Legal

    Privacy Policy

    Last updated: 5 August 2026

    1. Data Controller

    The controller responsible for processing your personal data is AI Risk Intelligence AS ("we", "us", "PropComply"), org. no. 833 854 992, registered in the Norwegian Register of Business Enterprises with registered address in 1164 Oslo, Norway, with correspondence and representation at C. Piñon, 29639 Benalmádena, Málaga, Spain.

    Contact for privacy matters: support@propcomply.com

    2. Scope

    This policy explains how we process personal data on propcomply.com and through the PropComply solution, in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable Spanish (LOPDGDD 3/2018), Portuguese (Lei 58/2019) and Norwegian data protection law.

    3. Personal Data We Process

    • Website visitors: technical data strictly necessary to deliver the site (IP address in server logs, browser type, pages viewed). We do not use analytics, advertising or tracking cookies.
    • Contact & access requests: name, business email, company, role, country and any message content you submit.
    • Email recipients: email address and delivery metadata required to send transactional and service communications, and to honour unsubscribe requests.
    • Job applicants: name, email address, phone number, LinkedIn profile and the content of your application, submitted through our careers form.
    • Solution users (where applicable): account data and KYC/CDD records processed on behalf of our business customers under a separate Data Processing Agreement.

    4. Purposes & Legal Bases

    • Operating the website — legitimate interest (Art. 6(1)(f) GDPR) in providing a secure, functional site.
    • Responding to enquiries and access requests — pre-contractual measures and legitimate interest (Art. 6(1)(b) and (f) GDPR).
    • Service and transactional emails — performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR).
    • Recruitment — assessing applications and communicating with candidates: pre-contractual measures and legitimate interest (Art. 6(1)(b) and (f) GDPR).
    • Legal & regulatory obligations — including AML record-keeping where applicable (Art. 6(1)(c) GDPR; Spanish Law 10/2010).

    5. Cookies & Tracking

    Strictly necessary technical storage required for the site to function is always active. In addition, subject to your prior consent, we load the LinkedIn Insight Tag to measure the effectiveness of our professional marketing. It is not loaded unless you accept it in our consent banner, and you can decline without losing any functionality. See our Cookie Policy for details.

    6. Data Sharing

    We share personal data only with vetted processors acting on our instructions under written data processing agreements, including:

    • EU-based cloud and database hosting providers
    • Transactional email delivery providers
    • LinkedIn Ireland Unlimited Company (Microsoft) — only where you have consented to the LinkedIn Insight Tag, for marketing measurement (Art. 6(1)(a) GDPR)

    We do not sell personal data.

    7. International Transfers

    Personal data is primarily processed within the European Economic Area (EEA). Where a transfer outside the EEA is necessary, it is protected by appropriate safeguards (e.g. EU Standard Contractual Clauses) in accordance with Chapter V GDPR.

    8. Retention

    We retain personal data only as long as needed for the purposes above and to comply with legal obligations. Contact and enquiry records are retained for up to 24 months unless a longer period is required by law. Job applications are retained for up to 12 months after the recruitment process ends, unless you ask us to delete them earlier. AML/KYC records processed on behalf of customers are retained per the Spanish 10-year statutory period.

    9. Your Rights

    Under GDPR you have the right to:

    • access your personal data and request a copy;
    • request rectification or erasure;
    • request restriction of processing or object to it;
    • data portability;
    • withdraw consent at any time, where processing is based on consent;
    • lodge a complaint with your supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD); in Norway, Datatilsynet.

    To exercise your rights, email support@propcomply.com.

    10. Security

    We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, audit logging and EU-region hosting. See our Security & GDPR page for more detail.

    11. Changes to This Policy

    We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated through the site or by email where appropriate.