Conforly

Privacy policy

Effective date: 2026-09

Last updated: 2026-09-15



1. Introduction

Conforly AB ("Conforly," "we," "us," or "our") operates a cloud-based Governance, Risk & Compliance (GRC) platform designed to help organizations manage EU AI Act compliance and related governance requirements.

This Privacy Policy explains how we collect, use, and protect personal data when you use our Services. It applies to:

  • Organizations: our customers, whether an established business or an individual signing up to try the Service
  • End users: people with access to an Organization's workspace, including team members and outside consultants managing compliance on an Organization's behalf
  • Visitors: people using our public website and free assessment tools

This policy complies with the GDPR and applies to everyone whose data we handle, in the EU and elsewhere.


2. Data controller and processor roles

Conforly AB is the data controller for:

  • User account data (email, name, job title, profile information)
  • Organization account and billing data (company name, address, VAT number, etc.)
  • End user activity logs and operational data
  • Visitor data from our free assessment tool

Your organization is the data controller for the compliance content it creates and uploads, such as AI system records, risk assessments, and evidence documents.

Conforly is the data processor for this compliance content, handling it on your organization's behalf under a Data Processing Agreement (DPA).


3. What data we collect

3.1 User account data

When you create an account, we collect:

  • Email address (required)
  • First and last name (required)
  • Job title (optional)
  • Profile picture (optional)
  • Role within Conforly (admin, member, or viewer)
  • Account status (active, pending setup)
  • Activity timestamps (when you log in, create records, etc.)

3.2 Organization data

When your organization signs up, we collect:

  • Company name (required)
  • Country and postal code (required only for paid plans, collected at checkout)

The following are optional, and can be added later from company settings:

  • Address, city

  • VAT/tax number

  • Registration number

  • Legal entity type (sole proprietor, Ltd, AB, etc.)

  • Website

  • Phone number

  • Organization logo

  • Billing information (Stripe customer ID when payments are activated)

3.3 Compliance & governance content

Your organization controls what compliance content is entered into Conforly:

  • AI system records — descriptions of your AI systems and their governance
  • Risk assessments & technical specifications — security and compliance documentation
  • Governance workflows — your organization's internal processes
  • Evidence documents — uploaded files, reports, certifications
  • Chat conversations — interactions with our AI compliance assistant
  • Classification history — how content has been categorized and processed

You remain the owner of this content. We process it only on your behalf, under our Data Processing Agreement.

3.4 Identity provider links

To enable seamless login, we record which identity providers are linked to your account:

  • Provider type (Google, Microsoft, Apple)
  • Provider subject ID (unique identifier from that provider)
  • Email associated with each provider

This allows you to sign in via OAuth without sharing passwords with Conforly.

3.5 Operational logs

We maintain logs for security, troubleshooting, and audit purposes:

  • Log level (info, warning, error, debug)
  • Log message (what action was performed)
  • Structured details (relevant context)
  • Associated user/organization (who triggered the action)
  • Timestamp (when it occurred)

We do not collect or store IP addresses, user agents, or browser fingerprints in these logs.

3.6 Anonymous visitor data

For our public free-assessment tool (available without login):

  • Client IP address (used only to enforce a shared rate limit)
  • Rate-limit counters (via Upstash Redis)

This data is not stored in our database or application logs — it exists only as a transient rate-limit counter and is deleted automatically once the rate-limit window expires.


4. How we use your data

4.1 To provide the service

  • Create and maintain your account
  • Authenticate you via OAuth providers (Google, Microsoft, Apple)
  • Process and store compliance content you enter
  • Generate compliance assessments and recommendations
  • Provide customer support and technical assistance
  • Send transactional emails (invites, account notifications)

4.2 To improve the service

  • Analyze usage patterns to improve platform features
  • Debug errors and optimize performance
  • Conduct analytics on feature adoption (anonymized where possible)

We do not use your account or compliance content to train AI models. Our AI assistant uses Google's Gemini API to process each request as it comes in — your data is not used to train or fine-tune any model, ours or Google's.

4.3 Legal & compliance

  • Comply with legal obligations (GDPR, Swedish law, EU regulations)
  • Investigate and prevent fraud, abuse, or unauthorized access
  • Enforce our Terms of Service and other agreements
  • Respond to lawful government requests

4.4 Communications

  • Send service updates and security alerts
  • Inform you of changes to our policies or terms

Under GDPR, we process your data based on:

Data typeLegal basisPurpose
Account creation & authenticationContract performanceProviding the service
Organization & billing dataContract performanceBilling & service delivery
Compliance contentContract performance (as processor)You control this; we store it on your behalf
Activity logs & operational dataLegitimate interestSecurity, fraud prevention, troubleshooting
CommunicationsLegitimate interestService updates, support, business communications
Visitor data (free tool)Legitimate interestRate-limiting, abuse prevention

6. Data sharing & third parties

We do not sell your personal data. We share data with third parties only as necessary to operate the Service:

6.1 Essential subprocessors

Infrastructure & storage

  • Google Cloud (databases, file storage, secret management)

Authentication & identity

  • Google, Microsoft, Apple (OAuth/SSO)

Email

  • AWS SES (transactional email)

AI processing

  • Google Gemini API — processes compliance content you enter to provide AI-powered gap identification and assessment features, on a per-request basis (see Section 4.2)

6.2 Payment processing

  • Stripe — payment processing

6.3 Rate limiting

  • Upstash Redis — transient rate-limit counters (non-persistent)

6.4 Legal requirements

We will disclose your data to law enforcement, courts, or regulatory bodies only with a valid legal request (warrant, court order, etc.).

