Last updated and effective: 20 July 2026
Privacy Policy
How Conformly handles account, payment, support, process-input, uploaded-file and generated-content data.
LRD QMS LIMITED is the data controller for Conformly. Our registered contact address is 13 Endeavour Close, Hartlepool, England, TS25 1EY, United Kingdom. Questions and privacy-rights requests can be sent to support@lrdqmss.shop, +44 7932037434, or LRD QMS LIMITED, 13 Endeavour Close, Hartlepool, England, TS25 1EY, United Kingdom.
We collect account, order and support data that you provide, including name, email, company, telephone where supplied, account credentials, selected plan, subscription status, support correspondence and consent records. Technical records may include IP address, device and browser information, timestamps, security events, cookie choices and service logs.
We receive transaction identifiers, plan, payment status, billing country and limited fraud signals from Stripe or PayPal when you use that payment provider. Stripe and PayPal process payment credentials under their own privacy terms. Conformly does not receive or store full card numbers, card security codes or complete payment credentials.
We collect data directly from you when you create an account, enter a process brief, upload a file, request a generation, export work, subscribe, change cookie choices or contact support. We collect ordinary technical data automatically from your browser and service interactions.
Stripe or PayPal supplies limited transaction and fraud-prevention data; hosting, file-delivery, email and security providers supply operational records; and an authorised workspace administrator may supply account or team details. We do not obtain private quality-system content from data brokers or unrelated third parties.
The workspace processes the text prompts, quality-process descriptions, selected document and diagram types, revision instructions, bulk-import rows, example data and files you choose to upload. It also processes the resulting documents, checklists, diagrams and video outputs so that you can review, revise, download or delete them. Contracted AI providers receive only the input and context needed for the generation you request.
Account workspace content is retained while your account remains open unless you delete it sooner. Deleted inputs, uploaded files and generated outputs are scheduled for removal from active systems within 30 days, protected backups rotate within 90 days, and generation transport caches are ordinarily removed within 30 days.
Conformly does not use user prompts, uploaded files, example data or generated outputs to train its own or a third party's general-purpose model.
We process account, prompt, generation, export and subscription data to perform our contract with you. We process support, service-improvement and security data for our legitimate interests in operating and protecting the service. We retain payment, invoice and tax records to meet legal obligations. We use optional analytics or marketing technologies only with consent where consent is required.
Automated processing creates editable draft content, but Conformly does not make decisions that produce legal or similarly significant effects. Users decide whether and how to adopt each output after competent professional review.
The service is available worldwide, so our processors may handle data outside the United Kingdom or European Economic Area. Where required, we rely on adequacy regulations or decisions, the UK International Data Transfer Agreement or Addendum, EU Standard Contractual Clauses and appropriate supplementary safeguards. Contact us for information about the mechanism applicable to your data.
Support records are normally retained for 24 months, security logs for up to 12 months, and payment, invoice and tax records for up to 7 years where required. User inputs, uploaded files and generated outputs follow the periods stated in the User input, uploads and AI-generated output section.
You can request deletion of stored workspace content. Deletion may not remove records we must retain to comply with law, prevent fraud, handle a dispute or establish, exercise or defend legal claims.
We use access controls, encrypted transport, restricted service credentials, payment-provider boundaries, security logging and backups appropriate to the service. No online system is risk-free. Users should minimise confidential data, control team access and remove passwords, API keys and other secrets from prompts and files.
Depending on where you live, you may request access, correction, deletion, restriction or portability of your personal data; object to processing; withdraw consent; and complain to a data-protection authority. UK users may complain to the Information Commissioner's Office. EEA users may complain to the authority responsible for their location.
California residents may request to know, correct or delete covered personal information and may exercise applicable rights without discriminatory treatment. We verify requests and normally respond within the period required by applicable law. An authorised agent may act where identity and authority can be verified, and we will explain any lawful exception.
Conformly does not sell personal information and does not share it for cross-context behavioural advertising. We therefore do not offer a separate sale or sharing opt-out. If this practice changes, we will update this policy and provide the required controls before the change takes effect.
Strictly necessary cookies support account and admin sessions, security, checkout continuity and saved privacy choices. Optional analytics are used only after consent where required. The Cookie Policy explains each category and how to accept, reject or change optional-cookie choices.
Conformly is not for children under 13. Users aged 13 to 17 require permission from a parent or guardian. We do not knowingly collect personal data from a child under 13; contact us to request removal. Generated content is not an automated certification, legal finding or professional decision and must receive competent review.
Questions and privacy-rights requests can be sent to support@lrdqmss.shop, +44 7932037434, or LRD QMS LIMITED, 13 Endeavour Close, Hartlepool, England, TS25 1EY, United Kingdom.
Please put "Privacy request" in the subject line. We will confirm receipt, verify identity where appropriate and explain the outcome. You may also complain to the Information Commissioner's Office or another competent data-protection authority without first contacting us.