • Proposal content, compliance documents, and government form submissions
  • Vendor certifications, past performance records, and contract documentation
  • Templates, workflows, and organizational configurations

Important: Content Data is owned by your organization. We process this data solely to provide the Services as described in your subscription agreement.

2.3 Usage and Interaction Data

We automatically collect information about how you interact with our Services:

  • Pages visited, features used, and actions taken within the platform
  • Search queries, filter selections, and navigation patterns
  • Session duration, frequency of use, and feature adoption metrics
  • Error logs and performance data to diagnose technical issues

2.4 Device and Technical Data

We collect technical information from the devices and browsers used to access our Services:

  • IP address, browser type and version, and operating system
  • Device identifiers, screen resolution, and language preferences
  • Referring URLs, access timestamps, and session tokens
  • Cookie identifiers and similar tracking technologies (see Section 12)

2.5 Payment Data

Payment processing is handled entirely by Stripe, Inc. We do not store, process, or have access to full credit card numbers, CVV codes, or bank account details. We receive and retain only: last four digits of the payment method, card brand, expiration date, billing address, and transaction history for invoicing purposes.

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Delivery and Operations

  • Provisioning and managing your account and organization
  • Processing work orders, candidate submissions, and proposal generation
  • Generating, prefilling, and managing government compliance forms and documents
  • Facilitating AI-powered candidate matching and document processing
  • Processing payments, managing subscriptions, and generating invoices

3.2 Service Improvement and Development

  • Analyzing aggregate usage patterns to improve platform features and user experience
  • Identifying and resolving bugs, performance issues, and security vulnerabilities
  • Developing new features and functionality based on aggregated, de-identified usage trends

3.3 Communication

  • Sending transactional notifications related to your account, submissions, and workflow events
  • Providing customer support and responding to inquiries
  • Delivering product updates, security alerts, and administrative messages
  • Sending marketing communications with your consent, where required by applicable law

3.4 Security and Compliance

  • Detecting, preventing, and responding to fraud, abuse, and security incidents
  • Enforcing our Terms of Service, Acceptable Use Policy, and other agreements
  • Complying with legal obligations, regulatory requirements, and lawful governmental requests
  • Maintaining audit logs for SOC 2 compliance and internal governance

For users in the European Economic Area (EEA), United Kingdom (UK), and other jurisdictions that require a legal basis for processing personal data, we rely on the following grounds:

4.1 Performance of a Contract

Processing is necessary to fulfill our contractual obligations under your subscription agreement, including providing the Services, managing your account, and processing transactions.

4.2 Legitimate Interests

We process data where necessary for our legitimate business interests, provided those interests are not overridden by your fundamental rights. Our legitimate interests include: improving and securing the Services, preventing fraud and abuse, understanding how users interact with the platform, and communicating about the Services.

We process data where necessary to comply with applicable laws, regulations, and legal processes, including tax reporting, data breach notification requirements, and responses to lawful government requests.

Where required by applicable law, we obtain your consent before processing personal data for specific purposes such as marketing communications or the use of certain cookies and tracking technologies. You may withdraw consent at any time, which will not affect the lawfulness of processing conducted prior to withdrawal.

5. AI Data Processing

ComplyFormAI incorporates artificial intelligence capabilities powered by the Claude API, provided by Anthropic, PBC. This section explains how AI features process your data and the safeguards we maintain.

5.1 AI-Powered Features

Our AI capabilities include:

  • Candidate Matching: Analyzing candidate qualifications against position requirements to generate match scores and recommendations
  • Document Processing: Extracting structured data from resumes, government forms, and compliance documents
  • Form Prefilling: Automatically populating government forms based on work order, candidate, and organizational data
  • Proposal Assistance: Generating and refining proposal content based on solicitation requirements and organizational capabilities

5.2 How AI Processes Your Data

When you use AI-powered features, relevant portions of your Content Data are transmitted to the Anthropic API via encrypted connections for real-time processing. This data is used solely to generate the requested output (such as a match score, extracted field, or suggested text) and is returned to our platform.

5.3 No Training on Customer Data

Anthropic does not use data submitted through the ComplyFormAI platform to train, fine-tune, or improve its AI models. We use the Anthropic API under commercial terms that expressly prohibit the use of customer inputs and outputs for model training purposes. Your Content Data processed by AI features remains your organization's property.

5.4 AI Data Retention

Data sent to the Anthropic API for processing is not retained by Anthropic beyond the duration necessary to generate a response and fulfill applicable short-term logging obligations. We maintain our own logs of AI interactions for audit, debugging, and quality-assurance purposes, subject to the retention periods described in Section 7.

5.5 Human Oversight

All AI-generated outputs are presented as suggestions and require human review before being finalized. ComplyFormAI does not make automated decisions that produce legal or similarly significant effects on individuals without human involvement.

