Compliance & recordsv4.1.0

Complia

A complaints register that records each complaint, its acknowledgment clock and its outcome, with a public form.

For UK data controllers handling data-protection complaints. Often replaces HappyFox or ProvePrivacy.

Single license $79 · Extended license $179 · paid once, yours for good

Try the live demoNo sign-up. The demo resets itself, so click anything.

What it does

Public complaint form

A no-login form you link from your privacy notice. Complainants get a private tracking code on submission.

An acknowledgment timer

The register shows days remaining and overdue flags against the acknowledgment window, which is a setting.

Status with an audit log

Move complaints from received to resolved or rejected, with an append-only, timestamped investigation log per complaint.

A report for the board

For any period: complaints received, acknowledged on time or late, median days to acknowledge and close, and outcomes.

A receipt to the complainant

Reference, dates, the response deadline and their tracking link, and not one word they wrote. You switch it on and they tick the box.

Your procedure beside your register

Every version of your complaints procedure, with its effective and next review dates. Link it from your public form.

The records beside a complaint

Link a complaint to its subject access request or breach record. With Privara, Complia reads that request's status and deadline.

Evidence from the complainant

The public form can accept up to 3 files, typed by their bytes. Off by default; a refused file never loses the complaint.

Public status page

Complainants check progress with their tracking code: status only, no personal data shown.

Audit CSV export

Export the full register, with status history, as CSV to share with your DPO or a regulator.

Your team's chat, told too

Each new complaint and acknowledgment reminder can post one line to your chat. The number and date only.

Also: a dashboard of what is due, a named owner per complaint and a calendar feed.

Is it right for you?

What Complia deliberately doesn’t do.

  • Single-tenant: one organization per installation (your team shares it, with viewer / member / admin roles and invite links).
  • Email goes through your own SMTP server, never ours. Acknowledgment reminders are optional and off until you switch them on; they are checked whenever someone opens the dashboard, and by a daily cron call on days nobody does.
  • Not a case-management suite: each complaint can have one named owner and acknowledgment reminders, but there is no workload allocation, no escalation between people and no billing. Attachments and an append-only investigation log are in.
  • English-language UI.
  • A records aid, not legal advice; buying it does not make you compliant.

What renting costs instead

HappyFoxHelp desk "starting at $24 / agent / mo"; service desk $49 / agent / mo; contact-center suite $99 / agent / mo; HappyFox AI adds "$14 per agent / month" and the chatbot is billed at "$0.33 per resolution". Every tier meters per agent, and the AI meters again on top

If you use a help desk as your complaints log: HappyFox starts at $24 per agent per month (read 2026-09-03). Complia is $79.00, once, and does a narrower job.

Read Sep 3, 2026 · source

The full comparison: every rival, what each does better, and who should stay with them →

Replacing one of these? HappyFox alternative · ProvePrivacy (representative vendor) alternative

Release history

Own It 4.1Client installations and your other toolsOct 4, 2026

For Complia, 4.1 makes two changes that every app gets. What’s new in 4.1 →

Own It 4.0It updates and backs itself upSep 29, 2026

For Complia, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →

Own It 3.3The import preview tells the truthSep 27, 2026

The CSV import's preview used to count a complaint dated a day that does not exist as ready, and the import then skipped it. What’s new in 3.3 →

Own It 3.2The register, reported upwardSep 26, 2026

For Complia, the 3.2 wave brought a leadership report for the board, your complaints procedure kept beside the register with every version and its review date, and a…

Own It 3.1It writes to the people you serveAug 20, 2026

The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…

Own It 3.0Works for your AI, not just for youAug 9, 2026

Your statutory deadlines land in your calendar: a read-only feed of every open acknowledgment deadline, overdue ones saying so in the title, complaints you have marked…

Own It 2.0API, 2FA, backups, dark modeAug 6, 2026

Complia 2.0 adds the 2.0 owner layer.

What’s in the zip

The tree as the zip ships it — the working leftovers the packager deletes are not listed

  • .htaccess
  • API.md
  • Dockerfile
  • LICENSE.txt
  • QUICKSTART.txt
  • README.md
  • assets/
  • bin/
  • config.sample.php
  • controllers/
  • deploy/
  • index.php
  • install/
  • manifest.json
  • offline.html
  • router.php
  • src/
  • sw.js
  • tests/
  • views/
src/Complaints.php: a real module, the first 24 of 385 lines

Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.

