This Privacy Policy explains how [COMPANY NAME] ("we", "us", "our"), registered at [ADDRESS], collects, uses, and protects your personal data when you use the GORA AI platform. We are the data controller for the purposes of UK GDPR and EU GDPR.
| Category | Examples | Why we collect it |
|---|---|---|
| Account data | Name, work email address, job title, organisation name | To create and manage your account and provide the service |
| Profile data | Role, organisation size, primary regulatory market | To personalise your workspace experience |
| Workspace data | Products selected, regulatory markets, readiness checklist state, notes, templates | To provide and restore your workspace across sessions |
| Payment data | Billing name, payment card details (handled by Stripe) | To process subscription payments. We never store card numbers. |
| Usage data | Pages visited, features used, browser type, IP address, timestamps | To improve the platform and diagnose errors |
| Communications | Emails you send us, support requests | To respond to your enquiries |
We do not collect special category data (health, biometric, etc.) and do not ask for it. We do not collect data from children under 16.
We use essential cookies only — small files necessary to keep your session active and remember your consent choice. We do not use advertising or tracking cookies. You can control cookies through your browser settings, though disabling essential cookies may break core functionality.
| Cookie | Purpose | Duration |
|---|---|---|
| gora-ai-demo-session | Keeps you authenticated between page loads | Session |
| gora-cookie-consent | Remembers your cookie consent choice | 1 year |
| gora-target-date | Saves your regulatory submission target date | 1 year |
| gora-claude-api-key | Stores your Anthropic API key locally (never sent to our servers) | Until cleared |
We share data only with processors necessary to operate the service, each bound by data processing agreements:
We do not sell your data to third parties. We do not use your data for advertising.
Your data may be processed outside the UK/EEA by our sub-processors. Where this occurs, we rely on standard contractual clauses or adequacy decisions to ensure equivalent protection.
Under UK and EU GDPR you have the following rights:
To exercise any right, contact us at admin@goregulatory.com. We will respond within 30 days.
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but take our obligations seriously.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice in the platform. The date at the top of this page reflects when it was last updated.
Data controller: [COMPANY NAME], [ADDRESS]
Privacy enquiries: admin@goregulatory.com
If you are in the EEA and have a concern we have not resolved, you have the right to contact your local data protection authority.