Privacy Notice
Last updated: June 2026
This Privacy Notice explains how ComplianceDesk.ie (“we”, “us”, “our”) collects, uses, and protects your personal data. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. We are the data controller for personal data collected through this website. For data protection queries, contact us at hello@compliancedesk.ie.
What data we collect
- Account data — name and email address when you create an account via Clerk.
- Document inputs — information you enter into our compliance tools (e.g. tenancy details, planning details, appeal grounds) to generate documents. The sensitivity varies by tool.
- Payment information — handled entirely by Stripe; we do not store your card details.
- Subscription data — your plan tier and subscription status, stored in our database.
- Technical data — IP address, browser type, and pages visited (anonymous analytics only).
Why we collect it (legal basis)
- Contract performance — to generate and deliver compliance documents you have requested.
- Legitimate interest — to operate, secure, and improve the service and to prevent fraud.
- Legal obligation — to comply with Irish tax and financial record-keeping requirements.
- Consent — for any marketing communications; you can withdraw consent at any time.
Who we share data with
We do not sell your personal data. We share data only with trusted service providers necessary to operate the service:
- Anthropic (Claude API) — to generate your compliance documents. Inputs are retained by Anthropic for up to 30 days for safety and security monitoring, then permanently deleted. Anthropic does not use API data to train its models.
- Stripe — payment processing and subscription management.
- Clerk — user authentication and identity management.
- Supabase — database hosting for your account and deadline data.
- Resend — transactional email delivery (welcome emails, deadline reminders).
- Vercel — website hosting and serverless compute.
International data transfers
To generate your compliance documents we send the information you enter to our AI provider, Anthropic, which processes it on servers in the United States. Where personal data is transferred outside the EEA — to Anthropic, Stripe, Clerk, Supabase, Resend, and Vercel — the transfer is protected by appropriate safeguards, namely Standard Contractual Clauses and/or the EU–US Data Privacy Framework, under each provider's data-processing terms. Anthropic retains API inputs for up to 30 days for safety and security purposes, then permanently deletes them, and does not use data submitted through its API to train its models.
How long we keep your data
- Document inputs: not retained after your document is generated.
- Account and subscription data: retained for the life of your account, then deleted within 90 days of account closure.
- Deadline records: retained until you delete them or close your account.
- Payment records: kept as legally required (Irish tax law — 7 years).
- Contact messages: deleted within 12 months.
Your rights under GDPR
To exercise any right, email hello@compliancedesk.ie and we will respond within 30 days.
Cookies
We use only essential cookies required to operate the site (authentication session cookies set by Clerk). We do not use advertising or tracking cookies. No cookie consent banner is required as we do not use non-essential cookies.
Complaints
If you believe your data has been mishandled, you have the right to lodge a complaint with the Data Protection Commission (Ireland).
Changes to this notice
We may update this notice from time to time. The “last updated” date at the top of this page will reflect any changes. Continued use of the site after changes constitutes acceptance.