Legal

Privacy Policy

Effective date: 1 August 2026 · Last updated: 1 August 2026

1. Who we are

Regulaton ("we", "our", "us") operates the Regulaton platform at regulaton.com. We provide EU AI Act compliance tooling for small and medium businesses.

For the purposes of the GDPR, Regulaton is the data controller for personal data processed through our platform.

Contact us about privacy: privacy@regulaton.com

2. Data we collect

Account data: Your name, email address, and authentication data (via GitHub OAuth or email magic link). We use NextAuth to manage authentication.

Organisation data: Company name, country, industry, employee count, and VAT number that you provide during onboarding.

Compliance data: AI tool inventories, compliance documents, staff training records, and oversight procedures that you create within the platform. This data belongs to you.

Billing data: Payment is processed by Stripe. We store your Stripe customer ID and subscription status, but never your card details.

Usage data: Standard server logs including IP addresses, browser type, pages visited, and timestamps. We use this to operate and improve the service.

3. How we use your data

  • To provide the Regulaton service, generating compliance documents, calculating your compliance score, and storing your inventory
  • To process payments through Stripe
  • To send you service emails (sign-in links, subscription receipts, important updates)
  • To improve the platform based on aggregated, anonymised usage patterns
  • To comply with our own legal obligations

We do not sell your data to third parties. We do not use your compliance data to train AI models.

4. Legal basis for processing (GDPR)

We process your data on the following legal bases under Article 6 GDPR:

  • Contract (Art. 6(1)(b)): Processing necessary to provide you with the Regulaton service under our Terms of Service.
  • Legitimate interests (Art. 6(1)(f)): Service improvement, security, and fraud prevention.
  • Legal obligation (Art. 6(1)(c)): Retaining billing records as required by tax law.

5. Data retention

We retain your account and compliance data for as long as your account is active. If you close your account, we delete your data within 30 days, except where we are required by law to retain it (e.g. billing records, which we retain for 7 years for tax purposes).

6. Third-party processors

We use the following sub-processors to provide our service. Where a processor is based outside the EU/EEA, we rely on the specific safeguard named below to make that transfer lawful under GDPR Chapter V.

  • Neon — PostgreSQL database hosting. Data is stored in an EU region. No international transfer occurs for this processor.
  • Vercel — Application hosting and edge network. Vercel Inc. (US) is certified under the EU-U.S. Data Privacy Framework (DPF), which the European Commission recognises as providing an adequate level of protection for transfers to certified U.S. organisations. Some content may be cached transiently at EU edge locations but is not stored there permanently.
  • Stripe — Payment processing. For EEA/UK customers, data is generally processed by Stripe Payments Europe Limited (an EU entity) and/or Stripe, LLC (US), which is DPF-certified; Stripe's Data Processing Agreement additionally incorporates the EU Standard Contractual Clauses (SCCs) as a supplementary safeguard.
  • Resend — Transactional email delivery. Resend (US) is DPF-certified, and its Data Processing Agreement also incorporates SCCs as a supplementary transfer mechanism.
  • GitHub — OAuth authentication (if you choose to sign in with GitHub). GitHub, Inc. (US) is DPF-certified.

All processors are bound by data processing agreements consistent with Article 28 GDPR. We review our sub-processor list periodically and will update this policy if it changes.

7. Your rights under GDPR

As a data subject in the EU/EEA or UK, you have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Correct inaccurate personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Portability: Receive your data in a machine-readable format.
  • Restriction: Ask us to restrict processing in certain circumstances.
  • Objection: Object to processing based on legitimate interests.

To exercise any of these rights, email privacy@regulaton.com. We will respond within 30 days.

You also have the right to lodge a complaint with your national data protection authority.

8. Cookies

We use the following cookies:

  • next-auth.session-token: Required for authentication. Contains a signed JWT. Expires after 30 days.
  • next-auth.csrf-token: Required for security (CSRF protection).

We do not use advertising cookies, tracking pixels, or analytics cookies that identify individual users.

9. Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), encrypted database connections, and access controls. No system is 100% secure — if you discover a security vulnerability, please disclose it responsibly to privacy@regulaton.com.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the product. Continued use of Regulaton after changes constitutes acceptance of the updated policy.

11. Contact

For privacy questions, data subject requests, or to reach our Data Protection contact:

privacy@regulaton.com