GibComply

Privacy Policy

Last updated: 5 September 2026

Who is responsible for your data

GibComply plays two different roles, and the difference matters for your rights. • For your account itself - your name, email address, sign-in credentials, and the record of your use of the product - GibComply is the controller. We decide why and how that data is processed. • For the operator data you enter into the platform - licences, regulated individuals, suppliers, marketing records, substance evidence, board minutes, reports and the audit log - your organisation is the controller and GibComply is the processor. We hold and process that data on your instructions, for the purpose of running your compliance register, and for no other purpose. • For a GOSS readiness assessment or an access request submitted on the public site, GibComply is the controller. That data is submitted to us directly, before any account exists.

What we collect

Account information (name, email address, hashed password, and any two-step sign-in factor you enrol) and the operator data you enter into the platform: corporate licence details, regulated individuals, vendor and supplier records, marketing campaigns, affiliate partners, substance documents, calendar events, board minutes, attestations, and reports. We also store an immutable audit log of every change made within your account, and any files you upload (substance documents). If you complete the public GOSS readiness assessment, we store the answers you gave, the resulting gap list, and the contact details you provided. If you request access to the private beta, we store your name, email address, organisation, and anything you chose to tell us.

How your data is stored

All data is stored in a PostgreSQL database hosted by Supabase with Row-Level Security (RLS) enforcing strict tenant isolation - one operator's data is never accessible to another. Uploaded files are held in private Supabase Storage buckets. OAuth refresh tokens (for calendar sync) are encrypted with AES-256-GCM before storage. All connections use TLS.

Where your data is processed

GibComply runs on Supabase and Vercel, each of which operates in a specific region chosen when the deployment was created. We will tell you the exact regions on request, and we will tell you in advance if they change. We do not claim that all processing takes place in Gibraltar, the United Kingdom or the European Economic Area. Our subprocessors are established in several jurisdictions, and any transfer outside the EEA is made on the terms those providers publish for it. If your own regulatory position depends on where data is held, ask us before you enter data, rather than relying on an assumption.

Subprocessors

We use the following third-party services to operate GibComply: • Supabase (Supabase Inc) - database hosting, authentication, and file storage. • Vercel (Vercel Inc) - application hosting, serverless functions, and scheduled jobs. • Resend (Resend Inc) - transactional email delivery (deadline alerts, invitations). • Anthropic (Anthropic PBC) - AI-assisted features: the in-app help assistant, licensing determination adjudication, and application narrative drafting. Used only when the relevant feature is enabled for your workspace. The assistant receives your question and any file you attach to it. If you choose to ask for a scope group, it also receives that group's confirmed company profile: facts about the companies (activities, licences, jurisdictions, which entity performs which function), not about any person. None of this is stored by GibComply. • Firecrawl (Mendable Inc) - URL content extraction for the regulatory change monitor. • Google (Google LLC) - Calendar API, for syncing deadlines to Google Calendar (optional, and only if you connect it). • Microsoft (Microsoft Corporation) - Microsoft Graph, for syncing deadlines to Outlook Calendar (optional, and only if you connect it). • Sentry (Functional Software Inc) - error monitoring and performance tracking. Calendar sync sends the deadline title, date and description to the provider you connected. It does not send licence numbers, uploaded documents, individuals' details or audit records.

Data retention

Your account data is retained for as long as your account is active. Audit logs are retained indefinitely as they form part of the compliance record. You may request deletion of your account and all associated data at any time (see Your Rights below). Backups are retained for up to 30 days after deletion. Assessment submissions and access requests are retained while we are still in contact with you about them, and deleted on request.

Your rights

Gibraltar's data protection regime - the Gibraltar GDPR, given effect by the Data Protection Act 2004 - gives you the right to: • Access - request a copy of all personal data we hold about you. • Rectification - correct any inaccurate or incomplete data. • Erasure - request deletion of your data (subject to legal retention obligations). • Portability - receive your data in a structured, machine-readable format. • Object, and to restrict processing, in the circumstances the legislation provides for. • Withdrawal of consent - where processing is based on consent, withdraw it at any time. Where GibComply is the processor rather than the controller - that is, for the operator data inside a workspace - direct your request to the organisation whose workspace it is. If you send it to us, we will pass it on to them and support them in answering it.

How to complain

If you are not satisfied with how we have handled your personal data, you can complain to the Gibraltar Regulatory Authority, which supervises data protection in Gibraltar. You can also raise it with us first - we would rather hear it directly.

Cookies

GibComply uses only functional cookies required for authentication (Supabase session cookies) and a short-lived cookie that protects the calendar OAuth flow from cross-site request forgery. We do not use advertising or tracking cookies. Vercel Analytics collects privacy-friendly, aggregated usage data without cookies.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notification. The date at the top of this page reflects the last update.