🔒 Legal

Privacy Policy

How ComplianceWorxs collects, processes, and protects information across its case file products and decision authorization services.

✓ No Data Selling ✓ No AI Training on Customer Data ✓ International Transfer Safeguards ✓ User Rights

Effective Date: September 16, 2026

1. Information We Collect

ComplianceWorxs collects information necessary to deliver its case file products and decision authorization services.

Purchase and Account Information

When users purchase a case file or create an account we may collect:

  • name
  • email address
  • organization name
  • billing information processed by our payment provider
  • account credentials where applicable

Compliance-Related Information

Users may submit compliance-related descriptions through the platform, including:

  • descriptions of compliance decisions
  • inspection preparation information
  • deviation or investigation summaries
  • compliance documentation context

Users should avoid submitting confidential regulatory documentation unless authorized by their organization.

Usage Information

We collect operational information including access timestamps, platform feature usage, session activity, case file page interactions, scroll depth, and system interaction logs.

Technical Information

We collect limited technical data for security and performance purposes including IP address, browser type, device type, and operating system.

Business Visitor Information

When organizations visit the ComplianceWorxs website, we may collect business-level information through third-party identity-resolution services. This can include company name, industry, and general location.

We use this information to understand site traffic and identify organizations that may have an interest in our products. Personal information collected through this process is limited to publicly available professional information.

2. AI-Assisted Processing

Certain features of the ComplianceWorxs platform use artificial intelligence to analyze user inputs and generate documentation outputs.

AI-assisted processing may include:

  • compliance scenario analysis
  • inspection intelligence explanations
  • documentation generation
  • structured decision authorization outputs

User inputs may be processed by AI service providers solely for the purpose of delivering platform functionality.

AI Training Restriction — ComplianceWorxs does not permit customer data to be used to train public AI models. Customer-submitted compliance information is not used for model training.

3. How We Use Information

Information collected through the platform may be used to:

  • deliver purchased case file products and platform services
  • generate platform outputs and analysis
  • improve platform functionality and case file content
  • identify organizations visiting the site for business development purposes
  • monitor security and prevent misuse
  • respond to support requests

We do not sell customer data.

4. Compliance Data and Regulatory Documentation

ComplianceWorxs case files are designed to assist compliance professionals in understanding inspection expectations and identifying authorization gaps in compliance decisions.

Organizations remain responsible for determining what information may be uploaded to the system and ensuring compliance with internal data governance policies.

The platform is not intended to store regulated records requiring validated system controls unless validated by the customer organization.

5. Support for Regulated Environments

ComplianceWorxs is designed to support documentation practices aligned with electronic records principles described in FDA 21 CFR Part 11 and similar regulatory frameworks.

However, each organization remains responsible for determining whether the platform must be validated within its own regulatory environment.

ComplianceWorxs does not represent that the system is automatically validated for any specific organization's regulatory requirements.

6. Healthcare Data

ComplianceWorxs is not designed to store or process Protected Health Information (PHI).

Users should not submit PHI unless a separate Business Associate Agreement (BAA) has been executed.

7. Data Security

ComplianceWorxs implements commercially reasonable technical safeguards designed to protect user information.

Security measures may include:

  • encryption in transit using TLS
  • encryption of stored data where appropriate
  • controlled system access
  • infrastructure monitoring
  • security incident response procedures
  • row-level access controls on every table holding customer-submitted information

Security standards and certifications

ComplianceWorxs applies security and access controls designed for regulated life-sciences workflows. ComplianceWorxs is not currently ISO/IEC 27001 certified, and we do not represent or imply otherwise.

Certifications, audit reports, or compliance attestations held by third-party service providers apply to those providers. They do not constitute certification or compliance of ComplianceWorxs.

Encryption and the providers we transmit to

Information transmitted between your browser, ComplianceWorxs, and our service providers is encrypted in transit using TLS. This includes the providers named in Section 9, such as Google, Anthropic, and OpenAI.

Google, Anthropic, and OpenAI each publish their own security standards for encryption in transit and at rest. They process information to deliver the functions ComplianceWorxs requests.

ComplianceWorxs does not control those providers' internal systems. We also do not represent that a provider's practices meet a particular customer's validation requirements. Current processing terms are available from the provider and may also be requested from us.

