Return to Dashboard

Privacy Policy

ComplianceRadar Intelligence

Last updated: September 2026

1. Introduction

ComplianceRadar (“Platform”, “we”, “us”) is an AI-powered regulatory tracking tool for financial compliance professionals, operated by WearableDevDesign (Switzerland). This policy explains what personal data we collect, why, and your rights regarding that data.

This policy is compliant with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG).

2. Data We Collect

DataDescriptionPurpose
Identity DataEmail address, collected via Google OAuth or Magic LinkAuthentication and account management
Account DataSubscription tier (Silver/Gold), internal user identifiersAccess control and quota enforcement
Usage DataCount of AI summaries generated per dayResource management and cost control
PersonalizationPinned regulations and saved search configurations (“Missions”)Personalisation of your experience
Security LogsIP address of requests, timestamps of access attemptsDetection and blocking of unauthorized access

We do not collect payment information, sensitive personal data, or any data beyond what is listed above.

3. Legal Basis for Processing (GDPR Art. 6)

Data TypeLegal Basis
Identity and AccountPerformance of contract (Art. 6(1)(b)) — necessary to provide the service
Usage and PersonalizationLegitimate interest (Art. 6(1)(f)) — to operate and improve the Platform
Security LogsLegitimate interest (Art. 6(1)(f)) — to protect the Platform from unauthorized access

4. AI Processing and Data Privacy

ComplianceRadar uses Google Gemini to generate regulatory summaries and translations.

  • We send to AI models: only public regulatory text sourced from official government sources (FINMA, ESMA, FCA, EUR-Lex, etc.)
  • We never send to AI models: your email address, identity, account data, pins, missions, or any personal information.

5. Third-Party Service Providers

ProviderRoleData Location
SupabaseDatabase and authenticationAWS us-east-1 (United States)
VercelHosting and edge deliveryGlobal CDN (United States)
Google CloudOAuth and Gemini AIUnited States

International Data Transfers:Supabase, Vercel, and Google Cloud are US-based providers. Transfers of personal data to the United States are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission, providing appropriate safeguards under GDPR Art. 46.

6. Data Retention

Data CategoryRetention Period
User profile, pins, and missionsRetained for the duration of your active account
Security logs (IP addresses)Retained for 90 days, then deleted
Regulatory contentRolling 365-day history

Upon account deletion, all personal data associated with your account is permanently removed within 30 days.

7. Your Rights

Under GDPR and Swiss nDSG, you have the following rights:

AccessRequest a copy of your personal data
RectificationCorrect inaccurate data
ErasureDelete your account and data
PortabilityExport pins/missions in portable format
ObjectObject based on legitimate interest
RestrictionRestrict processing in certain cases

To exercise any of these rights, contact us at the address in Section 11. We will respond within 30 days.

Swiss Users:

Lodge complaints with the FDPIC: www.edoeb.admin.ch

EU Users:

Lodge complaints with your local supervisory authority.

8. Security

All API access is strictly session-validated. Unauthenticated requests are blocked at the application layer. IP addresses of unauthorized access attempts are logged for security purposes as described in Section 2.

9. Beta Status

ComplianceRadar is currently in public beta. Core functionality is operational. Features and data coverage may change without notice. This privacy policy applies in full regardless of beta status.

10. Changes to This Policy

We may update this policy as the Platform evolves. We will notify registered users by email of any material changes. The “Last updated” date at the top of this document reflects the most recent revision.

11. Contact

DeveloperWearableDevDesign
JurisdictionSwitzerland