RunCompliance

Legal

Privacy Notice

Version 1.1 · Last updated 3 June 2026

Note. This notice applies to our website during early access and may be revised as the product develops. It is not legal advice.

1. Who we are

This notice describes how RunCompliance ("RunCompliance", "we", "us") handles personal data collected through this website, runcompliance.com. For questions about this notice or your data, contact us at [email protected].

2. The data boundary — your documents stay with you

RunCompliance is built local-first. The public regulatory corpus (laws, standards and frameworks) is the only content hosted in the cloud. Your compliance documents, client data and analysis results are processed on infrastructure you control and are never transmitted to or stored on our servers. This website (runcompliance.com) is a static marketing site and has no access to any customer workspace or document.

3. What we collect on this website

  • Details you submit through the contact form — the email address (and any message) you provide when you request early access through the form on this site.
  • Details you send us by email — when you write to us directly (for example at [email protected], [email protected] or [email protected]), we receive your email address and the content of your enquiry.
  • Basic technical data from your visit — standard server and network information (such as IP address, browser type and request metadata) that our hosting and content-delivery providers process automatically to serve and secure the site.

We do not ask for, and you should not submit, any confidential or client compliance information through this website.

4. Why we use it (purposes & legal basis)

  • To handle your visit — delivering the website's pages reliably and keeping it available — based on our legitimate interest in operating the site.
  • To respond to your contact-form requests and email enquiries — replying to early-access requests and questions you send us — based on your consent and our legitimate interest in responding to people who contact us.
  • To secure the website — see section 7 — based on our legitimate interest in protecting the site, its visitors and our infrastructure.

5. Sharing & processors

We do not sell your personal data. We rely on a small number of trusted providers that process data on our behalf, under appropriate data-processing agreements:

  • Content delivery & security (Cloudflare) — delivers and protects the site at the network edge.
  • Web hosting (LH.pl) — serves the website's files.
  • Form handling (Formspree) — receives and forwards messages sent through the contact form.

Some of these providers may process data outside the European Economic Area (for example, Formspree in the United States). Where that happens, the transfer is covered by appropriate safeguards such as the EU Standard Contractual Clauses or an equivalent mechanism. We disclose data to others only where required by law.

6. Cookies

This site uses only strictly necessary cookies — for example, cookies our content-delivery provider sets to keep the site secure and available. We do not use analytics, advertising or tracking cookies, and we do not profile visitors. Because we set nothing beyond what is technically necessary, no cookie-consent banner is required. If we ever introduce non-essential cookies, we will ask for your consent first and update this notice.

7. Website security

We take reasonable measures to keep this website, its visitors and our infrastructure safe from malicious actors, bots and other threats. This includes traffic filtering and bot mitigation at our content-delivery layer, enforced HTTPS encryption (HSTS) on every connection, a modern minimum TLS version, and standard security headers. These protections process limited technical data — such as IP address and request characteristics — for the sole purpose of detecting and blocking abuse and keeping the service reliable.

8. Retention

We keep contact details only as long as needed for the purpose you provided them — for example, until we conclude the early-access process or you ask us to delete them — and then delete or anonymise them. Security and server logs are retained only for as long as needed to protect the service.

9. Your rights

Depending on your location, you may have the right to access, correct, delete or restrict processing of your personal data, to object to processing, and to data portability. To exercise any of these, email [email protected]. You may also have the right to lodge a complaint with your local data protection authority.

10. Changes to this notice

We may update this notice as the product develops. When we do, we will change the version and "last updated" date at the top of this page.