Regmaply

Privacy Policy

Last updated: 12 August 2026

This Privacy Policy explains what personal data Regmaply collects, why we process it, who we share it with, and the rights you have over it. It applies to the Regmaply web application and our public website.

1. Information we collect

We collect the following categories of information:

  • Account information — your name, email address, hashed password, and the date your account was created.
  • Company profile — company name, industry, approximate size, headquarters location and the countries in which you operate.
  • AI system inventory — the details you record about each AI system, including its name, vendor, system types, impact level, use case, data types processed and deployment locations.
  • Compliance evidence — files and links you upload or attach to requirements, together with the notes and completion statuses you record.
  • Generated documents — the compliance drafts produced at your request and any edits you make to them.
  • Technical and usage data — IP address, browser and device information, log data, and records of the pages and features you use.

We do not collect payment card details. Any future payments will be handled by a payment provider that processes card data directly.

3. AI processing — please read this section

Your compliance map is not generated by AI. Requirements are produced by a deterministic rule engine that we maintain. No customer data is sent to any AI provider for that purpose.

AI document drafting is a paid feature that runs only when you explicitly request a draft. When you do, we send the following context to Anthropic PBC: your company name, industry, size and country; the relevant AI system's name, vendor, system types, impact level, use case, data types and deployment locations; and the specific requirement being drafted for. Anthropic's commercial API terms provide that customer inputs and outputs are not used to train its models.

Every drafting request is recorded in an internal call log so we can trace what was sent and when. Please do not enter special-category personal data (for example health, biometric or political data) into free-text fields.

4. Who we share data with

We do not sell personal data and we do not share it for cross-context behavioural advertising. We use the following processors:

ProcessorPurposeLocation
Supabase Inc.Database, authentication, file storage and functionsUnited States (AWS us-east-1)
LovableApplication hostingEU / US
ResendTransactional emailUnited States
Anthropic PBCAI document drafting, only on your explicit requestUnited States

We may also disclose data where required by law, regulation or valid legal process, and in connection with a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.

Public trust page. The public trust page is opt-in. When enabled it shows only your company name, industry, the number of AI systems tracked, the jurisdictions you operate in and requirement counts. It never shows individual requirements, evidence, generated documents or personal data. You can disable it at any time, which immediately takes the page and any badges offline.

5. International transfers

Our infrastructure is based in the United States. Where personal data is transferred out of the UK or EEA, we rely on Standard Contractual Clauses together with supplementary measures including encryption in transit and at rest and strict access controls.

6. Retention

We keep your data for as long as your account is active. When you delete your account, your personal data, company profile, AI system inventory, evidence and generated documents are deleted within 30 days, except where we are legally required to retain them. Non-identifying operational logs are kept for up to 12 months.

7. Your rights

UK and EEA residents. You have the right to access, rectify, erase, restrict processing of and port your personal data, to object to processing, to withdraw consent at any time, and to lodge a complaint with your supervisory authority.

California residents. You have the right to know, delete and correct your personal information and the right to non-discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.

To exercise any right, email info@regmaply.ai. We respond within 30 days. We may need to verify your identity first.

8. Security

  • TLS encryption for all data in transit.
  • Encryption at rest for stored data.
  • Row-level security policies that isolate each customer's data.
  • Evidence files held in private storage and served only via short-lived signed links.
  • Internal telemetry that is not accessible from the client.
  • Passwords stored only as salted hashes.

If a personal data breach affects you, we will notify you and the relevant authorities without undue delay.

9. Cookies

We use strictly necessary cookies and browser local storage to keep you signed in. We do not use advertising cookies or cross-site tracking.

10. Children

Regmaply is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 16.

11. Changes

If we make material changes to this policy we will notify you by email or in-app before they take effect.

12. Contact

Questions about this policy or your data: info@regmaply.ai.

Regmaply is a compliance information tool. It provides factual regulatory summaries and does not provide legal advice.