Information ComplianceWorxs does not retain

Some information is never stored on ComplianceWorxs systems at all:

  • Payment card details. Card information is collected and held by Stripe. It never reaches ComplianceWorxs infrastructure.
  • CAPA Risk Audit decision content. The CAPA reference and any decision summary you enter remain in your browser. They are not transmitted to ComplianceWorxs, and no copy is created. Only your scores and the decision type you selected are recorded, as analytics.
  • Email message content. Our correspondence tracking operates on message metadata only — sender, recipient, subject line, and timestamp. The body of an email you send us is not ingested into our systems.
  • AI request and response logs beyond 180 days. The inputs and outputs of AI-assisted processing are automatically erased from our logs after 180 days by a scheduled process.

Information you submit to generate an Inspection Response Record is retained — see Section 8, which describes what is kept and for how long.

No system can guarantee absolute security.

8. Data Retention

ComplianceWorxs retains information only as long as necessary to provide the Services.

Retention practices include:

  • purchase and account data retained while accounts remain active
  • usage logs retained for security and system integrity
  • compliance descriptions retained for platform functionality
  • business visitor identification data retained for a reasonable period for business development purposes
  • AI request and response logs erased automatically after 180 days

Information submitted to generate an Inspection Response Record is retained so the record remains available to you. This can include the decision statement, evidence described, authorization reasoning, and the generated record itself.

IRR information is not subject to an automatic expiry period. Section 7 lists the categories of information ComplianceWorxs does not retain.

Users may request deletion of their data at any time by writing to privacy@complianceworxs.com. Deletion is carried out manually and confirmed to the requester.

ComplianceWorxs may retain anonymized platform analytics data for service improvement.

9. Third-Party Service Providers

ComplianceWorxs uses trusted third-party service providers to deliver its products and services.

Infrastructure and Data

Supabase Cloud database infrastructure and backend services
Vercel Hosting and deployment infrastructure

Payments

Stripe Payment processing. ComplianceWorxs does not store payment card data. All payment information is processed directly by Stripe.

Communications

Google (Gmail) Transactional and business email delivery, and reply metadata used to track correspondence with prospective and existing customers

Analytics and Tracking

PostHog Product analytics and behavioral event tracking
Vercel Analytics Site performance and traffic analytics
Google Analytics Website traffic and audience analytics

Business Identity Resolution

Prospeo Business contact and company enrichment. Prospeo may return professional contact and organizational information from publicly available and licensed business data sources.
PostHog Organization-level attribution of site activity, in addition to the product analytics described above

Customer Relationship Management

Attio Customer relationship management and contact tracking

Artificial Intelligence

Anthropic AI-assisted documentation generation and analysis
OpenAI AI-assisted content generation

Third-party providers process data to deliver platform functionality. Where required, they operate under contractual data-protection obligations. A full list of subprocessors may be provided upon request.

10. International Data Transfers

ComplianceWorxs may process data using infrastructure located in multiple jurisdictions.

When personal data is transferred internationally, we implement appropriate safeguards designed to protect that information in accordance with applicable law.

11. User Rights

Depending on jurisdiction, users may have rights regarding their personal data, including:

  • the right to access data
  • the right to request correction
  • the right to request deletion
  • the right to object to certain processing
  • the right to opt out of business identity resolution tracking

Requests may be submitted using the contact information below.

12. Cookies and Analytics

The ComplianceWorxs website uses cookies and similar technologies to improve site functionality, understand site usage patterns, and measure performance of platform features.

ComplianceWorxs uses business identity-resolution tools, including Prospeo and PostHog, in addition to standard analytics cookies. These tools may associate a site visit with the organization it originated from by using publicly available and licensed business data.

They do not access personal device data beyond what is standard for web analytics. They may, however, associate your visit with your employer or organization.

Users may manage cookie preferences through browser settings. To opt out of business identity resolution, contact us at privacy@complianceworxs.com.

13. Security Incidents

If a security incident affecting personal data is identified, ComplianceWorxs will respond in accordance with applicable legal requirements and internal incident response procedures.

14. Children's Privacy

The Services are intended for professional use by adults.

ComplianceWorxs does not knowingly collect information from individuals under 18 years of age.

15. Changes to This Policy

We may update this Privacy Policy periodically.

Updates will be posted on this page and reflected by an updated effective date.

Continued use of the Services after changes indicates acceptance of the updated policy.

16. Contact Information

Privacy inquiries and data subject requests may be directed to:

Questions About Your Data?

Contact us directly if you have questions about how we handle your data. You may also contact us for subprocessor or data-processing information, or to opt out of business identity resolution.

We respond to all privacy inquiries within 30 days, or sooner as required by applicable law.