CoComply Application Privacy Policy
CoComply Application Privacy Policy
Effective Date: March 4, 2026
Last Updated: March 4, 2026
Version: 1.0
1. Introduction
This Privacy Policy applies specifically to the CoComply Application, the compliance and data governance platform accessed by authorized users of our client organizations.
Who This Policy Applies To: Employees, contractors, and authorized representatives of client organizations (collectively "Application Users") who access the CoComply platform to perform compliance and data governance activities.
What This Policy Does NOT Cover: This policy does not apply to client business data or end-customer data processed through our platform. Such data is governed by separate Data Processing Agreements (DPAs) with our clients. For information about our website privacy practices, please see our separate Website Privacy Policy.
1.1 CoComply's Role as Data Processor and Controller
- Data Processor for Client Business Data: CoComply acts as a Data Processor for all business data, documents, policies, compliance records, and confidential information uploaded by clients. We do not access, use, or process this data except as explicitly instructed by our clients.
- Data Controller for Application Telemetry: CoComply acts as a Data Controller for limited usage telemetry and technical performance data collected from Application Users. This policy governs how we collect and use this telemetry data.
1.2 Our Commitment to Data Separation
CoComply operates a single-tenant architecture where each client's data is completely isolated in separate database instances. We are contractually and technically prohibited from accessing client business data for any purpose other than providing technical support as explicitly requested by the client.
2. Information We Collect from Application Users
2.1 User Identification and Authentication Data
When you access the CoComply application, we collect:
- User Account Information: Username, email address, role/designation, organization affiliation
- Authentication Data: Login timestamps, session duration, authentication method used (password, SSO, MFA)
- Security Events: Failed login attempts, password reset requests, account lockouts, suspicious activity alerts
Purpose: User authentication, security monitoring, access control, and fraud prevention.
2.2 Application Usage and Performance Data (Telemetry)
We collect limited telemetry data about how you interact with the application:
- Feature Usage: Which features and modules you access (e.g., policy management, audit trails, dashboard views), buttons clicked, screens viewed, workflow completion rates
- Session Data: Session start/end times, session duration, frequency of application use, time of day patterns
- Navigation Patterns: Page transitions, menu selections, search queries within the application interface, filter configurations
- Performance Metrics: Page load times, API response times, error messages encountered, system timeouts, crash reports
- Interaction Data: Configuration changes you make to application settings (not the content of your work), export requests, report generation activity
Purpose: Product improvement, performance optimization, bug detection, and user experience enhancement.
2.3 Technical and Device Data
We automatically collect technical information about your device and connection:
- Device Information: Device type (desktop, mobile, tablet), operating system and version, screen resolution
- Browser Information: Browser type and version, language preferences, time zone
- Network Information: IP address, ISP, general geographic location (city/country level)
- Application Version: Version of CoComply application you are using
Purpose: Technical support, compatibility testing, security monitoring, and infrastructure optimization.
2.4 What We Do NOT Collect
Client Business Data: We do not collect, access, read, or process any of the following:
- Documents, policies, or compliance records you upload or create
- Audit findings, risk assessments, or compliance status information
- Comments, notes, or annotations you add to records
- Client names, customer lists, or business relationships
- Financial data, transaction records, or account information
- Any confidential or proprietary information belonging to your organization or its customers
Content vs. Metadata: Our telemetry captures that you accessed a feature (e.g., "User opened Policy Management module"), but never captures what you did within that feature (e.g., the content of policies you created or edited).
Bank Customer Data: We do not collect or process any personal information about your organization's customers, such as bank account holders, loan applicants, or other end-customers of financial institutions.
Sensitive Personal Information: We do not intentionally collect sensitive personal information such as health data, financial account details, social security numbers, racial or ethnic origin, political opinions, religious beliefs, or biometric data.
