Privacy Policy

Last updated: 29 June 2026

1. Data Controller

iCOMPLY is operated by AimRank AI Innovation Labs ("we", "us", "our"). We are the data controller for the personal data processed through the iCOMPLY platform.

Contact: privacy@aimrank.io

Data Protection Officer

Under GDPR Article 37a DPO is mandatory when the controller's core activities consist of regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special-category data (Article 9). iCOMPLY processes only business-to-business compliance data; the personal data we hold is account-level (names, work emails) plus customer-supplied AI system descriptions. We do not reach the Article 37 mandatory threshold and we have not formally appointed a DPO.

The privacy@aimrank.io mailbox is monitored by the founder (AIGP-certified) and serves as the single point of contact for all data-protection enquiries, subject-rights requests, and breach reports. This position will be re-assessed (and a formal DPO appointed) if (i) we begin large-scale processing of special-category data, (ii) we add features that systematically monitor natural persons at scale, or (iii) our headcount or processing volume crosses a threshold where a part-time external DPO becomes appropriate.

2. What Data We Collect

Account data

When you register, we collect your name, email address, and a password hash (bcrypt, cost 12). We also store your organization name and country.

AI system descriptions

You provide descriptions of your AI systems, including technical details, deployment information, model names, subprocessor lists, and uploaded documentation (model cards, DPIAs, vendor docs). This data is stored in our database and used exclusively to provide the compliance advisory service.

Conversation data

Conversations with our AI classification, mapping, and guidance engine are stored in full (your messages and the AI assistant's responses). These are retained to maintain conversation state, enable document generation from conversation data, and provide audit trail evidence.

Generated documents

Compliance documents generated by the platform (classification reports, Annex IV documentation, risk management plans) are stored as structured JSON and as downloadable DOCX files.

Audit logs

We maintain an immutable audit log of every significant action on the platform: system creation/edits, document generation, review submissions, and status changes. This log includes your user ID, IP address, user agent, and a description of the action.

Technical data

We collect standard server-side technical data: IP addresses, HTTP request metadata, and session tokens (via secure, HTTP-only cookies).

Waitlist / access requests

If you request private-beta access via our website, we store the email address you provide (and any optional name, company, or use-case notes) to contact you about access. The lawful basis is your consent (GDPR Article 6(1)(a)), which you give by ticking the consent box on the form.

For abuse prevention we also store a salted, irreversible hash of your IP address (not the raw IP) on the basis of our legitimate interest (Article 6(1)(f)) in protecting the form from automated submissions.

We keep waitlist data until access is granted or you ask us to remove it, and we delete stale or unconverted entries when we close the beta. We do not share waitlist data with third parties or use it for marketing. To withdraw consent or have your details erased, email privacy@aimrank.io.

3. Why We Process Your Data (Legal Basis)

PurposeLegal basis (GDPR)
Providing the compliance advisory serviceArticle 6(1)(b) — performance of a contract
Sending transactional emails (verification, password reset, review notifications, team invites)Article 6(1)(b) — necessary for the service
Maintaining audit logsArticle 6(1)(f) — legitimate interest (regulatory compliance and security)
Improving the platformArticle 6(1)(f) — legitimate interest (service improvement). We do NOT train AI models on your data.

4. AI Processing Disclosure (EU AI Act Article 50)

iCOMPLY uses artificial intelligence to deliver its core service. Specifically:

We do notuse your data to train, fine-tune, or improve any AI model. Conversation data is sent to OVH AI Endpoints for real-time inference only and is subject to OVHcloud's data-protection terms. Inference runs on EU-hosted infrastructure in France and OVH AI Endpoints do not use customer inputs/outputs for model training.

5. Sub-Processors

Sub-processorPurposeLocation
OVHcloud (OVH SAS)Cloud hosting (compute), OVH Managed PostgreSQL, and OVH Object Storage (S3-compatible file storage) — the EU infrastructure the platform runs onEU (France — Gravelines / GRA)
OVHcloud — OVH AI Endpoints (OVH SAS)AI inference. Open-weight models (Qwen3.5-397B-A17B and Mistral-Small-3.2-24B) hosted by OVHcloud on its OpenAI-compatible managed-inference service. Prompts and outputs are processed for real-time inference only and are not used for model training.EU (France)
Brevo (Sendinblue SA) or Mailjet SASTransactional email delivery (verification, password reset, review notifications, team invites)EU (France)

6. Data Retention

7. Your Rights (GDPR Articles 15–22)

You have the right to:

To exercise any of these rights, email privacy@aimrank.io. We will respond within 30 days.

8. International Transfers

Your data stays in the EU end to end. Hosting (compute), the OVH Managed PostgreSQL database, and OVH Object Storage file storage all run on OVHcloud infrastructure in France (Gravelines / GRA). AI inference runs on OVH AI Endpoints, OVHcloud's EU-hosted managed-inference service in France, on open-weight models hosted by OVHcloud — your prompts and outputs are processed for real-time inference only and are not retained or used for training. Transactional email is processed by Brevo or Mailjet in France.

No transfer outside the EEA. Every sub-processor (OVHcloud for hosting, database, storage, and inference; Brevo / Mailjet for email) is an EU company processing your personal data within the EU. There is no transfer of personal data to a US sub-processor for inference or any other purpose, so no Standard Contractual Clauses, adequacy decision, or EU-US Data Privacy Framework reliance is required for this processing.

Supplementary measures we apply regardless:

9. Cookies

iCOMPLY uses a single session cookie set by NextAuth.js. This cookie is:

We do not use any third-party tracking cookies. If we add analytics in the future, we will update this policy and implement a consent mechanism before setting any non-essential cookies.

10. Children

iCOMPLY is a business-to-business service. We do not knowingly collect data from individuals under 16 years of age.

11. Changes to This Policy

We will update this page when our data practices change. Material changes will be communicated via email to registered users.

12. Personal Data Breach Notification (GDPR Articles 33–34)

If we become aware of a personal data breach affecting your data, our process is:

Suspected breach? Report it to security@aimrank.io — this mailbox is monitored alongside the data-protection mailbox above and triggers the same 72-hour clock internally.

13. Records of Processing Activities (GDPR Article 30)

We maintain an internal Record of Processing Activities (RoPA) per Article 30, covering categories of data subjects, categories of personal data, purposes, legal basis, recipients, retention periods, international transfers, and security measures. The summary is publicly available in the repository at docs/RoPA.md; the full record is available to supervisory authorities on request.

14. Supervisory Authority

If you believe we are processing your data unlawfully, you have the right to lodge a complaint with your national data protection authority.

Questions? Contact privacy@aimrank.io.