
Legal
Privacy Policy
Last updated: 2 August 2026
This Privacy Policy explains how ComplianceGap (“we,” “us”) collects, uses, and protects your personal data when you use this website or submit a policy for review.
Who we are
ComplianceGap is a sole proprietorship providing AML/CTF compliance review services, based in Vilnius, Lithuania. For any questions about this policy or your data, contact us at contact@compliancegap.io.
What we collect
When you submit the form on this site, we collect your name and email address; company name; the country where your company is established and the country of your licence (held or applied for); licence type and the countries you serve; the AML/CTF policy document you upload; and any additional details you provide about what you need help with.
Why we collect it
We use this information solely to understand your business and licensing context so we can review your policy accurately; communicate with you about your submission and deliver your report; and process payment for the service you’ve selected.
Legal basis
We process this data on the basis of contract performance - to deliver the service you’re requesting - and, where applicable, legitimate interest, such as responding to enquiries you send us before any contract is formed. We only rely on this where processing your data is proportionate and does not override your own rights and interests.
International data transfers
We use third-party providers (Tally for form processing and Stripe for payments) who may process or store data outside the European Economic Area (EEA). Where this happens, we rely on the safeguards those providers have in place, including Standard Contractual Clauses approved by the European Commission, to ensure your data remains protected to EU standards.
How long we keep it
We retain your submitted information and policy document for as long as necessary to deliver the service and respond to any follow-up questions, and no longer than 12 months after our engagement ends, unless you ask us to delete it sooner or we’re required by law to keep it longer. Tally and Stripe may retain certain data separately, in line with their own retention policies, for purposes such as fraud prevention or legal compliance.
Sensitive nature of policy documents
We understand that the AML/CTF policy documents you share with us may reference internal risk assessments, controls, or other sensitive operational details. We treat these documents as confidential, access them only for the purpose of the review you’ve requested, and delete them in line with the retention period above.
Who we share it with
We do not sell or share your data with third parties for marketing purposes. Your data may be processed by the tools we use to run this business (form processing via Tally, payment processing via Stripe), each of which has its own privacy practices and data protection safeguards.
Cookies and analytics
This website does not use cookies or analytics tools beyond what is strictly necessary for the site to function.
Your rights
Under GDPR, you have the right to access, correct, or request deletion of your personal data, and to object to or restrict its processing. To exercise any of these rights, contact us at contact@compliancegap.io. You also have the right to lodge a complaint with a supervisory authority. In Lithuania, this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija).
Security
We take reasonable technical and organisational measures to protect your data, including relying on reputable third-party providers (Tally and Stripe) for form handling and payment, both of which maintain their own security and compliance standards.
Changes to this policy
We may update this policy from time to time. The “last updated” date at the top will reflect the most recent version.
Contact
Questions about this policy or your data: contact@compliancegap.io