Privacy Policy

Last updated: 3 October 2026

Complee is operated by Leashed (CVR 44802228), C/O KU Lighthouse, Tagensvej 16 A, 2200 København N, Denmark.

Who we are

Complee is a product operated by Leashed (CVR 44802228), a sole proprietorship registered in Denmark. We are the data controller for personal data described in this policy.

Contact: [email protected] · C/O KU Lighthouse, Tagensvej 16 A, 2200 København N, Denmark

Who this policy covers

This policy applies to visitors of https://complee.eu, people who run a free assessment, buyers of a document pack, Complee Plus subscribers, contact-form senders, and newsletter subscribers. The service is aimed at businesses. If you use it as a consumer, the same rules apply unless mandatory law gives you additional rights.

What we collect

Assessment. Website URL, description of how you use AI, work email, country, and any follow-up answers. We fetch the submitted website with the user agent CompleeAssessment/1.0 to add context to the assessment.

Account and vault. If you buy Plus or sign in, we store your email and assessment records linked to your account or download token.

Payments. Stripe processes payment and billing address. We store order metadata (product, amount, status, assessment id) but not full card numbers.

Contact form. Name, email, company, and message.

Newsletter. Email address, only if you tick the separate opt-in box during an assessment.

Public verify page. If you turn on the Complee Assessed badge with Plus, we publish: hostname, assessment date, expiry date, risk tier, role, named systems, and obligation articles. This page is public and indexed with noindex, but anyone with the link can open it.

Technical data. Server logs (IP address, browser type, timestamps) and, if you accept analytics cookies, usage events through Google Analytics.

How we use data and legal bases

  • Provide the assessment, generate documents, deliver downloads, and run your Plus vault (contract / steps before contract).
  • Process payments and keep accounting records (contract and legal obligation).
  • Send service emails such as download links and subscription receipts (contract).
  • Send EU AI Act compliance updates by email (consent; you can unsubscribe at any time).
  • Publish badge verification data when you activate the badge (contract and your instruction).
  • Improve security, prevent abuse, and understand product usage (legitimate interest; analytics only with consent).

Assessment text is sent to an AI provider (OpenRouter or TypeSafe) for classification. Do not submit confidential information you are not allowed to share.

Only submit a website you own or are authorised to assess. You must have a lawful basis to provide personal data about your organisation and staff.

Processors and international transfers

We use trusted providers to run the service:

  • Stripe: Payment processing and billing records. Location: EU and United States (with appropriate safeguards).
  • Supabase: Database, authentication, and file storage. Location: EU or United States (depending on project region).
  • OpenRouter / TypeSafe: AI classification of assessment text. Location: United States (with appropriate safeguards).

Where data is transferred outside the EU/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or the EU-US Data Privacy Framework, as offered by the provider.

Retention

  • Assessment and vault records: while your Plus subscription is active, or up to 24 months after your last interaction if you do not subscribe.
  • Document pack orders and billing metadata: up to 7 years for accounting and tax rules.
  • Contact messages: up to 24 months after we resolve the enquiry.
  • Newsletter list: until you unsubscribe, then suppressed from future mailings.
  • Public badge data: while the badge is active; status may show expired or revoked after that.
  • Server logs: up to 90 days unless needed for security investigations.

Cookies

Essential cookies and local storage are used to keep you signed in and remember cookie choices. Google Analytics is loaded only if you click "Accept analytics" in the cookie banner. You can change your mind by clearing site data in your browser.

Your rights

Under GDPR you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. Where we rely on consent, you can withdraw it at any time without affecting earlier processing.

Email [email protected] to exercise your rights. We respond within one month.

You may complain to the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority.

We do not make decisions with legal or similarly significant effects based solely on automated processing.

Security

We use encryption in transit (HTTPS), access controls, and reputable infrastructure providers. No method of transmission or storage is completely secure.

Children

The service is not directed at children under 16.

Changes

We may update this policy. Material changes will be posted on this page with a new date. Continued use after the effective date means you accept the updated policy.

See also our Terms of Service and Legal notice.