Privacy notice
How ComplAIOS currently handles account, organisation and compliance-workspace information.
Draft issued 29 July 2026
What this draft covers
ComplAIOS is operated by Toplorgical Ltd. This draft describes the production platform as currently built and must be approved by Nigerian and UK counsel before public self-service launch.
Information handled
- Account and security information, including name, work email, authentication events and multi-factor authentication state.
- Organisation profile, regulator, branch, product and compliance-owner information entered during onboarding.
- Compliance records, tasks, evidence, assessments, findings, reports and audit history created in a customer workspace.
- Billing, usage and support records required to operate the service.
Why it is used
- To create and secure accounts and tenant-isolated workspaces.
- To provide contracted compliance, reporting, workflow, billing and support functions.
- To protect the platform, investigate faults and retain an auditable history.
- To process AI requests only when an authorised user invokes an enabled AI capability.
Storage, providers and retention
The production service uses Supabase for authentication and data services and Vercel for application hosting. Approved AI requests use the configured model provider through server-side controls. Final processor, international-transfer and retention wording remains subject to legal review and the executed customer agreement.
Tenant data is separated by row-level security. Audit records are intentionally append-only. Retention and deletion requests must therefore be assessed against contractual, regulatory and evidential obligations.
Rights and enquiries
A customer may use its named Toplorgical account contact to request access, correction, export, restriction or deletion review. A public privacy contact and response timetable must be approved before unrestricted public launch.