Last Updated: August 19, 2026
Welcome to ComplianceKit. We are committed to protecting your personal data and respecting your privacy rights in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
This Privacy Policy explains how ComplianceKit ("we", "us", or "our") collects, uses, shares, and protects your personal information when you use our GDPR compliance platform and services.
Controller: Nyrvex Digital (Pty) Ltd, trading as ComplianceKit, is the data controller responsible for your personal data.
EU/UK/EEA Representative and DSA Legal Representative
Nyrvex Digital (Pty) Ltd has appointed Data Protection Representative Limited (trading as DataRep) as its representative under Article 27 GDPR (EU/EEA) and Article 27 UK GDPR, and as its legal representative under Article 13 of the Digital Services Act (EU/EEA). DataRep is incorporated in Ireland (company number 616588).
To exercise your GDPR/UK GDPR rights via our representative, contact DataRep by email at datarequest@datarep.com (quoting "ComplianceKit, AccessKit"), via their webform at datarep.com/data-request, or by post to DataRep's office in your EU/EEA/UK country of residence (addresses published at datarep.com).
For DSA-related matters, contact DataRep by email at digitalrequest@datarep.com (quoting "ComplianceKit, AccessKit"), via the webform above, by post to DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Republic of Ireland, or by phone at +353 (1) 919 8899.
Correspondence must be addressed to "DataRep", not "ComplianceKit", or it may not reach them. For general product support, please use privacy@compliancekit.tech instead.
We process your personal data for the following purposes:
We do not sell your personal data. We only share your data in these circumstances:
All service providers are contractually required to protect your data and only use it for specified purposes.
We do not use data sent to Anthropic to train its AI models — Anthropic's commercial API does not use customer inputs or outputs for model training by default, and we have not enabled any account-level override. Our AI features (policy generation, scan analysis) produce informational output for you to review; we do not use AI to make automated decisions producing legal or similarly significant effects about anyone (Article 22 GDPR).
We may disclose your data if required by law, court order, or government request.
If ComplianceKit is involved in a merger, acquisition, or sale, your data may be transferred. You will be notified of any such change.
We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
You have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you.
You can update or correct your personal data at any time through your account settings.
You can request deletion of your account and all associated data. Use the account deletion feature in your settings.
You can export all your data in a machine-readable format (JSON) at any time.
You can request that we stop processing your data in certain circumstances.
You can object to processing based on legitimate interests or direct marketing.
Where processing is based on consent, you can withdraw consent at any time.
You have the right to lodge a complaint with your local data protection authority:
How to Exercise Your Rights:
We will respond to all requests within 30 days as required by GDPR.
We implement industry-standard security measures to protect your data:
See our Security Documentation for more details.
Your core data is hosted within the European Economic Area (EEA) - our database (Supabase, Ireland) and application hosting (Railway, Netherlands). Some data is transferred outside the EEA: transactional email delivery (Resend), error monitoring (Sentry), and AI policy generation (Anthropic) are processed in the United States, and Google OAuth (if used) is operated by Google in the United States. Paddle (payment processing) operates from the United Kingdom, which the EU recognises as providing an adequate level of data protection.
We ensure adequate protection for these transfers through:
ComplianceKit is operated by NYRVEX DIGITAL (Pty) Ltd, a South African company, which acts as a "responsible party" under the Protection of Personal Information Act 4 of 2013 ("POPIA"). Where we transfer personal information to a service provider located outside South Africa, section 72 of POPIA requires that one of the following applies:
We rely on the first ground above: our service providers outside South Africa (Resend, Sentry, Railway and Anthropic in the United States; Google, where used) are each bound by a data processing agreement incorporating the EU Standard Contractual Clauses, and Paddle (United Kingdom) is bound by its own data protection addendum incorporating the equivalent UK-approved clauses. We consider these binding agreements to provide a level of protection substantially similar to POPIA's conditions for lawful processing, including restrictions on further transfer.
We use cookies to provide and improve our services. For detailed information about the cookies we use, please see our Cookie Policy.
Essential Cookies: Required for authentication and security (cannot be disabled)
Optional Cookies: Analytics and preferences (you can manage these in cookie settings)
ComplianceKit is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by:
Your continued use of ComplianceKit after changes become effective constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Controller: Nyrvex Digital (Pty) Ltd, registration number 2026/404632/07, South Africa
Email: privacy@compliancekit.tech
We will respond to all inquiries within 30 days.
If you are a ComplianceKit customer and we process personal data on your behalf (as a data processor), our Data Processing Agreement applies automatically and is accepted at account registration — no separate signature is required. You can review its full terms at any time at the link above.
This Privacy Policy is compliant with GDPR (Regulation (EU) 2016/679) and other applicable data protection laws.