Complia
A complaints register that records each complaint, its acknowledgment clock and its outcome, with a public form.
For UK data controllers handling data-protection complaints. Often replaces HappyFox or ProvePrivacy.
Single license $79 · Extended license $179 · paid once, yours for good
What it does
A no-login form you link from your privacy notice. Complainants get a private tracking code on submission.
The register shows days remaining and overdue flags against the acknowledgment window, which is a setting.
Move complaints from received to resolved or rejected, with an append-only, timestamped investigation log per complaint.
For any period: complaints received, acknowledged on time or late, median days to acknowledge and close, and outcomes.
Reference, dates, the response deadline and their tracking link, and not one word they wrote. You switch it on and they tick the box.
Every version of your complaints procedure, with its effective and next review dates. Link it from your public form.
Link a complaint to its subject access request or breach record. With Privara, Complia reads that request's status and deadline.
The public form can accept up to 3 files, typed by their bytes. Off by default; a refused file never loses the complaint.
Complainants check progress with their tracking code: status only, no personal data shown.
Export the full register, with status history, as CSV to share with your DPO or a regulator.
Each new complaint and acknowledgment reminder can post one line to your chat. The number and date only.
Also: a dashboard of what is due, a named owner per complaint and a calendar feed.
What Complia deliberately doesn’t do.
- Single-tenant: one organization per installation (your team shares it, with viewer / member / admin roles and invite links).
- Email goes through your own SMTP server, never ours. Acknowledgment reminders are optional and off until you switch them on; they are checked whenever someone opens the dashboard, and by a daily cron call on days nobody does.
- Not a case-management suite: each complaint can have one named owner and acknowledgment reminders, but there is no workload allocation, no escalation between people and no billing. Attachments and an append-only investigation log are in.
- English-language UI.
- A records aid, not legal advice; buying it does not make you compliant.
What renting costs instead
If you use a help desk as your complaints log: HappyFox starts at $24 per agent per month (read 2026-09-03). Complia is $79.00, once, and does a narrower job.
Read Sep 3, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? HappyFox alternative · ProvePrivacy (representative vendor) alternative
Release history
For Complia, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Complia, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
The CSV import's preview used to count a complaint dated a day that does not exist as ready, and the import then skipped it. What’s new in 3.3 →
For Complia, the 3.2 wave brought a leadership report for the board, your complaints procedure kept beside the register with every version and its review date, and a…
The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…
Your statutory deadlines land in your calendar: a read-only feed of every open acknowledgment deadline, overdue ones saying so in the title, complaints you have marked…
Complia 2.0 adds the 2.0 owner layer.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- LICENSE.txt
- QUICKSTART.txt
- README.md
- assets/
- bin/
- config.sample.php
- controllers/
- deploy/
- index.php
- install/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Complaints.php: a real module, the first 24 of 385 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php /** * Complaints.php — THE core: DUAA s.103 complaints lifecycle (fully covered by tests/run.php, offline). * * 1. ACKNOWLEDGMENT TIMER. DPA 2018 s.164A(3) (inserted by the Data (Use and Access) Act * 2025 s.103) requires controllers to acknowledge a data-protection complaint "within the * period of 30 days beginning when the complaint is received". Ack due date = * received date + ack_window_days (configurable in Settings). daysRemaining() * yields a signed day count against "today" in the business timezone. * * WHY THE DEFAULT IS 29, NOT 30: the statute counts "beginning WHEN the complaint is * received" — unusual drafting, new Act, no case law yet. If the day of receipt is day 1 * (the strict reading), received + 30 days is ONE DAY LATE. A 29-day window is safe under * both readings: worst case you acknowledge a day early, which costs nothing; the * alternative worst case is a breach. If guidance settles the construction, change one * setting — no code. * * 2. DERIVED STATUS. Stored status is one of: received / acknowledged / investigating / * resolved / rejected. deriveStatus() injects 'ack_overdue' when the complaint is still * awaiting acknowledgment past its due date. * Precedence: rejected -> resolved -> ack_overdue -> investigating -> acknowledged -> received * * 3. TRACKING TOKEN. Public token: 40 hex chars (random_token(20)), unguessable, unique. * Lookups are exact parameterized matches; misses 404.
