Effective date: 1 August 2026 · Last updated: 1 August 2026
Regulaton ("we", "our", "us") operates the Regulaton platform at regulaton.com. We provide EU AI Act compliance tooling for small and medium businesses.
For the purposes of the GDPR, Regulaton is the data controller for personal data processed through our platform.
Contact us about privacy: privacy@regulaton.com
Account data: Your name, email address, and authentication data (via GitHub OAuth or email magic link). We use NextAuth to manage authentication.
Organisation data: Company name, country, industry, employee count, and VAT number that you provide during onboarding.
Compliance data: AI tool inventories, compliance documents, staff training records, and oversight procedures that you create within the platform. This data belongs to you.
Billing data: Payment is processed by Stripe. We store your Stripe customer ID and subscription status, but never your card details.
Usage data: Standard server logs including IP addresses, browser type, pages visited, and timestamps. We use this to operate and improve the service.
We do not sell your data to third parties. We do not use your compliance data to train AI models.
We process your data on the following legal bases under Article 6 GDPR:
We retain your account and compliance data for as long as your account is active. If you close your account, we delete your data within 30 days, except where we are required by law to retain it (e.g. billing records, which we retain for 7 years for tax purposes).
We use the following sub-processors to provide our service. Where a processor is based outside the EU/EEA, we rely on the specific safeguard named below to make that transfer lawful under GDPR Chapter V.
All processors are bound by data processing agreements consistent with Article 28 GDPR. We review our sub-processor list periodically and will update this policy if it changes.
As a data subject in the EU/EEA or UK, you have the following rights:
To exercise any of these rights, email privacy@regulaton.com. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection authority.
We use the following cookies:
We do not use advertising cookies, tracking pixels, or analytics cookies that identify individual users.
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encrypted database connections, and access controls. No system is 100% secure — if you discover a security vulnerability, please disclose it responsibly to privacy@regulaton.com.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the product. Continued use of Regulaton after changes constitutes acceptance of the updated policy.
For privacy questions, data subject requests, or to reach our Data Protection contact: