Skip to content
Legal

Privacy Policy

Last updated October 1, 2026

Ankord Labs LLC ("Ankord Labs", "we", "us", "our") operates ComplyMo, a service that provides website tools and automated functionality to assist business customers with website accessibility-support, consent-management and website-content review functions. ComplyMo does not determine, certify or guarantee compliance with any law, regulation, standard or guideline, does not provide legal advice, and does not relieve customers of responsibility for their own websites, content, notices, consents or compliance practices. This policy explains what personal information we handle, why we handle it, who we share it with, and the choices and rights available to you.

A note on our two roles. Where a business customer uses ComplyMo in connection with its website or other Property, that customer or its client determines the purposes and means of the processing carried out for that Property. We act as a processor or sub-processor for Customer Data, including data relating to a Property or its End Users, that we handle solely to provide, secure or support the Service on the customer's instructions. We act as an independent controller for account information and limited information we use for our own administration, security, legal compliance or claims. This policy describes the personal information for which we determine the purposes and means of processing. If you are an End User of a customer's Property, please see Section 2.3.

1. Who we are and how to contact us

Ankord Labs LLC is a Delaware limited liability company with its principal office at 8549 Wilshire Blvd #5173, Beverly Hills, CA 90211, United States.

For any privacy question, request or complaint, contact privacy@complymo.com.

Data protection officer. We have not appointed a data protection officer. We keep under review whether Article 37 of the GDPR requires us to do so.

2. Information we collect

2.1 Information you provide

Account information: business email address, password in hashed form, workspace or organization information, subscription plan, billing identifiers and account preferences.

Billing information: billing contact, billing address, tax identifiers, subscription plan, billing status, trial end date and purchase history. Stripe processes payment-card details directly, and we do not receive or store complete card numbers.

Property and Service configuration: the web addresses and other information a customer configures for use with the Service, together with relevant schedules, exclusions or access settings.

Communications: support tickets, sales inquiries, survey responses, messages submitted through interactive Service features, and correspondence with us.

2.2 Information collected automatically

Service and device information: information generated through use of our application and services, including browser and device information, session information, and security and diagnostic information, to the extent applicable to the relevant activity.

Device and connection information: browser type and version, operating system, language settings and similar technical information reasonably necessary to operate, secure and support the Service.

Security and diagnostic information: authentication and session information, security events, and diagnostic logs.

Depending on the processing activity, we may handle service telemetry and security, diagnostic and operational information as a controller for our own business administration, security, legal compliance or claims, or as a processor or sub-processor when we handle it solely to provide, secure or support the Service on a customer's instructions.

2.3 Information generated through the Service

When a customer uses ComplyMo in connection with a Property, we may process Property configuration information, content made available through the Property, automated or AI-assisted review results, reports, messages submitted through interactive Service features, and related information necessary to provide the configured Service functions. That information may incidentally include personal information appearing in publicly available Property content or submitted by an account user. We process that information solely on the business customer's instructions and do not use it for an independent purpose. Automated outputs are intended to assist the customer's evaluation and do not determine or certify accessibility, legal compliance or any other outcome.

We may also process limited information relating to individuals who use a customer's Property, such as a pseudonymous identifier, interaction or consent choices, country, browser or device information, a configuration or policy version, and timestamps. The Service is not designed to store End User IP addresses or form-field content through these functions.

The customer, or the controller on whose behalf the customer acts, determines the purposes and means of this processing and is responsible for the privacy notice and choices applicable to its Property. If you are an End User of a customer's Property, please direct any privacy request or question to that customer or other controller. We will assist the customer with such requests as required by applicable law and our agreement with the customer.

This Section does not apply to personal information for which Ankord Labs independently determines the purposes and means of processing, such as account, billing, business-contact, support, security and administrative information. That information is addressed elsewhere in this policy.

2.4 Information from third parties

We may receive business contact information from our customers and partners and billing and fraud-prevention information from Stripe and other payment-related providers.

2.5 Cookies and similar technologies

We use strictly necessary cookies and similar technologies to authenticate users, maintain sessions, remember preferences and protect the security of the Service. We use Google Analytics on our public website and signup pages to understand website use; analytics is not used in the logged-in application. Visitors in the EEA, United Kingdom and Switzerland are asked to consent before analytics storage is enabled. In the United States, visitors may opt out, and we honor applicable browser-based opt-out signals. We do not use advertising cookies.

Where a customer deploys ComplyMo functionality on its Property, a cookie and browser local storage may record an End User's consent choice, a pseudonymous visitor identifier and accessibility-tool preferences in accordance with the customer's configuration. ComplyMo does not set advertising or analytics cookies on customer Properties. The customer remains responsible for the notices and choices required for its Property.

