Privacy Policy — Compass Island
Legal

Privacy Policy

Effective August 25, 2026 Last updated August 25, 2026

1. Who we are

Compass Island, LLC (“Compass Island”, “we”, “us”) is the company responsible for the personal information described in this policy, except where section 2 explains that we handle information on a customer’s behalf. In data protection terms, that makes us the controller of the information covered here.

You can reach us in writing at Compass Island, LLC, 808 Lady Street, Suite D #57, Columbia, SC 29201, United States, or by email at privacy@compassisland.com. Privacy questions sent to that address reach the people who can answer them.

2. What this policy covers

This policy covers this website and the inquiries people send through it. It also explains, at a high level, the difference between two very different kinds of information involved in our business.

The first is the operational content a customer puts into the CI360 or LiveSOP application: travelers, personnel, missions, locations, procedures, messages and records of what happened. For that content we generally act as a processor, handling it on the customer’s instructions and under the agreement we have with them. That agreement, not this policy, governs how it is used, who may access it, how long it is retained and what happens at the end of the relationship. If you are an individual whose information sits in an application because your employer or another organization put it there, that organization is the right first point of contact, and we will support them in responding to you.

The second is the limited information we process for our own purposes as a controller: account administration for the people who use and manage the applications, business contact details, billing information, security and service logs, and support correspondence. We are responsible for that information directly, and this policy describes how we handle it.

The line between the two matters in practice. A record of who logged in and when is ours to manage as part of running a service securely. The mission that person was working on is the customer’s. We do not use operational content from an application for our own purposes, and we do not use it to market to anyone. Where a request touches both kinds of information, we answer for our part and refer the rest to the customer.

3. What we collect

Information you give us

What you type into a form on this site: your name, organization, work email address, your role, the subject of your inquiry and a description of how your operation runs today. Anything you send us afterward by email, and our replies, sit alongside it.

Technical information

Standard server logs recorded when a page is served: IP address, browser and device type, the pages requested, the referring page and a timestamp.

Anti-spam signals

Our form measures how long it took to complete and includes a hidden field that a person filling in the form never sees. Automated submissions behave differently on both counts. These signals are used only to reject spam.

We do not ask for special category data, we do not build profiles of site visitors, and we make no automated decisions about anyone.

We may also hold professional contact details we obtained another way — from a conference, a referral, a public professional profile or a business-development tool — used only to get in touch about CI360 or LiveSOP, and deleted on request.

4. Why we use it, and our legal basis

Where the GDPR or the UK GDPR applies, these are our purposes and the legal bases we rely on.

Responding to a demonstration request or inquiry, evaluating a potential customer relationship and following up appropriately
Legitimate interests
Keeping the site available and preventing spam and abuse
Legitimate interests
Measuring how the site is used, if and when analytics are added
Consent
Meeting legal, tax and record-keeping obligations
Legal obligation

When you send an inquiry from a work address you are almost always acting for your employer, so we treat that correspondence as our legitimate interest in pursuing a business relationship rather than as steps taken before a contract with you personally. You can object to that processing at any time; see section 10. Consent for measurement would be asked for before any such tool is introduced, and can be withdrawn whenever you like.

5. Cookies and similar technologies

This site sets no advertising cookies and runs no third-party tracking pixels.

Strictly necessary storage. One record of the choice you make in the cookie banner, kept in your browser so we do not ask again. It contains no identifier and is not transmitted anywhere.
Analytics. None is installed at present. If we add a measurement tool, it will load only after you accept it.

You can change your choice at any time through cookie settings, which is also linked in the footer of every page.

6. Who we share it with

We do not sell personal data and we do not share it for advertising. We disclose it only in these categories:

Service providers working under written contract on our instructions: website hosting, email and business communications, and the tools we use to keep track of sales inquiries.
Professional advisers, such as legal and accounting, where they need it to advise us.
Authorities, where the law requires it or to protect rights and safety.
An acquirer, if the business or part of it changes hands, subject to this policy.

