Privacy Policy
Last updated: 5 July 2026
1. Who we are
ComplyPages is operated by Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.
Privacy contact: privacy@complypages.com General contact: hello@complypages.com
For the purposes of this Privacy Policy, “ComplyPages”, “we”, “us”, and “our” refer to Bobook Limited and the ComplyPages service.
2. What this policy covers
This Privacy Policy explains how we collect, use, store, share, and protect personal data when you:
- Visit complypages.com;
- Request a free EAA accessibility snapshot;
- Contact us;
- Use or purchase ComplyPages services;
- Receive communications from us;
- Interact with our website, forms, reports, or related services.
ComplyPages provides practical accessibility QA and EAA-readiness support for public website transaction flows. Our services may include public-page checks, snapshots, developer-ready fix packs, retesting, and monitoring.
This policy does not cover websites, platforms, or services operated by third parties.
3. Personal data we collect
We collect only the data reasonably needed to operate, secure, improve, and provide ComplyPages services.
3.1 Data you provide to us
You may provide:
- Name;
- Business email address;
- Company name;
- Website URL;
- Country or market;
- Job title or role;
- Message or project details;
- Billing details, where applicable;
- Support or correspondence content;
- Information submitted through website forms.
3.2 Scan-request and report data
When you request a snapshot, scan, fix pack, retest, or monitoring service, we may process:
- Website URL and public page URLs;
- Website segment, such as e-commerce, hotel booking, ticketing, online courses, or forms;
- Public page content needed to perform the review;
- Screenshots or visual references of public pages;
- Accessibility observations and issue descriptions;
- DOM element descriptions, selectors, or technical references where available;
- Reproduction steps;
- Browser, viewport, timing, and technical metadata;
- Scan status, scan logs, and report history.
3.3 Incidental public-page data
We do not intentionally collect personal data from scanned websites. However, because scans may include screenshots or public page content, publicly visible names, contact details, profile information, or other information may be incidentally captured if it appears on a reviewed public page.
We use incidentally captured information only to generate accessibility observations, quality checks, evidence, reports, retests, and related service records. We do not use incidentally captured public-page information for profiling, resale, advertising, or unrelated purposes.
3.4 Technical and usage data
When you visit our website or use our services, we may process:
- IP address (transiently, for security and approximate country detection only — not stored long-term for analytics);
- Browser type and version (aggregated as browser family for internal analytics);
- Device type;
- Operating system;
- Referring page domain (not full URL with query strings for internal analytics);
- Pages viewed;
- Date and time of access (rounded to hour or day for internal analytics);
- Approximate location derived from IP address (country code only for internal analytics);
- Cookie and consent preferences;
- Security logs;
- Error logs and performance logs.
3.5 Payment and billing data
If paid services are purchased, payment processing may be handled by third-party payment or invoicing providers. We may receive limited billing information, such as invoice status, customer details, billing address, VAT number, transaction reference, and payment confirmation. We do not intentionally store full payment card details on our own servers.
3.6 Support widget and contact messages
If you contact us through the support widget or contact form, we may collect your name, business email address, website URL, message content, timestamp, and related technical metadata needed to deliver and secure the message.
We use this information to respond to your request, provide support, prevent abuse, route the message internally, and improve our service. We do not use support messages for unrelated advertising or sell contact data.
3.7 AI-assisted support
We may use AI-assisted tools to help classify, summarize, or draft responses to support messages and scan requests. Human review may be used where appropriate, especially for complex, legal, pricing, or service-specific questions.
Do not include passwords, payment details, customer data, or sensitive personal information in support messages.
3.8 Internal analytics
We use privacy-friendly internal analytics to understand website performance and improve the service. We do not use Google Analytics, advertising pixels, cross-site tracking, session replay, or analytics cookies.
We may collect aggregated information such as page path, event type, approximate country, referrer domain, device type, browser family, and timestamp rounded to hour or day. We do not store full IP addresses, persistent visitor identifiers, or fingerprinting data for analytics purposes.
4. Why we process personal data
We process personal data for the following purposes:
| Purpose | Examples |
|---|---|
| Provide requested services | Free snapshots, reports, fix packs, retests, monitoring |
| Respond to enquiries | Contact forms, support emails, project discussions |
| Prepare and deliver reports | Accessibility observations, screenshots, issue documentation |
| Improve services | Debugging, quality review, product improvement |
| Security and abuse prevention | Fraud prevention, rate limiting, system logs |
| Business administration | Billing, accounting, customer records |
| Legal and compliance | Record keeping, legal obligations, dispute handling |
| Marketing communications | Relevant business updates where permitted |
| Analytics and website improvement | Understanding website performance and visitor behaviour where permitted |
5. GDPR legal bases
Where the GDPR applies, we rely on one or more of the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Responding to your enquiry | Legitimate interests or pre-contractual steps |
| Providing a requested snapshot or paid service | Contract or pre-contractual steps |
| Creating scan reports and service records | Contract, pre-contractual steps, or legitimate interests |
| Retesting and monitoring selected flows | Contract or legitimate interests |
| Service security and fraud prevention | Legitimate interests |
| Billing, tax, and accounting | Legal obligation and contract |
| Optional marketing emails | Consent, or legitimate interests where permitted for B2B communications |
| Non-essential cookies and analytics | Consent where required |
| Compliance with legal requests | Legal obligation |
Our legitimate interests include operating and improving ComplyPages, communicating with business users, securing our systems, preventing abuse, documenting requested services, and providing practical accessibility QA for public website flows. We balance these interests against the rights and freedoms of affected individuals.
