Security & Trust

Everything your reviewer asks for, in one place.

Subprocessors, retention windows, security controls, transfer arrangements, incident response and the person who answers. Nothing here is a certification; controls that are not yet formalised are labelled as such.

Compass Performance Consulting, Inc. is the legal entity behind this site; Compass Performance, Inc. and Compass Performance are the names it trades under. They are the same organization. Data governance version 1.0.0, effective 19 August 2026. Privacy notice version 2026-08-03. This page consolidates practice already published in the privacy notice, the IT Security Policy, the Personal Data Notice and the System Use & Data Processing Agreement. Those documents remain the governing texts.

Subprocessors

These providers may process personal data on Compass’s instruction under a data processing agreement. Each is engaged for the stated purpose only.

Subprocessors, purpose and location
SubprocessorPurposeLocation
HubSpotClient relationship records, meeting scheduling, and follow-up correspondence.United States / European Union
Supabase (Lovable Cloud)Application database, authentication, and encrypted file storage for the platform.United States
LovableHosting, delivery, and transactional email for this site and its instruments.United States / European Union
ScoreAppComplimentary Compass Profiles completed on the provider's own scorecard platform.United Kingdom
Positive IntelligenceLicensed PQ® Mental Fitness program delivery for enrolled participants.United States
YouTube (Google)Video playback, loaded only when you choose to play a video.United States / European Union
LinkedInPublishing Compass articles and recording share clicks you initiate.United States / European Union

EU transfer arrangements

Transfers of personal data outside the European Economic Area rely on EU Standard Contractual Clauses or an adequacy decision, as recorded per provider below.

No Article 27 representative in the European Union has been appointed; European enquiries are answered directly by the contact below.

Transfer safeguard by subprocessor
SubprocessorTransfer safeguard
HubSpotEU Standard Contractual Clauses under HubSpot's data processing agreement.
Supabase (Lovable Cloud)EU Standard Contractual Clauses under the provider's data processing agreement.
LovableEU Standard Contractual Clauses under the provider's data processing agreement.
ScoreAppUK adequacy decision; the provider's own notice applies to data entered there.
Positive IntelligenceEU Standard Contractual Clauses under the licensor's terms.
YouTube (Google)EU Standard Contractual Clauses under Google's terms.
LinkedInEU Standard Contractual Clauses under LinkedIn's terms.

Data subject requests are answered within 30 days. Use the data rights request form.

Retention

Retention is enforced nightly by an automated job. When a window closes, identifying fields are irreversibly redacted or the record is deleted. Client engagement records follow the engagement agreement.

Retention windows by data type
DataWindowWhat happens
Assessment and diagnostic submissions (Mental Fitness, FOUNDATION, and related instruments)24 months from submissionName, email, phone, and company are irreversibly redacted; anonymous scores remain for benchmarking.
Outreach and campaign responses24 months from responseContact detail redacted; the response itself is kept anonymously.
Forum fit profiles and uploaded resumes12 months from applicationContact detail redacted and the uploaded document reference deleted.
Measurement events (page views, CTA clicks, scroll depth, share clicks)24 months from the eventDeleted outright.
Access and security logs (hashed visitor fingerprints, gate attempts)12 months from the eventDeleted outright.
Compass 360° feedback and client engagement recordsPer the engagement agreement, then on requestReturned or destroyed at the client's instruction; individual ratings are never released by name outside Compass administration.

Security controls

The control register as it stands. “Being formalised” means the control operates but the written procedure and evidence schedule are still being documented — it is stated rather than implied. Full detail sits in the IT Security Policy.

Control register and status
DomainControlStatusDetail
EncryptionData encrypted in transit and at restIn placeTLS between browser, platform and providers; encryption at rest by the hosting and database platform.
Access controlNamed accounts, server-side roles, two-step administrator sign-inBeing formalisedImplemented in the platform; the written access-review procedure and evidence schedule are being documented for client review.
LoggingAudit record of access, refusals, report release, export and printBeing formalisedRecorded by the platform; the retention window and the client extract format are being documented.
RetentionClient-directed retention with a documented defaultBeing formalisedDefault of 24 months stated in Section 4.4; per-engagement schedules are being written into engagement agreements.
AI useDraft-only AI use with recorded human verificationBeing formalisedSection 4.5 states the operating rule; the provenance record and verification sign-off are being standardised across every AI-assisted artifact.
Incident response72-hour notification to the client system ownerBeing formalisedSection 8 states the commitment; the tested runbook is being written.
SubcontractorsWritten processing terms with each provider; notice before a new one is usedBeing formalisedProvider list published in the Personal Data Notice; the change-notice step is being formalised.
Business continuityProvider backup plus an independent document record of truthBeing formalisedBackups run at the provider; restore testing is being scheduled.

Incident response

Access to client material is restricted by role and logged. If a breach affecting personal data occurs, Compass notifies the relevant supervisory authority within 72 hours of becoming aware, notifies the client system owner within the same window, and informs affected people without undue delay where the risk to them is high.

Report a suspected vulnerability, exposure or misdirected record to skopecky@compassperformanceinc.com. Include what you observed and when; do not include the affected personal data in the message.

Contact

Security questions, IT review requests, subprocessor queries and incident reports go to one address.

This document is Compass's standard operating position, not legal advice. Compass is not your counsel. Have your own legal and IT functions review it before execution, and where an executed master agreement exists, that agreement controls.

Not sure where to start?

Three questions, and we point you to the right instrument.

Under a minute. From this page, most leaders begin with The organization.