Privacy Policy
Last updated: 17 July 2026 · Kainos Consultants Australia Pty Ltd, trading as CompliDesk
This Privacy Policy explains how we handle personal data collected through the CompliDesk Ireland website. It is written for the current pre-launch phase, during which this site collects waitlist sign-ups and demo requests only. It will be updated when the CompliDesk Ireland platform launches.
1. Who We Are
CompliDesk Ireland is operated by Kainos Consultants Australia Pty Ltd (ABN 46 678 061 535, ACN 678 061 535), trading as CompliDesk ("CompliDesk", "we", "us"). We provide anti-money-laundering compliance software. For the personal data collected through this website (such as waitlist sign-ups and demo requests), we are the data controller within the meaning of the EU General Data Protection Regulation (GDPR).
Contact: admin@complidesk.com.au
2. What Personal Data We Collect
Through this website we collect only what you give us:
- Waitlist sign-ups: your email address and, optionally, your sector.
- Demo requests: your name, firm name, work email, optional phone number, sector, and any message you include.
- Correspondence: anything you send us by email.
- Cookies and similar technologies: see our Cookie Policy. We do not load analytics or marketing cookies without your consent.
We do not collect special-category data through this website, and we ask that you do not send us any.
3. Why We Process It (Purposes and Legal Bases)
We process this data to:
- Keep you informed about CompliDesk Ireland and your waitlist place — on the basis of your consent (Article 6(1)(a) GDPR), which you may withdraw at any time via the unsubscribe link or by emailing us.
- Respond to and arrange demo requests — on the basis of taking steps at your request prior to entering into a contract (Article 6(1)(b)) and our legitimate interest in responding to enquiries (Article 6(1)(f)).
- Operate, secure and improve the website — on the basis of our legitimate interests (Article 6(1)(f)).
We do not sell personal data, and we do not send marketing email without a lawful basis under the ePrivacy rules (in Ireland, S.I. No. 336/2011).
4. Where Your Data Is Stored (EU Data Residency)
Waitlist and demo-request data submitted on this site is stored in our database hosted by Supabase in Amazon Web Services region eu-west-1 (Dublin, Ireland). Website hosting and delivery is provided by Vercel.
When the CompliDesk Ireland platform launches, customer and KYC data will likewise be hosted in the EU (AWS Dublin).
5. Sub-Processors and Service Providers
We use a small number of service providers to run CompliDesk. Depending on the service you use, these may include:
- Supabase (database and authentication — EU region for Ireland data)
- Vercel (website hosting and delivery)
- Stripe (payment processing — when paid subscriptions launch)
- Resend (transactional email — when platform email launches)
- Didit (identity verification — within the platform)
- Anthropic (AI-assisted screening analysis — within the platform)
- Zoho (customer relationship management and email campaigns)
A maintained sub-processor list for the platform will be published on our Security page. Where a provider processes personal data outside the EU/EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
6. International Transfers
CompliDesk is operated by an Australian company, so limited personal data (for example, email correspondence and CRM records) may be accessed from Australia. Where personal data is transferred outside the EU/EEA, we use appropriate safeguards under Chapter V GDPR, including Standard Contractual Clauses, and we minimise what leaves the EU. Product data for Irish customers remains hosted in the EU as described in section 4.
7. How Long We Keep It
- Waitlist data: until you unsubscribe or ask us to delete it, or 12 months after CompliDesk Ireland launches, whichever is earlier.
- Demo-request data: for as long as needed to follow up, and no longer than 24 months after our last contact.
- Correspondence: for as long as reasonably needed for the purpose it was sent.
When the platform launches, retention for customer compliance records will follow the AMLR’s retain-then-delete requirements and will be set out in the platform documentation.
8. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have inaccurate data rectified
- Have your data erased ("right to be forgotten")
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time (without affecting processing already carried out)
To exercise any of these rights, email admin@complidesk.com.au. We will respond within one month.
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC) — dataprotection.ie — or with your local supervisory authority.
9. Automated Decision-Making
This website makes no automated decisions producing legal or similarly significant effects about you. Within the future platform, AI-assisted screening outputs are decision-support only: a qualified person at the customer firm reviews every output, and no compliance decision is made solely by automated means.
10. Security
We take reasonable technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls, row-level security on our databases, and the minimisation of data collected in the first place. No internet service can be guaranteed 100% secure, but we design for restraint: this website collects only what it needs.
11. Personal Data Breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission without undue delay and, where required, within 72 hours of becoming aware of it, and we will inform affected individuals where the risk is high — in accordance with Articles 33 and 34 GDPR.
12. Cookies
See our Cookie Policy for full details. In short: essential cookies only by default; analytics and marketing cookies are loaded only with your prior consent, with no pre-ticked boxes, and you can change your preferences at any time.
13. EU Representative
As a company established outside the EU offering services to individuals in the EU, we are reviewing our obligations under Article 27 GDPR regarding the appointment of an EU representative, in parallel with plans for an Irish corporate presence. Until that appointment is published here, please direct all data protection enquiries to admin@complidesk.com.au and we will respond as controller.
14. Changes to This Policy
We may update this policy as CompliDesk Ireland develops — in particular when the platform launches and our processor role begins. Material changes will be flagged on this page with a new "last updated" date.
15. Contact Us
Kainos Consultants Australia Pty Ltd, trading as CompliDesk
ABN 46 678 061 535 · ACN 678 061 535
Email: admin@complidesk.com.au
This policy applies to the CompliDesk Ireland website. The Australian CompliDesk service is governed by its own privacy policy under the Australian Privacy Principles. Questions? Contact admin@complidesk.com.au.