Privacy Policy
Version 2.0 · September 2026 · issued by Clarety B.V.
In short. We are Clarety B.V. in Landsmeer. As a controller we hold little more than business contact details, account data and website statistics. The documents your organisation uploads stay yours: for those we are a processor, our infrastructure is in Germany, the content is never used to train or fine-tune an AI model, and nobody here reads it unless you ask us to. Our website sets no cookies and shows no banner. This summary is here to orient you. The numbered sections are the policy.
1. Who we are
GenCompl.ai is a trademark of Clarety B.V. This policy explains what we do with personal data, and where our responsibility ends and our customer's begins.
Clarety B.V. is registered in the Netherlands and builds AI-supported compliance, risk management and governance software. GenCompl.ai is a business-to-business Software-as-a-Service platform that uses artificial intelligence to help organisations identify relevant regulatory authorities, publications and news, and to support their regulatory compliance work.
Who is responsible
| Item | Detail |
|---|---|
Legal entity | Clarety B.V. |
Address | Zuideinde 50A, 1121 CM Landsmeer, Netherlands |
Chamber of Commerce (KvK) | 42089416 |
Privacy contact | |
Lead supervisory authority | Autoriteit Persoonsgegevens, the Netherlands |
We have appointed a privacy contact, who can be reached at the address above. We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one. Because Clarety B.V. is established in the Netherlands, we do not need a representative under Article 27 GDPR. Our only establishment is in Landsmeer, which is why the Autoriteit Persoonsgegevens is our lead supervisory authority.
Where this policy refers to "GenCompl.ai" or "Clarety", "we", "us" or "our", it means the entity above. We issue it under Articles 13 and 14 GDPR.
2. What this policy covers
Under the GDPR, responsibilities differ depending on whether we decide why and how personal data is processed, or process it on someone else's instructions. GenCompl.ai does both, and this policy is explicit about which is which.
This policy applies where GenCompl.ai acts as a controller, meaning the personal data for which we determine the purposes and means of processing ourselves. That covers:
- visitors to our websites and readers of our marketing material;
- prospective customers and business contacts;
- the people at our customer organisations who hold accounts and log in to the platform, principally their business email addresses and account administration data;
- job applicants, including applicants for internships, and other people who contact us.
This policy does not govern the data our customers upload into the platform. For that content the customer organisation is the controller and GenCompl.ai is the processor, acting on that organisation's documented instructions. The binding terms are in our Data Processing Agreement, which we provide on request. Section 7 describes the handling for transparency.
3. The personal data we process as a controller
We practise data minimisation and keep what we hold to a minimum.
- Account and platform-user data. For each authorised user at a customer organisation we typically process the business email address, name where provided, organisational role, authentication data, and records of activity within the platform such as log-in events and audit logs. We do not require, and we ask customers not to submit, home addresses, government identifiers, financial account details or special category data for account provisioning.
- Customer relationship and billing data. Contact details of customer and prospect representatives (name, business email, business phone, employer, role), contract and billing information, and our correspondence with you.
- Website and marketing data. Aggregated website statistics as described in Section 11, newsletter and event sign-ups, and marketing preferences.
- Support and communications data. What you tell us when you contact us for support, sales or general questions, including the content of those messages.
- Job applicant data. What you provide when you apply for a role with us: CV, contact details and the content of your application. We handle applications ourselves and do not use an external recruitment system.
Where the data comes from
We collect this data from you directly, or from the customer organisation that authorises your account. We do not buy contact data from data brokers or business data providers.
Whether you have to provide it
Providing account data is a contractual requirement: without a name, a business email address and authentication data we cannot give you access to the platform. Providing marketing preferences, or answering a survey, is voluntary, and declining has no effect on your use of the service.
We do not intentionally collect special categories of personal data (Article 9 GDPR: for example health, political opinions, religious beliefs, biometric data) in our controller capacity, and we ask users not to submit such data through account or support channels.
4. Why we process your data, and our legal bases
We rely on the following legal bases under Article 6 GDPR. Where more than one basis is listed for a purpose, we rely on whichever applies in the circumstances.
| Purpose | Personal data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
Providing, administering and securing platform accounts | Account and platform-user data | Performance of a contract (Art. 6(1)(b)); legitimate interests in operating and securing the service (Art. 6(1)(f)) |
Managing the customer relationship, contracts and billing | Customer relationship and billing data | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
Responding to enquiries and providing support | Support and communications data | Legitimate interests (Art. 6(1)(f)); contract (Art. 6(1)(b)) |
Sending our newsletter and other marketing email | Contact and marketing data | Consent (Art. 6(1)(a)), or the existing customer exception in Art. 11.7 Telecommunicatiewet where it applies |
Measuring website traffic | Aggregated website statistics (Section 11) | Legitimate interests (Art. 6(1)(f)). No consent is required because nothing is stored on or read from your device |
Improving and developing the platform | Account and usage metadata, not customer-uploaded content | Legitimate interests (Art. 6(1)(f)) |
Information security, preventing fraud and misuse | Account, log and security data | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
Meeting legal, regulatory and accounting obligations | As required | Legal obligation (Art. 6(1)(c)) |
Recruitment | Job applicant data | Pre-contractual steps and legitimate interests (Art. 6(1)(b), (f)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms, and you can ask us for information about that assessment. Where we rely on consent, you may withdraw it at any time, which does not affect processing carried out before you withdrew it. Every marketing message we send contains an unsubscribe link.
