ComplyPages

Privacy Policy

Última actualización: 5 July 2026

1. Who we are

ComplyPages is operated by Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.

Privacy contact: privacy@complypages.com General contact: hello@complypages.com

For the purposes of this Privacy Policy, “ComplyPages”, “we”, “us”, and “our” refer to Bobook Limited and the ComplyPages service.

2. What this policy covers

This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:

  • Visit complypages.com;
  • Request a free EAA accessibility snapshot;
  • Contact us;
  • Use or purchase ComplyPages services;
  • Receive communications from us;
  • Interact with our website, forms, reports, or related services.

ComplyPages provides practical accessibility QA and EAA-readiness support for public website transaction flows. Our services may include public-page checks, snapshots, developer-ready fix packs, retesting, and monitoring.

This policy does not cover websites, platforms, or services operated by third parties.

3. Personal data we collect

We collect only the data reasonably needed to operate, secure, improve, and provide ComplyPages services.

3.1 Data you provide to us

You may provide:

  • Name;
  • Business email address;
  • Company name;
  • Website URL;
  • Country or market;
  • Job title or role;
  • Message or project details;
  • Billing details, where applicable;
  • Support or correspondence content;
  • Information submitted through website forms.

3.2 Scan-request and report data

When you request a snapshot, scan, fix pack, retest, or monitoring service, we may process:

  • Website URL and public page URLs;
  • Website segment, such as e-commerce, hotel booking, ticketing, online courses, or forms;
  • Public page content needed to perform the review;
  • Screenshots or visual references of public pages;
  • Accessibility observations and issue descriptions;
  • DOM element descriptions, selectors, or technical references where available;
  • Reproduction steps;
  • Browser, viewport, timing, and technical metadata;
  • Scan status, scan logs, and report history.

3.3 Incidental public-page data

We do not intentionally collect personal data from scanned websites. However, because scans may include screenshots or public page content, publicly visible names, contact details, profile information, or other information may be incidentally captured if it appears on a reviewed public page.

We use incidentally captured information only to generate accessibility observations, quality checks, evidence, reports, retests, and related service records. We do not use incidentally captured public-page information for profiling, resale, advertising, or unrelated purposes.

3.4 Technical and usage data

When you visit our website or use our services, we may process:

  • IP address (transiently, for security and approximate country detection only — not stored long-term for analytics);
  • Browser type and version (aggregated as browser family for internal analytics);
  • Device type;
  • Operating system;
  • Referring page domain (not full URL with query strings for internal analytics);
  • Pages viewed;
  • Date and time of access (rounded to hour or day for internal analytics);
  • Approximate location derived from IP address (country code only for internal analytics);
  • Cookie and consent preferences;
  • Security logs;
  • Error logs and performance logs.

3.5 Payment and billing data

If paid services are purchased, payment processing may be handled by third-party payment or invoicing providers. We may receive limited billing information, such as invoice status, customer details, billing address, VAT number, transaction reference, and payment confirmation. We do not intentionally store full payment card details on our own servers.

3.6 Support widget and contact messages

If you contact us through the support widget or contact form, we may collect your name, business email address, website URL, message content, timestamp, and related technical metadata needed to deliver and secure the message.

We use this information to respond to your request, provide support, prevent abuse, route the message internally, and improve our service. We do not use support messages for unrelated advertising or sell contact data.

3.7 AI-assisted support

We may use AI-assisted tools to help classify, summarize, or draft responses to support messages and scan requests. Human review may be used where appropriate, especially for complex, legal, pricing, or service-specific questions.

Do not include passwords, payment details, customer data, or sensitive personal information in support messages.

3.8 Internal analytics

We use privacy-friendly internal analytics to understand website performance and improve the service. We do not use Google Analytics, advertising pixels, cross-site tracking, session replay, or analytics cookies.

We may collect aggregated information such as page path, event type, approximate country, referrer domain, device type, browser family, and timestamp rounded to hour or day. We do not store full IP addresses, persistent visitor identifiers, or fingerprinting data for analytics purposes.

4. Why we process personal data

We process personal data for the following purposes:

PurposeExamples
Provide requested servicesFree snapshots, reports, fix packs, retests, monitoring
Respond to enquiriesContact forms, support emails, project discussions
Prepare and deliver reportsAccessibility observations, screenshots, issue documentation
Improve servicesDebugging, quality review, product improvement
Security and abuse preventionFraud prevention, rate limiting, system logs
Business administrationBilling, accounting, customer records
Legal and complianceRecord keeping, legal obligations, dispute handling
Marketing communicationsRelevant business updates where permitted
Analytics and website improvementUnderstanding website performance and visitor behaviour where permitted

5. GDPR legal bases

Where the GDPR applies, we rely on one or more of the following legal bases:

Processing activityLegal basis
Responding to your enquiryLegitimate interests or pre-contractual steps
Providing a requested snapshot or paid serviceContract or pre-contractual steps
Creating scan reports and service recordsContract, pre-contractual steps, or legitimate interests
Retesting and monitoring selected flowsContract or legitimate interests
Service security and fraud preventionLegitimate interests
Billing, tax, and accountingLegal obligation and contract
Optional marketing emailsConsent, or legitimate interests where permitted for B2B communications
Non-essential cookies and analyticsConsent where required
Compliance with legal requestsLegal obligation

Our legitimate interests include operating and improving ComplyPages, communicating with business users, securing our systems, preventing abuse, documenting requested services, and providing practical accessibility QA for public website flows. We balance these interests against the rights and freedoms of affected individuals.

