Privacy Policy

Last updated: March 2026

1. Who We Are

Compliora is operated by Penguin Alley, founded by Luis Gerardo Rodríguez García, based in Monterrey, NL, Mexico. When we say “we,” “us,” or “our,” we mean Penguin Alley and its products.

2. Information We Collect

  • Account data: email address, full name, professional title, and organization name provided during registration.
  • Decision records: the AI decision descriptions, rationale, compliance analysis results, and attachments you create within the platform.
  • Usage data: page views, feature usage, and performance metrics collected via standard analytics.
  • Payment data: processed securely by Stripe. We never store credit card numbers on our servers.

3. How We Use Your Information

  • To provide, maintain, and improve the Compliora service.
  • To process payments and manage subscriptions via Stripe.
  • To generate AI-powered compliance analysis using Anthropic's Claude API. Decision record content is sent to the Claude API for analysis and is subject to Anthropic's usage policies.
  • To send transactional emails (account confirmation, billing receipts).
  • To respond to support requests.

4. Data Storage and Security

Your data is stored in Supabase (hosted on AWS). We use row-level security (RLS) to ensure organizations can only access their own data. All records are integrity-protected with SHA-256 hashes upon finalization.

We use HTTPS for all data transmission. Authentication is handled via Supabase Auth with secure session management.

5. Third-Party Services

  • Supabase: database, authentication, and file storage.
  • Stripe: payment processing and subscription management.
  • Anthropic (Claude API): AI-powered compliance analysis.
  • Vercel: application hosting and CDN.

6. Data Retention

We retain your account data and decision records for as long as your account is active. You can export all your data at any time via PDF or JSON exports. Upon account deletion, we remove your data within 30 days.

7. Your Rights

You have the right to:

  • Access and export your data.
  • Correct inaccurate personal information.
  • Request deletion of your account and data.
  • Object to data processing where applicable.

For GDPR and data protection inquiries, contact us at the email below.

8. Cookies

We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of significant changes via email.

10. Contact

For privacy-related questions, contact: privacy@penguinalley.com