PRIVACY POLICY
Last updated: July 18, 2026
1. Introduction and Who We Are
This Privacy Policy describes how One Empire, doing business as AI Compliance Navigator ("Company", "we", "us", or "our"), collects, uses, discloses, and protects personal information when you use comply.one-empire.com and the AI Compliance Navigator service (the "Services").
AI Compliance Navigator helps organizations assess their AI systems against international compliance frameworks — including NIST AI RMF, ISO/IEC 42001, OWASP LLM Top-10, and the EU AI Act — through guided assessments, AI-generated gap analysis reports, a Code Analyzer for OWASP LLM Top-10 security review, and a regulations library covering AI-related laws across 88 countries.
By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Services.
2. Data We Collect
We collect the following categories of personal information:
- Email addresses — collected at signup and used as your account identifier.
- Names and organization names — collected when you create an account or organization.
- Billing information — collected and processed by Stripe when you subscribe to a paid plan; we do not directly store full payment card numbers.
- Authentication data — session tokens and sign-in records, used to keep your account secure.
- Uploaded code files — pasted code, ZIP archives, or repository contents you submit to the Code Analyzer for security review.
We also process assessment answers, evidence, and context notes you provide when running a compliance assessment.
3. How We Use Your Data
We use the data described above to:
- create and maintain your account and organization;
- generate AI-assisted compliance assessments, gap analysis reports, and code security findings;
- process billing and manage subscriptions via Stripe;
- send transactional and account-related email (e.g. sign-in links, trial and billing notices) via Resend;
- authenticate you and keep your account secure;
- monitor for fraud, abuse, and violations of our Terms of Service; and
- comply with applicable law.
4. Third-Party Services
We rely on the following third-party service providers to operate the Services. Each processes personal information only as necessary to perform its function for us:
- Stripe — payment processing and subscription billing. Stripe is PCI-compliant; we do not store your full card details ourselves.
- Supabase — database, authentication, and row-level-security (RLS) enforcement for your account and organization data.
- Vercel — application hosting.
- Resend — transactional email delivery.
- Anthropic (Claude API) — AI processing for assessments, gap analysis, and code security review. See Section 5.
5. AI-Powered Features Disclosure
Assessment gap analysis, security findings, and refactored code are generated using Anthropic's Claude API. When you run an assessment or submit code to the Code Analyzer, the relevant text or code is sent to Anthropic to generate a response. In accordance with Anthropic's own commercial API terms, inputs and outputs sent through the API are not used to train Anthropic's models by default.
Separately from Anthropic's own handling of the request, we retain a copy of submitted code and generated results in our own systems for as long as your account remains active (see Section 6) — this is what lets you review past scan findings and regenerate refactored code later without resubmitting your files. AI-generated output may contain errors and is not a substitute for professional legal or security review; see our Terms of Service for the full disclaimer.
6. Data Retention
We retain your personal information, assessment data, and uploaded code for as long as your account remains active. If you close your account, we will delete or anonymize your personal information within a reasonable period, except where we are required to retain it to comply with legal, tax, or accounting obligations, or to resolve disputes.
7. Your Rights Under GDPR and CCPA
If you are in the European Economic Area, United Kingdom, or Switzerland (GDPR), you have the right to access, correct, or erase your personal information, restrict or object to its processing, receive a copy of it in a portable format, and withdraw consent at any time.
If you are a resident of California or another US state with a comprehensive privacy law (including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia), you have the right to know what personal information we hold about you, request access to or deletion of it, correct inaccuracies, and opt out of the sale or sharing of personal information — we do not sell or share your personal information with third parties for advertising purposes.
If you are in Australia, we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You may lodge a complaint with the Office of the Australian Information Commissioner.
If you are in South Africa, we process your personal information in accordance with the Protection of Personal Information Act (POPIA). You may lodge a complaint with the Information Regulator (South Africa).
To exercise any of these rights, contact comply@one-empire.com.
8. ASEAN and Korea Privacy Rights
Singapore (Personal Data Protection Act 2012): Users in Singapore have the right to access, correct, and withdraw consent for their personal data.
Korea (Personal Information Protection Act): Users in Korea have the right to access, correct, delete, and suspend processing of their personal information.
Malaysia (Personal Data Protection Act 2010): Users in Malaysia have the right to access and correct their personal data held by us.
Thailand (Personal Data Protection Act B.E. 2562): Users in Thailand have the right to access, correct, delete, and port their personal data.
Indonesia (UU PDP — Personal Data Protection Law): Users in Indonesia have the right to access, correct, and delete their personal data.
To exercise any of these rights, contact comply@one-empire.com. For all ASEAN and Korea users, data subject requests will be responded to within 30 days of receipt.
9. International Data Transfers
Our infrastructure is hosted with Vercel (United States) and Supabase, self-hosted in Singapore. Using the Services means your personal information may be transferred to, stored in, and processed in both the United States and Singapore, which may have data protection laws different from those of your home country. We take appropriate safeguards — including relying on our providers' own standard contractual clauses and security commitments — to protect personal information transferred internationally.
10. Cookie Policy
We use a small number of cookies: an essential session cookie (via Supabase) that keeps you signed in, and a cookie set by our cookie-consent tool to remember your cookie preferences. We do not use advertising or third-party tracking cookies. See our full Cookie Policy for details on what each cookie does and how to manage them.
11. Children's Privacy
The Services are not directed to, and we do not knowingly collect personal information from, anyone under 18 years of age. If you believe a user under 18 has provided us with personal information, please contact us at comply@one-empire.com and we will take steps to delete that information.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our handling of your personal information, please contact us at:
One Empire
519D Tampines Central 8
Singapore 524519
Singapore
comply@one-empire.com