<?php
/**
 * Complaints.php — THE core: DUAA s.103 complaints lifecycle (fully covered by tests/run.php, offline).
 *
 * 1. ACKNOWLEDGMENT TIMER. DPA 2018 s.164A(3) (inserted by the Data (Use and Access) Act
 *    2025 s.103) requires controllers to acknowledge a data-protection complaint "within the
 *    period of 30 days beginning when the complaint is received". Ack due date =
 *    received date + ack_window_days (configurable in Settings). daysRemaining()
 *    yields a signed day count against "today" in the business timezone.
 *
 *    WHY THE DEFAULT IS 29, NOT 30: the statute counts "beginning WHEN the complaint is
 *    received" — unusual drafting, new Act, no case law yet. If the day of receipt is day 1
 *    (the strict reading), received + 30 days is ONE DAY LATE. A 29-day window is safe under
 *    both readings: worst case you acknowledge a day early, which costs nothing; the
 *    alternative worst case is a breach. If guidance settles the construction, change one
 *    setting — no code.
 *
 * 2. DERIVED STATUS. Stored status is one of: received / acknowledged / investigating /
 *    resolved / rejected. deriveStatus() injects 'ack_overdue' when the complaint is still
 *    awaiting acknowledgment past its due date.
 *    Precedence: rejected -> resolved -> ack_overdue -> investigating -> acknowledged -> received
 *
 * 3. TRACKING TOKEN. Public token: 40 hex chars (random_token(20)), unguessable, unique.
 *    Lookups are exact parameterized matches; misses 404.

Runs on: Two-minute web installer; PHP 8.1+ with MySQL or SQLite, standard shared-hosting compatible; Nginx snippet included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.

Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- complia <your license key>

Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run

Which license do I need?

It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.

Single license$79
One (1) domain or subdomain · One business, running it on one site.
  • Install it on one domain or subdomain you own or operate
  • Change the source however you like for that installation
  • Run your own business on it commercially, client work included
  • Re-download the current build any time from your buyer portal
  • A second site, or an installation you hand to a client as theirs, needs the Extended license
  • No reselling, redistributing or sublicensing the source
  • Not for offering it to other people as a hosted service
Buy the Single license, $79
Extended license$179
Unlimited sites you own or operate, plus up to 10 client installations (white-label included) · Agencies, and anyone running it on more than one site.
  • Everything the Single license grants
  • Install it on as many domains as you own or operate — no cap on the number
  • Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
  • White-label: remove or replace the product name and logo in the screens of client installations
  • Still no reselling or redistributing the source itself
  • Running it as a multi-tenant service others sign up for needs a SaaS agreement
Buy the Extended license, $179

Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.

After you buy

Updates

The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.

Help

Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers

If it isn’t right

Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms

If we disappear

It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.

Questions

Does this make me DUAA-compliant?
No tool can claim that. Complia implements the record-keeping and acknowledgment mechanics the duty describes; your policies, responses, and legal position are yours. It's a documentation and records aid, not legal advice.
Is the 19 June 2026 deadline real?
The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025, and S.I. 2026/82 reg. 3(a) brought the complaints-handling duty in s.103 fully into force on 19 June 2026 — it now sits in s.164A of the Data Protection Act 2018. Check legislation.gov.uk and ico.org.uk before publishing your own compliance dates.
Will this run on shared hosting?
Yes. Complia requires PHP 8.1+ with pdo — present on virtually all cPanel/Plesk hosts. Installation takes about two minutes through the web installer.
Can multiple organizations share one install?
No — Complia is single-tenant: one organization per installation. Your team shares it with viewer, member and admin roles, invited by link. DPOs running logs for several clients use one install per client.
Does it send emails automatically?
It emails you the moment a complaint arrives, through your own SMTP server. It emails the complainant only when you switch receipts on and they tick the box. With acknowledgment reminders switched on, it emails a complaint's owner and your notification address before the acknowledgment date and once the day after it passes.
Does it email the complainant?
Only with double consent: you switch receipts on in Settings AND the complainant ticks the box on the form. The receipt carries the reference, the deadline and their tracking link — never the text of the complaint — and it is sent exactly once.
Is Complia a subscription?
You buy it once and own that copy. There is no subscription, no per-user fee and nothing that renews — the license tier decides how many sites you may run it on, not how many people use it. A complaints register is a record you may need years after the complaint, so owning the copy matters more here than most.
We are quoted a per-user price by a compliance suite. How does this compare?
This is not priced per user at all — the license tier governs sites, not seats, so the price does not move when the team grows. We will not characterize anyone else's pricing; compare it against the quote you actually hold.
What exactly do I get for the money?
The download is the complete PHP source with the database schema. Read it, change it, keep it. If we vanished tomorrow the copy on your server keeps working, because nothing in it phones home to us.
Can I get the register out for an auditor?
Yes — the register and the audit trail both export as CSV, which is what an auditor usually asks for. The export records what was logged and when; it does not certify that your handling met any obligation, and neither does this product.
Better together
Compliance Suite: Privara, Confida, Complia, Packora and Cyresora
Five registers that record GDPR requests, whistleblowing reports, NIS2 and CRA reporting deadlines, complaints and packaging data, on your own server.
5 tools for$299
$435 separatelySave $136

Covered in these guides

More about Complia

Since 19 June 2026, UK data controllers acknowledge a data-protection complaint within 30 days (DPA 2018 s.164A). Complia, a self-hosted complaints register, records each complaint, its clock and its outcome.

