Conforly AB ("Conforly," "we," "us," or "our") operates a cloud-based Governance, Risk & Compliance (GRC) platform designed to help organizations manage EU AI Act compliance and related governance requirements.
This Privacy Policy explains how we collect, use, and protect personal data when you use our Services. It applies to:
Organizations: our customers, whether an established business or an individual signing up to try the Service
End users: people with access to an Organization's workspace, including team members and outside consultants managing compliance on an Organization's behalf
Visitors: people using our public website and free assessment tools
This policy complies with the GDPR and applies to everyone whose data we handle, in the EU and elsewhere.
2. Data controller and processor roles
Conforly AB is the data controller for:
User account data (email, name, job title, profile information)
Organization account and billing data (company name, address, VAT number, etc.)
End user activity logs and operational data
Visitor data from our free assessment tool
Your organization is the data controller for the compliance content it creates and uploads, such as AI system records, risk assessments, and evidence documents.
Conforly is the data processor for this compliance content, handling it on your organization's behalf under a Data Processing Agreement (DPA).
3. What data we collect
3.1 User account data
When you create an account, we collect:
Email address (required)
First and last name (required)
Job title (optional)
Profile picture (optional)
Role within Conforly (admin, member, or viewer)
Account status (active, pending setup)
Activity timestamps (when you log in, create records, etc.)
3.2 Organization data
When your organization signs up, we collect:
Company name (required)
Country and postal code (required only for paid plans, collected at checkout)
The following are optional, and can be added later from company settings:
Address, city
VAT/tax number
Registration number
Legal entity type (sole proprietor, Ltd, AB, etc.)
Website
Phone number
Organization logo
Billing information (Stripe customer ID when payments are activated)
3.3 Compliance & governance content
Your organization controls what compliance content is entered into Conforly:
AI system records — descriptions of your AI systems and their governance
Risk assessments & technical specifications — security and compliance documentation
Governance workflows — your organization's internal processes
Chat conversations — interactions with our AI compliance assistant
Classification history — how content has been categorized and processed
You remain the owner of this content. We process it only on your behalf, under our Data Processing Agreement.
3.4 Identity provider links
To enable seamless login, we record which identity providers are linked to your account:
Provider type (Google, Microsoft, Apple)
Provider subject ID (unique identifier from that provider)
Email associated with each provider
This allows you to sign in via OAuth without sharing passwords with Conforly.
3.5 Operational logs
We maintain logs for security, troubleshooting, and audit purposes:
Log level (info, warning, error, debug)
Log message (what action was performed)
Structured details (relevant context)
Associated user/organization (who triggered the action)
Timestamp (when it occurred)
We do not collect or store IP addresses, user agents, or browser fingerprints in these logs.
3.6 Anonymous visitor data
For our public free-assessment tool (available without login):
Client IP address (used only to enforce a shared rate limit)
Rate-limit counters (via Upstash Redis)
This data is not stored in our database or application logs — it exists only as a transient rate-limit counter and is deleted automatically once the rate-limit window expires.
4. How we use your data
4.1 To provide the service
Create and maintain your account
Authenticate you via OAuth providers (Google, Microsoft, Apple)
Process and store compliance content you enter
Generate compliance assessments and recommendations
Analyze usage patterns to improve platform features
Debug errors and optimize performance
Conduct analytics on feature adoption (anonymized where possible)
We do not use your account or compliance content to train AI models. Our AI assistant uses Google's Gemini API to process each request as it comes in — your data is not used to train or fine-tune any model, ours or Google's.
4.3 Legal & compliance
Comply with legal obligations (GDPR, Swedish law, EU regulations)
Investigate and prevent fraud, abuse, or unauthorized access
Enforce our Terms of Service and other agreements
Respond to lawful government requests
4.4 Communications
Send service updates and security alerts
Inform you of changes to our policies or terms
5. Legal basis for processing
Under GDPR, we process your data based on:
Data type
Legal basis
Purpose
Account creation & authentication
Contract performance
Providing the service
Organization & billing data
Contract performance
Billing & service delivery
Compliance content
Contract performance (as processor)
You control this; we store it on your behalf
Activity logs & operational data
Legitimate interest
Security, fraud prevention, troubleshooting
Communications
Legitimate interest
Service updates, support, business communications
Visitor data (free tool)
Legitimate interest
Rate-limiting, abuse prevention
6. Data sharing & third parties
We do not sell your personal data. We share data with third parties only as necessary to operate the Service:
6.1 Essential subprocessors
Infrastructure & storage
Google Cloud (databases, file storage, secret management)
Authentication & identity
Google, Microsoft, Apple (OAuth/SSO)
Email
AWS SES (transactional email)
AI processing
Google Gemini API — processes compliance content you enter to provide AI-powered gap identification and assessment features, on a per-request basis (see Section 4.2)
We will disclose your data to law enforcement, courts, or regulatory bodies only with a valid legal request (warrant, court order, etc.).
