UK GDPR Compliant

    Privacy Policy

    Document Reference: DC-PP-2026-V2 (Dual-Framework B2B/B2C)
    Last Modified: June 2026
    Classification: Public Transparency / Legal Infrastructure

    UK GDPR Compliant

    Fully aligned with UK GDPR and the Data Protection Act 2018

    Your Data, Your Rights

    Access, correct, or erase your data at any time

    No Hidden Practices

    Complete transparency on how AI processes your information

    1. OVERVIEW & SCOPE

    Data Compass Ltd (“Data Compass,” “we,” “us,” and “our”) respects your privacy and is committed to protecting it through compliance with this Privacy Policy (“Privacy Policy”). This document outlines our structural protocols regarding the collection, use, safeguarding, and disclosure of Personal Information when you visit our website at https://datacompass.co.uk, register for an account, or interface with any segment of our operational operating system platform (collectively, the "Platform").

    This Privacy Policy adapts dynamically to protect both Business-to-Business (B2B) corporate clients and Business-to-Consumer (B2C) individual users or sole traders.

    The Processor vs. Controller Boundary:

    • Data Compass as a Controller: We act as a standalone Controller for the basic relationship management details, meta-account configurations, profile logins, and direct billing histories of our registered Customers.
    • Data Compass as a Processor: This Privacy Policy does not apply to data subjects or downstream end-consumers whose Personal Information is uploaded, ingested, or routed through the Platform by our Customers. In those scenarios, our Customers act as the Controllers of their own data pipelines, and Data Compass acts strictly as a Processor under the terms of our Customer Data Processing Addendum (DPA).

    2. PERSONAL INFORMATION WE COLLECT

    To deliver our integrated all-in-one operational environment and collapse complex software stacks (The Frankenstack), we collect several categories of information based on your interaction type:

    A. Information You Provide Natively

    • Account and Profile Credentials: Full name, corporate or personal email address, telephone contact points, business entity names, and verified log-in sequences.
    • Transactional and Invoice Meta-Data: Billing addresses and secure payment tokens. Please note: Data Compass does not store raw credit card numbers on its servers; all card transactions are processed via encrypted, PCI-DSS compliant third-party payment gateways (e.g., Stripe).
    • Support and Interaction Logs: Text strings, support tickets, and communication records generated when you interface with our compliance desk or request technical support.

    B. Information Collected Automatically via Platform Telemetry

    When you navigate our Website or log into your dashboard, our native cloud infrastructure automatically captures system health parameters, including:

    • Device and Routing Metrics: IP addresses, browser types, operating system profiles, access timestamps, and geographic region settings.
    • Usage and Performance Data: Logic-driven workflow execution histories, page routing trends, click paths, and system performance telemetry.
    • Tracking and Cookie Elements: Data retrieved through native session trackers, pixels, and web analytics tools (including Google Analytics, Microsoft Clarity, and LinkedIn tracking pixels utilized to measure conversion pathways). For a granular breakdown, please consult our Cookie & Tracking Technology Policy.

    3. HOW WE UTILISE YOUR PERSONAL INFORMATION

    We process your personal information based on lawful grounds under the UK GDPR, including contract execution, legitimate commercial optimization, and legal compliance. Explicitly, we use your data to:

    • Provision and Maintain the Platform: Set up your multi-tenant account silo, secure login access nodes, verify system uptime, and track user configurations.
    • Manage Dynamic Billing and Auto-Renewals: Track your subscription choices and map consumption-based Utility Fees ("Fuel") such as telephony minutes, SMS segments, email delivery layers, and AI Compute Tokens.
    • Execute Logic-Driven Personalization: Fuel our communication triage pipelines, handle calendar synchronization schedules, and run background automation routines.
    • Provide Customer Care: Route and resolve system diagnostic tickets through our support tracking infrastructure.
    • Maintain System Security: Intercept malicious bot networks, detect unauthorized credential use, and safeguard server node stability.

    4. CORE TECHNICAL BOUNDARIES & FINANCIAL LIMITATIONS

    4.1. The Logic-Driven AI Boundary: Artificial Intelligence capabilities within Data Compass operate as structural processing utilities that execute autonomous background routines, triage inbound conversational threads, and ingest knowledge bases based on the customer's direct consumption of AI Compute Tokens. These systems do not perform unverified, standalone independent neural net forecasting.

    4.2. The Unified Revenue Core Boundary: Our Revenue Core module connects customer digital signatures, proposals, estimates, and billing data straight to your payment gateway. This framework does not constitute automated tax compliance, accounting, or regulatory CPA bookkeeping software. The processing of financial records for statutory tax ledger compliance remains entirely external to Data Compass.

    5. COMMERCIAL INTEGRITY: NO SELLING OF DATA

    Data Compass explicitly reinforces that it receives no personal data as currency or consideration. As between the parties, the Customer retains absolute ownership and title over all ingested pipeline data. Data Compass shall never sell, rent, trade, lease, or commercially exploit Personal Information or customer databases to third-party data-brokers or external marketing houses. Your data remains strictly confidential and securely isolated within your operational silo.

