Last updated: June 2026
ACE Regulatory collects information you provide directly (name, email, company, billing details) and usage data (features used, pages visited, API calls) to provide and improve our service. We also collect workspace content that you choose to monitor through the platform (regulatory sources, gap analyses, remediation tasks).
We use your information to operate the platform, authenticate users, send service notifications, bill for paid plans, and ensure platform security. We do not sell personal information. We do not use workspace content to train third-party AI models.
We implement industry-standard safeguards including encryption at rest and in transit, workspace-level database isolation, layered access controls, and continuous security monitoring. Our security program is built on SOC 2-aligned controls and we are actively pursuing SOC 2 Type II attestation. Internal security reviews are run on a recurring cadence, and third-party penetration testing is on our roadmap.
We retain workspace data for as long as your account is active. On account closure, workspace data is deleted from production systems within 30 days and from backups within 90 days, unless retention is required by law. You can request deletion of your account or specific data at any time via our contact form.
We process data in the United States. If you access the service from outside the United States, you understand that your data will be transferred to, stored, and processed in the United States. For transfers from the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses.
Depending on your jurisdiction, you may have rights to access, correct, port, delete, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, use our contact form. We respond within 30 days.
The data controller for personal data of EEA and UK residents is ACE Regulatory, Inc. Our EU representative can be reached via our contact form. You also have the right to lodge a complaint with your local data protection authority.
California residents have the right to know what personal information we collect, the right to delete personal information we have collected, the right to correct inaccurate personal information, and the right to limit the use of sensitive personal information. ACE Regulatory does not sell or share personal information for cross-context behavioral advertising.
We engage vetted subprocessors to provide hosting, infrastructure, authentication, email delivery, and payment processing. A current list of subprocessors is available on request. We will notify customers of new subprocessors in advance of any material change.
A Data Processing Addendum (DPA) is available to all customers on request and is incorporated into our Enterprise agreements by default. The DPA includes Standard Contractual Clauses for international transfers. To request the DPA, use our contact form.
In the event of a personal-data breach affecting your workspace, we will notify the primary workspace owner without undue delay and in any case within 72 hours of confirmation, consistent with GDPR Article 33 obligations.
For privacy questions, data-subject requests, or DPA requests, use our contact form.