Last updated: 12 August 2026
This Privacy Policy explains what personal data Regmaply collects, why we process it, who we share it with, and the rights you have over it. It applies to the Regmaply web application and our public website.
We collect the following categories of information:
We do not collect payment card details. Any future payments will be handled by a payment provider that processes card data directly.
| Purpose | Legal basis |
|---|---|
| Creating and administering your account | Performance of a contract |
| Generating your compliance map, requirements and reports | Performance of a contract |
| Sending regulatory change alerts | Performance of a contract, or consent |
| Security, fraud prevention, service reliability and debugging | Our legitimate interests |
| Aggregate, non-identifying product improvement analytics | Our legitimate interests |
| Marketing email about Regmaply | Consent, withdrawable at any time |
Your compliance map is not generated by AI. Requirements are produced by a deterministic rule engine that we maintain. No customer data is sent to any AI provider for that purpose.
AI document drafting is a paid feature that runs only when you explicitly request a draft. When you do, we send the following context to Anthropic PBC: your company name, industry, size and country; the relevant AI system's name, vendor, system types, impact level, use case, data types and deployment locations; and the specific requirement being drafted for. Anthropic's commercial API terms provide that customer inputs and outputs are not used to train its models.
Every drafting request is recorded in an internal call log so we can trace what was sent and when. Please do not enter special-category personal data (for example health, biometric or political data) into free-text fields.
Our infrastructure is based in the United States. Where personal data is transferred out of the UK or EEA, we rely on Standard Contractual Clauses together with supplementary measures including encryption in transit and at rest and strict access controls.
We keep your data for as long as your account is active. When you delete your account, your personal data, company profile, AI system inventory, evidence and generated documents are deleted within 30 days, except where we are legally required to retain them. Non-identifying operational logs are kept for up to 12 months.
UK and EEA residents. You have the right to access, rectify, erase, restrict processing of and port your personal data, to object to processing, to withdraw consent at any time, and to lodge a complaint with your supervisory authority.
California residents. You have the right to know, delete and correct your personal information and the right to non-discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
To exercise any right, email info@regmaply.ai. We respond within 30 days. We may need to verify your identity first.
If a personal data breach affects you, we will notify you and the relevant authorities without undue delay.
Regmaply is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under 16.
If we make material changes to this policy we will notify you by email or in-app before they take effect.
Questions about this policy or your data: info@regmaply.ai.
Regmaply is a compliance information tool. It provides factual regulatory summaries and does not provide legal advice.