5. Artificial intelligence, transparency and human oversight
GenCompl.ai is an AI platform, so we are explicit about how the AI features work. Article 50 of the EU AI Act (Regulation (EU) 2024/1689) has applied since 2 August 2026, and this section is written to meet it alongside the GDPR.
- You are interacting with an AI system. The platform uses AI to surface relevant regulatory authorities, publications and news and to assist with compliance tasks. Outputs are generated by AI and are labelled as such.
- A human stays in the loop, and that human is one of yours. AI output is reviewed by a person in your own organisation before anything is done with it. Our staff do not review your content for you. Section 7 sets out the single exception and the controls on it.
- No solely automated decisions with legal or similar effects. Because a person always reviews the output, we do not take decisions based solely on automated processing that produce legal effects concerning you, or that similarly significantly affect you, within the meaning of Article 22 GDPR.
- The AI works on regulatory texts, not on people. Outputs concern regulations, authorities, publications and obligations. The platform does not score, rank or profile individuals.
- Outputs have to be verified. AI-generated results may contain errors or omissions and are not legal advice. Users are responsible for checking outputs against primary sources before relying on them.
6. How we share your data
We do not sell personal data, and we do not share it with advertising networks. We share it only as described here.
- Sub-processors and service providers. We engage a limited set of providers to help us run the service, for example our cloud hosting provider and the AI service behind our AI features. They act as sub-processors under written agreements that impose confidentiality and data protection obligations at least equal to our own, and, for the AI service, the zero data retention and no training terms described in Section 7.
- Professional advisors, auditors and assessors such as legal and accounting advisors and the security auditors engaged in connection with our ISO/IEC 27001 work, under confidentiality.
- Authorities and legal requirements. Where we are legally required to do so, or to establish, exercise or defend legal claims, or to protect the rights, safety and security of GenCompl.ai, our customers or others.
- Corporate transactions. In connection with a merger, acquisition, financing or sale of assets, subject to confidentiality and to continuity of the protections in this policy.
Sub-processor list. We keep a current list of our sub-processors, naming the service each one provides and the country of processing. We send it on request, together with our Data Processing Agreement. Customers are notified of changes to the list and can object, as set out in that agreement.
7. Customer-uploaded content
Employees of a customer organisation upload that organisation's documents and company data onto the platform. For that content GenCompl.ai acts as a processor on the customer's documented instructions, and the customer is the controller. The binding terms are in our Data Processing Agreement. We describe the handling here because it is central to how the service works.
- Purpose limitation. Uploaded content is used only to provide the service, including, for example, to identify relevant regulatory authorities, publications and news and to support the customer's compliance work. It is not used for any other purpose. The authoritative description of that purpose is in the Data Processing Agreement, which is where new features are reflected.
- Where it is stored. Uploaded content is stored in the customer's own environment on our infrastructure in Germany, for the term of the subscription. Customer environments are logically separated, and content is encrypted in transit and at rest.
- Zero data retention at the AI layer. Content sent to the AI service that powers our AI features is processed under zero data retention terms. It is used transiently to generate a response and is not stored there.
- No training and no fine-tuning. We do not build or operate an AI model of our own. Our AI features run on models supplied by third parties, and the terms that apply exclude the use of your content to train or fine-tune any model, theirs or anyone else's.
- What we do improve, and how. We improve the platform by changing our own prompts and agent configurations. Those changes are generic. They are based on aggregated platform behaviour and on our own test material, and customer content is not copied into a prompt, an example or a test set.
- Who at GenCompl.ai can see your content. In normal operation, nobody. Our personnel access uploaded content only where a customer asks us to look at a specific problem, so that we can provide support. Everyone with such access is bound by the confidentiality obligation in the customer contract, access is limited to named staff and it is logged.
Three commitments. Zero data retention at the AI layer. No training or fine-tuning on your content. Nobody here reads it unless you ask us to. These are contractual, not settings. They are repeated in the Data Processing Agreement, which is the document that binds us.
8. International transfers
We process personal data inside the European Economic Area. Our platform and customer data run on cloud infrastructure located in Germany.
Where personal data is transferred to, or accessed from, a country outside the EEA, for example because a sub-processor is established elsewhere, we put a safeguard under Chapter V GDPR in place:
- an adequacy decision by the European Commission for the destination country; or
- the European Commission's standard contractual clauses, together with any additional technical and organisational measures identified in a transfer impact assessment.
