Privacy

Last updated: 28 August 2026

Complyee is sold to organisations, and most of the data processed in the service belongs to the customer organisation using it, not to the individual reading this notice. This notice separates the two: what we decide ourselves as a controller, and what we handle strictly on a customer's instructions as a processor.

The providers we rely on are named on our sub-processors page, and the controls around them on our security page.

This page is an information notice, not legal advice. Where it differs from a signed customer agreement or data processing agreement, those documents govern.

Who we are

Complyee is operated by Prodengo AB, a company registered in Sweden with organisation number 559161-6452, at Kvarndammsringen 11, 134 39 Gustavsberg, Sweden.

For anything in this notice, including access, deletion and other data subject requests, write to privacy@complyee.ai.

We have not appointed a data protection officer, and as an EU-established company we do not require an EU representative. Requests are handled directly at the address above.

The two roles we play

We are the controller for the marketing site, the workspace request form, sign-in, account and role records, billing, and our correspondence with you. We decide why and how that data is processed.

We are a processor for everything inside a customer workspace: the documents uploaded to it, the questions asked, the answers generated, document requests and audit events. The customer organisation is the controller for that data, and we act only on its instructions.

If you are an employee using your employer's Complyee workspace, your employer decides what is uploaded, who has access and how long it is kept. Start with your own organisation for requests about that content.

Data we handle as controller

  • Site visits — request metadata such as IP address, user agent and page requested, used to serve the site and protect it against abuse. Legal basis: legitimate interest.
  • Workspace requests — the name, work email, company, requested subdomain, allowed email domains and any message you send us through the request form, used to respond and to set up a workspace. Legal basis: steps taken at your request prior to a contract.
  • Sign-in — your work email address and a short-lived one-time code, or the identity your organisation's single sign-on returns. Legal basis: performance of the contract with the customer organisation.
  • Account records — workspace membership, role, workspace settings and administrative actions, used to operate the service. Legal basis: performance of the contract.
  • Support, feedback and sales correspondence — what you write to us and our replies. Legal basis: legitimate interest in running and improving the service.
  • Billing — for paid plans, billing name, email address, country and order metadata. Card details are entered in our payment provider's own checkout and never reach us. Legal basis: performance of the contract and legal obligations such as accounting.

Data we handle as processor

Inside a workspace we process the policy and guideline documents uploaded to it, the questions members ask, the answers generated, document requests and their status, and audit events recording who did what and when.

We process this only to deliver the service to the customer and on that customer's documented instructions. We do not sell it, do not use it for advertising, and do not use it to train models. Access by our staff is limited to what is needed for support and incident handling, and is logged.

AI processing

Answers are generated by Google's Gemini models through Vertex AI, in the same Google region as the workspace being served. Retrieval is scoped to that workspace's own indexed documents, so a question in one workspace cannot reach another workspace's material.

Documents, questions and answers are not used to train foundation models. Answers are generated automatically from the uploaded material; they are guidance for the reader, not a decision about a person, and they do not produce legal effects on their own.

Sub-processors

We use a small number of third parties to run the service — hosting, database and authentication, the AI platform and document storage, network protection, email delivery and payments. Each is named, with what it does and where it runs, on our sub-processors page, which is the authoritative list.

A workspace can also run inside the customer's own Google Cloud project. In that case the customer's cloud is its own provider rather than our sub-processor, and we hold only a scoped credential the customer issues and can revoke.

International transfers

New workspaces are placed in the EU by default, and the region is fixed for the lifetime of the workspace. Documents, the search index, generated answers and audit logs stay in that region.

Some supporting services — edge network protection, email delivery and payments — operate globally. Where a provider processes personal data outside the EEA, transfers rely on the European Commission's standard contractual clauses together with the provider's own safeguards.

