compass · privacy policy · last updated 2026-08-11

Privacy Policy

Draft for review — this is a working template pending sign-off by qualified legal counsel. It is not the final agreement and should not be relied on as legal advice.

Compass ('Compass', 'we', 'us', or 'our') runs an invite-only origination desk for commodity sourcing and brokering, together with Boards — a marketplace where members publish contract, service, and job postings and where people can respond to them. This Privacy Policy explains what personal data we collect when you access the platform, why we collect it, who we share it with, how long we keep it, and the rights you have — wherever in the world you are. By accessing or using Compass you acknowledge the practices described here.

1. Who We Are and What This Covers

Compass is an origination desk provided to a closed group of invited members (administrators, managers, and members of the operating team). Desk accounts are provisioned by us; there is no public sign-up. For data-protection purposes, Compass is the controller of the personal data described here. Where local law requires a named operating entity or representative, that detail will be confirmed before this policy is finalised.

Compass also operates Boards, where members publish postings and where you may respond to one — by claiming a contract or service posting, sending an enquiry, or applying to a job posting. If you interact with Boards you are covered by this policy even if you are not a member of the operating team.

Who is responsible for your job application. When you apply to a job posting, both Compass and the member who published the posting are responsible for your personal data, together. We decide how applications are collected, assessed, stored, and for how long, and we build the scoring guide and the tool that applies it. The member who published the posting decides what they are hiring for and who they hire. Neither of us could run the process without the other, so the law treats us as joint controllers. We have a written arrangement setting out who does what, and this paragraph is its essence — you can ask us for more detail. You can exercise any of your rights against either of us, whatever that arrangement says. Contact us first if you are unsure: we can act on access, correction and deletion directly, and we will pass anything else to the member who published the posting.

This policy applies to personal data we process through the platform, through email and electronic messages between you and us, and through the activity you carry out on the desk. It does not cover third-party services that operate under their own privacy policies, even where we link to them.

2. Information We Collect

Account and identity data — your name, work email address, the role assigned to you (administrator, manager, or member), the team you belong to, authentication data (including any two-factor method you enrol), and the timestamped record of any agreement you accept.

Activity and deal data — the records you create or act on while using the desk: leads, quests, findings, deals, vault documents, notes, tasks, and the outcomes of that work. This is the core operating data of the desk.

Communications you bring into the desk — Compass lets you paste, forward, or connect inbound messages (for example from email, WhatsApp, Instagram, or Discord) into a shared inbox so the team can act on enquiries. Anything you import — including the message content and the contact details of the counterparties who sent it — is processed by Compass on your instruction. You are responsible for ensuring you have a lawful basis to bring third-party communications and personal data into the platform.

Automated processing and AI — to sort, grade, and extract structured information from inbox messages and research you submit, we and our processors run automated and AI-assisted analysis. Where you supply your own AI provider key, your content is sent to that provider under their terms; usage is metered and capped.

Boards postings, claims, and enquiries — the postings you publish (including the structured fields, descriptions, and any supporting documents you attach), the claims you make on other members' postings, and the enquiries you send or receive through a posting.

Job applications and the documents you attach — if you apply to a job posting, we collect your answers to the application questions and any document you attach, such as a CV or résumé. A CV typically contains your name, contact details, work history, education, and whatever else you choose to include. Your application and its documents are shown to the member who published the posting.

Voluntary self-identification data (special category data) — on job applications we may invite you to provide demographic self-identification, which can include information revealing racial or ethnic origin, or disability or health status. Providing it is entirely voluntary, it is never shown to the member who published the posting, it never affects your application or any score, and it is used only to produce aggregate, anonymised fairness statistics. We omit any statistic that would describe fewer than five people, so no group is small enough to identify anyone. You may decline and still apply. Under the EU/UK GDPR this is 'special category' data and we process it only with your explicit consent.

Screening data — to meet sanctions, export-control, and anti-money-laundering obligations we screen postings and counterparties against published sanctions and restricted-party sources, and we keep a record of the result.

Voice and audio — where you use a voice feature, we process the audio you record and any transcript produced from it, on the basis of the consent you give at the point of recording.