The problem it solves

If someone complains about how you handled their personal data, you have to be able to show three things later: when the complaint arrived, what it said, and what you did about it. Many small organizations keep complaints in an inbox and a spreadsheet, with no timer and no audit trail. The UK now puts a clock on it: section 103 of the Data (Use and Access) Act 2025 adds a complaints duty for UK data controllers, including acknowledgment within 30 days; check its current text and commencement at legislation.gov.uk. Complia records each complaint against that clock, and the window is a setting. Complia ships configured for that clock, but the window is a setting - the register, intake form and audit export suit any regime that expects a complaints record.

Most small organizations currently handle this in an inbox and a spreadsheet, with no timer, no audit trail, and nothing to show the regulator.

Every feature

  • A receipt to the complainant. Reference, dates, the response deadline and their tracking link — and deliberately not one word they wrote, because a register must never become the leak it exists to record. Doubly opt-in: you switch it on AND they tick the box. Sent once, ever.
  • Evidence from the complainant. The public form can accept up to 3 files (PDF, PNG, JPEG, TXT, EML — decided by the file's bytes, not its name). Off by default; a refused file never loses the complaint, and the complainant is told what was kept.
  • A tracking link that opens the case. The emailed link lands the complainant on their own case status — no re-typing a 40-character code. Bad tokens 404; the code alone stays the only credential.
  • Public complaint form. A no-login public form you link from your privacy notice; complainants get a private tracking code on submission.
  • Public status page. Complainants check progress with their tracking code — status only, no personal data exposed.
  • 29-day acknowledgment timer. The admin register shows days-remaining and OVERDUE flags against the statutory acknowledgment window.
  • Status workflow with audit log. Move complaints through received, acknowledged, investigating, resolved, or rejected, with an append-only, timestamped investigation log per complaint.
  • Compliance dashboard. See open complaints, acknowledgments due within 7 days, overdue acknowledgments, and resolutions this month.
  • Audit CSV export. Export the full register, including status history, as CSV to share with your DPO or a regulator.
  • Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
  • A report for the board. For any period: complaints received, acknowledged on time, late or not yet, the median days to acknowledge and to close, the outcomes, month by month, and who holds the open ones. Download it as CSV.
  • Your procedure beside your register. Every version of your complaints procedure with the date it takes effect and its next review date; link the current one from your public complaint form.
  • The records beside a complaint. Link a complaint to the subject access request it is about, or a breach record. If you run Privara, Complia reads that request's status and deadline for you.
  • Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
  • Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
  • Own It 4.0.1 — fixes and an up-to-date manual. For Complia, 4.0.1 fixes an installer that had lost its styling and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
  • Own It 4.0.2 — the installer opens on every host. For Complia, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Complia's Docker image also gives the web server the whole app folder, so a Docker install can finish and update itself. Your license covers it: press Check for updates on the Updates page, or download it from your order page.

Release notes in full

  • Own It 4.1: client installations and your other tools. For Complia, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Complia to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
  • Own It 4.0: it updates and backs itself up. For Complia, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
  • Own It 3.3: the import preview tells the truth. The CSV import's preview used to count a complaint dated a day that does not exist as ready, and the import then skipped it. Now the preview shows it as skipped before you confirm, and the import itself refuses such a date.
  • Own It 3.2: the register, reported upward. For Complia, the 3.2 wave brought a leadership report for the board, your complaints procedure kept beside the register with every version and its review date, and a complaint linked to the subject access request or breach record it concerns. Each new complaint and each acknowledgment reminder can also post one line to your team's chat: the number and the date, never what the complainant wrote.
  • Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
  • Own It 3.0: works for your AI, not just for you. Your statutory deadlines land in your calendar: a read-only feed of every open acknowledgment deadline, overdue ones saying so in the title, complaints you have marked as acknowledged dropping out automatically. The statutory-clock page computes overdue and due-soon the moment you look — deliberately a page, not a nightly email that can silently stop.
  • Own It 2.0: API, 2FA, backups, dark mode. Complia 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.

Browse self-hosted: Compliance software

Complia$79 once
Demo Buy