Privacy policy

Last updated: 11 September 2026

Short version: we collect an email address if you give us one, we use it only to send you what you asked for, we set no tracking cookies, and we run no analytics or advertising scripts. You can unsubscribe or ask us to delete your data at any time with one email.

1. Controller

The controller of your personal data is [[LEGAL ENTITY NAME]], [[REGISTERED ADDRESS]], [[COUNTRY]]. Contact: contact@compliantbook.com. We have not appointed a data protection officer; we are not required to.

2. What we collect, why, and on what legal basis

Categories of personal data, purpose, legal basis and retention
DataWhyLegal basisKept
Email address (mailing list)To send you updates on EU compliance deadlines and new material, which you asked forConsent — Art. 6(1)(a) GDPRUntil you unsubscribe, or 24 months with no engagement
Confirmation timestamp and the fact you confirmedTo prove your consent was given, as GDPR requires us to be able to doLegal obligation — Art. 6(1)(c), and our legitimate interest in demonstrating complianceSame as above, plus 12 months
Name and email at purchase, billing country, transaction recordsTo fulfil your order and meet tax and accounting obligationsContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)As required by tax law, typically 6–10 years
Server logs (IP address, request, user agent, timestamp)To keep the site running and to detect and stop abuseLegitimate interests — Art. 6(1)(f): operating and securing our own websiteMaximum 14 days, then deleted
Emails you send usTo answer youLegitimate interests — Art. 6(1)(f): responding to correspondence24 months
We do not collect anything else. No analytics. No advertising or remarketing pixels. No social media trackers. No fingerprinting. No profiling. No automated decision-making that produces legal or similarly significant effects. We do not buy, sell, rent or trade personal data, ever.

3. The mailing list works by double opt-in

When you enter your email address we send you a confirmation link. Nothing is added to the list until you click it. If you never click, the pending record is deleted automatically after seven days. Every email we send carries a working one-click unsubscribe link, and unsubscribing removes your address rather than flagging it.

4. Who else processes your data

  • Our hosting provider — stores the site and the mailing list database, in the European Union. Acting as our processor under a data processing agreement.
  • Our payment reseller — acts as merchant of record for purchases and is an independent controller for the payment data it collects. It handles card data; we never see or store card numbers. Its own privacy notice governs that processing and is shown at checkout.
  • Our email delivery provider — sends confirmation, download and update emails, as our processor.

We disclose personal data to no one else, except where we are legally required to.

5. International transfers

We choose providers that store data in the European Economic Area wherever we can. Where a provider processes data outside the EEA, that transfer is covered by an adequacy decision or by Standard Contractual Clauses adopted by the European Commission, together with any additional measures required. You can ask us for details of the safeguards applying to any specific transfer.

6. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Rectification of inaccurate or incomplete data.
  • Erasure — we will delete your data unless we are legally required to keep it (for example, transaction records for tax purposes).
  • Restriction of processing in certain circumstances.
  • Data portability — your data in a structured, commonly used, machine-readable format.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. For the mailing list, the unsubscribe link does this instantly.
  • Complain to a supervisory authority — in the EU, the data protection authority of your country of residence, place of work, or of the alleged infringement.

To exercise any right, email contact@compliantbook.com. We respond within one month. We do not charge, and we do not require you to create an account or provide identification beyond what is needed to locate your record and be reasonably confident it is yours.

7. Storage on your device

We set no cookies of our own. The site stores two small items in your browser's local storage, both only when you act: your colour theme choice, and the fact that you dismissed the storage notice. Neither identifies you, neither is sent to our server, and both stay on your device until you clear your browser data. Details →

8. Children

This site is for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, tell us and we will delete it.

9. Security

The site is served over HTTPS with a strict transport security policy and a content security policy. The mailing list database sits in a directory the web server refuses to serve, under a filename derived cryptographically from a server-side secret, and it is not reachable from the internet. Administrative access requires a password hashed with Argon2id and is rate-limited. We keep the minimum data necessary, which is the most effective security measure available to us. Security policy →

10. Breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will inform you without undue delay where the risk is high.

11. Changes

If we change this policy we update the date at the top. If a change materially affects how we use data you have already given us, we will email subscribers before it takes effect.


Questions about this page: contact@compliantbook.com