Device, usage, and analytics data — technical data such as IP address, device and browser type, pages and features used, timestamps, and diagnostic logs, collected to operate, secure, and improve the service and to produce aggregate performance analytics.

Cookies and similar technologies — strictly-necessary cookies for sign-in and security, and limited analytics as described in the Cookies section below.

3. How We Use Your Information

We use personal data to: operate and secure the desk and your account; authenticate you and prevent fraud, abuse, and unauthorised access; carry out the deal, outreach, and inbox workflows you initiate; publish and rank Boards postings and route claims, enquiries, and applications to the member who published a posting; grade postings against a published rubric and assess job applications as described in the 'Automated Decision-Making' section; screen against sanctions and restricted-party sources; produce aggregate business and performance analytics; maintain audit logs; provide support; comply with legal obligations; and operate, improve, and develop the product and future products.

We describe our data use broadly and openly so that it remains accurate as the product evolves. We do not use your personal data for purposes that are incompatible with those described here, and we do not sell your personal data.

4. Legal Bases for Processing (EU/EEA & UK)

Where the EU General Data Protection Regulation (GDPR) or the United Kingdom GDPR (UK GDPR) applies, we rely on one or more of the following legal bases: performance of a contract (to give you access to the desk and provide the service); our legitimate interests (to secure, operate, analyse, and improve the platform, balanced against your rights); your consent (where we ask for it, such as certain analytics, voice recording, and voluntary self-identification — you may withdraw it at any time); and compliance with a legal obligation (including sanctions and anti-money-laundering screening).

Where you take a step towards a contract — applying to a job posting, or claiming a contract or service posting — we process the data you submit on the basis of taking steps at your request prior to entering into a contract, and on our legitimate interest in operating a marketplace that works for both sides.

Special category data — the voluntary self-identification described above can reveal racial or ethnic origin or disability status. We process it only on the basis of your explicit consent, given separately at the point you provide it, and only to produce fairness statistics that are aggregated so that no group smaller than five people is ever reported. It is never shown to the member who published a posting and is never an input to any score. Declining has no effect on your application. You may withdraw that consent at any time — the control is in your account settings, and it deletes what you told us.

5. How We Share Information

Service providers and sub-processors — hosting, database, authentication, email, and AI-processing providers who act on our instructions under contract and may process data only for the purposes we specify. Our core infrastructure and sub-processors are available on request.

Within the team — your activity on the desk is visible to other members of your team in line with your assigned role and our access controls.

Legal and safety — where required to comply with a law, court order, or lawful request, or to protect the rights, property, safety, or security of Compass, our users, or others.

Business transfers — in connection with a merger, acquisition, financing, reorganisation, or sale of assets, in which case we will require the recipient to honour this policy.

We do not sell your personal data, and we do not 'share' it for cross-context behavioural advertising as those terms are defined under California law.

6. Cookies, Analytics, and Tracking

We use strictly-necessary cookies to keep you signed in and to protect the platform. We may use a limited set of privacy-respecting analytics to understand how the desk is used so we can improve it. Where required by law, we ask for your consent before setting non-essential cookies, and you can control cookies through your browser settings. We honour recognised opt-out signals (such as Global Privacy Control) where applicable.

How you use the boards — we keep a record of how you move around the boards: which postings you open, and when you start and complete an application. That record is stored under a random reference rather than your name or account id, and the table connecting the reference to you is kept separately so the connection can be broken. Where we use an analytics provider to process this kind of usage data on our behalf, it receives only that random reference — never your name, email, or account id — and when the connection is broken on our side, we also instruct the provider to delete what it holds under that reference.

We keep these usage records for up to 24 months. After that, the records themselves are deleted and what remains is counting — totals with nobody's identity in them. If you ask us to erase your data, we delete these records straight away, break the connection, and instruct our provider to delete its copy; the totals stay, because they no longer describe anyone. One thing to be clear about: erasure removes what we held, it does not switch this off — if you keep using the boards afterwards, a new record starts from that point under a new reference.

