Last updated: 2/8/2025
This Privacy Policy complies with the General Data Protection Regulation (GDPR) and Irish Data Protection Act 2018
ComplianceHub ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our management systems platform and related services.
As an Irish company, we comply with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. We are committed to transparency and giving you control over your personal data.
ComplianceHub is the data controller for your personal data.
Company: ComplianceHub Limited
Address: Ireland
Email: privacy@compliancehub.ie
Data Protection Officer: dpo@compliancehub.ie
Processing necessary to provide our services, manage your account, and fulfill our contractual obligations.
Improving our services, security monitoring, and business communications where balanced against your rights.
Marketing communications, cookies, and optional features where you have provided explicit consent.
Compliance with Irish and EU legal requirements, including tax obligations and regulatory compliance.
Providing and maintaining our platform, processing your requests, and delivering support
Protecting our platform and users from security threats, fraud, and unauthorized access
Analyzing usage patterns to improve our platform and develop new features
Sending service updates, security alerts, and marketing communications (with consent)
Meeting our legal obligations under Irish and EU law
We do not sell your personal data to third parties.
We only share data in the limited circumstances outlined below.
Trusted third-party providers who help us deliver our services (hosting, email, analytics) under strict data processing agreements.
When required by Irish or EU law, court orders, or to protect our legal rights and those of our users.
In the event of a merger, acquisition, or sale of assets, with appropriate safeguards for your data.
We implement industry-standard security measures to protect your data.
We retain your data only as long as necessary for the purposes outlined in this policy or as required by Irish law.
Retained while your account is active plus 3 years after closure for legal compliance.
Anonymized after 2 years and retained for analytics and service improvement.
Retained as per your subscription terms and deleted upon request or account closure.
As an individual in the EU/EEA, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Correct inaccurate or incomplete personal data.
Request deletion of your personal data in certain circumstances.
Limit how we process your data in certain situations.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or for marketing.
Withdraw consent for processing where consent is the legal basis.
Lodge a complaint with the Irish Data Protection Commission.
To exercise your rights: Contact us at privacy@compliancehub.ie. We will respond within 30 days and may require identity verification.
We work with trusted third-party providers to deliver our services. All providers are carefully vetted and bound by data processing agreements.
We primarily process data within the EU/EEA to ensure GDPR protection.
When we transfer data outside the EU/EEA, we ensure appropriate safeguards are in place:
Transfers to countries with EU adequacy decisions (e.g., UK, Switzerland).
EU-approved contracts ensuring GDPR-level protection in third countries.
Our services are not intended for children under 16.
We do not knowingly collect personal data from children under 16. If you believe we have collected such data, please contact us immediately for deletion.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of significant changes through:
Direct email to registered users
In-app notifications and banners
Advance notice for material changes
If you're not satisfied with our response to your privacy concerns, you can contact the Irish Data Protection Commission:
We are committed to protecting your privacy and will respond to all inquiries within 30 days.