Complify Privacy Policy
Effective Date: 2026-08-31
This Privacy Policy explains how HResolved Inc. (“HResolved”, “we”, “us”) collects, uses, discloses, and protects personal information when you visit our website or use Complify.
Complify is intended for use by businesses and other organizations, and collects personal information only as needed for HResolved’s own business purposes, such as account administration, billing, communications, security, and service delivery; it is not intended to process personal information on behalf of customers, including personal information about their employees, contractors, or other personnel.
The Information We Collect
Website visitors and automatic collection
When you visit our website, our web server and application logs automatically record limited information for each request to operate, secure, and troubleshoot our services. This is limited to IP address, user-agent (such as browser type and version), and the URL requested.
Free gap assessment
If you complete a free gap assessment, we collect information about your business through an online questionnaire, such as province, industry, number of employees, and operational yes/no facts. We also collect your email address to deliver your report, maintain consent records, and, where permitted, send follow-up communications about Complify. We collect your IP address for rate limiting purposes and to maintain consent records.
When you complete the free assessment, we generate a simple reference token that identifies that submission. If you later purchase a Complify subscription, this token is included in the checkout link and returned to us after payment. We use it to connect your purchase to the earlier assessment, even if you use a different email address at checkout. The token contains no personal information and is used only to link the assessment and the purchase.
Account Information
If you become a Complify customer, we collect account-related information (name, email, company name) and billing information (processed by Stripe; we do not store full card details). If you book a meeting through our scheduling tool, Calendly collects your name, email address, and scheduling details on our behalf to facilitate the booking.
Documents you upload
Customers may upload workplace compliance documents to their Complify library, including documents Complify did not generate and documents submitted for expert review. As explained in our Terms of Service, you are instructed not to include personal information in uploaded documents. We may decline or delete uploaded documents that appear to include personal information. However, you are responsible for ensuring that uploaded documents do not contain personal information, and we have no obligation to review, remove, or redact personal information from those documents.
Cookies and similar technologies
Complify does not use cookies, tracking pixels, or other browser-based identifiers to track visitors or customers. The application does not store information in visitors’ or customers’ browsers for tracking or analytics purposes, and we do not use technologies that monitor email opens or link clicks. The only browser storage used by Complify is an authentication token for users who sign in to their account or the administrative dashboard. This token is stored in secure browser storage, such as localStorage. It is not a cookie and is not used for tracking or analytics.
Two external services—Stripe (checkout) and Calendly (booking)—are accessed only when a visitor clicks through to those providers. Because these services are not embedded on our pages, they do not place cookies or run scripts on the Complify website. Any cookies set by those providers apply only once a visitor navigates to their respective sites.
How we use your information
We use information to:
- Generate and deliver your gap assessment results
- Provide paid services, including policy drafting and subscription features
- Store and manage documents you upload, and facilitate expert review where you request it
- Communicate with you
- Prevent abuse and secure our systems
- Maintain accurate consent records
- Meet legal and regulatory obligations
Disclosures of personal information
We disclose personal information only as needed to operate Complify, provide the services you request, comply with legal obligations, protect our rights and systems, or as otherwise permitted or required by law. This may include disclosure to service providers that host, process, support, or secure our services; payment and scheduling providers; professional advisers; regulators or law enforcement where legally required; and a successor organization if there is a business transaction involving HResolved or Complify.
AI-assisted drafting
Complify may use AI-assisted tools to help generate draft policy language or recommendations. We do not intentionally send uploaded documents or personal information to AI tools. Where AI tools are used, we use de-identified business facts where possible, and outputs are reviewed before being used to provide services.
Retention and storage of information
We retain information only as long as necessary for the purposes described in this policy, after which it is deleted or de-identified, subject to the specific retention periods below.
- Free gap assessment leads: Assessment data and consent records are kept to maintain an accurate history of what you agreed to. If you neither confirm your email address nor purchase a subscription, your records are de-identified after 90 days. If you unsubscribe from email communications, we retain a minimal suppression record — a one-way hash of your email address and a timestamp — so that we can continue to honour your request. We do not retain the email address itself.
- Subscribing customers: Account information and compliance data are retained while your Complify account is active. If your account is cancelled or becomes dormant, your documents remain available for export for 2 years after your account closes; after that, your documents and related customer content are deleted.
- Business records: We retain transaction records and our email send-log, including order confirmations, for 7 years for business, accounting, tax, legal, and records-management purposes. To the extent possible, personal information is removed from business records if your account is deleted.
- Website logs and operational metadata: Automatically collected logs, such as IP address, browser details, and security events, are retained only for as long as reasonably necessary for security, troubleshooting, fraud prevention, and operational integrity, unless a longer period is required to investigate an incident or comply with legal obligations.
- Deletion requests: We respond to deletion requests within 30 calendar days and complete deletion within 90 days. We maintain daily full database backups on a 35-day rotation, with no long-term archives. Information removed from active systems within 90 days of a request is purged from backups approximately 35 days later.
How we protect information
We implement and maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, collection, use, disclosure, modification, loss, or destruction, taking into account the sensitivity of the information and the nature of our services. These safeguards include: encryption in transit and at rest; access controls and role-based permissions; secure upload channels; and internal data-handling policies.
Although we take reasonable steps to protect personal information, no system or method of transmission or storage can be guaranteed to be completely secure.
Your core compliance data and any documents you upload are stored on servers that are located in Canada. However, some of the services we use may result in the transfer of your personal information outside Canada. We use the following service providers:
- AWS: hosting and storage
- Stripe: payment processing
- Calendly: meeting scheduling
- Anthropic: AI drafting using de-identified facts only
- Google Workspace: Business email and communications metadata
Personal information transferred to or accessed through service providers outside Canada may be subject to the laws of those other jurisdictions and may be accessible to courts, law enforcement agencies, national security authorities, or other governmental authorities in those jurisdictions in accordance with applicable law.
Your rights
You may request access to, or correction of, your personal information. You may also withdraw consent where our processing is based on consent, request deletion of personal information where applicable, or ask questions about how we handle personal information. Some of the personal information we hold about you, including your name, email address and account details, is accessible through your account. For anything else, please contact our Privacy Officer using the contact information below.
Children and minors
Complify is intended for business use and is not directed to children or minors. We do not knowingly collect personal information from children or minors.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on our website with a revised effective date. If we make material changes, we will take reasonable steps to notify affected users where required by law.
Contact us
If you have questions or concerns about our personal information handling practices, or would like to make a complaint, please contact our Privacy Officer by email at privacy@hresolved.ca or by mail at 3374 McCarthy Rd, Ottawa ON K1V 1Z6, Canada.
Complify — by HResolved