6. Cookies and similar technologies
We may use cookies and similar technologies to operate the website, remember preferences, measure performance, and improve the service.
Essential cookies may be used without consent where necessary to provide the website or requested service. Analytics, marketing, or other non-essential cookies will be used only where permitted by applicable law and, where required, after consent.
For more information, see our Cookie Policy at /legal/cookie-policy.
7. Marketing communications
We may send business communications about ComplyPages where permitted by law. You can opt out of marketing communications at any time by using the unsubscribe link in the email, replying to the message, or contacting privacy@complypages.com.
We will continue to send necessary service, transactional, security, or administrative messages where required.
8. How we share personal data
We do not sell personal data.
We may share personal data with:
- Hosting and infrastructure providers;
- Email and communication providers;
- Analytics providers, where used and permitted;
- Payment, accounting, and invoicing providers;
- Contractors or service providers who support ComplyPages;
- Professional advisers, such as accountants, lawyers, or auditors;
- Authorities, courts, regulators, or law enforcement where legally required;
- A successor entity in connection with a merger, acquisition, restructuring, or asset transfer.
Where service providers process personal data on our behalf, we use appropriate contractual safeguards.
9. Subprocessors and service providers
ComplyPages may use third-party service providers to host, operate, secure, analyse, and deliver the service. These providers may process personal data only as needed to provide their services to us.
Suggested table:
| Provider | Purpose | Location |
|---|---|---|
| [Hosting provider] | Website and application hosting | [Region] |
| [Email provider] | Email delivery and communication | [Region] |
| OpenAI | AI-assisted support classification and response drafting | United States |
| Slack (if configured) | Internal support routing and team notifications | United States |
| [Payment provider, if any] | Payment processing | [Region] |
| [Error monitoring provider, if any] | Security, logging, debugging | [Region] |
We may use hosting, email, support, internal communication, AI-assistance, and infrastructure providers to operate ComplyPages. Where these providers process personal data on our behalf, they act as processors or subprocessors subject to appropriate contractual safeguards.
10. International transfers
Personal data may be processed in countries outside the European Economic Area, depending on the providers we use.
Where personal data is transferred internationally, we use appropriate safeguards where required, such as adequacy decisions, Standard Contractual Clauses, or equivalent measures.
11. Data retention
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required by law.
Suggested retention periods:
| Data type | Typical retention |
|---|---|
| Contact form enquiries | Up to 24 months after last interaction |
| Free snapshot request data | Up to 24 months after delivery or last interaction |
| Scan reports and screenshots | Up to 24 months, unless a longer period is agreed for monitoring or retest records |
| Paid customer records | Duration of service plus up to 7 years where needed for accounting, tax, or legal records |
| Billing and invoice data | Up to 7 years or as required by applicable law |
| Security logs | Usually up to 12 months, unless needed for investigation |
| Marketing preferences | Until opt-out, plus suppression records as needed to honour the opt-out |
We may retain limited records where necessary to resolve disputes, enforce agreements, prevent abuse, comply with law, or maintain audit trails.
12. Security
We use reasonable technical and organisational measures to protect personal data, including access controls, secure hosting practices, limited access to service records, and appropriate provider safeguards.
No website or online service can be guaranteed to be completely secure. If you believe information you provided to us has been compromised, contact privacy@complypages.com.
13. Your GDPR rights
Depending on your location and the circumstances, you may have the right to:
- Access personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request deletion of your personal data;
- Request restriction of processing;
- Object to processing based on legitimate interests;
- Request data portability;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with a data protection authority.
To exercise your rights, contact privacy@complypages.com.
We may need to verify your identity before responding. Some rights are subject to legal exceptions, such as record-keeping, legal claims, security, or contractual obligations.
14. Complaints
If you are based in the EU or believe GDPR applies to our processing, you may lodge a complaint with your local data protection authority.
As ComplyPages is operated by Bobook Limited in Ireland, you may also contact the Irish Data Protection Commission:
Website: https://www.dataprotection.ie/
15. Children
ComplyPages is intended for business use and is not directed to children. We do not knowingly collect personal data from children.
16. Third-party links
Our website may link to third-party websites. We are not responsible for the privacy practices, accessibility, content, or security of third-party websites.
17. Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new “Last updated” date.
Material changes may be communicated by email or website notice where appropriate.
18. Contact
Privacy contact: privacy@complypages.com General contact: hello@complypages.com
Operator: Bobook Limited, Venture Hub, 136 Capel Street, Dublin 1, D01 T2C9, Ireland.