ComplianceRadar (“Platform”, “we”, “us”) is an AI-powered regulatory tracking tool for financial compliance professionals, operated by WearableDevDesign (Switzerland). This policy explains what personal data we collect, why, and your rights regarding that data.
This policy is compliant with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG).
| Data | Description | Purpose |
|---|---|---|
| Identity Data | Email address, collected via Google OAuth or Magic Link | Authentication and account management |
| Account Data | Subscription tier (Silver/Gold), internal user identifiers | Access control and quota enforcement |
| Usage Data | Count of AI summaries generated per day | Resource management and cost control |
| Personalization | Pinned regulations and saved search configurations (“Missions”) | Personalisation of your experience |
| Security Logs | IP address of requests, timestamps of access attempts | Detection and blocking of unauthorized access |
We do not collect payment information, sensitive personal data, or any data beyond what is listed above.
| Data Type | Legal Basis |
|---|---|
| Identity and Account | Performance of contract (Art. 6(1)(b)) — necessary to provide the service |
| Usage and Personalization | Legitimate interest (Art. 6(1)(f)) — to operate and improve the Platform |
| Security Logs | Legitimate interest (Art. 6(1)(f)) — to protect the Platform from unauthorized access |
ComplianceRadar uses Google Gemini to generate regulatory summaries and translations.
| Provider | Role | Data Location |
|---|---|---|
| Supabase | Database and authentication | AWS us-east-1 (United States) |
| Vercel | Hosting and edge delivery | Global CDN (United States) |
| Google Cloud | OAuth and Gemini AI | United States |
International Data Transfers:Supabase, Vercel, and Google Cloud are US-based providers. Transfers of personal data to the United States are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission, providing appropriate safeguards under GDPR Art. 46.
| Data Category | Retention Period |
|---|---|
| User profile, pins, and missions | Retained for the duration of your active account |
| Security logs (IP addresses) | Retained for 90 days, then deleted |
| Regulatory content | Rolling 365-day history |
Upon account deletion, all personal data associated with your account is permanently removed within 30 days.
Under GDPR and Swiss nDSG, you have the following rights:
To exercise any of these rights, contact us at the address in Section 11. We will respond within 30 days.
Swiss Users:
Lodge complaints with the FDPIC: www.edoeb.admin.ch
EU Users:
Lodge complaints with your local supervisory authority.
All API access is strictly session-validated. Unauthenticated requests are blocked at the application layer. IP addresses of unauthorized access attempts are logged for security purposes as described in Section 2.
ComplianceRadar is currently in public beta. Core functionality is operational. Features and data coverage may change without notice. This privacy policy applies in full regardless of beta status.
We may update this policy as the Platform evolves. We will notify registered users by email of any material changes. The “Last updated” date at the top of this document reflects the most recent revision.