NAMEPROVIDERPURPOSEDURATIONCATEGORY
cw_sessionComplyMoMaintains an authenticated application sessionBrowser session, or 30 days if stay signed in is selectedStrictly necessary
cw_consent_[site ID]ComplyMoStores the visitor's cookie choice182 daysStrictly necessary
_gaGoogleDistinguishes visitors for website analyticsUp to 2 yearsAnalytics; subject to applicable consent or choice
_ga_[property ID]GoogleMaintains website analytics session stateUp to 2 yearsAnalytics; subject to applicable consent or choice

3. How and why we use information

The table below summarizes the purposes for which information is processed. Where Ankord Labs acts as a controller, the table identifies its legal basis under the GDPR. Where we process Customer Data, including information relating to a customer’s Property or its End Users, solely to provide, secure or support the Service, we do so on the customer’s instructions under the applicable agreement and Data Processing Addendum, and the customer determines the applicable legal basis.

PURPOSECATEGORIES USEDLEGAL BASIS OR PROCESSING ROLE UNDER THE GDPR
Create and administer accounts; authenticate usersAccount, device, securityPerformance of a contract, Art. 6(1)(b), where the individual is a party to the contract; otherwise legitimate interests, Art. 6(1)(f)
Provide and support configured Service functions, including website tools, automated functionality, reports and other Service outputsAccount information; Property and Service configuration; information generated through the ServicePerformance of a contract, Art. 6(1)(b), where the individual is a party to the contract; otherwise legitimate interests, Art. 6(1)(f); or, for Customer Data, processing on the customer's instructions
Secure the Service; detect, investigate and prevent abuseDevice, connection, usage, securityLegitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c); or the customer's instructions where processed on its behalf
Invoice and collect payment; prevent fraudAccount, billingPerformance of a contract, Art. 6(1)(b), where the individual is a party to the contract; legitimate interests, Art. 6(1)(f); or legal obligation, Art. 6(1)(c), as applicable
Provide support and respond to inquiriesAccount, communicationsPerformance of a contract, Art. 6(1)(b), where the individual is a party to the contract; otherwise legitimate interests, Art. 6(1)(f)
Send service and administrative noticesAccountPerformance of a contract, Art. 6(1)(b), where the individual is a party to the contract; otherwise legitimate interests, Art. 6(1)(f)
Operate, secure, improve, develop and troubleshoot the ServiceUsage, aggregated and de-identified dataLegitimate interests, Art. 6(1)(f)
Market to business contactsBusiness contact details, usageLegitimate interests, Art. 6(1)(f), or consent where required
Comply with legal obligations; establish, exercise or defend legal claimsAs relevantLegal obligation; legitimate interests

Our legitimate interests. Where we rely on legitimate interests, those interests are operating, administering and securing our business and the Service, preventing fraud and abuse, supporting and improving the Service, and communicating with business contacts. We consider the impact on individuals and do not rely on this basis where their interests override ours. You may object to processing based on legitimate interests as described in Section 8.

Automated decision-making. We do not make decisions producing legal or similarly significant effects concerning individuals based solely on automated processing.

Use of information for model training. We do not use customer personal information to train, fine-tune or develop machine learning models made available to third parties, and we contractually prohibit our providers from doing so.

4. When we share information

We share personal information in the following circumstances, and not otherwise:

Service providers and sub-processors. With providers that support our hosting, database, AI-assisted functionality, email delivery and related operations. Providers that process Customer Personal Data on a customer's behalf are identified on our sub-processor page and are bound by written agreements restricting their use of the information.

Payments. Stripe processes subscription payments and may act as our processor or as an independent controller for fraud prevention, payment compliance and its own legal obligations. Stripe's handling of personal information for its independent purposes is governed by its privacy notice.

Website analytics. We use Google Analytics to measure use of our public website and signup pages, subject to the choices described in Section 2.5. Google processes that information under its applicable data-processing and privacy terms.

Professional advisers. With lawyers, accountants, auditors and insurers, where necessary and subject to confidentiality.

Legal and safety. With courts, regulators, law enforcement and other authorities where we are legally required to do so, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of any person. We assess each request, disclose only what is legally required, and notify affected customers unless legally prohibited from doing so.

Corporate transactions. With a counterparty and its advisers in connection with a merger, acquisition, financing, reorganization or sale of assets, subject to confidentiality; and with the successor entity on completion, in which case we will notify affected individuals where required by law.

With your direction. Where you ask us to share information, for example by exporting a report.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.

5. International transfers

We are established in the United States and host the Service in the United States. Our providers may process personal information in the United States and other locations identified on our sub-processor page. If you are located in the EEA, the United Kingdom, Switzerland or Canada, your personal information will be transferred to, and processed in, the United States.

Where we transfer personal information out of the EEA, the United Kingdom or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss adaptations or another valid transfer mechanism, as applicable, together with supplementary technical, contractual and organizational measures. The applicable mechanism depends on the parties' roles and the transfer concerned and is described in our Data Processing Addendum. We maintain an assessment of the risks associated with these transfers.