If you need to know which providers we currently use, ask us and we will tell you.

7. International transfers

We are based in the United States and the information described in this policy is stored there. If you contact us from outside the United States, your information travels there.

Where privacy law requires a transfer mechanism for personal data leaving the European Economic Area or the United Kingdom, an appropriate one is used — for example standard contractual clauses, or a provider’s certification under a recognized transfer framework. The mechanism that applies to a specific transfer is available on request.

Where an application holds operational content, the storage location for that content is a term of the customer’s agreement rather than something set by this policy, and customers with a requirement about where their data sits should raise it with us before signing.

8. How long we keep it

Inquiries and the correspondence around them, where they do not lead to a customer relationship: up to 36 months from our last contact, after which they are deleted. Server logs: up to 12 months. Records we are required to keep for tax or other legal reasons: for the period the law requires.

Retention of operational content inside an application is set by the customer’s agreement, not by these periods.

9. Security

Traffic to this site and to the applications travels over TLS. Access to the information described here is limited to the people who need it for their work, through individual accounts with multi-factor authentication. We collect as little as we can, because the smallest amount of information is the easiest to protect.

Access is removed when someone changes role or leaves. No method of transmission or storage is completely secure, and we do not claim otherwise. If a security incident affects personal data we hold, we will notify the people and authorities the law requires us to notify, within the time the law allows. Customers evaluating us formally should ask for the security documentation that goes with a contract rather than relying on this section.

10. Your rights in the EEA and the UK

If the GDPR or the UK GDPR applies to you, you have the right to ask for a copy of the personal data we hold about you, to have it corrected, to have it deleted, to have our use of it restricted, to object to processing we base on legitimate interests, to receive it in a portable form, and to withdraw consent where you have given it.

Write to privacy@compassisland.com. We respond within one month. Exercising these rights is free and will not count against you in any way. We may ask you to confirm your identity first, so that we do not hand your information to someone else.

11. California privacy rights

If the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to us, the following describes our practices for California residents.

The categories of personal information we collect are identifiers such as name and email address, professional and employment information such as your role and organization, internet activity from server logs, and the contents of the messages you send us. We collect them for the purposes in section 4, from you and from the sources named in section 3, and disclose them to the categories of recipient in section 6.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

You may request to know what we hold, request deletion or correction, and use an authorized agent to make a request on your behalf. We will not deny you service, charge you a different price or give you a lesser experience for exercising any of these rights.

12. Canada

Where applicable Canadian privacy law applies, including the Personal Information Protection and Electronic Documents Act where it applies, you have the right to access the personal information we hold about you and to challenge its accuracy and completeness. If you are not satisfied with how we have handled a request, a complaint to the Office of the Privacy Commissioner of Canada may be available to you.

Send Canadian requests to the same address as everything else in this policy. If we cannot act on part of a request, we will say which part and why, so that you can decide what to do next.

13. Children

We sell to organizations, not to consumers, and this site is not directed at children. We do not knowingly collect personal information from anyone under 16. Nothing on this site asks for a date of birth or is designed to appeal to a child. If you believe a child has sent us information, tell us and we will delete it. Where an application holds information about a minor because a customer put it there, that is covered by the customer’s agreement and a request should go to them.

14. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects information we already hold about you and we have a way to reach you, we will tell you directly rather than leaving you to notice. We will not apply a change retroactively to weaken the protections that applied when we collected your information. Earlier versions of this policy are available on request.

15. Contact and complaints

Write to privacy@compassisland.com, or to Compass Island, LLC, 808 Lady Street, Suite D #57, Columbia, SC 29201, United States.

Compass Island is based in the United States. Where applicable law requires us to appoint a representative in the European Economic Area or the United Kingdom, one will be appointed and the details published here. Until then, please send requests directly to the address above.

If you are not satisfied with our answer, you have the right to complain to your national data protection authority, or to the Information Commissioner’s Office in the United Kingdom.