7. Data Retention

We keep personal data for as long as your account is active and for as long as needed to provide the service, then for a limited period afterwards to meet legal, tax, accounting, security, and dispute-resolution obligations, after which it is deleted or anonymised. Some records — job applications and the assessment records for them — are deliberately stored in a form we cannot alter, so they cannot be deleted or edited. For those, we do something equivalent instead: the personal content inside them is encrypted with a key held for you alone, and we destroy that key, which leaves the record in place but makes what it holds permanently unreadable to anyone, including us. Signed agreements and audit records are retained for the period required to evidence them. You may ask us to delete your data as described in 'Your Privacy Rights', subject to those obligations.

Specific periods we apply today: personal data on inbound enquiries in the shared inbox is automatically redacted 180 days after receipt unless it is attached to work still in progress. Job applications, the documents attached to them, and the assessment records for them are kept while the posting is open and for a defined period afterwards, set by where the posting is based — for example four weeks in the Netherlands, six months in the United Kingdom and Germany, and longer in France, where the law expects us to be able to evidence how a selection was made. We publish the period we apply and the reason for it, and we can change a period without changing the software. Two things about that record are worth stating plainly rather than leaving you to assume. First, we store your application in a form we cannot alter after the fact — that is deliberate, because it is what lets us show a decision was not quietly changed after you questioned it, and it is the basis on which we can tell you an automated assessment is reproducible. Second, and as a direct consequence, we cannot selectively edit or remove parts of that record. That is why the answers you write are encrypted with a key held for you alone: when you ask us to erase them we destroy the key, and the record stays exactly as it was while everything you wrote inside it becomes unreadable — to the member who published the posting, and to us. It cannot be recovered afterwards, and that is the point rather than a limitation. The control is in your account settings. What remains is the fact of the application itself: that you applied, when, and to which posting. What else we can erase on request is described in 'Your Privacy Rights' and in the statistical-archive paragraph below. Records that a notice was acknowledged, and voluntary self-identification data, are kept only in the form needed to evidence compliance and to produce aggregate statistics. Where a specific period is fixed by law — for example a record-keeping obligation that applies to the member who published a posting — that period governs.

Statistical archive — separately from the records above, we keep a pseudonymised statistical record of each job application for five years from the date it was submitted. 'Pseudonymised' here means the record is attached to a random reference rather than to you: it holds no name, no contact details, no CV, and none of the free text you wrote, and the link between that reference and your identity is deleted when your application is deleted. From that point the record cannot be traced back to you by anyone, including us. We keep it solely to produce statistics — for example how long applications take to be decided, and how outcomes vary by category — and to develop and improve the service. We never consult it to make, support, or review a decision about any individual, and it is technically arranged so that looking up a single person is not possible: it can only be queried in aggregate, and any figure describing fewer than five people is withheld. Where the EU or UK GDPR applies, this is processing for statistical purposes under the research, archiving and statistics provisions of that law, which is why it is kept for longer than the operational record above. You can object to it, or ask us to delete it, at any time while we can still connect the record to you — that is, up until the point the link is deleted with your application. After that we hold nothing that can be traced to you, so there is nothing left for us to find, change, or delete on request.

8. International Transfers and Where We Offer the Service

Compass operates globally and our providers may process data in countries other than your own, including outside the EEA, the UK, and your home jurisdiction. Where we transfer personal data across borders, we use a lawful transfer mechanism — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, an adequacy decision, or, where required, your explicit consent — and apply appropriate safeguards.

Some countries impose strict data-localisation or separate-consent requirements (for example under China's PIPL or Russia's data-localisation law). We offer Compass only where we can lawfully provide it, and we may restrict, decline, or withdraw access from any jurisdiction whose requirements we cannot currently meet. Nothing here is an offer of the service where it would be prohibited.

9. Your Privacy Rights

Your rights depend on where you live. In every case you can contact us using the details below, and we will respond within the time limits set by applicable law. We will not discriminate against you for exercising your rights, and we may need to verify your identity before acting on a request.

EU/EEA and United Kingdom (GDPR / UK GDPR): you have the right to access, rectify, erase, restrict, and object to processing of your personal data, the right to data portability, the right to withdraw consent, and the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — including the right to obtain human intervention, to express your point of view, to an explanation of the logic involved, and to contest the outcome. See 'Automated Decision-Making and Candidate Assessment' below for how this works in practice.

