Privacy Policy
Last updated: 29 July 2026
ReguLume, LLC ("ReguLume", "we", "us") operates the ReguLume platform at regulume.com and app.regulume.com. This policy covers the personal data we process, our legal bases, where it is held, how long we retain it, and your rights under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
To ask a question or exercise a right, write to info@regulume.com.
1. Who is the controller and who is the processor
For personal data of our own account holders (the compliance professionals who use ReguLume), ReguLume is the data controller.
For client information uploaded into a customer's workspace (inventories, policies, model cards, DPIAs, contracts, and similar governance records), the customer is the controller. ReguLume acts as a data processor and handles that content only on the customer's documented instructions. Those terms are set out in our Data Processing Agreement.
2. Data we process
- Account data: name, work email, hashed password, role, and tenant association.
- Usage and audit data: logins, actions taken in the platform, and an append-only audit trail of AI analyses (model used, confidence, and reasoning) kept as a compliance record.
- Customer content: the regulatory and governance documents a customer uploads for assessment. This may contain personal data or confidential business information belonging to the customer's own clients. We process it only to provide the service.
- Billing data: handled by our payment processor; we do not store full card details.
- Site analytics: see Section 7 (Cookies and analytics).
3. How we use it
We process personal data to run the platform: to authenticate accounts, produce obligation maps and gap analyses, generate reports, keep the audit trail, take payment, and contact account holders about the service. We do not sell personal data. We do not use customer content to train third-party AI models.
4. Where your data is stored (residency)
Platform data is hosted on Amazon Web Services in the EU (Ireland), region eu-west-1. Each customer's content sits in a logically isolated, per-client data store. Some sub-processors (see Section 6) process limited data outside the EU under safeguards such as Standard Contractual Clauses.
5. How long we keep it (retention)
- Account data: retained for the life of the account and deleted within 30 days of account closure, unless we must keep it to meet a legal obligation.
- Customer content: retained for the duration of the engagement. On termination, it is deleted or returned within 30 days, per the Data Processing Agreement.
- Audit trail: because it is a compliance record, the audit log is append-only and retained for the life of the account.
- Backups: encrypted backups are cycled out within 30 days.
6. Sub-processors
We engage sub-processors to run the service. The current list, with each one's purpose and processing location, is published at regulume.com/subprocessors.
7. Cookies and analytics
Our public website uses privacy-friendly, cookieless analytics (Plausible) to measure aggregate traffic. It sets no cookies and does no cross-site tracking, so no consent banner is required. The authenticated application uses only the essential cookies needed to run it, such as keeping you signed in.
8. How we protect data
Passwords are hashed with bcrypt. Sensitive fields are encrypted at rest. Access is scoped by tenant so that one customer cannot access another's data. Transport is encrypted with TLS. Personal data is kept out of application logs.
9. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. Account holders can exercise these rights by contacting info@regulume.com. Where a customer is the controller of uploaded content, we will refer or assist requests to that customer.
10. Changes
We will post any changes to this policy on this page and update the date above.
Contact
ReguLume, LLC
30 N Gould St, Ste N, Sheridan, WY 82801, USA
info@regulume.com