How long we keep data

  • Workspace documents and their index entries: until deleted by a workspace administrator, or on termination of the customer agreement.
  • Questions, answers and conversation history: retained for the workspace as part of the service and removed with the workspace.
  • Audit events: written to the workspace's own storage bucket and kept for the lifetime of the workspace unless a shorter lifecycle is configured on that bucket. For workspaces hosted in Complyee's cloud, we apply the lifecycle rules agreed with the customer and can change them on request to privacy@complyee.ai; there is no self-service control in the product. Where the workspace runs in the customer's own Google Cloud project, the customer's cloud administrator sets the lifecycle. Audit events are deleted with the bucket when the workspace is deleted.
  • Residual copies in storage: workspace storage keeps non-current object versions for up to 90 days and soft-deleted objects for up to 7 days, after which they expire automatically. They are never restored to recover deleted customer data.
  • Residual copies in backups: application database records are removed from the live database immediately, and any residual copies persist only in the automated daily backups taken by our managed platform provider, expiring with that normal backup cycle. Residual copies are used only for disaster recovery of the service as a whole, never to restore deleted customer data. Our security page describes the backup and recovery arrangement in more detail.
  • Account and membership records: for the life of the customer agreement, then deleted. Sign-in accounts that exist only for that workspace are deleted with it.
  • Sign-in codes: valid for a few minutes and discarded after use.
  • Billing and accounting records: kept for the period Swedish law requires.
  • Workspace requests we do not proceed with: deleted once the conversation is closed.

Deletion when a workspace closes

Deleting a workspace removes the documents in it, their entries in the search index, the workspace's storage bucket and everything in it including the audit trail, the sign-in accounts that exist only for that workspace, and every database record belonging to the workspace — members, roles, settings, API keys, document requests and query history.

A workspace administrator can download a full JSON export of the workspace at any time from workspace settings, and can request deletion from the same page or by writing to privacy@complyee.ai. We complete a deletion request within 30 days of receiving it. After that, the only data we retain is what law requires: billing and accounting records for the period Swedish accounting law prescribes.

When a workspace administrator removes a member, we replace that person’s name and email in the records they left behind — document requests and feedback — with an anonymous placeholder, and delete their sign-in account unless they belong to another workspace. Audit events already written to your workspace’s storage keep the identifier of the person who performed the action until the whole audit trail is deleted — with the workspace, or under the retention period your administrator has set on the storage bucket. That is a record of actions taken in the workspace, kept for security and traceability. If a data processing agreement requires those historical entries to be pseudonymised individually, contact privacy@complyee.ai and we will handle it as a documented request.

Where a workspace runs in the customer's own Google Cloud project, deletion is performed with the credential the customer issued. If the credential has already been revoked, the customer's own cloud administrator completes the removal in their tenancy.

One record survives deletion by design: a deletion receipt. It is stored outside the workspace and lists what was removed — the workspace name and identifier, the resources deleted, who requested it and when. It contains no document content and no personal data beyond the identifier of the administrator who performed the deletion, and exists so that a completed deletion stays provable after the workspace and its audit trail are gone.

Security

Each workspace has its own isolated storage and search index. Access is controlled per workspace and role, transport is encrypted, and administrators can restrict access to approved networks and require single sign-on. Our security page describes the controls in more detail.

Your rights

Where we are the controller, you can ask for access to your personal data, correction of it, erasure, restriction of processing, a portable copy, or object to processing based on legitimate interest. Where consent is the basis, you can withdraw it at any time. Write to privacy@complyee.ai and we will respond within one month.

Where we act as processor for a customer workspace, requests belong to that customer as controller. If you contact us directly we will forward the request to the customer without delay and support them in answering it, rather than acting on the content ourselves.

Cookies and similar technologies

We use only what the service needs to work: a session and authentication token so you stay signed in, and a browser-stored language preference for the interface. Payment pages load our payment provider's script when you are checking out.

We do not use advertising cookies and we do not track you across other sites.

Data processing agreement

For every customer, a data processing agreement forms part of the customer agreement and governs our processing of workspace data. It sets out the subject matter, duration, nature and purpose of processing, the categories of data and data subjects, and our obligation to act only on documented instructions.

It also covers confidentiality of our personnel, the technical and organisational security measures we maintain, the use and authorisation of sub-processors, assistance with data subject requests and with data protection impact assessments, notification of personal data breaches without undue delay, audit and information rights, international transfer safeguards, and deletion or return of data on termination.

Where a notice period for new sub-processors matters to you, we are happy to agree one in the agreement. Request the current version at privacy@complyee.ai.

Changes to this notice

This page carries the date it was last updated and is the authoritative version. When a change materially affects how we handle customer data, we tell workspace administrators as well as updating this page.

Contact and complaints

Privacy questions, data subject requests and data processing agreement requests: privacy@complyee.ai. Vulnerability reports and security questionnaires: security@complyee.ai.

Prodengo AB, organisation number 559161-6452, Kvarndammsringen 11, 134 39 Gustavsberg, Sweden.

If you believe we have handled your personal data incorrectly, you can lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), or with the supervisory authority in your own country.

Ask us about privacy

Data subject requests, privacy questions and data processing agreement requests go to privacy@complyee.ai.