Runs on: Two-minute web installer; PHP 8.1+ with MySQL or SQLite, standard shared-hosting compatible; Nginx snippet included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- complia <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Does this make me DUAA-compliant?
Is the 19 June 2026 deadline real?
Will this run on shared hosting?
Can multiple organizations share one install?
Does it send emails automatically?
Does it email the complainant?
Is Complia a subscription?
We are quoted a per-user price by a compliance suite. How does this compare?
What exactly do I get for the money?
Can I get the register out for an auditor?
Covered in these guides
More about Complia
Since 19 June 2026, UK data controllers acknowledge a data-protection complaint within 30 days (DPA 2018 s.164A). Complia, a self-hosted complaints register, records each complaint, its clock and its outcome.
The problem it solves
If someone complains about how you handled their personal data, you have to be able to show three things later: when the complaint arrived, what it said, and what you did about it. Many small organizations keep complaints in an inbox and a spreadsheet, with no timer and no audit trail. The UK now puts a clock on it: section 103 of the Data (Use and Access) Act 2025 adds a complaints duty for UK data controllers, including acknowledgment within 30 days; check its current text and commencement at legislation.gov.uk. Complia records each complaint against that clock, and the window is a setting. Complia ships configured for that clock, but the window is a setting - the register, intake form and audit export suit any regime that expects a complaints record.
Most small organizations currently handle this in an inbox and a spreadsheet, with no timer, no audit trail, and nothing to show the regulator.
Every feature
- A receipt to the complainant. Reference, dates, the response deadline and their tracking link — and deliberately not one word they wrote, because a register must never become the leak it exists to record. Doubly opt-in: you switch it on AND they tick the box. Sent once, ever.
- Evidence from the complainant. The public form can accept up to 3 files (PDF, PNG, JPEG, TXT, EML — decided by the file's bytes, not its name). Off by default; a refused file never loses the complaint, and the complainant is told what was kept.
- A tracking link that opens the case. The emailed link lands the complainant on their own case status — no re-typing a 40-character code. Bad tokens 404; the code alone stays the only credential.
- Public complaint form. A no-login public form you link from your privacy notice; complainants get a private tracking code on submission.
- Public status page. Complainants check progress with their tracking code — status only, no personal data exposed.
- 29-day acknowledgment timer. The admin register shows days-remaining and OVERDUE flags against the statutory acknowledgment window.
- Status workflow with audit log. Move complaints through received, acknowledged, investigating, resolved, or rejected, with an append-only, timestamped investigation log per complaint.
- Compliance dashboard. See open complaints, acknowledgments due within 7 days, overdue acknowledgments, and resolutions this month.
- Audit CSV export. Export the full register, including status history, as CSV to share with your DPO or a regulator.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- A report for the board. For any period: complaints received, acknowledged on time, late or not yet, the median days to acknowledge and to close, the outcomes, month by month, and who holds the open ones. Download it as CSV.
- Your procedure beside your register. Every version of your complaints procedure with the date it takes effect and its next review date; link the current one from your public complaint form.
- The records beside a complaint. Link a complaint to the subject access request it is about, or a breach record. If you run Privara, Complia reads that request's status and deadline for you.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Complia, 4.0.1 fixes an installer that had lost its styling and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Complia, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Complia's Docker image also gives the web server the whole app folder, so a Docker install can finish and update itself. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Complia, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Complia to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Complia, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.3: the import preview tells the truth. The CSV import's preview used to count a complaint dated a day that does not exist as ready, and the import then skipped it. Now the preview shows it as skipped before you confirm, and the import itself refuses such a date.
- Own It 3.2: the register, reported upward. For Complia, the 3.2 wave brought a leadership report for the board, your complaints procedure kept beside the register with every version and its review date, and a complaint linked to the subject access request or breach record it concerns. Each new complaint and each acknowledgment reminder can also post one line to your team's chat: the number and the date, never what the complainant wrote.
- Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
- Own It 3.0: works for your AI, not just for you. Your statutory deadlines land in your calendar: a read-only feed of every open acknowledgment deadline, overdue ones saying so in the title, complaints you have marked as acknowledged dropping out automatically. The statutory-clock page computes overdue and due-soon the moment you look — deliberately a page, not a nightly email that can silently stop.
- Own It 2.0: API, 2FA, backups, dark mode. Complia 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Compliance software