Privacy Policy
Last updated: August 2026
1. Who we are
Komply is a service operated by Growtal. We help UK venue managers prepare for the Terrorism (Protection of Premises) Act 2025 (Martyn's Law). Our registered address and ICO registration number will appear here before launch.
2. What data we collect
- Account data: email address, organisation name, and password hash (stored by Supabase Auth).
- Venue data: site name, address, venue type, expected occupancy, and compliance assessment responses.
- Evidence documents: PDFs, images, and other files you upload as compliance evidence.
- Billing data: subscription status and payment history. Card details are held by Stripe — we never store card numbers.
3. How we use your data
- To provide the Komply compliance readiness service
- To generate AI-powered action plans and compliance reports
- To send transactional emails (receipt, reminders, compliance deadlines)
- To improve the service and fix bugs
4. Legal basis for processing (UK GDPR)
- Contract: processing necessary to deliver the service you subscribed to
- Legal obligation: retaining billing records
- Legitimate interest: security monitoring and fraud prevention
- Consent: optional reminder emails (you can unsubscribe at any time)
5. Where your data is stored and processed
Your account details, assessment answers and uploaded evidence are held in our Supabase database and file storage, in London, United Kingdom. Evidence documents are encrypted at rest (AES-256) and are never reachable through a public URL — download links are signed and expire after 15 minutes for evidence files, and 60 minutes for generated compliance reports.
We require multi-factor authentication (MFA) on all accounts, and all data in transit is encrypted with TLS 1.3.
Some of our suppliers process data outside the UK.Our application runs on Vercel, and its server-side requests are currently processed in the United States. Error diagnostics are sent to Sentry in the European Union. Files you upload as evidence are checked against VirusTotal's known-malware database by cryptographic hash — the file itself is never sent.
6. Suppliers who process data for us
- Supabase — database, authentication, and file storage
- Vercel — application hosting and content delivery
- Sentry — error monitoring (European Union)
- Upstash — background job queue and rate limiting; receives record identifiers, not document contents
- Stripe — payment processing
- Resend — transactional email delivery
- Anthropic — generating your action plan and Section 7 statements from your assessment answers
- Voyage AI — generates the search embeddings that retrieve relevant statutory guidance for your action plan and Section 7 statements; receives question and guidance text, not your venue or assessment data
- VirusTotal — checks uploaded evidence files against its known-malware database by cryptographic hash; the file itself is never sent
7. Your rights
Under UK GDPR, you have the right to:
- Access your data — available via Account > Export my data
- Erasure — available via Account > Delete my account
- Rectification, portability, objection, and restriction of processing
- Lodge a complaint with the ICO: ico.org.uk
8. Data retention
We retain your data for as long as your account is active. When you delete your account, your organisation's data is disabled immediately and you have 30 days to restore it yourself if you change your mind. After that window, it is permanently deleted on our next scheduled purge. Financial records of what you were charged are kept afterwards — de-linked from your organisation, not deleted — to satisfy our own financial record-keeping obligations.
9. Contact
Data protection enquiries: info@komply.uk