1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
[bitte ergänzen][bitte ergänzen][bitte ergänzen] [bitte ergänzen]DeutschlandRepresented by: [bitte ergänzen]
Phone: [bitte ergänzen]
Email: datenschutz@itcompli.com
Commercial register: [bitte ergänzen]
VAT identification number: [bitte ergänzen]
2. Data protection officer
We are currently not required to appoint a data protection officer under Art. 37 GDPR in conjunction with § 38 BDSG. For any data protection matter, please contact datenschutz@itcompli.com.
3. Principles of processing
We process personal data solely on the basis of the GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). We process data only where this is necessary to provide our website and platform, where it is permitted by law, or where you have given your consent.
Depending on the processing, the legal bases are:
- Art. 6(1)(a) GDPR — your consent
- Art. 6(1)(b) GDPR — performance of a contract or pre-contractual measures
- Art. 6(1)(c) GDPR — compliance with a legal obligation
- Art. 6(1)(f) GDPR — our legitimate interests
Personal data is erased as soon as the purpose of processing ceases to apply and no statutory retention obligations — in particular under the German Commercial Code and Fiscal Code — prevent erasure.
4. Visiting the website and server log files
When you visit our website, our web server automatically processes the following data transmitted by your browser:
- IP address of the requesting device
- date and time of access
- requested URL and volume of data transferred
- HTTP status code and referrer URL
- browser type, browser version and operating system
The purpose is the technical delivery of the website and the detection and prevention of attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure and uninterrupted operation. This data is erased after 7 days and is not combined with other data sources.
5. Hosting
Our website and platform run on servers operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in a data centre in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner. No transfer to a third country takes place as part of hosting.
6. Fonts and third-party content
All fonts used on this website are served locally from our own server. Your browser does not connect to third-party servers — in particular not to Google Fonts — and your IP address is not disclosed to third parties in this context. We do not embed maps, videos or social media plugins.
7. Cookies and storage on your device
We use strictly necessary cookies only, which are essential for operating the website and signing in to the platform:
| Cookie | Purpose | Storage period |
|---|---|---|
| __Secure-authjs.session-token | maintaining your signed-in session | 15 minutes |
| __Host-authjs.csrf-token | protection against cross-site request forgery | end of session |
| authjs.callback-url | technical redirect after sign-in | end of session |
| NEXT_LOCALE | storing your language selection | end of session |
These cookies are only set once you sign in or select a language. Simply visiting our website sets no cookies at all.
The legal basis for this storage is § 25(2)(2) TDDDG; it is strictly necessary to provide the service you have expressly requested. No consent is required, which is why we do not display a consent banner. We do not use analytics, tracking, profiling or marketing cookies, and we do not measure reach.
8. Contacting us and demo requests
If you contact us by email or through a form, we process the data you provide — name, email address, company and the content of your enquiry — in order to respond. The legal basis is Art. 6(1)(b) GDPR where your enquiry is aimed at concluding a contract, and otherwise Art. 6(1)(f) GDPR. We erase this data once your enquiry has been dealt with conclusively and no retention obligations apply.
9. User account and use of the platform
A user account is required to use the platform. In this context we process:
- name and email address
- password, stored exclusively as a cryptographic hash
- company affiliation and role within the company
- sign-in and sign-out times and session information
- your language setting
The purpose is to provide the user account, to authenticate you and to attribute work in progress. The legal basis is Art. 6(1)(b) GDPR.
We log administrative actions and security-relevant events together with the user identifier, timestamp, IP address and browser identifier. The legal basis is Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR. These logs are erased after 12 months.
10. Processing on behalf of our customers
A large part of the data processed in the platform does not originate from us but is entered by our customers: uploaded policies, procedures, evidence documents, audit answers and — where system integrations are used — inventory data from our customers’ IT systems.
For this data, our customers are the controllers within the meaning of Art. 4(7) GDPR. In that respect we act exclusively as a processor under Art. 28 GDPR, on the basis of a data processing agreement and solely on our customers’ instructions.
This privacy policy therefore does not govern the processing of that data; the privacy policy of the respective customer does. Data subjects — in particular employees of our customers — should address their data subject rights to their employer as the controller. We support our customers in fulfilling those rights pursuant to Art. 28(3)(e) GDPR.
11. Use of artificial intelligence
To evaluate answers and documents and to produce audit reports, we use large language models provided by Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA. The content entered — including uploaded documents — is transmitted to and processed by Anthropic.
- Anthropic is contractually bound as a processor, including the EU Standard Contractual Clauses (Module 2).
- According to the provider, the transmitted content is not used to train models.
- According to the provider, content is retained for up to 30 days for safety purposes and is then deleted.
- A transfer to the USA takes place; see section 13.
No automated decision-making producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR takes place. All AI-assisted assessments are reviewed by qualified auditors before they are used.
Please do not enter personal data into free-text fields where it is not required for the assessment, and redact evidence documents where personal details are not needed.
12. Sending email
For system and notification emails we use Amazon Simple Email Service provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, with processing in the Frankfurt am Main region. We process your email address and the content and delivery status of the message. The legal basis is Art. 6(1)(b) and (f) GDPR. A data processing agreement is in place; the EU Standard Contractual Clauses apply in addition.
13. Recipients and third-country transfers
| Recipient | Purpose | Location | Basis |
|---|---|---|---|
| Hetzner Online GmbH | hosting and storage | Germany | Art. 28 GDPR |
| Anthropic PBC | AI-assisted evaluation | USA | Art. 28, Art. 46(2)(c) GDPR |
| Amazon Web Services EMEA SARL | sending email | Luxembourg / Frankfurt | Art. 28 GDPR, SCC |
Where data is transferred to the USA, there is a risk that US authorities may access it under US law without you having remedies equivalent to those available in the European Union. We address this risk through the EU Standard Contractual Clauses, a documented transfer impact assessment, transport encryption and data minimisation.
Beyond this, we disclose personal data only where we are legally obliged to do so or where you have consented. We do not sell data.
14. Retention periods at a glance
| Category of data | Period |
|---|---|
| Server log files | 7 days |
| User account and master data | term of the contract, then 30 days until erasure |
| Uploaded documents and audit data | as instructed by the customer, at the latest 90 days after the contract ends |
| Security and administration logs | 12 months |
| Invoices and commercial correspondence | 10 and 6 years respectively (§ 147 AO, § 257 HGB) |
| Contact enquiries | until the enquiry has been dealt with |
15. Your rights
You have the following rights regarding personal data relating to you:
- access to the data processed (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on legitimate interests (Art. 21 GDPR)
- withdrawal of consent with effect for the future (Art. 7(3) GDPR)
An informal message to datenschutz@itcompli.com is sufficient to exercise these rights.
16. Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is:
[bitte ergänzen]
17. Data security
We implement technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, destruction, manipulation and unauthorised access. These include in particular:
- transport encryption for all connections (TLS)
- encryption of particularly sensitive database content, in particular stored credentials for customer systems
- a role-based authorisation concept and tenant separation
- logging of administrative access
- regular backups and updating of the components in use
These measures are continuously adapted to the state of the art.
18. Changes to this privacy policy
We update this privacy policy whenever changes to our processing activities or to the legal framework require it. The controller is [bitte ergänzen], [bitte ergänzen], [bitte ergänzen] [bitte ergänzen], Deutschland.