Where legally permitted, we will notify you of such requests so you can seek legal recourse if appropriate.
7. Data retention
7.1 User account data
Active accounts: Retained while your account is active
Deleted accounts: We delete your data within 30 days of account termination, except where legal obligations require longer retention
Backups: May be retained for up to 90 days for disaster recovery
7.2 Organization data
Active organizations: Retained while subscribed
Terminated organizations: Most organization data is deleted within 30 days of termination, in line with Section 7.1
Billing and accounting records: Retained for 7 years, as required by Swedish accounting law (Bokföringslagen)
7.3 Compliance content
Your content: You control retention. You can delete content at any time.
Backups: Retained up to 90 days for recovery purposes
Legal holds: If your content becomes subject to a legal hold (e.g., litigation or regulatory investigation), we retain it until the hold is lifted
7.4 Activity logs
Standard logs: Retained for 90 days
Security and audit logs: Retained for 1 year to support security investigations and audits
7.5 Visitor data (free tool)
Rate-limit data: Deleted automatically within 24 hours
8. Your rights under GDPR
Under GDPR, you have the following rights regarding your personal data:
8.1 Right of access
You can request a copy of all personal data we hold about you.
8.2 Right to rectification
You can correct inaccurate or incomplete data.
8.3 Right to erasure ("right to be forgotten")
You can request deletion of your data, subject to legal retention requirements.
8.4 Right to restrict processing
You can ask us to limit how we use your data while you dispute its accuracy or processing.
8.5 Right to data portability
You can request your data in a standard, machine-readable format (CSV, JSON) to transfer to another service.
8.6 Right to object
You can object to processing based on legitimate interest.
8.7 Right to withdraw consent
If processing is based on consent, you can withdraw it at any time.
8.8 Rights related to automated decision-making
Our AI compliance assistant provides recommendations, but final decisions about your compliance remain with you. We do not make decisions with legal or similarly significant effects based solely on automated processing.
We will respond within one month, as required by GDPR. In complex cases, we may extend this by up to two further months, and will notify you if we do.
9. Data security
We implement the following security measures:
Encryption in transit: TLS/SSL for all data in transit
Encryption at rest: Google Cloud encryption for stored data
Access controls: role-based access; principle of least privilege
Authentication: OAuth 2.0 via trusted providers; no passwords stored by Conforly
Security event logging: security-relevant events (e.g., login attempts, rejected requests) are recorded in logs
We are actively building toward:
Active log monitoring and alerting (currently, security events are logged but not actively monitored in real time)
A formal written incident response plan
Independent third-party security audits
In the event of a personal data breach, we will notify affected users and relevant authorities within 72 hours, as required by GDPR.
However, no system is 100% secure. We recommend using strong, unique passwords and enabling multi-factor authentication on your identity provider accounts.
10. Data transfers & international processing
Conforly is headquartered in Sweden and primarily uses Google Cloud infrastructure.
EU/EEA data: Processed in accordance with GDPR
Google Cloud: Operates under Standard Contractual Clauses (SCCs) and Binding Corporate Rules
Third-country transfers: Data may be transferred to the US (Google, Microsoft, AWS) under adequacy mechanisms and SCCs
We ensure appropriate safeguards are in place for all international transfers.
11. Cookies & tracking
We use cookies only for:
Session management (keeping you logged in)
Preference storage (your UI settings)
We do not use:
Tracking pixels
Advertising networks
Behavioral advertising cookies
Analytics cookies or third-party analytics tools
12. Children's privacy
Conforly is not designed for children under 13. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 13, we will delete it immediately.
13. Data Processing Agreement (DPA)
Organizations using Conforly are data controllers for their own compliance content. We enter into a Data Processing Agreement with each customer to ensure compliance with GDPR Article 28.