You may request a copy of the relevant safeguards by contacting us at the address in Section 1.

6. How long we keep information

We keep personal information only for as long as necessary for the purposes described in this policy, after which we delete it or de-identify it.

CATEGORYRETENTION
Customer Data processed for a customerAs instructed by the customer and described in our DPA. Unless deleted earlier, End User consent records are retained for 24 months, tracker detection records for 90 days after the last detection, and automated review results for 12 months. Deletion is completed within 30 days after the applicable period ends.
Account informationFor the customer relationship and deleted within 30 days after account closure
Unconverted trial and abandoned signup information90 days after the trial ends or the signup is abandoned
Password-reset records24 hours after issue; reset links expire after one hour
Website analytics event data2 months
Hosting-provider runtime logs1 day or less
Database recovery historyUp to 7 days after deletion from active systems
Support and sales correspondence3 years from the last interaction
Billing and financial records7 years, or longer where tax or accounting law requires
Marketing suppression recordsAs long as needed to honor an opt-out or unsubscribe request

Where we are unable to delete information for technical reasons, we isolate it and protect it from further processing. We may retain data that has been aggregated and de-identified so that it does not identify and is not reasonably capable of being associated with a customer, property, user or individual. We maintain such data in aggregated and de-identified form and do not attempt to re-identify it.

7. Security

We maintain administrative, technical and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration and destruction, appropriate to the risk. These measures include encryption in transit, provider-managed encryption at rest, account and role-based access controls, tenant-level logical segregation, controls over production credentials, multi-factor authentication for administrative provider accounts, endpoint encryption and automatic screen locking. We may update our safeguards from time to time as the Service develops. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any relevant authority where required by law.

8. Your rights and choices

8.1 If you are in the EEA, the United Kingdom or Switzerland

You have the right to: access your personal information and receive a copy; have inaccurate information corrected; have information erased in certain circumstances; restrict processing in certain circumstances; receive information you provided to us in a portable format and have it transmitted to another controller; object to processing based on our legitimate interests, and to direct marketing at any time; and withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

You also have the right to lodge a complaint with your supervisory authority. We would welcome the chance to address your concerns first.

8.2 If you are a California resident

The categories of personal information we collect are described in Section 2, the sources in Section 2, the purposes in Section 3, the categories of recipients in Section 4, and retention in Section 6. You have the right to: know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it; delete personal information, subject to exceptions; correct inaccurate personal information; opt out of the sale or sharing of personal information, noting that we do neither; limit the use and disclosure of sensitive personal information, noting that we do not use sensitive personal information for purposes requiring this right; and not be discriminated or retaliated against for exercising any of these rights.

You may designate an authorized agent to make a request on your behalf, in which case we will require proof of authorization and may require you to verify your identity directly.

8.3 If you are a resident of another United States state with a comprehensive privacy law

You may have rights to access, correct, delete and obtain a portable copy of your personal information, to opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects, and to appeal a decision we make in respect of a request. To appeal, reply to our decision or contact us at the address in Section 1, and we will respond within the period required by applicable law and tell you how to contact your state attorney general if you remain dissatisfied.

8.4 If you are in Canada

Subject to applicable law, you may have the right to access personal information we hold about you, request correction of inaccurate information, and withdraw consent where processing is based on consent, subject to legal and contractual restrictions. You may also ask questions or challenge our privacy practices and complain to the Office of the Privacy Commissioner of Canada or the applicable provincial privacy regulator. For information we process on behalf of a business customer, see Section 2.3.

8.5 Making a request

Contact us at the address in Section 1. We will verify your request, which may require you to provide information sufficient to confirm your identity, and we will respond within the timeframe required by applicable law. We will not charge a fee unless your request is manifestly unfounded or excessive, in which case we will tell you before proceeding.

8.6 Marketing

You may opt out of marketing email at any time using the unsubscribe link in any marketing message, or by contacting us. We will continue to send service and administrative messages relating to your account.

9. Children

The Service is intended for business use by adults. We do not knowingly collect personal information directly from children under the age of 16. Information relating to a child may appear incidentally in content made available through a customer Property, in which case we process it solely on the customer's instructions. Requests concerning that information should ordinarily be directed to the customer or other controller responsible for the Property. If you believe a child has provided personal information directly to us, please contact us.

10. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page and revise the "last updated" date above. Where a change materially affects how we use personal information, we will provide advance notice to account holders and, where required, obtain consent.

11. Complaints

If you are dissatisfied with how we have handled your personal information or a request, contact us at the address in Section 1. If you remain dissatisfied, you may complain to your applicable supervisory authority or government regulator.

ComplyMo

Compliance, handled
in five minutes.

Accessibility, GDPR, and cookies. One script. One price. 14 days free.