3. How We Use Application Telemetry Data
3.1 Permitted Uses
We use application telemetry data solely for the following purposes:
- Product Improvement: Identifying frequently used features, understanding user workflows, prioritizing development efforts based on actual usage patterns
- Performance Optimization: Monitoring system performance, identifying bottlenecks, improving response times, optimizing database queries
- Bug Detection: Identifying errors, crashes, and technical issues; reproducing and resolving bugs reported by users
- Security Monitoring: Detecting suspicious activity, unauthorized access attempts, potential security threats, and anomalous behavior patterns
- User Experience: Understanding navigation patterns to improve interface design, simplifying complex workflows, reducing friction points
- Feature Planning: Determining which features provide value to users and which require enhancement or deprecation
- Technical Support: Diagnosing and resolving technical issues reported by Application Users or their administrators
- Compliance Reporting: Demonstrating to clients that their users are actively engaging with compliance workflows (aggregate statistics only)
3.2 Prohibited Uses
We explicitly do NOT:
- Use application telemetry data for marketing, advertising, or promotional purposes
- Share or sell application telemetry data to third parties for their commercial purposes
- Use telemetry data to make employment-related decisions about individual Application Users
- Use telemetry data to profile individual users for purposes other than security monitoring
- Access, analyze, or derive insights from client business data stored in the application
- Combine telemetry data with client business data to create derived datasets
4. Data Sharing and Disclosure
4.1 Sharing with Client Organizations
Your employer or client organization (the "Client") may request aggregate usage statistics about their organization's use of the CoComply platform. We may provide:
- Aggregate login frequency and session duration statistics
- Feature adoption rates across the organization
- Overall system performance metrics
- Compliance workflow completion rates (aggregate, not individual)
Individual-level data: We will only share individual user activity data with your organization if explicitly authorized in our contract with them or required by law.
4.2 Third-Party Service Providers
We share limited telemetry data with trusted service providers who perform services on our behalf.
Processor Obligations: All service providers are contractually required to:
- Process data only according to our documented instructions
- Implement appropriate technical and organizational security measures
- Maintain strict confidentiality of all data
- Assist us in responding to data subject rights requests
- Notify us immediately of any data breaches or security incidents
- Delete or return data upon termination of services
4.3 Legal and Regulatory Disclosure
We may disclose telemetry data when required by law or in good faith belief that disclosure is necessary to:
- Comply with legal obligations, court orders, subpoenas, or regulatory requirements
- Protect the rights, property, or safety of CoComply, our clients, or Application Users
- Investigate suspected fraud, security incidents, or violations of our Terms of Service
- Respond to lawful requests from government authorities, law enforcement, or regulatory bodies
- Enforce our contractual rights or defend against legal claims
Notice: Where legally permitted, we will notify affected Application Users and/or their client organizations before disclosing data to authorities.
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, telemetry data may be transferred to the acquiring entity. Any such transfer will be subject to:
- Continuation of the same privacy protections described in this policy
- Notice to affected Application Users and client organizations
- Opportunity to exercise data deletion rights prior to transfer (where feasible)
4.5 No Sale of Data
We do not sell, rent, lease, or trade Application User telemetry data to third parties under any circumstances.
5. Data Retention and Deletion
5.1 Retention Periods for Telemetry Data
- Session logs and usage data: 90 days (Performance monitoring)
- Error logs and crash reports: 180 days (Bug troubleshooting)
- Security logs: 1 year (Security audits and compliance)
- Authentication logs: 1 year (Forensic investigation)
- Aggregated analytics: Indefinite (Anonymized trend analysis)
5.2 Automated Deletion
Telemetry data is automatically purged from our systems when the retention period expires. This process is:
- Automated and runs on a scheduled basis (weekly)
- Irreversible, deleted data cannot be recovered
- Logged and auditable for compliance purposes
- Applied consistently across all client environments
5.3 Client Business Data Retention (Our Role as Processor)
Client business data stored in the CoComply application is retained according to the terms of our Data Processing Agreement with each client. Upon contract termination:
1. Export Period (30 days): Clients have 30 days to export all their data from the platform
2. Secure Deletion (Day 31): All client data is securely deleted from production systems using cryptographic erasure
3. Backup Retention (60 additional days): Encrypted backups are retained for disaster recovery purposes, then permanently destroyed
4. Deletion Certification: Upon request, we provide written certification of data deletion
5.4 User-Initiated Deletion
If your organization's contract with CoComply terminates, your associated telemetry data will be deleted according to the schedule in Section 5.3. Individual Application Users cannot independently request deletion of telemetry data while their organization remains an active client, as this data is necessary for service delivery and security monitoring.
