Privacy Policy
Last updated: [DATE] (draft, pending legal review)
Now that clients may be based in the US as well as the UK: everything below is currently written for UK GDPR only. It does not cover US state privacy law (e.g. the CCPA/CPRA for California residents) or HIPAA for US healthcare clients. Those need their own review before this policy can honestly describe how US client data is handled. Don't take on a US client under this policy as-is; get the US-specific sections added first.
Who we are
[Compass Response Ltd], company number [COMPANY NUMBER], registered in England and Wales at [REGISTERED ADDRESS], is the data controller for the personal data described in this policy unless stated otherwise. Our ICO registration reference is [ICO REGISTRATION NUMBER].
You can contact us about this policy or your data at hello@compassresponse.co.uk.
What data we collect
Depending on how you interact with us, we may collect:
- Contact details you give us: name, business name, email address, phone number
- Details of your enquiry, submitted through our contact form, chatbot demo, or booking system
- Technical data: IP address, browser type, device information, and pages visited on our site
- Communications between us, including emails and call notes from an audit or consultation
We do not intentionally collect special category data (such as health information) through our own website. If you're a healthcare or aesthetics client, a separate data processing agreement governs how we handle your customers' data on your behalf. See "If you're a client" below.
Why we collect it, and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to your enquiry or audit request | Legitimate interests / steps to enter a contract |
| Delivering a service you've engaged us for | Performance of a contract |
| Sending relevant marketing to businesses | Legitimate interests (B2B) |
| Improving our website and services | Legitimate interests |
| Meeting our legal and accounting obligations | Legal obligation |
How long we keep it
We keep enquiry and lead data for [12 months] from your last contact with us, unless you become a client, in which case we retain records for the duration of our engagement plus [6 years] to meet our accounting and legal obligations.
Who we share it with
We use a small number of third-party services to run our business and deliver client work. These may include:
- Booking and scheduling tools (e.g. Calendly)
- Email and communication providers
- Cloud hosting and automation platforms (e.g. n8n, Make)
- AI providers used to power chatbot and automation services
Where any of these providers are based outside the UK, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum, to ensure your data stays protected.
If you're a client
Where we process your customers' data on your behalf (for example, running a lead-automation or chatbot service for your business), we act as a data processor and you remain the data controller. This relationship is governed by a separate Data Processing Agreement, not by this policy.
Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Ask us to correct inaccurate data
- Ask us to delete your data, in certain circumstances
- Object to or restrict how we use your data
- Request a copy of your data in a portable format
- Withdraw consent, where we rely on it
To exercise any of these rights, contact us at [hello@compassresponse.co.uk]. If you're not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Cookies
Our website uses cookies. Details of what we use and why are set out in our Cookie Policy.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the "last updated" date above.