MiCompli Privacy Policy
Version 1.0 — Beta release Effective date: [RENDERED AS DATA FIELD — set at counsel approval]
The Short Version
MiCompli is built so that the most sensitive information about your employees never enters our platform. We collect the operational business data needed to generate your compliance documents and track your obligations — and we deliberately refuse to collect private health information, employee contact lists, Social Security numbers, and dates of birth. Your privacy stays with you.
The rest of this policy explains exactly what that means.
1. Who We Are
MiCompli is a compliance software service for Michigan employers, operated by Compli LLC, a Michigan limited liability company. This policy covers information handled through the MiCompli platform at micompli.biz and its subscriber portal. Questions: support@micompli.biz.
2. What We Collect
Account and business information. Your name, business email address, and sign-in identity (via Google sign-in); your company profile — legal business name, DBA, business address, business phone, industry, employee headcount, workweek structure, plan year dates, and related operational facts you declare. Your federal Employer Identification Number (EIN) is collected solely because two generated documents — the Summary Plan Description and the Premium Only Plan — legally require it; it is used nowhere else in the Service.
Time-off tracking data. For the leave tracker, we store employee names and hours only — accrual, usage, and balances. Nothing else about your employees.
Attestation and activity records. When you attest that a real-world compliance action occurred (posting a notice, distributing a document), we record your typed name and a date/time stamp. The Service keeps an activity log of profile changes, document generations, and attestations. These records exist so you have an audit trail; they are a feature, and they are retained accordingly.
Uploaded documents. Upload slots are limited and labeled. Currently the Service accepts one upload type: your plan's Summary of Benefits and Coverage, in PDF form, accompanied by your logged attestation that it contains no individual health information. We do not scan, mine, or analyze uploads beyond providing them back to you within the Service.
HR reporting contacts. If you designate individuals to receive workplace reports in your employee handbook, we store the names, titles, and contact details you provide for them. These details appear in the documents you generate and are used for no other purpose. MiCompli does not use them to contact anyone.
Questions you ask. If you use the Ask MiCompli feature, we store your questions and the answers provided, associated with your account, so you have a dated history.
Payment information. Payments are processed by Stripe. MiCompli receives confirmation of payment status and subscription state; we do not store your full card number.
Technical data. Standard server logs (IP address, browser type, pages accessed, timestamps) used for security, debugging, and service operation. We do not run third-party advertising trackers on the subscriber portal.
3. What We Deliberately Do Not Collect
These are design commitments, not just policy statements — the platform is built to make them true:
- No private health information — ever. No diagnoses, no claims data, no enrollment health details, no medical certificates, no evidence-of-coverage uploads. Where a workflow touches benefits, the Service uses attestations instead of documents wherever a document would carry health information.
- No employee email addresses or contact lists for communication or distribution. MiCompli never communicates with your employees. You distribute required documents and notices; you attest that you did. The sole contact details we store are the ones you designate as HR reporting contacts for your handbook — they are printed in the documents you generate and are used for no other purpose. [COUNSEL: this commitment was narrowed on 2026-08-03 to match what the platform actually does; the handbook builder collects a reporting contact and an alternate. Confirm the narrowed wording reads as a commitment rather than a carve-out, and that "for communication or distribution" is the right boundary to draw.]
- No Social Security numbers or dates of birth. Forms that require them — such as the New Hire Information Sheet — are generated blank, completed on paper between you and your employee, and retained by you. The completed form never returns to the platform, and the form itself tells your employee so.
If information in a prohibited category is submitted despite these controls, we will delete it upon discovery and notify you.
4. How We Use Information
We use the information described above to: operate the Service and your account; generate your compliance documents from your declared profile; compute obligations, caps, and deadlines; notify you when monitored legal changes affect your documents; maintain your attestation and audit records; process billing; provide support; and secure and improve the Service.
We do not sell your information. We do not rent it. We do not use it for third-party advertising.
5. Your Employees' Information — Roles
For the limited employee information in the Service (names and hours in the time-off tracker; names appearing in documents you generate), you are the controller of that information and MiCompli processes it on your instructions to provide the Service. Your employees' questions about that information should come to you; where an employee contacts us directly about information you control, we will refer them to you and assist you in responding. [COUNSEL: confirm controller/processor framing is the posture you want stated for a US/Michigan-scope service.]
6. Who We Share Information With
We share information only with:
- Service providers that host and operate the platform on our behalf — currently including our hosting provider (Railway), our payment processor (Stripe), our identity provider (Google sign-in), and the AI service providers that power document generation and the Ask MiCompli feature. Service providers are bound to use your information only to provide their service to us.
- Professional advisors (our lawyers, accountants, auditors) under confidentiality obligations.
- Authorities, when legally required — in response to valid legal process, or to protect the rights, safety, or property of MiCompli, our subscribers, or others.
- A successor entity in the event of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your information.
There is no category of sharing for marketing, data brokerage, or advertising, because we do not do those things.
7. Retention and Deletion
Cancellation is not deletion. If you cancel your subscription, billing stops but your account, documents, and audit records remain — your compliance history is never destroyed by a billing event.
Deletion is deliberate. Account deletion is a separate action that prompts you to download your Audit Package first and requires typed confirmation. Deleted accounts are recoverable for 30 days. After 30 days, your data is permanently removed from production systems, except records we are required to retain by law and minimal records reasonably necessary for billing history, audit, and legal defense, which are retained only as long as those purposes require.
8. Security
We use commercially reasonable administrative, technical, and physical safeguards appropriate to the data we hold, including encrypted transport, access controls, role-based permissions, and audit logging. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you as required by applicable law, including Michigan's Identity Theft Protection Act. [COUNSEL: confirm breach-notification reference and whether contractual notification commitments beyond statute are desired.]
9. Your Choices and Rights
You can review and correct your company profile at any time in Settings; profile changes are previewed before they take effect and logged after. You can export your documents and Audit Package. You can cancel or delete your account as described above. If you have questions or requests regarding your information, contact support@micompli.biz and we will respond within a reasonable time.
10. Scope Notes
The Service is designed for U.S. business subscribers, specifically Michigan employers, and this policy is written to U.S. and Michigan law. The Service is not directed to children and we do not knowingly collect information from anyone under 16. The portal is a business tool; use it for business data only.
11. Changes to This Policy
We may update this policy. Material changes require your acknowledgment at next sign-in, and we log the version you accepted. The current version and its effective date are always displayed on this page, rendered from the document's version data.
12. Change History
Version 1.0 — draft, pending counsel review. This document has not yet taken effect and no subscriber has accepted it, so edits made during counsel review are recorded here rather than by a version bump. The version moves when the text changes after acceptance is possible.
- 2026-08-03 — Section 2: added HR reporting contacts, describing the names, titles, and contact details stored for individuals a subscriber designates to receive workplace reports in their handbook. Recorded because the handbook builder already collects these and Section 2 did not name them.
- 2026-08-03 — Section 3: narrowed the second commitment. It previously read "No employee email addresses or personal contact lists"; it now reads "No employee email addresses or contact lists for communication or distribution" and states that the sole contact details stored are the HR reporting contacts a subscriber designates for their handbook, printed in their documents and used for no other purpose. The commitment against contacting employees is unchanged. Narrowed rather than dropped: the boundary that matters is what the details are collected for, and MiCompli still never communicates with employees. Flagged for counsel with the rest of the document.