6. Data Sharing and Third-Party Processors

We do not sell, rent, or trade your personal information. We share data only as described below, and we require all third-party processors to maintain appropriate security measures and process data solely on our behalf.

6.1 Third-Party Service Providers

We engage the following categories of service providers to operate the Services:

ProviderPurposeData Processed
Neon, Inc.Database hosting (PostgreSQL)All platform data including account information, Content Data, and configuration data, encrypted at rest and in transit
Stripe, Inc.Payment processingBilling contact information, payment method details, transaction records, and subscription status
Anthropic, PBCAI processing (Claude API)Content Data submitted to AI features (candidate profiles, position descriptions, form fields, proposal content) for real-time processing only
Vercel, Inc.Application hosting and CDNTechnical and usage data, IP addresses, request logs; application code and server-side rendered content
Microsoft (Entra ID)Authentication providerEmail address, display name, and authentication tokens for users who sign in via Microsoft
Google (OAuth)Authentication providerEmail address, display name, and authentication tokens for users who sign in via Google

6.2 Organizational Data Sharing

Content Data within ComplyFormAI is scoped to your organization. Data is shared only within the members of your organizational account, subject to role-based access controls configured by your organization's administrators.

We may disclose personal information when we believe in good faith that disclosure is necessary to:

  • Comply with applicable law, regulation, or legal process
  • Protect the rights, property, or safety of ComplyFormAI Corp, our users, or the public
  • Detect, prevent, or address fraud, security, or technical issues
  • Enforce our agreements, including our Terms of Service and Subscription Agreement

6.4 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, personal information may be transferred as part of the transaction. We will notify affected users and provide choices consistent with applicable law before personal information is transferred and becomes subject to a different privacy policy.

7. Data Retention and Deletion

7.1 Retention Periods

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account Data: Retained for the duration of your active subscription plus 90 days following account closure to support account recovery and comply with legal obligations
  • Content Data: Retained for the duration of your organization's active subscription. Upon termination, Content Data is retained for 30 days to allow for data export, after which it is permanently deleted
  • Usage and Technical Data: Retained for up to 24 months in identifiable form; aggregated or de-identified data may be retained indefinitely for analytics purposes
  • Payment Records: Retained for 7 years to comply with tax and financial reporting obligations
  • Audit Logs: Retained for a minimum of 12 months to support SOC 2 compliance and security investigations

7.2 Data Deletion

Organization administrators may request deletion of their organization's Content Data at any time by contacting our support team or using the self-service data management tools within the platform. Upon receiving a verified deletion request, we will:

  • Delete or de-identify the requested data within 30 days from our primary systems
  • Remove the data from backup systems within 90 days
  • Provide written confirmation of deletion upon request

Certain data may be retained beyond these periods where required by law, regulation, or for the establishment, exercise, or defense of legal claims.

8. Data Security Measures

ComplyFormAI Corp maintains a comprehensive information security program designed to protect the confidentiality, integrity, and availability of your data. Our security controls are aligned with the SOC 2 Type II Trust Services Criteria and industry best practices.

8.1 Encryption

  • In Transit: All data transmitted between your browser and our Services is encrypted using TLS 1.2 or higher. API communications with third-party processors are similarly encrypted
  • At Rest: All data stored in our PostgreSQL databases (hosted by Neon) is encrypted at rest using AES-256 encryption. File storage, including uploaded resumes, government forms, and proposal documents, is encrypted at rest
  • Key Management: Encryption keys are managed through industry-standard key management systems with regular rotation schedules

8.2 Access Controls

  • Authentication: Multi-factor authentication (MFA) is supported and encouraged for all accounts. Integration with enterprise identity providers (Microsoft Entra ID, Google Workspace) enables organizations to enforce their own authentication policies
  • Role-Based Access Control (RBAC): Granular permissions ensure users can only access data and features appropriate to their role within the organization. Administrators have full control over role assignments and permission grants
  • Least Privilege: Internal access to production systems and customer data is restricted to authorized personnel on a need-to-know basis, with all access logged and periodically reviewed
  • Multi-Tenancy Isolation: Each organization's data is logically isolated through organization-scoped queries and access controls, ensuring that one organization's data is never accessible to another

8.3 Monitoring and Logging

  • Audit Logging: All significant user actions, administrative changes, and system events are logged with timestamps, user identifiers, and contextual details
  • Security Monitoring: Automated monitoring systems detect and alert on suspicious activities, unauthorized access attempts, and anomalous usage patterns
  • Vulnerability Management: Regular vulnerability scans and penetration testing are conducted to identify and remediate security weaknesses

8.4 Incident Response

We maintain a documented incident response plan that includes:

  • Defined severity levels and escalation procedures
  • Designated incident response team with clear roles and responsibilities
  • Notification procedures for affected customers within 72 hours of discovering a data breach involving personal data, or sooner where required by applicable law
  • Post-incident review and remediation processes

8.5 Vendor Security

All third-party service providers are evaluated for their security posture prior to engagement and on an ongoing basis. We require contractual commitments to data protection, including data processing agreements that address confidentiality, security measures, breach notification, and data return or deletion upon termination.

