privacy

Privacy Policy

Effective date: July 20, 2026 · Last updated: July 20, 2026

This policy explains what personal data AI Compliance Index (aicompliance.ai, "we", "us") collects, why, how long we keep it, who we share it with, and your rights. Written to meet EU GDPR (Articles 13–14), UK GDPR, and US state privacy law (CCPA/CPRA and similar) disclosure requirements to the extent they apply. Short version: this is a public directory and blog. No ads, no purchased lists, no data brokers, and very little personal data at all.

1. Who is responsible

The controller is the editorial team that publishes AI Compliance Index. Privacy contact: see the About page. If we are required to appoint an EU or UK representative we will publish their details here.

2. What we collect

2.1 Browsing. Hosting infrastructure processes standard request data (IP address, user-agent, requested URL, response code, timestamp) for security and debugging, retained up to 30 days.

2.2 Analytics. We use Google Analytics 4 (measurement ID G-PLPW6HVNTC) with IP anonymisation, no ad personalisation, no remarketing, and no Google Signals. Analytics cookies load only after you accept them via the consent banner.

2.3 The Tool Finder. Runs entirely in your browser; your answers are used to compute the recommendation and are encoded in the shareable link URL. Nothing about your Finder session is stored on our servers.

2.4 Tool submissions. The Submit a Tool page is currently a placeholder and does not yet collect any data. When the submission form ships we will update this section to list the exact fields collected, where they are stored, and retention. Submissions that are not accepted will be deleted within 12 months.

2.5 Email. If you contact us we process your name, email, and message to reply; threads kept up to 24 months.

2.6 Admin accounts. Directory editors sign in via authenticated accounts; applies to our team only.

2.7 What we don't collect. No visitor signup, no newsletter, no payments, no lead forms, no special-category data, no purchased or broker data.

3. Why and legal basis

Serving the site, security, and debugging — Art 6(1)(f) legitimate interests. Analytics for EEA/UK visitors — Art 6(1)(a) consent via the banner, withdrawable at any time. Analytics for US visitors — legitimate interests with state-law opt-outs honoured. Publishing the directory and blog — Art 6(1)(f) legitimate interests (we name individuals only as already identified in public primary sources). Tool submissions — Art 6(1)(b) steps at your request. Answering email — Art 6(1)(b)/(f). A legitimate-interests balancing summary is available via the privacy contact.

4. Who we share data with

Infrastructure processors: Lovable Cloud (hosting and Supabase database, US/EU); Contentful (blog content delivery, US/EU); Google (Google Fonts and Google Analytics 4, US); Google Tag Manager script host (googletagmanager.com). We do not sell personal data and do not share it for cross-context behavioural advertising. Legal requests are honoured only on valid legal process, with notice to you where the law allows.

5. International transfers

Providers are primarily US-based; transfers of EEA/UK/Swiss visitor data rely on EU Standard Contractual Clauses (2021/914), the UK Addendum, and/or the EU–US Data Privacy Framework where the provider is certified.

6. Retention

Request logs up to 30 days; Google Analytics data 14 months; tool submissions not accepted 12 months; email up to 24 months; admin accounts while the person is on the team.

7. Your rights

Access, rectification, erasure, restriction, portability, objection to legitimate-interests processing, withdrawal of consent (no effect on past processing). US state residents additionally: opt out of sale, sharing, and targeted advertising (we do neither today). No solely-automated decisions with legal or similarly significant effect. Contact us via the About page; response within 30 days, extendable with notice; no fee unless manifestly unfounded or excessive.

8. Children

B2B site for compliance, security, and engineering professionals; we do not knowingly collect data from anyone under 16; contact us for deletion.

9. Security

TLS in transit, encrypted storage at rest, role-scoped admin access, least-privilege credentials. If a breach affecting your data occurs we will notify supervisory authorities within 72 hours where required and affected individuals without undue delay where risk is high.

10. Complaints

EEA residents — your national supervisory authority (EDPB list); UK — the ICO; Switzerland — the FDPIC; US — your state attorney general. We'd welcome the chance to fix issues first: reach us via the About page.

11. Changes

We update "Last updated" for substantive changes; for changes to legal bases or recipients we give at least 30 days' notice via a site banner where feasible.