1. Who we are
Compliance Locker("Compliance Locker," "we," "us," or "our") operates the website compliancelocker.app and associated applications (the "Service"). For purposes of applicable data protection law, Compliance Locker is the controller of personal data described in this policy unless we act as a processor on behalf of your organization under a separate agreement.
Privacy inquiries and data subject requests: support@compliancelocker.app.
2. Scope
This policy applies to visitors, registered users, collaborators, and recipients who access shared content through Compliance Locker. It does not apply to third-party websites or services you may access through links we do not control.
3. Zero-knowledge design (important)
Compliance Locker uses client-side cryptography. Your master password, derived vault keys, and plaintext document contents are processed in your browser. We do not receive or store your master password in readable form.
We store encrypted file payloads, wrapped encryption keys, encrypted metadata, and operational records needed to run the vault. In ordinary operation we cannot decrypt your document contents without keys and credentials that remain under your control.
Zero-knowledge architecture reduces our access; it does not eliminate all personal data processing. Account, security, and audit data described below are still processed by us and our infrastructure providers.
4. Personal data we process
Account and identity data: email address; internal user identifier; password verifier derived from your master password (not the password itself); per-user cryptographic salt; RSA public key; encrypted private key material and associated IV values required for collaboration.
Vault and sharing data: file identifiers; encrypted filenames and file metadata; storage object keys; folder markers; share tokens; collaborator relationships; encrypted file encryption keys; expiration settings for share links; creation and update timestamps.
Audit and security data: action types (such as UPLOAD, VIEW, SHARE, DELETE); UTC timestamps; pseudonymized actor identifiers (hashed user or session identifiers); pseudonymized network identifiers (hashed IP data). Audit records may persist after a file record is deleted because the ledger is designed to be insert-only for traceability.
Technical and support data: session cookie values; browser and device information in server logs; error diagnostics; communications you send to support.
We do not intentionally collect government ID numbers, payment card data, or special categories of personal data through the core Service. If you upload such information inside encrypted files, you are responsible for lawful basis, notices, and safeguards applicable to that content.
5. How we use personal data
- Provide, operate, secure, and maintain the Service
- Authenticate users and manage sessions
- Store and deliver encrypted content you upload or receive
- Enable sharing, collaboration, audit trails, and exports
- Detect abuse, fraud, and security incidents
- Respond to support requests and legal demands
- Improve reliability and performance
- Enforce our Terms of Service and protect rights and safety
We do not sell personal information. We do not use document contents for advertising or automated model training. We do not use cookies for cross-context behavioral advertising.
6. Legal bases (EEA, UK, and similar jurisdictions)
Where GDPR or equivalent laws apply, we rely on:
- Contract: processing necessary to provide the Service you request
- Legitimate interests: security monitoring, fraud prevention, service improvement, and defending legal claims, balanced against your rights
- Legal obligation: compliance with applicable law and lawful requests
- Consent: where required for optional communications or non-essential technologies
7. How we disclose information
Infrastructure providers: we use subprocessors for application hosting, managed PostgreSQL database services, and Cloudflare R2-compatible object storage. These providers process data on our instructions under contractual safeguards. Encrypted file blobs are not meaningfully readable by those providers without your cryptographic keys. See our subprocessor list page for the current list.
Legal and safety: we may disclose information if we believe disclosure is required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Compliance Locker, our users, or others.
Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, data may be transferred subject to this policy and notice where required by law.
8. International transfers
We and our subprocessors may process data in countries other than your own, including the United States and other regions where our providers operate. Where required, we implement appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
9. Retention
We retain personal data for as long as needed to provide the Service, comply with law, resolve disputes, and enforce agreements. Account data is retained while your account remains active. Audit records may be retained after file deletion to preserve an immutable compliance trail. Server and provider backups may retain copies for limited periods under their retention schedules.
To delete your account and associated vault metadata, use Vault Settings → Delete Account in the application, or email support@compliancelocker.app. We will delete or anonymize data we control where we have no lawful reason to retain it. We may retain audit ledger entries, security logs, and information required for legal compliance even after account closure. Encrypted blobs without accessible keys may remain cryptographically inaccessible.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port personal data, and to withdraw consent where processing is consent-based. You may also lodge a complaint with a supervisory authority in your country of residence or workplace.
Because we cannot decrypt your documents, access requests may be limited to account, metadata, and log data we actually hold in identifiable form. We will respond to verified requests within the timeframe required by applicable law, typically within 30 days.
Submit requests to support@compliancelocker.app. We may need to verify your identity before fulfilling a request.
11. California privacy notice
If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the CPRA, including rights to know, delete, correct, and opt out of certain processing. Compliance Locker does not sell or share personal information for cross-context behavioral advertising as those terms are defined under California law.
To exercise California privacy rights, contact support@compliancelocker.app, or delete your account from Vault Settings in the application. We will not discriminate against you for exercising these rights.
12. Security
We use administrative, technical, and organizational measures including TLS encryption in transit, signed HTTP-only session cookies, access controls, and audit logging. No system is perfectly secure. You are responsible for safeguarding your master password, recovery materials, devices, and share links. See our Security overview.
13. Children
The Service is intended for adults and business use. It is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us and we will take appropriate steps to delete it.
14. Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will change when we do. Material changes will be posted on this page. Where required by law, we will provide additional notice. Continued use after the effective date constitutes acceptance where permitted.
15. Contact
Compliance Locker · compliancelocker.app
Email: support@compliancelocker.app