Last updated: June 2026
We believe that every Tech-Driven SME should start their compliance journey by implementing a rigorous Information Security Management System (ISMS).
At Compleye, we advise our clients to integrate the ISO27001 norm at the core of their compliance processes. An external auditor once referred to the ISO27001 as ‘Your licence to operate’.
We stand by that statement, and we believe that the ISO27001 certification enables immediate trust between you and your customers.
We perform Internal Audits with all our customers and share best practices amongst our customer portfolio.
Without an adequate security system, you can’t protect the privacy of data—that is why privacy follows.
We implemented the ISO27701 (Privacy Information Management System) for one of our SuperCoolCustomers. Every nitty-gritty detail of the GDPR needs to be documented and verified, ensuring every ‘i’ is dotted and every ‘t’ is crossed.
However, we also learned that becoming ISO27701 certified is a huge documentation burden. For companies processing a lot of PII (Personally Identifiable Information) Data, it can be recommended—or even requested—by customers or other stakeholders.
Compleye adopted the privacy-by-design principle.
Once your organization is ready to scale, you can start streamlining your ‘way of working’ and consider implementing a quality framework (e.g., ISO9001).
Implementing a quality system—in general—will increase the amount of documentation and can sometimes slow down scaling and innovation. However, it is not always your choice: external stakeholders can demand such certification.
At Compleye, delivering quality is all about organizing a strong customer-feedback loop. For us, it’s not just about the UX for the customer—we focus on results and feedback from external auditors and regulators. This input directly feeds into our product roadmap.
Compleye works with Audit View in mind—ensuring compliance and continuous improvement.
Compliance is our business, and we closely follow developments in new regulations and industry standards. It is our mission to translate complex laws into practical approaches and measures that are fit-for-purpose and aligned with the stage and phase of your organization.
Compliance with AI regulations is key for all businesses and will need to be embedded in your Compliance Management System.
Compleye supports customers with the implementation of AI within their organization, ensuring alignment with the EU AI Act, ISO42001 and other emerging standards.
It is important to share compliance information with stakeholders about your implemented frameworks, please find below security and privacy information and links to shared documents.
List of sub-processors:
AWS, location EU
– for processing of compliance data on our platform.
Google Analytics
– Analytical tool
Sendgrid
– Email notification from platform to individual users.
Documentation:
Data Processing Agreement
Terms of Use
Terms & Conditions
Available upon request
(for customers only)
Security Policy Statement and ISO 27001 – Statement of Applicability
| Cookie | Looptijd | Omschrijving |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |