← Back to homepage

Privacy Policy

Last updated: [DATE] (draft, pending legal review)

This is a working draft built to cover the standard UK GDPR requirements for a business like this. It hasn't been reviewed by a solicitor. Replace every bracketed placeholder and have it checked before this page goes live, particularly the sections on special-category data if you're working with healthcare clients.

Now that clients may be based in the US as well as the UK: everything below is currently written for UK GDPR only. It does not cover US state privacy law (e.g. the CCPA/CPRA for California residents) or HIPAA for US healthcare clients. Those need their own review before this policy can honestly describe how US client data is handled. Don't take on a US client under this policy as-is; get the US-specific sections added first.

Who we are

[Compass Response Ltd], company number [COMPANY NUMBER], registered in England and Wales at [REGISTERED ADDRESS], is the data controller for the personal data described in this policy unless stated otherwise. Our ICO registration reference is [ICO REGISTRATION NUMBER].

You can contact us about this policy or your data at hello@compassresponse.co.uk.

What data we collect

Depending on how you interact with us, we may collect:

We do not intentionally collect special category data (such as health information) through our own website. If you're a healthcare or aesthetics client, a separate data processing agreement governs how we handle your customers' data on your behalf. See "If you're a client" below.

Why we collect it, and our lawful basis

PurposeLawful basis
Responding to your enquiry or audit requestLegitimate interests / steps to enter a contract
Delivering a service you've engaged us forPerformance of a contract
Sending relevant marketing to businessesLegitimate interests (B2B)
Improving our website and servicesLegitimate interests
Meeting our legal and accounting obligationsLegal obligation

How long we keep it

We keep enquiry and lead data for [12 months] from your last contact with us, unless you become a client, in which case we retain records for the duration of our engagement plus [6 years] to meet our accounting and legal obligations.

Who we share it with

We use a small number of third-party services to run our business and deliver client work. These may include:

Where any of these providers are based outside the UK, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum, to ensure your data stays protected.

If you're a client

Where we process your customers' data on your behalf (for example, running a lead-automation or chatbot service for your business), we act as a data processor and you remain the data controller. This relationship is governed by a separate Data Processing Agreement, not by this policy.

Your rights

Under UK GDPR, you have the right to:

To exercise any of these rights, contact us at [hello@compassresponse.co.uk]. If you're not satisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

Cookies

Our website uses cookies. Details of what we use and why are set out in our Cookie Policy.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the "last updated" date above.