Where legally permitted, we will notify you of such requests so you can seek legal recourse if appropriate.


7. Data retention

7.1 User account data

  • Active accounts: Retained while your account is active
  • Deleted accounts: We delete your data within 30 days of account termination, except where legal obligations require longer retention
  • Backups: May be retained for up to 90 days for disaster recovery

7.2 Organization data

  • Active organizations: Retained while subscribed
  • Terminated organizations: Most organization data is deleted within 30 days of termination, in line with Section 7.1
  • Billing and accounting records: Retained for 7 years, as required by Swedish accounting law (Bokföringslagen)

7.3 Compliance content

  • Your content: You control retention. You can delete content at any time.
  • Backups: Retained up to 90 days for recovery purposes
  • Legal holds: If your content becomes subject to a legal hold (e.g., litigation or regulatory investigation), we retain it until the hold is lifted

7.4 Activity logs

  • Standard logs: Retained for 90 days
  • Security and audit logs: Retained for 1 year to support security investigations and audits

7.5 Visitor data (free tool)

  • Rate-limit data: Deleted automatically within 24 hours

8. Your rights under GDPR

Under GDPR, you have the following rights regarding your personal data:

8.1 Right of access

You can request a copy of all personal data we hold about you.

8.2 Right to rectification

You can correct inaccurate or incomplete data.

8.3 Right to erasure ("right to be forgotten")

You can request deletion of your data, subject to legal retention requirements.

8.4 Right to restrict processing

You can ask us to limit how we use your data while you dispute its accuracy or processing.

8.5 Right to data portability

You can request your data in a standard, machine-readable format (CSV, JSON) to transfer to another service.

8.6 Right to object

You can object to processing based on legitimate interest.

8.7 Right to withdraw consent

If processing is based on consent, you can withdraw it at any time.

8.8 Rights related to automated decision-making

Our AI compliance assistant provides recommendations, but final decisions about your compliance remain with you. We do not make decisions with legal or similarly significant effects based solely on automated processing.

To exercise any of these rights, contact: privacy@conforly.com

We will respond within one month, as required by GDPR. In complex cases, we may extend this by up to two further months, and will notify you if we do.


9. Data security

We implement the following security measures:

  • Encryption in transit: TLS/SSL for all data in transit
  • Encryption at rest: Google Cloud encryption for stored data
  • Access controls: role-based access; principle of least privilege
  • Authentication: OAuth 2.0 via trusted providers; no passwords stored by Conforly
  • Security event logging: security-relevant events (e.g., login attempts, rejected requests) are recorded in logs

We are actively building toward:

  • Active log monitoring and alerting (currently, security events are logged but not actively monitored in real time)
  • A formal written incident response plan
  • Independent third-party security audits

In the event of a personal data breach, we will notify affected users and relevant authorities within 72 hours, as required by GDPR.

However, no system is 100% secure. We recommend using strong, unique passwords and enabling multi-factor authentication on your identity provider accounts.


10. Data transfers & international processing

Conforly is headquartered in Sweden and primarily uses Google Cloud infrastructure.

  • EU/EEA data: Processed in accordance with GDPR
  • Google Cloud: Operates under Standard Contractual Clauses (SCCs) and Binding Corporate Rules
  • Third-country transfers: Data may be transferred to the US (Google, Microsoft, AWS) under adequacy mechanisms and SCCs

We ensure appropriate safeguards are in place for all international transfers.


11. Cookies & tracking

We use cookies only for:

  • Session management (keeping you logged in)
  • Preference storage (your UI settings)

We do not use:

  • Tracking pixels
  • Advertising networks
  • Behavioral advertising cookies
  • Analytics cookies or third-party analytics tools

12. Children's privacy

Conforly is not designed for children under 13. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 13, we will delete it immediately.


13. Data Processing Agreement (DPA)

Organizations using Conforly are data controllers for their own compliance content. We enter into a Data Processing Agreement with each customer to ensure compliance with GDPR Article 28.

Our DPA is available upon request: privacy@conforly.com


14. Privacy by design

We build privacy into every feature:

  • Data minimization: We collect only what's necessary
  • Purpose limitation: Data is used only for stated purposes
  • Storage limitation: Data is deleted when no longer needed
  • Transparency: Clear explanations of what data is collected and why
  • User control: You control your data; we provide export and deletion tools

15. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements.

  • Material changes: We'll notify you via email or in-app notification
  • Non-material changes: We'll update this page with a new "Last updated" date

Your continued use of Conforly after changes constitutes acceptance of the updated policy.


16. Contact us

Questions or concerns about privacy?

  • Email: privacy@conforly.com

  • Mailing address: Conforly AB [Your address in Sweden] Sweden

  • Data Protection Officer: [Name/contact if applicable]

  • Swedish Data Protection Authority (Integritetsskyddsmyndigheten): Box 8114 104 20 Stockholm Sweden www.imy.se


17. Jurisdiction & applicable law

This Privacy Policy is governed by Swedish law and the GDPR. Any disputes are subject to Swedish courts.


Thank you for trusting Conforly with your compliance data.