8.6 Business Continuity

Our infrastructure is designed for high availability with automated backups, redundant systems, and disaster recovery procedures. Database backups are encrypted and stored in geographically separate locations with regular restoration testing.

9. Your Rights

Depending on your jurisdiction, you may have specific rights regarding your personal information. We are committed to honoring these rights and have implemented processes to facilitate their exercise.

9.1 Rights Under the General Data Protection Regulation (GDPR)

If you are located in the EEA or UK, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete personal data
  • Erasure: Request deletion of your personal data, subject to applicable legal retention requirements
  • Restriction: Request that we limit the processing of your personal data under certain circumstances
  • Data Portability: Receive your personal data in a structured, commonly used, machine-readable format
  • Objection: Object to the processing of your personal data based on legitimate interests or for direct marketing purposes
  • Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects

You may also lodge a complaint with your local data protection supervisory authority.

9.2 Rights Under the California Consumer Privacy Act (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, and sell (we do not sell personal information)
  • Delete personal information we have collected, subject to certain exceptions
  • Correct inaccurate personal information
  • Opt Out of the sale or sharing of personal information (not applicable, as we do not sell or share personal information for cross-context behavioral advertising)
  • Non-Discrimination for exercising your privacy rights

9.3 Rights Under Other U.S. State Privacy Laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and port their personal data, as well as the right to opt out of certain data processing activities. We honor these rights consistent with applicable state law.

9.4 Exercising Your Rights

To exercise any of the above rights, please contact us at privacy@complyformai.com or use the privacy request form available in your account settings. We will verify your identity before processing your request and respond within the timeframes required by applicable law (generally 30 days for GDPR requests and 45 days for CCPA requests).

For organizational accounts, please note that your organization's administrator is the primary data controller for Content Data. Requests related to Content Data may need to be directed to your organization's administrator in the first instance.

10. International Data Transfers

ComplyFormAI is operated from the United States. If you access the Services from outside the United States, your personal information will be transferred to and processed in the United States, where our servers and service providers are located.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses (SCCs): We enter into EU Commission-approved Standard Contractual Clauses with our data processors and customers as appropriate
  • UK International Data Transfer Addendum: For transfers from the UK, we supplement our SCCs with the UK Addendum as required
  • Supplementary Measures: We implement additional technical and organizational measures, including encryption and access controls, to ensure an adequate level of protection for transferred data

We evaluate and update our transfer mechanisms in light of regulatory developments and guidance from data protection authorities.

11. Children's Privacy

ComplyFormAI is a B2B platform designed for use by businesses and professionals in the government contracting industry. Our Services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children under 16.

If we become aware that we have collected personal information from a child under 16, we will take immediate steps to delete such information. If you believe that a child under 16 has provided personal information to us, please contact us at privacy@complyformai.com.

ComplyFormAI uses cookies and similar tracking technologies to provide and improve the Services. A detailed description of the cookies we use, their purposes, and your choices is available in our separate Cookie Policy, accessible at https://complyformai.com/legal/cookies.

In summary, we use the following categories of cookies:

  • Strictly Necessary Cookies: Required for the operation of the Services, including authentication session cookies and security tokens. These cannot be disabled
  • Functional Cookies: Enable enhanced functionality and personalization, such as language preferences and saved display settings
  • Analytics Cookies: Help us understand how users interact with the Services by collecting aggregate usage data. These are only set with your consent where required by applicable law

We do not use advertising or behavioral tracking cookies. You can manage your cookie preferences through the cookie banner displayed upon your first visit, or by adjusting your browser settings.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated Policy on our website with a revised "Last Updated" date
  • Provide prominent notice within the platform, such as a banner notification or in-app alert
  • For material changes that significantly affect your rights or how we process your data, provide direct notice via email to account administrators at least 30 days prior to the changes taking effect

Your continued use of the Services after the effective date of any updated Policy constitutes your acceptance of the changes. We encourage you to review this Policy periodically.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the information below:

ComplyFormAI Corp
Attn: Privacy Team / Data Protection Officer
Email: privacy@complyformai.com
Website: https://complyformai.com

Data Protection Officer (DPO)
Email: dpo@complyformai.com

For data subjects in the European Union, our EU representative can be contacted at eu-representative@complyformai.com. For data subjects in the United Kingdom, our UK representative can be contacted at uk-representative@complyformai.com.

We aim to respond to all privacy-related inquiries within 5 business days and to resolve requests within the timeframes required by applicable law.