We do not rely on the EU-US Data Privacy Framework on its own. Where a recipient is in the United States, we put standard contractual clauses and a transfer impact assessment in place alongside any certification that recipient holds. We do this because the adequacy decision behind that framework is under appeal at the Court of Justice of the European Union (Case C-703/25 P), and we would rather our transfers did not depend on the outcome.
The zero data retention design described in Section 7 reduces transfer exposure, because content sent to the AI layer is not stored there. You can ask us for more information about the safeguards we use, and for a copy where we are permitted to share it, using the details in Section 14.
9. How long we keep data
We keep personal data only for as long as it is needed for the purposes described, and then delete or anonymise it.
| Category | Retention period |
|---|---|
Account and platform-user data | For the term of the subscription, then deleted or anonymised within 30 days of account closure, unless a longer period is agreed in writing or required by law |
Customer-uploaded content (processor role) | For the term of the subscription, then deleted as set out in the Data Processing Agreement. Never retained at the AI layer |
Customer relationship and billing records | The contract term plus the seven-year Dutch fiscal retention period |
Support and communications | 24 months after the request is closed |
Marketing data | Until you unsubscribe or object, after which we keep a minimal suppression record so that we do not contact you again |
Security and audit logs | 12 months, in line with our information security policy |
Job applicant data | Four weeks after the procedure ends, or one year if you give us permission to keep your details for future vacancies |
Specific periods are set out in our internal retention schedule and, for customer data, in the Data Processing Agreement.
10. How we protect your data
We build and run our information security programme against ISO/IEC 27001:2022, with measures appropriate to the risk, as Article 32 GDPR requires.
These include encryption in transit and at rest, access control on a least-privilege basis, multi-factor authentication, logging and monitoring, secure software development practices, vulnerability and patch management, supplier security assessment, business continuity and incident response, and security awareness training for staff.
Certification status
We are implementing an information security management system designed to meet ISO/IEC 27001. We are not certified yet, and we say so plainly rather than implying otherwise. We will publish the certificate, the issuing body and the validity date once it is granted.
What that certificate would not do. ISO/IEC 27001 has never been approved as a certification mechanism under Article 42 GDPR. It is evidence of a managed security programme. It does not by itself demonstrate compliance with data protection law, and we do not present it that way.
Personal data breaches
If a breach affects your data, we follow our incident response process. Where the law requires it, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach (Article 33 GDPR) and, where the risk to you is high, we notify you as well (Article 34 GDPR). Where we act as a processor, we notify the customer without undue delay so that they can meet their own obligations.
11. Cookies and website analytics
Our website sets no cookies and uses no comparable techniques. There is no cookie banner and no consent request, because there is nothing to consent to. We run Plausible Analytics on our own servers. It counts visits without cookies, without storing or reading information on your device, and without building a profile of you.
Article 11.7a of the Dutch Telecommunicatiewet requires consent for storing information on, or gaining access to information stored on, a user's device. Our analytics does neither, so that requirement does not apply.
We do not use Google Analytics, Google Tag Manager, advertising pixels or social media trackers. If we ever add a technique that stores or reads information on your device, we will ask for your consent first and update this policy before it goes live.
12. Your rights
Subject to the conditions and exceptions in data protection law, you have the right to:
- access the personal data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure, the right to be forgotten;
- restriction of processing;
- object to processing based on legitimate interests, and to object to direct marketing at any time;
- data portability for data you provided, where processing is based on consent or contract and is carried out by automated means;
- withdraw consent at any time where processing is based on consent; and
- not be subject to a solely automated decision producing legal or similarly significant effects. As explained in Section 5, we do not take such decisions.
Where we act as a processor on behalf of a customer, including for uploaded content, please send rights requests to that organisation as the controller. We will assist them as the Data Processing Agreement requires.
To exercise your rights, contact us using the details in Section 14. We answer within one month, and may extend that by two further months for complex requests, in which case we tell you why within the first month (Article 12(3) GDPR). We do not charge a fee unless a request is manifestly unfounded or excessive, and we may ask for information to confirm your identity.
You can also complain to a supervisory authority. Ours is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also complain to the authority in the country where you live or work.
13. Children
The platform is a business tool intended for organisations and their staff. It is not directed at children and we do not knowingly collect personal data from them. In the Netherlands the age limit for a child's own consent under Article 8 GDPR is 16.
14. How to contact us
For any question about this policy or about how we handle your personal data, or to exercise your rights, contact our privacy contact.
| Channel | Detail |
|---|---|
Post | Clarety B.V., attn. privacy contact, Zuideinde 50A, 1121 CM Landsmeer, Netherlands |
Documents on request | Data Processing Agreement and the current sub-processor list, via trust@gencompl.ai |
If your question concerns data that your employer or another organisation uploaded into the platform, contact that organisation first. They are the controller, and we support them with your request.