
The compliance platform for lean teams.
Cob learns your business, evaluates it against 100+ US and European laws, builds tailored solutions, and keeps you compliant as things change.
Laws covered: GDPR CCPA EU AI Act PECR CIPA and 100+ more
You already have all we need.
Your website, investor materials or unstructured notes are enough to get started. We’ll meet you wherever you are.
northsend.example.com
- pitch-deck.pdf
- business-notes.txt
- data-flows.png
We start by learning your business.
Cob analyzes what you handed over and builds a detailed profile of your company. How your product works, how you operate, what data flows through your systems, who your customers are, and where they are located. This profile is the foundation that everything else rests on.
northsend.example.com
Northsend is bookkeeping for small teams — invoices, expenses, and the year-end return without the spreadsheet. Start your free trial — all you need is an email address. Built in Denver, used by 12,000 small businesses in the US and the UK. Now serving Germany, Ireland and the Netherlands. Need help with a number? Ask our AI assistant — it knows your books as well as you do. Subscribe to our newsletter for product updates. We use cookies to improve your experience.
Northsend
Bookkeeping software for small teams, based in Denver, serving US and European markets
Who it sells to
- Consumers
What it handles
- Personal data
Where it sells
- US
- UK
- DE
- IE
- NL
What it does
- AI assistant
- Marketing
- Tracking
How big it is
A short conversation completes the picture.
A conversation with an AI compliance advisor that helps fill gaps, work through uncertainty, and answer your questions. Speak with it in terms that make sense to you.
Where does your customer data actually sit?
In the US — all of it’s on AWS in Oregon.
Your assistant handles financial data. Does it decide anything for a user, or just answer questions?
It only answers questions about their own books.
That distinction matters. Systems that make decisions about people fall under stricter rules.
How many Californians do you reach in a year?
A few hundred at most.
We evaluate your business against 100+ laws.
Your business profile becomes a set of facts. Our rule engine evaluates your business against every law that we review, document, and maintain.
Facts about your business
- Uses an AI chatbot Yes
- Tracks people's behaviour in the EEA Yes
- Records user sessions Yes
- Runs sales and discounts Yes
- Makes green claims Yes
- California consumers reached each year at least 1 and up to 900 persons per year
and 98 more
Cob’s legal database
- Arkansas Children and Teens' Online Privacy Protection Act
- California (CCPA/CPRA)
- Switzerland — revised Federal Act on Data Protection (revFADP)
- Switzerland — TCA Art. 45c(b) Cookie Rules
- Switzerland — Unfair Competition Act (UWG/UCA) + PBV
- Colorado ADMT (SB 26-189)
- Colorado biometric identifiers
- ePrivacy Directive (2002/58/EC)
- EU ADR consumer-information duties
- EU Consumer Rights Directive
- EU Geo-blocking Regulation
- EU General Product Safety Regulation
- EU Price Indication Directive
- EU Unfair Commercial Practices Directive
- EU AI Act (Reg. (EU) 2024/1689)
- EU Cyber Resilience Act (Reg. (EU) 2024/2847)
- EU Data Act — cloud switching (Reg. (EU) 2023/2854)
- EU Digital Services Act (Reg. (EU) 2022/2065)
- European Accessibility Act (Dir. (EU) 2019/882)
- eIDAS 2 / EUDI wallet (Reg. (EU) 2024/1183)
- EU NIS2 — digital entities (Dir. (EU) 2022/2555)
- EU P2B platform-fairness rules (Reg. (EU) 2019/1150)
- Florida (FDBR)
- Florida §501.715 — for-profit sensitive-sale duty
- EU GDPR (Regulation (EU) 2016/679)
- Illinois BIPA (biometric privacy)
- Illinois GIPA (genetic privacy)
- Massachusetts WISP (201 CMR 17.00)
- Maryland Kids Code
- Minnesota MCDPA — small-business sensitive-sale duty
- Nebraska NDPA — small-business sensitive-sale duty
- Nevada consumer health data (SB 370)
- New York Child Data Protection Act
- New York SHIELD Act
- UK PECR (Privacy and Electronic Communications Regulations 2003)
- Rhode Island third-party disclosure notice
- Texas TDPSA — small-business sensitive-sale duty
- Texas CUBI (biometric)
- UK DMCC Act 2024 (consumer provisions)
- UK GDPR (Retained Regulation (EU) 2016/679 as amended)
- UK Online Safety Act 2023
- US breach notification
- CAN-SPAM Act
- US AI chatbot disclosure
- COPPA (children's online privacy)
- US data broker registration
- FTC Act §5 (federal baseline)
- FTC Health Breach Notification Rule
- Session-tracking wiretap exposure (CIPA)
- TCPA (marketing calls & texts)
- Video Privacy Protection Act (VPPA)
- Virginia reproductive/sexual health (SB 754)
- Vermont consumer health data (VDPOSA)
- Washington My Health My Data Act
- Alabama (APDPA)
- Colorado (CPA)
- Connecticut (CTDPA)
- Delaware (DPDPA)
- Indiana (INCDPA)
- Iowa (ICDPA)
- Kentucky (KCDPA)
- Louisiana (LDPA)
- Maryland (MODPA)
- Minnesota (MCDPA)
- Montana (MCDPA)
- Nebraska (NDPA)
- New Hampshire (NHPA)
- New Jersey (NJDPA)
- Oklahoma (SB 546)
- Oregon (OCPA)
- Rhode Island (RIDTPPA)
- Tennessee (TIPA)
- Texas (TDPSA)
- Utah (UCPA)
- Vermont (VDPOSA)
- Virginia (VCDPA)
- Arkansas Children and Teens' Online Privacy Protection Act
- California (CCPA/CPRA)
