Privacy
Policy.
Our commitment to your privacy and data security.
Effective Date
December 10, 2025
Jurisdiction
India
Status
Version 1.0.5
1. Introduction
1.1 CompliEZ (collectively, "we", "us", or "our") is engaged in the provision of legal technology and compliance automation services. At CompliEZ, we are committed to respecting the privacy and protecting the personal data of our users, clients, staff, and other third parties ("you").
1.2 In order to engage with you or provide services, CompliEZ needs to process personal data about you. This Privacy Notice ("Notice") outlines our practices in relation to the processing of your personal data that may be accessed by us or you may have chosen to share with us when you engage with us or visit our platform available at https://www.compliez.com ("Platform").
1.3 Please read this Notice carefully to understand our practices regarding your personal data and how we will treat it. This Notice sets out the basis on which any personal data we collect from you, we collect about you, or that you provide to us, will be processed by us as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDPA").
2. The Data We Collect
2.1 We collect or obtain data relating to you in a variety of ways, as described below. Such data may include personal data or information, that is, information relating to an identified or identifiable natural person. We may collect or receive the following categories of data about you:
(a) Identity Data: This includes data such as your first and last name, date of birth, job title, gender, business entity name, type of business, and other identification documents.
(b) Contact Data: This includes data such as your phone number, email address (including corporate email), and official business address.
(c) Compliance Data: This includes regulatory filings, license numbers, expiry dates, and other business compliance information you provide to generate documents or track deadlines.
(d) Technical Data: This includes data such as your internet protocol (IP) address, browser type and versions, platform usage data, operating systems, device information, and data collected through cookies.
(e) Financial Data: Where applicable for payments, we may process transaction IDs and billing details (payment processing is handled by secure third-party gateways).
2.2 We are required to collect your personal data to engage with you or provide you with our services. If you fail to provide us that data as and when requested by us, we may not be able to engage with you or provide our services.
3. How We Collect Data
3.1 We use different methods, as permitted under applicable laws, to process personal data about you. This includes:
(a) Direct Interactions: This is the information (such as Identity Data, Contact Data, and Compliance Data) you consent to give us when you register an account, use our document generation tools, subscribe to our services, or contact us.
(b) Automated Technologies: Each time you visit the Platform, we may automatically collect Technical Data using cookies and server logs to improve platform performance and user experience.
(c) Third Parties: We may receive personal data about you from third parties such as analytics providers (e.g., Google Analytics) or publicly available sources where you have made such data public.
4. How We Use Data
4.1 We will only use your personal data in accordance with applicable laws. Most commonly, we will use your personal data to provide legal-tech solutions or where we need to comply with a legal obligation.
4.2 Specifically, we use your personal data for the following purposes:
- To register you as a new user/client.
- To generate requested legal documents and compliance reports.
- To manage our relationship with you, including notifying you of changes to services or terms.
- To administer and protect our business and the Platform (troubleshooting, data analysis).
- To use data analytics to improve our website, products/services, and customer experience.
- To comply with legal or regulatory obligations.
- To detect and prevent fraud or cybersecurity incidents.
- To send you updates about relevant legal changes (where you have opted in).
4.3 Legal Bases for Processing: We rely on the following grounds under DPDPA 2023:
- Consent: Where you have explicitly agreed to the processing of your data for a specific purpose.
- Legitimate Uses: As per Section 7 of the Act, for purposes such as fulfilling your voluntary request for service, employment-related purposes, or compliance with law.
6. Hosting & Infrastructure
6.1 CompliEZ is a digital-first platform. We utilize secure, industry-leading cloud infrastructure providers to host our services. Your data is securely hosted and processed on servers provided by:
- — Amazon Web Services (AWS)
- — Microsoft Azure
These providers act as Data Processors under strict contractual confidentiality and security obligations.
6.2 We do not transfer your personal data to other entities for marketing purposes without your explicit consent.
7. Data Security
7.1 We have put in place appropriate security measures to prevent your personal data being accidently lost, used, or accessed in an unauthorised way, altered, or disclosed.
7.2 We have put in place procedures to deal with any actual or suspected data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. Data Retention
8.1 We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.
8.2 Upon completion of the retention period for each category of personal data, we shall delete or destroy, to the extent technically possible, personal data in our possession or control, or render the personal data into anonymised data, so that it no longer constitutes personal data.
9. Your Legal Rights
9.1 Under certain circumstances, you have rights under data protection laws in relation to your personal data. Subject to the data protection laws that apply to you, you may have the right to:
(a) Request access: This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
(b) Request confirmation: Request confirmation as to whether or not your personal data is being processed.
(c) Request correction: This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
(d) Request erasure: This enables you to ask us to delete or remove personal data where there is no reason for us to continue processing it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing, where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law.
(e) Object to processing: Object where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object as you feel it impacts your fundamental rights and freedoms.
(f) Request restriction: Suspend the processing of your personal data if: (i) you want us to establish accuracy; (ii) use is unlawful but no erasure; (iii) we no longer require it but you need it for legal claims; or (iv) you objected but we need to verify grounds.
(g) Request transfer: To you or to a third party in a structured, commonly used, and machine-readable format.
(h) Withdraw consent: At any time where we are relying on consent. This will not affect the lawfulness of any processing carried out before you withdraw.
9.2 We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data.
9.3 We try to respond to all legitimate requests within one month.
9.4 If you wish to exercise any of the rights set out above, please write an email to the Grievance Officer, Whose details are mentioned in Section 14.
10. Transfer of Data
10.1 The personal data that we process may be transferred to countries other than where you are based. We undertake such transfers in accordance with applicable laws.
12. Business Transitions
You agree and acknowledge that in the event we go through a business transition, such as a merger, acquisition by another organisation, or sale of all or a portion of our assets, your personal data may be among the assets transferred.
13. Policy Changes
13.1 We keep our Policy under regular review and may amend it from time to time, at our sole discretion.
13.2 The terms of this Policy may change and if they do, these changes will be posted on this page and, where required by applicable laws, notified to you.
14. Grievance Redressal
Grievance Officer Details
Mr. Anand Raj
Founder & Partner at CompliEZ
Direct Liaison
contact@compliez.com
Data Protection Board of India
If your grievance is not resolved satisfactorily by us, you have the right to file a complaint with the Data Protection Board of India as per the DPDPA 2023.