Data Processing Addendum
A plain-English summary of how ComplyMo processes personal data on your behalf. It forms part of our agreement when you use the service.
Last updated August 2026
This Data Processing Addendum ("DPA") supplements our Terms of Service and applies where ComplyMo processes personal data on your behalf. It is written as a readable summary; it is not a substitute for legal review of your own obligations. As always, ComplyMo provides compliance tooling, not legal advice.
1. Roles of the parties
For personal data processed through the widget on your site, you are the controller and ComplyMo is the processor. You decide why and how that data is processed; we process it only to provide the service and on your documented instructions, which include these terms and your configuration choices.
2. Scope and subject matter
The subject matter is the provision of the ComplyMo compliance widget. Processing lasts for the duration of your subscription and any wind-down period. The nature and purpose of processing is to record and honor end-visitor consent decisions and to provide accessibility and cookie-management functions.
3. Details of processing
- Categories of data subjects — the end-visitors to your website.
- Types of personal data — pseudonymous identifiers and the consent decisions associated with them, plus limited technical data needed to deliver the widget.
- Purpose — to store and apply consent preferences and operate the widget.
4. Sub-processors
You authorize ComplyMo to engage sub-processors — including cloud hosting, payment processing (Stripe), and email delivery — to help provide the service. We bind each sub-processor to data-protection obligations no less protective than those in this DPA, and we remain responsible for their performance. We maintain a current list and will give notice of material changes so you can object on reasonable grounds.
5. Security measures
We apply industry-standard security practices appropriate to the risk, including encryption in transit, access controls, network protections, and regular review. We limit access to personal data to personnel who need it and who are bound by confidentiality.
6. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate technical and organizational measures in responding to end-visitor requests to exercise their rights — such as access, correction, or deletion — where you cannot address them through the dashboard yourself.
7. Personal data breach notification
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and provide the information reasonably available to help you meet your own notification obligations.
8. Audit
On reasonable request and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA and will contribute to audits conducted by you or an auditor you appoint, in a manner that does not compromise the security or confidentiality of other customers.
9. Deletion or return on termination
On termination of the service, we will delete or return the personal data we process on your behalf, at your choice, except where we are required by law to retain it. Residual copies in routine backups are deleted in the ordinary course.
10. International transfers
ComplyMo is based in the United States, and personal data may be transferred to and processed there or in other countries where we or our sub-processors operate. Where required, such transfers are governed by appropriate safeguards, including the Standard Contractual Clauses (SCCs), which are incorporated by reference where they apply.
11. Contact
For DPA questions or to raise a data-protection matter, email privacy@complymo.com.

