Effective and last updated: 16 August 2026
Who is responsible
The Azerbaijan-based operator of Complisera is responsible for personal data processed through the platform. Full registered operator details will be displayed before paid checkout is enabled.
Data we collect
We collect only information needed to provide the service: account identity, contact details, company information, product and packaging records, destination countries, uploaded document metadata, support requests, subscription records, consent records and security logs.
Why we process data
Data is processed to create and secure accounts, deliver requested software features, calculate packaging summaries, manage country workflows, provide support, administer subscriptions, maintain audit records and comply with legal obligations.
Legal bases
Depending on the activity, processing is necessary to perform a contract, comply with legal obligations, pursue legitimate interests in operating and securing the service, or act on consent. Non-essential marketing is not enabled without an appropriate basis.
Recipients and international transfers
Data may be processed by hosting, storage, authentication, email, analytics and payment providers acting under appropriate terms. Data is shared with an independent compliance partner only when requested or required for a separately contracted service. International transfers are handled using appropriate contractual or legal safeguards where required.
Retention
Account data is retained while the account is active and for necessary legal, accounting, security and dispute periods afterward. Support records and audit logs are retained only as long as reasonably necessary for those purposes.
Your choices and rights
You may request access, correction, export or deletion of eligible personal data through Customer Support. You may also object to or restrict certain processing and withdraw consent where consent is the legal basis. Mandatory records may be retained where required by law.
Security
The platform uses transport encryption, role-based access, audit logging and restricted storage access. No system can guarantee absolute security, and the platform does not claim to be “GDPR certified”.
Cookies
Essential cookies may be used for authentication, security and session continuity. Non-essential analytics or marketing cookies will remain disabled until an appropriate consent mechanism is active.