Skip to content
ComplyMynt

Legal

Privacy Policy

What we collect, why we collect it, how long we keep it, and the rights you can exercise at any time.

This Privacy Policy explains how ComplyMynt ("ComplyMynt", "we", "us") handles personal information collected through complymynt.com and in the course of delivering audit and remediation services. It applies to website visitors, prospective clients, and client contacts.

1. Information we collect

We collect only what we need to respond to you and deliver engagements:

  • Information you provide. Name, work email, role, optional phone number, company, product URL, company size, budget range, jurisdictions, services of interest, timeline, and the free-text details you submit through our contact form or by email.
  • Engagement information. Materials, URLs, documentation, and test accounts a client shares with us so we can perform an audit.
  • Technical information. IP address, device and browser type, referring page, and pages viewed. Analytics data is collected only where you have consented.
  • Consent records. Your cookie choices and the date they were made.

We do not knowingly collect information from children under 16 and we do not seek sensitive categories of personal information.

2. How we use information

  • Respond to audit requests and provide scope, timeline, and pricing.
  • Perform, document, and deliver audit and remediation services.
  • Administer contracts, invoicing, and records required for tax and legal purposes.
  • Secure the site, prevent abuse, and debug errors.
  • Send service and relationship communications. Where required, marketing email is sent only with consent and always includes a working unsubscribe mechanism.

4. How we share information

We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose information only to:

  • Service providers acting on our instructions (hosting, email delivery, document storage, analytics where consented), bound by confidentiality and data-processing terms.
  • Professional advisors, such as counsel and accountants, under duties of confidence.
  • Authorities or third parties where required by law, or to establish, exercise, or defend legal claims.
  • An acquirer in connection with a merger, financing, or sale of assets.

5. International transfers

We are a United States–based provider. Where personal information is transferred out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) together with supplementary technical and organizational measures. A copy of the relevant transfer mechanism is available on request.

6. Retention

  • Inquiry and contact-form data: up to 24 months from last contact.
  • Engagement records and deliverables: for the term of the engagement plus 7 years, or as otherwise agreed in the engagement letter.
  • Client-supplied evidence (logs, HAR files, screenshots): deleted or returned within 30 days of engagement close unless retention is expressly agreed.
  • Consent records: 24 months from the date of the choice.

7. Security

We enforce HTTPS/TLS in transit, encryption at rest with our storage providers, least privilege access, multi-factor authentication on administrative accounts, and confidentiality obligations for all personnel. No method of transmission or storage is perfectly secure; see our Trust Center for our current practices and responsible disclosure process.

8. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, to object to processing, and to withdraw consent. California residents (CCPA/CPRA) may request disclosure of the categories of personal information collected, request deletion or correction, and opt out of sale or sharing — ComplyMynt does not sell or share personal information as those terms are defined.

To exercise a right, email info@complymynt.com with the subject "Privacy Request". We verify requests using the email on file and respond within 45 days (extendable once where permitted). We will not discriminate against you for exercising a right. You may use an authorized agent, and you may lodge a complaint with your supervisory authority.

We honor Global Privacy Control (GPC) signals as an opt-out of non-essential cookies where your browser sends one.

9. Cookies

Non-essential cookies are off by default and load only after you opt in through our banner. You can change your choices at any time from the "Cookie settings" link in the footer. Full detail is in our Cookie Policy.

10. Controller and processor roles

ComplyMynt is the controller of information collected through this site and of client contact data. When we process personal data contained in a client's systems during an audit, we act as a processor (or service provider) on the client's documented instructions under a data processing agreement. Our standard DPA is available on request.

11. Changes and contact

We will update this policy when our practices change and will revise the "last updated" date above. Material changes will be highlighted on this page. Contact us at info@complymynt.com. ComplyMynt is a remote-first company operating from the United States.

Questions about this policy? Email info@complymynt.com or use our contact form.