6. Data Security
6.1 Technical Security Measures
CoComply implements comprehensive security controls to protect Application User data:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3 with perfect forward secrecy
- Encryption at Rest: All data stored in databases and file systems is encrypted using AES-256 encryption
- Single-Tenant Architecture: Complete logical and physical data isolation between clients; each client has dedicated database instances
- Access Controls: Role-based access control (RBAC) with principle of least privilege; multi-factor authentication (MFA) required for all administrative access
- Network Segmentation: Application infrastructure segmented into security zones with strict firewall rules
- Intrusion Detection: Real-time monitoring for suspicious activity, unauthorized access attempts, and anomalous behavior
- Vulnerability Management: Regular vulnerability scanning, penetration testing, and security patching
- Secure Development: Code reviews, static application security testing (SAST), and dependency scanning
6.2 Organizational Security Measures
- Security Training: All employees receive annual security awareness training and role-specific security training
- Background Checks: Employee background verification and signing of confidentiality agreements
- Access Management: Strict controls over who can access production systems; all access logged and audited
- Incident Response: Documented incident response procedures with defined escalation paths and notification protocols
- Vendor Management: Security assessments of all third-party service providers; contractual security requirements
- Change Management: Formal change approval process for production systems with security review
6.3 Physical Security
- Application infrastructure hosted in AWS data centers with:
- 24/7 physical security monitoring and guards
- Biometric access controls and multi-factor authentication
- Environmental controls (fire suppression, climate control, backup power)
- Physical access logging and audit trails
- CoComply office access restricted to authorized personnel with badge-based entry systems
6.4 Security Audits and Certifications
- SOC 2 Type II audit (Security, Confidentiality, and Privacy criteria), annual
- ISO 27001:2013 Information Security Management certification (in progress)
- Annual third-party penetration testing
- Quarterly vulnerability assessments
6.5 Data Breach Notification
In the unlikely event of a data breach affecting Application User data, we will:
1. Contain and remediate the breach immediately
2. Notify affected client organizations within 72 hours of discovery
3. Notify affected Application Users within 72 hours (if contact information is available)
4. Notify relevant supervisory authorities as required by applicable law
5. Provide detailed information about the nature of the breach, data affected, and remediation steps
6. Offer assistance to affected individuals (e.g., credit monitoring if financial data exposed)
7. Your Rights and Choices
7.1 Rights Under Data Protection Laws
Depending on your location, you may have the following rights regarding your telemetry data:
- Right to Access: Request a copy of the telemetry data we hold about you
- Right to Rectification: Request correction of inaccurate user account information
- Right to Erasure ("Right to be Forgotten"): Request deletion of your telemetry data (subject to legal retention requirements and operational necessity)
- Right to Restrict Processing: Request that we limit how we process your data
- Right to Data Portability: Receive your telemetry data in a structured, machine-readable format
- Right to Object: Object to processing of your data based on legitimate interests
- Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.2 Exercising Your Rights
To exercise any of these rights, please contact us at:
Email: privacy@cocomply.ai
Subject Line: Application User Data Rights Request
Include: Your full name, email address, organization name, and specific request
Verification: We may request additional information to verify your identity before processing requests. This is to protect your data from unauthorized access.
Response Time: We will acknowledge your request within 5 business days and provide a substantive response within 30 days. For complex requests, we may extend this period by an additional 30 days with written notice.
No Fee: Exercising these rights is free of charge, unless requests are manifestly unfounded or excessive.
7.3 Limitations on Rights
Certain rights may be limited in the following circumstances:
- Legal Obligations: We may be required to retain certain data to comply with legal or regulatory requirements (e.g., security logs for audit purposes)
- Operational Necessity: Some telemetry data is essential for providing the service securely and cannot be deleted while your organization remains a client
- Aggregated Data: Once data has been anonymized and aggregated, it may no longer be considered personal data and cannot be retrieved or deleted
- Client Organization Control: Your employer/client organization may have certain rights that supersede individual user rights under our contract with them
7.4 Contacting Your Organization
For requests related to your account access, role permissions, or business data (as opposed to telemetry data), please contact your organization's CoComply administrator or IT department. We process this data on behalf of your organization and must follow their instructions.