6. Cookies and similar technologies

We may use cookies and similar technologies to operate the website, remember preferences, measure performance, and improve the service.

Essential cookies may be used without consent where necessary to provide the website or requested service. Analytics, marketing, or other non-essential cookies will be used only where permitted by applicable law and, where required, after consent.

For more information, see our Cookie Policy at /legal/cookie-policy.

7. Marketing communications

We may send business communications about ComplyPages where permitted by law. You can opt out of marketing communications at any time by using the unsubscribe link in the email, replying to the message, or contacting privacy@complypages.com.

We will continue to send necessary service, transactional, security, or administrative messages where required.

8. How we share personal data

We do not sell personal data.

We may share personal data with:

  • Hosting and infrastructure providers;
  • Email and communication providers;
  • Analytics providers, where used and permitted;
  • Payment, accounting, and invoicing providers;
  • Contractors or service providers who support ComplyPages;
  • Professional advisers, such as accountants, lawyers, or auditors;
  • Authorities, courts, regulators, or law enforcement where legally required;
  • A successor entity in connection with a merger, acquisition, restructuring, or asset transfer.

Where service providers process personal data on our behalf, we use appropriate contractual safeguards.

9. Subprocessors and service providers

ComplyPages may use third-party service providers to host, operate, secure, analyse, and deliver the service. These providers may process personal data only as needed to provide their services to us.

Suggested table:

ProviderPurposeLocation
[Hosting provider]Website and application hosting[Region]
[Email provider]Email delivery and communication[Region]
OpenAIAI-assisted support classification and response draftingUnited States
Slack (if configured)Internal support routing and team notificationsUnited States
[Payment provider, if any]Payment processing[Region]
[Error monitoring provider, if any]Security, logging, debugging[Region]

We may use hosting, email, support, internal communication, AI-assistance, and infrastructure providers to operate ComplyPages. Where these providers process personal data on our behalf, they act as processors or subprocessors subject to appropriate contractual safeguards.

10. International transfers

Personal data may be processed in countries outside the European Economic Area, depending on the providers we use.

Where personal data is transferred internationally, we use appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, or equivalent measures.

11. Data retention

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required by law.

Suggested retention periods:

Data typeTypical retention
Contact form enquiriesUp to 24 months after last interaction
Free snapshot request dataUp to 24 months after delivery or last interaction
Scan reports and screenshotsUp to 24 months, unless a longer period is agreed for monitoring or retest records
Paid customer recordsDuration of service plus up to 7 years where needed for accounting, tax, or legal records
Billing and invoice dataUp to 7 years or as required by applicable law
Security logsUsually up to 12 months, unless needed for investigation
Marketing preferencesUntil opt-out, plus suppression records as needed to honour the opt-out

We may retain limited records where necessary to resolve disputes, enforce agreements, prevent abuse, comply with law, or maintain audit trails.

12. Security

We use reasonable technical and organisational measures to protect personal data, including access controls, secure hosting practices, limited access to service records, and appropriate provider safeguards.

No website or online service can be guaranteed to be completely secure. If you believe information you provided to us has been compromised, contact privacy@complypages.com.

13. Your GDPR rights

Depending on your location and the circumstances, you may have the right to:

  • Access personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of your personal data;
  • Request restriction of processing;
  • Object to processing based on legitimate interests;
  • Request data portability;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with a data protection authority.

To exercise your rights, contact privacy@complypages.com.

We may need to verify your identity before responding. Some rights are subject to legal exceptions, such as record-keeping, legal claims, security, or contractual obligations.

14. Complaints

If you are based in the EU or believe GDPR applies to our processing, you may lodge a complaint with your local data protection authority.

As ComplyPages is operated by Bobook Limited in Ireland, you may also contact the Irish Data Protection Commission:

Website: https://www.dataprotection.ie/

15. Children

ComplyPages is intended for business use and is not directed to children. We do not knowingly collect personal data from children.

16. Third-party links

Our website may link to third-party websites. We are not responsible for the privacy practices, accessibility, content, or security of third-party websites.

17. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new “Last updated” date.

Material changes may be communicated by email or website notice where appropriate.

18. Contact

Privacy contact: privacy@complypages.com General contact: hello@complypages.com

Operator: Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.

Privacy Policy | ComplyPages