Privacy Policy

Last updated: August 2026

1. Who we are

Komply is a service operated by Growtal. We help UK venue managers prepare for the Terrorism (Protection of Premises) Act 2025 (Martyn's Law). Our registered address and ICO registration number will appear here before launch.

2. What data we collect

3. How we use your data

4. Legal basis for processing (UK GDPR)

5. Where your data is stored and processed

Your account details, assessment answers and uploaded evidence are held in our Supabase database and file storage, in London, United Kingdom. Evidence documents are encrypted at rest (AES-256) and are never reachable through a public URL — download links are signed and expire after 15 minutes for evidence files, and 60 minutes for generated compliance reports.

We require multi-factor authentication (MFA) on all accounts, and all data in transit is encrypted with TLS 1.3.

Some of our suppliers process data outside the UK.Our application runs on Vercel, and its server-side requests are currently processed in the United States. Error diagnostics are sent to Sentry in the European Union. Files you upload as evidence are checked against VirusTotal's known-malware database by cryptographic hash — the file itself is never sent.

6. Suppliers who process data for us

7. Your rights

Under UK GDPR, you have the right to:

8. Data retention

We retain your data for as long as your account is active. When you delete your account, your organisation's data is disabled immediately and you have 30 days to restore it yourself if you change your mind. After that window, it is permanently deleted on our next scheduled purge. Financial records of what you were charged are kept afterwards — de-linked from your organisation, not deleted — to satisfy our own financial record-keeping obligations.

9. Contact

Data protection enquiries: info@komply.uk