About Policly
Compliance tooling that respects your time — and your judgement
Policly exists to close the gap between expensive consultancy retainers and the generic policy templates floating around the internet. We give small and mid-sized organisations the documents, classification and health-check tools they need to take privacy and information security seriously — without paying four figures a month for the privilege.
Our vision
Make compliance accessible
GDPR, UK DPA, ISO 27001, NIST/CMMC and EAR/ITAR shouldn't be reserved for organisations with a dedicated legal team. Clear documents, plain language, real citations.
Privacy by default
We process documents in-memory wherever possible and purge anything that touches storage within 30 minutes. The tool that helps you protect data shouldn't be hoarding it.
Practitioner-built, not template-built
Every suite, sample and check is grounded in current regulatory text and the realities of running a governance function — not stitched together from blog posts.
Cite everything
If we point at a clause, we link the source — ICO guidance, EUR-Lex, NIST publications, gov.uk. You should always be able to verify what Policly tells you.
About the founder

Callum Hendry, BSc (Hons), CDMP
Privacy & Data Governance Specialist · Ex-Military Intelligence · GDPR · DPIA · NIST / CMMC
Policly was built by a working privacy and data governance practitioner with day-to-day responsibility for protecting sensitive information in a regulated, security-conscious industrial setting. The platform is shaped by the documents, gaps and friction encountered in that role — not by guesses about what a compliance team might want.
Before moving into civilian data governance, Callum served in military intelligence, where handling classified material, controlled-information regimes and rigorous need-to-know discipline were the daily baseline. That background shapes Policly's posture on information assurance: assume the data matters, design as if a regulator (or an auditor with a clearance) will read it, and never ask the user to trust the platform on vibes alone.
Credentials include a BSc (Hons) and the CDMP (Certified Data Management Professional). Outside Policly, the focus is on building privacy programmes that survive audits, scale with the business, and stay readable to the humans who have to follow them.
Try it before you trust it
Run a free 60-second health check, or browse sample policies from every suite — no sign-up required.