Privacy Policy & Data Processing Addendum (DPA)

Last updated: September 10, 2026 • Assessment processing update

B2B Enterprise Data Governance Notice

EU AI Act Compliance Checker is operated by DIGITAL AND GROWTH LTD (Company No. 12741621). Assessment processing is an explicit choice: calculate locally in your browser or send and store in your cloud account. External model narration for compliance assessments is disabled pending provider and retention verification. We do not claim blanket zero data retention for our service or its providers.

Assessment processing choices and retention

Local mode calculates in your browser and sends no assessment answers to our APIs or model providers. Normal page delivery and infrastructure access logs remain separate. Answers remain in page memory unless you explicitly save a browser draft.

Browser drafts are optional. A draft expires after 24 hours and is removed when next accessed after expiry; it is not automatically erased while the browser is closed. Anyone with access to the browser profile may read it. Delete browser draft removes it immediately when storage is available.

Cloud mode requires sign-in and your explicit choice to send and retain system identity, answers, evidence references, report versions and audit identifiers in your organisation account. Authorised organisation members can read its reports. Hiding a report does not erase retained records, backups or logs. Usage and audit identifiers remain independently retained; hiding a report does not restore an allowance.

Exact primary-storage, object-storage, backup, access-log and provider retention periods and regions have not yet been verified for this release. We cannot promise an erasure deadline until those configurations and restoration procedures have been checked. Contact support for account-specific retention details or an erasure request. External AI narration remains disabled until the processing terms and transmitted fields can be disclosed.

1. Operating Entity & Regulatory Scope

This Privacy Policy applies to the website at EUAIActComplianceChecker.com and associated application services ("Service"), operated by:

DIGITAL AND GROWTH LTD

Company Registration No.: 12741621 (Registered in England and Wales)

Registered Office: 33 Boston Road South, Holbeach, Spalding, Lincolnshire, PE12 7LR, United Kingdom

Contact Email: support@euaiactcompliancechecker.com

We process personal data in compliance with the **UK GDPR**, the **EU GDPR** (Regulation (EU) 2016/679), the **California Consumer Privacy Act** as amended by CPRA (**CCPA/CPRA**), and the **ePrivacy Directive** (2002/58/EC).

2. Target Audience (Strictly B2B)

The Service is designed and operated exclusively for **Business-to-Business (B2B)** commercial organizations, enterprise compliance teams, and legal professionals aged **18 years or older**. We do not knowingly collect or process data from individual consumers (B2C) or minors.

3. Categories of Data We Collect

3.1 Account & Representative Data

Full name, business email address, company name, company size, job title, industry sector, and country of operation.

3.2 Compliance Assessment Data

Descriptions of client AI systems, designated system purposes, department ownership, responses to compliance questionnaires, risk scores, and generated readiness reports.

3.3 Financial & Payment Transaction Data

Billing email, billing address, selected plan (Monthly $97, Annual $997, or Strategy Review $1,497), tokenized payment card references, and transaction receipts. Credit card details are processed directly by **Stripe, Inc.** (PCI-DSS Level 1 certified) and are never stored on our servers.

3.4 Technical & Security Telemetry

Access metadata and diagnostic errors where enabled. We do not intentionally log assessment answers; replay is disabled and assessment-page errors are excluded from browser error reporting.

4. Legal Bases for Processing (UK/EU GDPR)

  • Contractual Necessity (Art. 6(1)(b)): Account management, compliance report generation, billing, and transactional service emails.
  • Legitimate Interests (Art. 6(1)(f)): Platform security, threat detection, and diagnostic error monitoring.
  • Legal Obligation (Art. 6(1)(c)): Accounting, tax, and VAT statutory reporting.

5. Third-Party Sub-Processors Directory

The service uses the providers below. Deployment regions, retention settings and contractual coverage require verification before any specific assurance is made:

Supabase, Inc. — Database & Auth

Provides account authentication and PostgreSQL storage. The deployed region, backup expiry and applicable transfer safeguards must be confirmed for your account.

Stripe, Inc. — Payment Gateway

Processes subscription billing, invoicing, and PCI-DSS Level 1 payment security.

OpenAI — Optional model processing (disabled for compliance assessments)

Compliance assessment narration is disabled pending verification of the actual provider project, data minimisation, contractual coverage and retention configuration. Deterministic assessment results do not require model processing.

Resend, Inc. — Transactional Email

Delivers account verifications, report notifications, and task reminders.

Functional Software, Inc. (Sentry) — Error Monitoring

Collects diagnostic stack traces and application telemetry for platform stability.

6. Data Processing Addendum (DPA) Summary for B2B Clients

Under Article 28 of the UK/EU GDPR, DIGITAL AND GROWTH LTD acts as a Data Processor for compliance assessment data submitted by clients. We warrant that:

  • Data is processed strictly in accordance with client instructions.
  • Personnel are bound by statutory confidentiality.
  • Technical measures include TLS 1.3 encryption in transit, AES-256 encryption at rest, Row-Level Security (RLS), and nonce-based CSP headers.
  • We notify client administrators of verified personal data breaches without undue delay (within 72 hours).
  • Contact support to request erasure. The report control hides records; primary storage, object storage, backups, legal holds and audit retention require separate handling. No specific erasure deadline is asserted until these lifecycle settings have been verified.

7. Cookie & Web Storage Policy

We use strictly essential cookies required for application security and authentication. We do not use third-party tracking, advertising, or cross-site behavioral cookies.

Cookie NamePurpose & Expirationsb-*-auth-tokenSupabase session authentication token (Essential, up to 30 days).sb-*-auth-token-code-verifierPKCE authentication verification code (Essential, Session).staging-accessPre-production IP security bypass cookie (Essential, 30 days).

8. California Privacy Rights (CCPA/CPRA)

DIGITAL AND GROWTH LTD does not sell personal information and does not share personal information for cross-context behavioral advertising. California business representatives retain rights to request access, deletion, and correction of their personal data.

9. Data Subject Rights & DSAR Fulfillment

Authorized business representatives may exercise statutory rights (Access, Rectification, Erasure, Restriction, Data Portability) by submitting a Data Subject Access Request (DSAR):

Email: support@euaiactcompliancechecker.com

Subject Line: Data Subject Request - [Company Name]

Requests must originate from the registered account email address. Requests are fulfilled within 30 calendar days following identity verification.