Privacy Policy
Last updated: June 2026
EU AI Act Compliance Checker ("we", "us", "our") is operated by Cyril Coste. We are committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website at EUAIActComplianceChecker.com and our compliance assessment services.
1. Data We Collect
We collect the following categories of personal data:
1.1 Account Information
- Email address
- Full name
- Company name and size
- Job title / role
- Country of operation
1.2 Assessment Data
- AI system descriptions and use-case details
- Responses to compliance assessment questionnaires
- Risk classification inputs
- Generated compliance readiness reports
1.3 Payment Information
Payment card details are collected and processed directly by our payment processor, Stripe. We do not store your full credit card number on our servers. We receive only a tokenised reference, your billing email, and transaction history from Stripe.
1.4 Technical Data
- IP address (anonymised where possible)
- Browser type and version
- Pages visited and timestamps
- Referring URL
2. How We Use Your Data
We use the data we collect for the following purposes:
- To generate compliance reports: Your assessment responses are processed by our AI engine to produce your EU AI Act compliance readiness report.
- To provide and improve the service: We use aggregated, anonymised assessment data to improve the accuracy and coverage of our compliance analysis.
- To manage your account: Including authentication, subscription management, and customer support.
- To process payments: Via our payment processor Stripe, for Professional and AI Strategy Review plans.
- To send essential communications: Such as account confirmations, subscription receipts, and material service updates. We do not send marketing emails without your explicit consent.
- To comply with legal obligations: Including tax, accounting, and regulatory requirements.
3. Third-Party Services
We work with trusted third-party service providers who process data on our behalf:
Stripe — Payment Processing
Handles all payment card processing, subscription billing, and invoicing. Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.
OpenAI — Report Generation
Powers the AI analysis engine that generates compliance readiness reports from your assessment responses. Assessment data is sent to OpenAI's API for processing and is not used by OpenAI to train their models. See OpenAI's Privacy Policy.
Supabase — Data Storage & Authentication
Provides secure database hosting and user authentication. Your data is stored in Supabase-managed PostgreSQL databases with encryption at rest and in transit. See Supabase's Privacy Policy.
4. Cookies
We use only essential cookies required for the service to function. We do not use any advertising, tracking, or analytics cookies.
Because these cookies are strictly necessary for the service to operate, they do not require consent under GDPR/ePrivacy Directive. No cookie banner is displayed.
5. Data Retention
- Assessment data and reports are retained for as long as your account is active. When you delete your account, all assessment data is permanently deleted within 30 days.
- Account information is retained for as long as your account exists, plus any period required by applicable tax and accounting laws (typically 6 years in the UK).
- Payment records are retained for 6 years in accordance with UK tax regulations.
- Technical logs are automatically deleted after 90 days.
6. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:
Right of Access
You can request a copy of the personal data we hold about you.
Right to Rectification
You can ask us to correct inaccurate or incomplete personal data.
Right to Erasure
You can request that we delete your personal data ("right to be forgotten").
Right to Data Portability
You can request your data in a structured, commonly used, machine-readable format (JSON or CSV).
Right to Object
You can object to the processing of your personal data in certain circumstances.
Right to Restrict Processing
You can request that we limit the processing of your personal data.
To exercise any of these rights, please contact us at compliance@euaiactcompliancechecker.com. We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (in the UK, this is the Information Commissioner's Office — ICO).
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Row-level security policies on all database tables
- Regular security audits and vulnerability assessments
- Principle of least privilege for all system access
- Secure authentication via Supabase Auth with PKCE
8. International Data Transfers
Some of our third-party processors (Stripe, OpenAI) may process data outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms under UK data protection law.
9. Children's Privacy
Our service is designed for business professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or by posting a prominent notice on our website. The "Last updated" date at the top of this page indicates when the policy was last revised.
11. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Controller: Cyril Coste, EU AI Act Compliance Checker
Email: compliance@euaiactcompliancechecker.com
Website: euaiactcompliancechecker.com