ComplyAI Get Started

Effective date: 16 February 2026 · Last updated: 16 February 2026

This Privacy Policy explains how SIRIUS GRUPA d.o.o. za ugostiteljstvo i usluge ("we", "us", "our") processes personal data when you use ComplyAI, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Croatian law.

1. Data Controller

SIRIUS GRUPA d.o.o. za ugostiteljstvo i usluge

OIB: 89545465964

MB: 05155410

MBS: 090032970

Registered seat: Ulica Kralja Zvonimira 4, Metković, Croatia

Commercial Court: Trgovački sud u Dubrovniku

Share capital: 2.500,00 EUR (paid in full)

Responsible person: Mato Glavinić, direktor

Email: info@siriusgrupa.com

Web: https://siriusgrupa.com

2. Personal Data We Collect

2.1 Registration and account data

  • Email address
  • Password (stored in encrypted/hashed form; never plain text)

2.2 Company profile data

  • Company name
  • Industry
  • Company size
  • AI usage status

2.3 Compliance service data

  • Selected compliance modules
  • Checklist completion/status data
  • AI chat messages and prompts

2.4 Automatically collected technical data

  • IP address (for rate limiting and abuse prevention)
  • User agent/device-browser metadata
  • Session/authentication tokens

2.5 Data we do not collect

  • Credit card/payment card details (processed by Stripe)
  • Health data
  • Biometric data
  • Location data

3. Purposes and Legal Bases (GDPR Art. 6)

Purpose Legal basis Data categories
Registration and account managementContract (Art. 6(1)(b))Email, password credentials
Provision of compliance serviceContract (Art. 6(1)(b))Company profile, modules, checklist data
AI chat analysis and responsesContract (Art. 6(1)(b))AI chat messages, context data
Abuse prevention and platform securityLegitimate interest (Art. 6(1)(f))IP address, user agent, session logs
Legal and tax obligationsLegal obligation (Art. 6(1)(c))Accounting/payment records

4. Processors (Sub-processors)

Processor Location Purpose Safeguards
SupabaseFrankfurt, EUAuthentication + databaseSupabase DPA, SOC 2
Google Gemini APIEU/USAI chat processingGoogle Cloud DPA, SCCs
VercelGlobal CDNHostingVercel DPA
Stripe (future billing)EU/USPayment processingStripe DPA, PCI DSS

We do not sell or rent personal data.

5. International Transfers (outside EU/EEA)

Where data is transferred outside the EU/EEA (e.g., to US-based infrastructure), we apply appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules (BCRs), where applicable
  • Recognized security/compliance certifications and contractual controls

6. Retention Periods

Data category Retention period
User accountUntil account closure + 30 days
Compliance dataUntil account deletion
AI chat historyUntil account deletion
Financial/accounting records7 years
Rate limiting/security logs24 hours

7. Your GDPR Rights

You have the right to request:

  • Access to your personal data
  • Rectification of inaccurate/incomplete data
  • Erasure ("right to be forgotten")
  • Restriction of processing
  • Data portability (machine-readable format)
  • Objection to processing based on legitimate interest
  • Withdrawal of consent (where processing is based on consent)

To exercise your rights, contact: info@siriusgrupa.com. We respond within legal deadlines.

8. Right to Lodge a Complaint (AZOP)

Croatian Personal Data Protection Agency (AZOP)

Selska cesta 136, 10000 Zagreb

Tel: +385 1 4609 000

Email: azop@azop.hr

Web: https://azop.hr

9. Data Security

  • Encrypted transport (HTTPS/TLS)
  • Encrypted/hashed passwords
  • Supabase Row Level Security (RLS) controls
  • Access controls and logging for security monitoring

10. Cookies and Local Storage

ComplyAI uses only essential storage/cookies for authentication and session continuity (auth session token). We currently do not use advertising cookies.

11. Contact

SIRIUS GRUPA d.o.o. za ugostiteljstvo i usluge

OIB: 89545465964 · MB: 05155410 · MBS: 090032970

Address: Ulica Kralja Zvonimira 4, Metković, Croatia

Court: Trgovački sud u Dubrovniku

Share capital: 2.500,00 EUR (paid in full)

Responsible person: Mato Glavinić, direktor

Email: info@siriusgrupa.com

Web: https://siriusgrupa.com