Last updated: March 31, 2026
This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the ComplianceForge AI platform. This policy applies to all users of our website and services.
DevLogic, sole proprietorship for IT services
Owner: Igor Vrgoč
Registered address: Šumetlica 66, 35404 Cernik, Šumetlica, Croatia
OIB (Personal Identification Number): 93106806915
Trade Register No.: 12010108940
Contact: info@complianceforge.eu
We collect the following categories of personal data:
We process your personal data for the following purposes under the GDPR:
| Purpose | Legal basis |
|---|---|
| Registration and authentication | Contractual necessity (čl. 6(1)(b)) |
| AI classification and compliance analysis | Contractual necessity (čl. 6(1)(b)) |
| Document generation | Contractual necessity (čl. 6(1)(b)) |
| Analytics (Google Analytics) | Consent (čl. 6(1)(a)) |
| Security and abuse prevention | Legitimate interest (čl. 6(1)(f)) |
| Error monitoring (Sentry) | Legitimate interest (čl. 6(1)(f)) |
| Legal obligations | Legal obligation (čl. 6(1)(c)) |
Your questionnaire answers are processed by the Claude API (Anthropic) to provide AI-powered risk classification, compliance scoring, gap analysis, and document generation. Important details:
AI-based risk classification and compliance scoring are recommendations, not automated decisions with legal effect. You make the final decision on all compliance matters. The Legal Review Mode enables human verification of all AI outputs. Article 22 of the GDPR does not apply as there is no automated decision-making with legal or similarly significant effect.
Paddle.com Market Ltd is a separate data controller for payment data. DevLogic does not receive, store, or process payment card information. Paddle processes: name, email, address, payment details, and transaction data. For details, see Paddle's Privacy Policy.
We do not sell, rent, or trade your personal data to third parties for advertising, profiling, or any other commercial purpose. Your data is never shared with data brokers or marketing companies. We only share data with the sub-processors listed in this policy, solely for the purpose of operating the service.
We use the following third-party services. Each processes data in accordance with their own privacy policies:
| Service | Location | Purpose |
|---|---|---|
| Supabase | EU (Frankfurt) | Database, authentication, storage |
| Anthropic (Claude API) | USA (DPF) | AI processing of questionnaire data |
| Paddle | UK | Payment processing (MoR) |
| Vercel | USA (DPF) | Hosting, serverless functions |
| Google Analytics | USA (DPF) | Web analytics (with consent) |
| Sentry | USA | Error monitoring |
| Inngest | USA | Background job processing |
Some of our sub-processors process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place: the EU-US Data Privacy Framework (DPF) for certified services, and Standard Contractual Clauses (SCCs) approved by the European Commission where DPF does not apply. All data transfers are protected by TLS encryption.
Your data is stored securely on Supabase servers in the EU (Frankfurt region). Security measures include:
While we implement industry-standard security measures, no method of electronic transmission or storage is 100% secure.
We retain your data for the following periods:
| Category | Retention Period |
|---|---|
| User account | while active + 30 days after deletion |
| Compliance data | until you request deletion |
| Analytics (GA4) | 14 months |
| Sentry logs | 90 days |
| Accounting records | 11 years (Croatian Accounting Act, Art. 10) |
We use essential cookies (authentication, language preference, consent storage) and analytics cookies (Google Analytics, with your consent). We do not use advertising or tracking cookies. For a complete list of cookies and how to manage them, see our Cookie Policy. Cookie Policy
As a data subject, you have the following rights:
To exercise these rights, contact us at info@complianceforge.eu. We will respond within 30 days.
If you are a California resident, you have additional rights under the CCPA/CPRA:
To exercise your California privacy rights, contact info@complianceforge.eu. We will respond within 45 days.
If you believe our processing violates data protection laws, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Croatian Personal Data Protection Agency (AZOP).
Croatian Personal Data Protection Agency (AZOP): azop.hr
If you are an EU consumer, you may also use the European Commission's Online Dispute Resolution platform.: ec.europa.eu/consumers/odr
We may update this Privacy Policy to reflect changes in our practices or applicable laws. We will notify you of material changes by posting a notice on our website or sending an email. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
The data controller responsible for your personal data is listed below. For questions about this Privacy Policy or your personal data, contact us at info@complianceforge.eu.
DevLogic, sole proprietorship for IT services
Owner: Igor Vrgoč
Registered address: Šumetlica 66, 35404 Cernik, Šumetlica, Croatia
Contact: info@complianceforge.eu