G
GORA AI
← Back to workspace
Legal

Privacy Policy

Effective date: [DATE] · Last updated: [DATE]

This Privacy Policy explains how [COMPANY NAME] ("we", "us", "our"), registered at [ADDRESS], collects, uses, and protects your personal data when you use the GORA AI platform. We are the data controller for the purposes of UK GDPR and EU GDPR.

1. Data we collect

CategoryExamplesWhy we collect it
Account data Name, work email address, job title, organisation name To create and manage your account and provide the service
Profile data Role, organisation size, primary regulatory market To personalise your workspace experience
Workspace data Products selected, regulatory markets, readiness checklist state, notes, templates To provide and restore your workspace across sessions
Payment data Billing name, payment card details (handled by Stripe) To process subscription payments. We never store card numbers.
Usage data Pages visited, features used, browser type, IP address, timestamps To improve the platform and diagnose errors
Communications Emails you send us, support requests To respond to your enquiries

We do not collect special category data (health, biometric, etc.) and do not ask for it. We do not collect data from children under 16.

2. Legal basis for processing

  • Contract performance — processing necessary to provide the subscription service you signed up for.
  • Legitimate interests — improving the platform, preventing fraud, security monitoring. We have assessed these interests do not override your rights.
  • Legal obligation — retaining certain records required by law (e.g. tax records).
  • Consent — where you have given explicit consent (e.g. marketing emails). You can withdraw consent at any time.

3. Cookies

We use essential cookies only — small files necessary to keep your session active and remember your consent choice. We do not use advertising or tracking cookies. You can control cookies through your browser settings, though disabling essential cookies may break core functionality.

CookiePurposeDuration
gora-ai-demo-sessionKeeps you authenticated between page loadsSession
gora-cookie-consentRemembers your cookie consent choice1 year
gora-target-dateSaves your regulatory submission target date1 year
gora-claude-api-keyStores your Anthropic API key locally (never sent to our servers)Until cleared

4. Third-party processors

We share data only with processors necessary to operate the service, each bound by data processing agreements:

  • Supabase — cloud database and authentication provider. Data hosted in [REGION].
  • Stripe — payment processing. Stripe is PCI-DSS Level 1 certified. See Stripe's Privacy Policy.
  • Anthropic — AI model provider (Claude API), used only when you enter your own API key. In that case, your queries go directly from your browser to Anthropic under their terms of service.
  • [EMAIL PROVIDER] — transactional email delivery (welcome emails, billing receipts).

We do not sell your data to third parties. We do not use your data for advertising.

5. Data retention

  • Account and workspace data is retained while your account is active and for 90 days after deletion, then permanently erased.
  • Payment records are retained for 7 years as required by UK tax law.
  • Server logs are retained for 30 days then deleted.

6. International transfers

Your data may be processed outside the UK/EEA by our sub-processors. Where this occurs, we rely on standard contractual clauses or adequacy decisions to ensure equivalent protection.

7. Your rights

Under UK and EU GDPR you have the following rights:

AccessRequest a copy of data we hold about you.
RectificationCorrect inaccurate personal data.
ErasureRequest deletion of your personal data ("right to be forgotten").
RestrictionAsk us to limit processing in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectObject to processing based on legitimate interests or for direct marketing.
Withdraw consentAt any time, where processing is based on consent.
Lodge a complaintWith the UK ICO (ico.org.uk) or your local supervisory authority.

To exercise any right, contact us at admin@goregulatory.com. We will respond within 30 days.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but take our obligations seriously.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the platform. The date at the top of this page reflects when it was last updated.

10. Contact us

Data controller: [COMPANY NAME], [ADDRESS]
Privacy enquiries: admin@goregulatory.com

If you are in the EEA and have a concern we have not resolved, you have the right to contact your local data protection authority.

© [YEAR] [COMPANY NAME] · Terms of Service · Privacy Policy · Back to GORA AI