Compliance Cockpit
Last Updated: September 2026

Privacy Policy

How ComplyPulse collects, processes, protects, and handles cloud audit telemetry and customer data.

1. Scope and Zero-Persistent Workload Principle

ComplyPulse operates as an automated compliance and audit evidence engine. Our core architectural design follows a strict Zero-Persistent Workload principle.

ComplyPulse connects to your cloud infrastructure (AWS, Google Cloud, Microsoft Azure, Google Workspace, GitHub) exclusively via read-only, least-privilege security roles (such as AWS STS AssumeRole with SecurityAudit, GCP Viewer, and Azure Reader).

We never inspect, copy, or store your application databases, customer personal records, or proprietary source code files. Telemetry collection is strictly limited to infrastructure configuration metadata and identity policies necessary to evaluate compliance controls.

2. Information We Collect

To deliver continuous compliance monitoring, ComplyPulse collects the following categories of data:

  • Account Information: Name, business email, organization name, and authentication identifiers.
  • Infrastructure Metadata: Cloud resource configurations, encryption states (AES-256/KMS), IAM policy definitions, access key ages, and security group rules.
  • Audit Evidence Telemetry: Read-only scan results, compliance pass/fail evaluations, and control gap findings.
  • Cryptographic Digests: Mathematical SHA-256 hashes generated from raw configuration snapshots for audit proof.

3. Cryptographic Evidence Integrity (SHA-256)

Every automated audit scan produces an immutable SHA-256 cryptographic checksum. This hash is embedded into your official PDF and JSON Evidence Packs, enabling independent auditors and CPA firms to mathematically verify that the evidence has not been altered since collection.

4. Third-Party Processors and Merchant of Record

We work with trusted sub-processors under rigorous Data Processing Agreements (DPAs):

Payments & Invoicing: Subscription payments, tax compliance, and VAT/sales tax invoicing are handled by our authorized Merchant of Record (Paddle / Lemon Squeezy). Your credit card details are processed directly by PCI-DSS Level 1 compliant gateways and are never stored on our servers.

Hosting & Database Infrastructure: Cloud hosting and databases are operated in encrypted multi-tenant isolated VPCs with automated backups and continuous vulnerability scanning.

5. Data Subject Rights (GDPR, KVKK, CCPA)

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Right of Access: Request a full copy of data held about your organization.
  • Right to Rectification: Correct inaccurate or incomplete account details.
  • Right to Erasure (Right to be Forgotten): Request complete deletion of your account and associated audit scans.
  • Right to Data Portability: Export raw audit packs in standard JSON and PDF formats at any time.

6. Security Contacts & Data Protection Officer

For any inquiries regarding this policy, data subject requests, or security vulnerability disclosures, please contact our security team at privacy@complypulse.com or security@complypulse.com.