Last updated: January 2025

Our Compliance Commitment

CompanionFrame API is committed to operating in compliance with applicable data protection and privacy regulations. As a growing platform, we implement comprehensive compliance measures and continuously improve our practices to meet evolving regulatory requirements.

Compliance Principles

Our compliance approach is built on:

  • Privacy by design - Data protection built into our platform architecture
  • Transparency - Clear policies and practices for data handling
  • User rights - Comprehensive support for data subject rights
  • Continuous improvement - Regular review and enhancement of compliance measures
  • Legal expertise - Working with legal professionals to ensure compliance

Data Protection Compliance

🇪🇺
GDPR Compliant
Full compliance with EU General Data Protection Regulation
🇬🇧
UK GDPR
Compliant with UK data protection laws and regulations
🍪
Cookie Law
EU Cookie Law and ePrivacy Directive compliance
🇺🇸
CCPA Ready
California Consumer Privacy Act readiness for US customers

GDPR Compliance Framework

📋 Data Processing Legal Bases

We process personal data under clear legal bases as required by GDPR:

  • Contract performance: API service delivery, account management, billing
  • Legitimate interests: Service improvement, security monitoring, fraud prevention
  • Consent: Marketing communications, optional analytics
  • Legal obligation: Tax records, regulatory reporting, law enforcement cooperation

🔒 Data Subject Rights Implementation

We provide comprehensive support for all GDPR data subject rights:

  • Right of access: Request copies of all personal data we hold
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Delete personal data ("right to be forgotten")
  • Right to restrict processing: Limit data processing in specific circumstances
  • Right to data portability: Receive data in machine-readable format
  • Right to object: Object to processing based on legitimate interests

How to exercise rights: Contact privacy@companionframe-api.com or use your dashboard settings

UK Data Protection Compliance

Industry and Technical Standards

Current Compliance Status

✅ Implemented Standards

  • Data encryption: AES-256-GCM for data at rest, TLS 1.3 for data in transit
  • Access controls: Role-based access with secure authentication
  • Data retention: Clear retention policies and automated deletion procedures
  • Privacy by design: Data protection built into our platform architecture
  • Incident response: Documented procedures for security incident handling

Compliance Roadmap

Growing Platform Notice

As CompanionFrame API grows, we're working toward additional compliance frameworks:

  • ISO 27001: Information security management system (planned for 2025)
  • SOC 2 Type I: Service organization controls (under evaluation)
  • HIPAA readiness: Healthcare data protection capabilities (roadmap)
  • Regional compliance: Additional jurisdictions as we expand internationally

Timeline: Formal certifications planned as we scale and establish dedicated compliance resources.

Mental Health Data Protection

Sensitive Data Handling

We recognize that emotional support conversations contain highly sensitive personal information and implement enhanced protection measures:

Professional Standards

Mental Health Compliance

While we're not a healthcare provider, we implement practices that support healthcare compliance:

  • Technical safeguards: Encryption, access controls, audit logs
  • Administrative safeguards: Data handling policies, staff training
  • Physical safeguards: Secure cloud infrastructure with enterprise providers
  • Business associate readiness: Framework for healthcare customer partnerships

Third-Party Compliance

Vendor Security and Compliance

We carefully evaluate the compliance posture of all third-party services we use:

🤝 Service Provider Compliance

  • MongoDB Atlas: SOC 2, ISO 27001, GDPR compliant cloud database
  • Vercel: SOC 2, GDPR compliant serverless hosting platform
  • OpenAI: Enterprise-grade AI processing with data protection agreements
  • Stripe: PCI DSS, SOC 1 & 2 compliant payment processing
  • Resend: GDPR compliant email delivery service

Data Processing Agreements

International Compliance

Cross-Border Data Transfers

Regional Compliance Considerations

Business Customer Compliance Support

Customer Due Diligence

We support our business customers' compliance needs through:

Enterprise Customer Support

Customer Compliance Responsibility

Important: While we provide a compliant platform, customers are responsible for ensuring their own compliance with applicable laws and regulations in their specific jurisdictions and use cases. We recommend consulting with legal professionals for compliance advice specific to your implementation.

Compliance Monitoring and Improvement

Ongoing Compliance Management

Incident Management

Audit and Documentation

Documentation and Records

Audit Readiness

Enterprise Audit Support

For enterprise customers requiring detailed compliance information:

  • Security questionnaires: We can complete standard security and compliance questionnaires
  • Documentation packages: Comprehensive compliance documentation available
  • Compliance calls: Available for compliance discussion calls with enterprise prospects
  • Custom agreements: Tailored compliance terms for large customer requirements

Regulatory Engagement

Supervisory Authority Relations

Industry Engagement

Customer Compliance Resources

Available Documentation

Implementation Guidance

Compliance Questions and Support

For compliance-related questions, documentation requests, or concerns about our regulatory practices:

Compliance Contact

Documentation Requests

  • Security questionnaires: We can complete standard compliance questionnaires
  • DPA requests: Data processing agreements available for enterprise customers
  • Audit documentation: Compliance documentation packages for customer audits

CompanionFrame Limited

Registered in England and Wales
United Kingdom

Compliance response commitment: We respond to compliance inquiries within 3-5 business days and prioritize enterprise customer compliance needs.