    6. SHARING AND DISCLOSURE OF INFORMATION

    We only share personal information with third-party vendors and contracted infrastructure processors who are bound by strict data processing terms and require access to execute primary platform functions:

    • Core Infrastructure Providers: Highly secure cloud container storage layers hosted via Google Cloud Services and Amazon Web Services (AWS).
    • Communication Routing Networks: Specialized API operators handling delivery layers for SMS, telephony, and emails (such as Twilio and Mailgun).
    • Payment Terminals: PCI-compliant billing networks (such as Stripe) to process transaction settlements.
    • AI Processing Utilities: Secure language models (such as OpenAI) tasked with executing specific token-based text summaries and triage flows.
    • Professional and Analytics Trackers: Operational analytics networks (such as Google, Microsoft Clarity, and LinkedIn) to audit campaign performance and optimize layout speeds.
    • Legal and Regulatory Authorities: We may disclose personal data if strictly mandatory under applicable UK or European statutes, or to protect our legal rights in the event of an active contract dispute.

    7. INTERNATIONAL DATA TRANSFERS

    Because our primary runtime infrastructure partners utilize secure cloud clusters located outside the United Kingdom and the European Economic Area (EEA)—specifically within the United States—your personal data may be transferred across international borders.

    To safeguard these restricted transfers, Data Compass ensures all downstream infrastructure nodes execute approved Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum. Furthermore, our upstream primary cloud routing layers maintain full alignment with authorized cross-border frameworks, including the UK Extension to the EU-U.S. Data Privacy Framework.

    8. DATA RETENTION AND ACCOUNT LIFECYCLE

    We retain your personal data only for as long as your software subscription account remains active or as required to fulfill the business purposes outlined in this Policy.

    Upon the formal cancellation or termination of your subscription service, Data Compass closes active dashboard access. Personal Data residing within our active database ledgers is systematically deleted or anonymized in accordance with our standard lifecycle protocols, except where retention is strictly mandatory under applicable UK corporate, financial, or statutory laws. Residual information inside non-indexed backup archives is securely isolated and left to naturally expire.

    9. SECURITY SAFEGUARDS

    Data Compass maintains rigorous technical and organizational measures (TOMs) to safeguard personal information from unauthorized access, loss, or alteration. Because our operating platform inherits premier cloud container architectures, our users benefit from:

    • Native AES-256 data encryption at rest and TLS 1.3 encryption across all transit routing endpoints.
    • Continuous logical firewalls and isolated cloud container security parameters.
    • Real-time security access control logging and centralized vulnerability tracking.

    10. YOUR PRIVACY RIGHTS AND CONTROL MECHANICS

    Depending on your regional location (such as the UK or EEA) and whether you interface with us as a B2B professional or a B2C individual, you possess the following rights under Applicable Data Protection Laws:

    • The Right to Access / Portability: Request a copy of the personal data we hold about you in a clean, structured format.
    • The Right to Rectification: Request the immediate correction of inaccurate or incomplete profile records.
    • The Right to Erasure ("Right to be Forgotten"): Request the erasure of your personal data when it is no longer required for active contract execution.
    • The Right to Restrict or Object: Object to the processing of your data based on our legitimate commercial interests.
    • Global Privacy Control (GPC) & Consent: Our website natively reads and honors GPC broadcasting signals. If your browser issues a GPC privacy flag, our systems interpret it as a binding instruction to opt out of all non-essential tracking (including performance and marketing cookies).

    To exercise any of these rights, please submit a formal query directly to our compliance desk at data@datacompass.co.uk. If you are a consumer and believe we have handled your data non-compliantly, you possess the right to lodge a formal complaint with the UK Information Commissioner’s Office (ICO) or your local supervisory body.

    11. REVISIONS AND CORPORATE CONTACT

    Data Compass Ltd reserves the right to modify this Privacy Policy dynamically to mirror new software deployments, feature updates, or legislative changes. Revisions will be made clear by an updated timestamp at the apex of this document.

    Contact Our Compliance Desk

    For all legal queries, regulatory data audits, or clarification regarding our privacy practices:

    Corporate Entity Name: Data Compass Ltd (Company Registration No: 16430399)

    Registered Corporate Address: Rosings, Smarden Rd, Headcorn, Kent, TN27 9HP, United Kingdom

    Primary Compliance Routing Portal: data@datacompass.co.uk

    Official Digital Address: https://datacompass.co.uk

    Free Enterprise Resource

    The Tech Stack Audit Pack

    Stop leaking revenue through fragmented software. Download our comprehensive audit framework to map your entity relationships, identify critical data bottlenecks, and calculate your exact consolidation savings.

    • Entity Relationship Diagram (ERD) mapping templates
    • Data silo & operational bottleneck identification
    • Step-by-step consolidation & savings calculator

    Claim Your Audit Pack

    Instant access to the complete framework.

    Start Your Audit