California (CCPA / CPRA): if you are a California resident you have the right to know what personal information we collect and how we use and disclose it, the right to access and delete it, the right to correct inaccurate information, and the right to opt out of any sale or sharing of personal information and of profiling — although we do not sell or share personal information as those terms are defined under California law. You may exercise these rights without discrimination and may use an authorised agent.

China (PIPL): if the Personal Information Protection Law of the People's Republic of China applies to you, we process your personal information on the basis of your consent or another lawful basis, and we obtain separate consent where the law requires it (including for cross-border transfers). You have the right to access, copy, correct, supplement, and delete your personal information, to withdraw consent, and to ask us to explain our processing rules.

Australia (Privacy Act 1988 / Australian Privacy Principles): if you are in Australia, we handle your personal information in line with the Australian Privacy Principles. You may request access to and correction of your personal information, and you may complain to us and, if unsatisfied, to the Office of the Australian Information Commissioner (OAIC).

Everywhere else in the world: wherever you are — including, for example, under Canada's PIPEDA, Brazil's LGPD, Japan's APPI, South Korea's PIPA, India's DPDP Act, Switzerland's FADP, South Africa's POPIA, Singapore's PDPA, the data-protection laws of the UAE, Saudi Arabia, and other Gulf states, New Zealand's Privacy Act, and equivalent data-protection laws in every other country — you may have similar rights. Whoever and wherever you are, contact us and we will honour the rights available to you under your local law. To exercise any right, email us using the contact details in the final section and describe your request so we can verify and action it.

10. Automated Decision-Making and Candidate Assessment

Some parts of Compass score or order things automatically. Postings are graded against a published rubric, and — where the law of the relevant place allows it — job applications may be scored and ordered for the member who published the posting. We tell you which of these is happening before you apply, and we record that you saw the notice.

A person makes every hiring decision. The tool never rejects anyone by itself, and no outcome on Compass is produced solely by automated means without a human deciding it. Because the assessment is a fixed, published rubric rather than a learned model, the same answers always produce the same result.

What the assessment uses: only what you submit — your answers to the application questions, the documents you attach, and whether your identity is verified on Compass. We do not buy data about you from data brokers, we do not infer anything from your browsing, and voluntary self-identification data is never an input to any score.

Where local law restricts automated hiring tools, we switch the behaviour off rather than rely on a disclaimer. Depending on the location of the role, the tool may score and order applications, or produce only a plain checklist of which stated requirements an application meets with no points and no ranking, or do nothing at all and simply show applications in the order they arrived. If the applicable rules change between the moment you read the notice and the moment you acknowledge it, we show you the correct notice and ask again.

Your rights here: you can ask for your application to be reviewed without the tool, ask us to explain the logic involved and the significance of the assessment, contest an outcome, and obtain human intervention. Because we and the member who published the posting are joint controllers of your application, you may bring any of these to either of us, and neither of us may turn you away on the ground that the other one handles it. Use the contact details at the end of this policy, or send an enquiry on the posting so the member who published it receives your request directly.

11. Security

We use administrative, technical, and organisational measures designed to protect personal data — including access controls scoped to your role, encryption in transit and at rest, authentication safeguards (including optional two-factor authentication), and audit logging. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security, and you are responsible for keeping your credentials confidential. If you discover a vulnerability, please report it responsibly to security@waitlistcompass.com. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities where the law requires.

12. Children

Compass is a workplace tool intended for adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 18 (or under the minimum age set by your local law, such as 16 in parts of the EEA). If you believe a child has provided us personal data, contact us and we will delete it.

13. Changes to This Policy

We may update this policy as the product or the law changes. The 'last updated' date at the top shows the current version. If we make material changes, we will take reasonable steps to notify you, for example by email to your account address or by a notice in the platform. Your continued use after an update means you accept the revised policy.

14. Contact and How to Reach Us

For any privacy question, or to exercise a right described above, contact us at privacy@waitlistcompass.com. (This contact route and the responsible legal entity are placeholders in this draft and will be confirmed before the policy is finalised.) Where the law requires a data-protection officer or local representative, their details will be added here.

This document does not constitute legal advice. Consult qualified legal counsel for jurisdiction-specific questions.