8. International Data Transfers
8.1 Data Location
CoComply is based in India. Application telemetry data may be transferred to, stored in, and processed in:
- India: Primary corporate operations
- United States: AWS cloud infrastructure (us-east-1, us-west-2 regions)
- Other AWS Regions: As specified in client contracts for data residency requirements
8.2 Transfer Safeguards
When we transfer personal data internationally, we implement appropriate safeguards:
- Standard Contractual Clauses (SCCs): European Commission-approved SCCs for transfers from EEA/UK to non-adequate countries
- Data Processing Agreements: Contractual commitments regarding security, confidentiality, and data subject rights
- Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Strict limitations on who can access data from which geographic locations
- Local Data Residency Options: For clients with regulatory requirements, we offer deployment in specific AWS regions
8.3 Compliance with Regional Laws
- GDPR (EU/EEA/UK): Full compliance with GDPR requirements for lawful basis, data subject rights, and international transfers
- India DPDP Act 2023: Compliance with India's Digital Personal Data Protection Act
- CCPA (California): Compliance with California Consumer Privacy Act requirements
- Sector-Specific Regulations: Additional compliance measures for banking and financial services clients (e.g., RBI guidelines in India)
9. Children's Privacy
The CoComply application is intended for use by adult professionals in business environments. We do not knowingly collect personal information from individuals under the age of 18.
If we become aware that an Application User is under 18, we will take steps to delete their account and associated data promptly. If you believe a minor has accessed the application, please contact us immediately at privacy@cocomply.ai.
10. Changes to This Privacy Policy
10.1 Update Notifications
We may update this Privacy Policy from time to time to reflect:
- Changes in our data processing practices
- New features or services
- Changes in applicable laws or regulations
- Feedback from users, auditors, or regulators
10.2 Notice of Material Changes
For material changes that affect your rights or how we use your data, we will provide notice through:
- Email notification to your registered email address (at least 30 days in advance)
- Prominent in-application banner or notification
- Notice to your organization's primary contact
10.3 Acceptance of Changes
Continued use of the CoComply application after the effective date of changes constitutes acceptance of the updated Privacy Policy. If you do not agree with changes, you may request account deactivation through your organization's administrator.
The "Last Updated" date at the top of this policy reflects the date of the most recent revision.
11. Contact Information
11.1 Privacy Inquiries
For questions, concerns, or requests regarding this Privacy Policy or our privacy practices:
CoComply Technologies Private Limited
Privacy Contact Email: privacy@cocomply.ai
Subject Line: Application Privacy Inquiry
Address: 169 West 2710 South Circle Suite 202A
St. George, UT 84790
11.2 Data Protection Officer
DPO Email: dpo@cocomply.ai
DPO Name: Vamsi Kunaparaju (primary), Chaitanya Kanumuri (backup)
11.3 Response Timeframes
- General privacy inquiries: 5 business days
- Data subject rights requests: 30 days (may be extended to 60 days for complex requests)
- Security incident notifications: Within 72 hours of discovery
12. Supervisory Authorities
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the relevant data protection authority:
For EU/EEA residents:
Contact your local Data Protection Authority, List of EU DPAs
For UK residents:
Information Commissioner's Office (ICO), www.ico.org.uk
Phone: 0303 123 1113
For California residents:
California Attorney General's Office, oag.ca.gov/privacy
Appendix: Definitions
Application Users: Employees, contractors, or authorized representatives of CoComply client organizations who have been granted access to the CoComply platform.
Client Business Data: All data, documents, policies, records, and information uploaded to or created within the CoComply application by clients. This data is owned and controlled by the client, and CoComply acts as a Data Processor with respect to this data.
Data Controller: The entity that determines the purposes and means of processing personal data. CoComply acts as Data Controller for Application User telemetry data.
Data Processor: The entity that processes personal data on behalf of and according to the instructions of the Data Controller. CoComply acts as Data Processor for Client Business Data.
Personal Data / Personal Information: Any information relating to an identified or identifiable natural person, including name, email address, IP address, device identifiers, and usage patterns.
Single-Tenant Architecture: A software architecture model where each client organization has a completely isolated and dedicated instance of the application infrastructure, including separate databases, ensuring no data commingling between clients.
Telemetry Data: Technical and usage information automatically collected when Application Users interact with the CoComply platform, strictly limited to application performance metrics, feature usage patterns, and technical diagnostics. Telemetry data does NOT include the content of client business data.
Acknowledgment: By accessing and using the CoComply application, you acknowledge that you have read, understood, and agree to be bound by this Application Privacy Policy.