Privacy Policy — ComplySquare
In effect from 25-Aug-2026
In effect from: 25-Aug-2026 Last updated: 25-Aug-2026
This policy is in effect from 25-Aug-2026. We review it periodically, and we will update this page when what we do changes. The sub-processor list and the storage-location statements below were verified against the live configuration on that date.
Company details (single source — update here and every reference below follows): Name: LeoPathway Solutions Address: LeoPathway Solutions, Sec 93A, Noida, Uttar Pradesh, India Contact email (all purposes — general, legal, privacy, security, grievances): hello@leopathway.com Grievance Officer: Aayush Jain
1. Who this policy is from, and what it covers
ComplySquare is operated by LeoPathway Solutions ("we", "us", "our"), at the address in the Company details above.
This policy explains what personal information we handle in connection with the ComplySquare website at complysquare.com and the ComplySquare platform (together, "the Service"), why we handle it, and the choices available.
It does not describe how a chartered accountancy firm using ComplySquare handles its own clients' information. For that, contact the firm directly.
2. Our two different roles — this distinction matters
(a) Information we decide about ("Account Information"). For information about the firms and individuals who use the Service — names, work email addresses, sign-in records, support correspondence, demo requests — we determine the purposes and means of processing. This policy governs that information.
(b) Information our customers decide about ("Customer Data"). Firms using the Service enter information about their own clients — client names, registration identifiers such as PAN, TAN and GSTIN, directors' and partners' details, filing statuses, notices, and related records. For that information, the firm decides what is collected and why; we process it only on the firm's instructions, to provide the Service.
In the language of India's Digital Personal Data Protection Act, 2023, the firm is the Data Fiduciary for Customer Data and we act as a Data Processor. If you are a client of such a firm and wish to exercise rights over your information, please contact that firm; we will support them in responding, but we cannot act on your request directly.
3. What we collect
From firms and their users: name, work email address, mobile number (where provided), role within the firm, firm name and address, authentication records, and preferences.
From use of the Service: sign-in and session events, actions taken within the application recorded in our audit log (including any support access), IP address, browser and device type, timestamps, and error diagnostics.
From the website: pages visited and basic technical information; and, where you submit a demo request or contact form, the name, work email, firm name and message you provide.
From email: delivery status of transactional emails we send (for example, whether an invitation was delivered or bounced).
Customer Data: as described in clause 2(b), entered by the firm. We do not collect it from any other source, and we do not enrich, buy or supplement it.
We do not knowingly collect information from anyone under 18. The Service is for professional use by businesses.
4. Why we handle it
- To create and administer accounts, authenticate users, and provide the Service.
- To send transactional messages — invitations, password resets, and service notices. (We do not send marketing email unless you ask us to, and you can opt out at any time.)
- To keep the Service secure: detect, investigate and prevent unauthorised access, abuse and fraud; maintain audit records of privileged and support access.
- To diagnose faults and improve reliability and performance.
- To respond to your enquiries and provide support.
- To meet legal, regulatory and tax obligations, and to establish, exercise or defend legal claims.
We do not sell personal information. We do not share it with advertisers. We do not use Customer Data to train machine-learning models for the benefit of other customers or third parties.
5. Cookies
We use strictly necessary cookies only — the session and security cookies required to sign you in and keep you signed in. We do not use advertising cookies, cross-site trackers, or third-party analytics that profile individuals. Blocking these cookies will prevent the Service from working.
6. Where information is stored and processed
The primary ComplySquare database is hosted in India (Mumbai region), and application servers are configured to run in the same region.
Some service providers we rely on operate outside India, so limited information may be processed abroad — specifically, error diagnostics (hosted in the European Union) and transactional email delivery. Where information is transferred outside India, we take reasonable steps to ensure it remains protected to a comparable standard, and we limit what is transferred: our error-monitoring pipeline is configured to strip identifiers such as email addresses, phone numbers, PAN, TAN and GSTIN before diagnostics leave the application.
7. Sub-processors
We use the following providers to deliver the Service. This list is current as at the "Last updated" date and may change; we will update this page when it does.
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase (on Amazon Web Services) | Database and authentication | India — Mumbai (ap-south-1) |
| Vercel | Application hosting and delivery | Serverless functions configured for Mumbai; global content delivery |
| Resend | Transactional email delivery | Outside India |
| Sentry | Error monitoring and diagnostics | European Union |
Each provider is engaged under its own terms, which include confidentiality and security obligations.
8. Sharing
We share personal information only:
- with the sub-processors listed above, to provide the Service;
- with your own firm — your administrators can see the membership and activity of their firm;
- with professional advisers (legal, accounting, insurance) under duties of confidentiality;
- where required by law, court order, or a lawful request from a public authority, or to protect our rights, property or safety, or those of our users or the public; and
- in connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.
9. Support access to your data
Our personnel do not routinely access Customer Data. Where support requires it, access is performed through an explicit, time-limited mechanism that is visibly flagged in the application and recorded in the audit log, showing who accessed what and when. Firms can review that record.
10. How long we keep information
- Customer Data: for as long as the firm's account is active. After termination, the firm may request an export within thirty (30) days; after that we delete Customer Data from active systems. Residual copies in encrypted backups are removed in the ordinary course of our backup rotation.
- Account Information: for as long as the account is active and thereafter as needed for legal, tax and record-keeping purposes.
- Audit and security logs: retained for a period appropriate to their security purpose.
- Demo requests and enquiries: retained for up to twenty-four (24) months unless you ask us to delete them sooner.
11. Security
We maintain reasonable technical and organisational measures appropriate to the Service, including: isolation of each firm's data enforced in the database itself rather than only in application code; encryption in transit and at rest; access control and least-privilege administration; audit logging of privileged and support access; automated daily backups retained on a rolling window; and monitoring of application errors.
No system can be guaranteed completely secure. We cannot and do not warrant that the Service will be free from unauthorised access. Your own practices — credential hygiene, device security, prompt removal of departed users, and the access decisions your administrators make — materially affect the security of your data.
If a security incident affecting personal information occurs, we will notify affected customers without undue delay and cooperate with them and, where applicable, with the relevant authority.
12. Your choices and rights
Subject to applicable law, you may ask us to: access the Account Information we hold about you; correct it if inaccurate; delete it where we are not required to retain it; or restrict or object to certain processing. You may also withdraw consent where processing is based on consent, and opt out of any non-transactional email at any time.
To make a request, write to hello@leopathway.com from the email address associated with your account. We may ask for information to verify your identity. We aim to respond within thirty (30) days.
If your request concerns Customer Data — information a firm has entered about you as its client — please direct it to that firm, which decides how that information is handled. We will assist the firm in responding.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, where changes are material, give notice by email or in-product notice.
14. Contact and grievances
LeoPathway Solutions Sec 93A, Noida, Uttar Pradesh, India All enquiries — privacy, security, grievances: hello@leopathway.com
Grievance Officer (in accordance with the Information Technology Act, 2000 and rules made thereunder): Name: Aayush Jain · Email: hello@leopathway.com · Address: as above
We aim to acknowledge grievances within forty-eight (48) hours and resolve them within thirty (30) days. If you are not satisfied with our response, you may escalate to the relevant authority in India.
See also our terms of service.