- Switzerland — revised Federal Act on Data Protection (revFADP)
- Switzerland — TCA Art. 45c(b) Cookie Rules
- Switzerland — Unfair Competition Act (UWG/UCA) + PBV
- Colorado ADMT (SB 26-189)
- Colorado biometric identifiers
- ePrivacy Directive (2002/58/EC)
- EU ADR consumer-information duties
- EU Consumer Rights Directive
- EU Geo-blocking Regulation
- EU General Product Safety Regulation
- EU Price Indication Directive
- EU Unfair Commercial Practices Directive
- EU AI Act (Reg. (EU) 2024/1689)
- EU Cyber Resilience Act (Reg. (EU) 2024/2847)
- EU Data Act — cloud switching (Reg. (EU) 2023/2854)
- EU Digital Services Act (Reg. (EU) 2022/2065)
- European Accessibility Act (Dir. (EU) 2019/882)
- eIDAS 2 / EUDI wallet (Reg. (EU) 2024/1183)
- EU NIS2 — digital entities (Dir. (EU) 2022/2555)
- EU P2B platform-fairness rules (Reg. (EU) 2019/1150)
- Florida (FDBR)
- Florida §501.715 — for-profit sensitive-sale duty
- EU GDPR (Regulation (EU) 2016/679)
- Illinois BIPA (biometric privacy)
- Illinois GIPA (genetic privacy)
- Massachusetts WISP (201 CMR 17.00)
- Maryland Kids Code
- Minnesota MCDPA — small-business sensitive-sale duty
- Nebraska NDPA — small-business sensitive-sale duty
- Nevada consumer health data (SB 370)
- New York Child Data Protection Act
- New York SHIELD Act
- UK PECR (Privacy and Electronic Communications Regulations 2003)
- Rhode Island third-party disclosure notice
- Texas TDPSA — small-business sensitive-sale duty
- Texas CUBI (biometric)
- UK DMCC Act 2024 (consumer provisions)
- UK GDPR (Retained Regulation (EU) 2016/679 as amended)
- UK Online Safety Act 2023
- US breach notification
- CAN-SPAM Act
- US AI chatbot disclosure
- COPPA (children's online privacy)
- US data broker registration
- FTC Act §5 (federal baseline)
- FTC Health Breach Notification Rule
- Session-tracking wiretap exposure (CIPA)
- TCPA (marketing calls & texts)
- Video Privacy Protection Act (VPPA)
- Virginia reproductive/sexual health (SB 754)
- Vermont consumer health data (VDPOSA)
- Washington My Health My Data Act
- Alabama (APDPA)
- Colorado (CPA)
- Connecticut (CTDPA)
- Delaware (DPDPA)
- Indiana (INCDPA)
- Iowa (ICDPA)
- Kentucky (KCDPA)
- Louisiana (LDPA)
- Maryland (MODPA)
- Minnesota (MCDPA)
- Montana (MCDPA)
- Nebraska (NDPA)
- New Hampshire (NHPA)
- New Jersey (NJDPA)
- Oklahoma (SB 546)
- Oregon (OCPA)
- Rhode Island (RIDTPPA)
- Tennessee (TIPA)
- Texas (TDPSA)
- Utah (UCPA)
- Vermont (VDPOSA)
- Virginia (VCDPA)
From hundreds of laws to the ones that apply to yours.
Every law that applies comes with the exact provision, the requirements it places on your business, and the steps you need to take to comply.
Here are four that apply, and one that doesn't.
- Applies
EU GDPR (Regulation (EU) 2016/679)
GDPR Arts. 2-3
- Applies
UK DMCC Act 2024 (consumer provisions)
Digital Markets, Competition & Consumers Act 2024 Pt. 3-4
- Applies
US AI chatbot disclosure
Me. LD 1727; Utah Code §13-2-12 (AIPA)
- Applies
CAN-SPAM Act
15 U.S.C. §§7701-7713
- Doesn’t apply
California (CCPA/CPRA)
- Annual gross revenue up to 2,000,000 USD
- Revenue from selling or sharing data up to 1 percent
- California consumers reached each year at least 1 and up to 900 persons per year
What your business needs to stay compliant — built, live, and maintained.
A consent banner configured for your specific obligations. Policies drafted and tailored to your business. A trust center that helps you build trust with customers and partners, current and prospective. All kept up to date as the law or your business change.
Privacy Policy
What we collect
Where it goes
Your rights
Transfers outside the EEA
Drafted by Cob
Trust center
Subprocessors
Data residency
How to make a request
Hosted by Cob
Questions
Who is Cob for?
Companies that are based in or serve customers in the US or Europe. We focus on businesses that have real compliance obligations but limited resources to manage them. Startups, growing organizations, and companies expanding into new markets.
What laws does Cob cover?
Over 100 laws, including GDPR, CCPA, the EU AI Act, PECR, state privacy statutes, and accessibility rules. We constantly expand coverage as the regulatory landscape changes.
How does Cob know which laws apply?
Every law Cob covers is documented, maintained, and reviewed by hand. Each one carries the conditions that trigger it, the obligations it creates, and the provision behind every answer. Our rule engine evaluates your business against that knowledge base, one law at a time.
Does Cob use AI?
Yes. We use AI to build a picture of your business and help manage your compliance. However, AI never makes legal determinations, and all final decisions are left in your hands.
Why not just ask ChatGPT or Claude?
Foundation models are useful but they hallucinate and have limited context on your business. Cob uses AI too. The difference is that every answer is grounded in your specific business profile and a body of law that doesn't change between questions.
Does Cob provide legal advice?
No. Cob is not a law firm and nothing on the platform constitutes legal advice. Cob is not responsible for any output it produces about your business, including determinations, documents, and recommendations. We recommend consulting with a lawyer for legal decisions.
See what applies to your business.
