Security & Trust
Everything your reviewer asks for, in one place.
Subprocessors, retention windows, security controls, transfer arrangements, incident response and the person who answers. Nothing here is a certification; controls that are not yet formalised are labelled as such.
Compass Performance Consulting, Inc. is the legal entity behind this site; Compass Performance, Inc. and Compass Performance are the names it trades under. They are the same organization. Data governance version 1.0.0, effective 19 August 2026. Privacy notice version 2026-08-03. This page consolidates practice already published in the privacy notice, the IT Security Policy, the Personal Data Notice and the System Use & Data Processing Agreement. Those documents remain the governing texts.
Subprocessors
These providers may process personal data on Compass’s instruction under a data processing agreement. Each is engaged for the stated purpose only.
| Subprocessor | Purpose | Location |
|---|---|---|
| HubSpot | Client relationship records, meeting scheduling, and follow-up correspondence. | United States / European Union |
| Supabase (Lovable Cloud) | Application database, authentication, and encrypted file storage for the platform. | United States |
| Lovable | Hosting, delivery, and transactional email for this site and its instruments. | United States / European Union |
| ScoreApp | Complimentary Compass Profiles completed on the provider's own scorecard platform. | United Kingdom |
| Positive Intelligence | Licensed PQ® Mental Fitness program delivery for enrolled participants. | United States |
| YouTube (Google) | Video playback, loaded only when you choose to play a video. | United States / European Union |
| Publishing Compass articles and recording share clicks you initiate. | United States / European Union |
EU transfer arrangements
Transfers of personal data outside the European Economic Area rely on EU Standard Contractual Clauses or an adequacy decision, as recorded per provider below.
No Article 27 representative in the European Union has been appointed; European enquiries are answered directly by the contact below.
| Subprocessor | Transfer safeguard |
|---|---|
| HubSpot | EU Standard Contractual Clauses under HubSpot's data processing agreement. |
| Supabase (Lovable Cloud) | EU Standard Contractual Clauses under the provider's data processing agreement. |
| Lovable | EU Standard Contractual Clauses under the provider's data processing agreement. |
| ScoreApp | UK adequacy decision; the provider's own notice applies to data entered there. |
| Positive Intelligence | EU Standard Contractual Clauses under the licensor's terms. |
| YouTube (Google) | EU Standard Contractual Clauses under Google's terms. |
| EU Standard Contractual Clauses under LinkedIn's terms. |
Data subject requests are answered within 30 days. Use the data rights request form.
Retention
Retention is enforced nightly by an automated job. When a window closes, identifying fields are irreversibly redacted or the record is deleted. Client engagement records follow the engagement agreement.
| Data | Window | What happens |
|---|---|---|
| Assessment and diagnostic submissions (Mental Fitness, FOUNDATION, and related instruments) | 24 months from submission | Name, email, phone, and company are irreversibly redacted; anonymous scores remain for benchmarking. |
| Outreach and campaign responses | 24 months from response | Contact detail redacted; the response itself is kept anonymously. |
| Forum fit profiles and uploaded resumes | 12 months from application | Contact detail redacted and the uploaded document reference deleted. |
| Measurement events (page views, CTA clicks, scroll depth, share clicks) | 24 months from the event | Deleted outright. |
| Access and security logs (hashed visitor fingerprints, gate attempts) | 12 months from the event | Deleted outright. |
| Compass 360° feedback and client engagement records | Per the engagement agreement, then on request | Returned or destroyed at the client's instruction; individual ratings are never released by name outside Compass administration. |
Security controls
The control register as it stands. “Being formalised” means the control operates but the written procedure and evidence schedule are still being documented — it is stated rather than implied. Full detail sits in the IT Security Policy.
| Domain | Control | Status | Detail |
|---|---|---|---|
| Encryption | Data encrypted in transit and at rest | In place | TLS between browser, platform and providers; encryption at rest by the hosting and database platform. |
| Access control | Named accounts, server-side roles, two-step administrator sign-in | Being formalised | Implemented in the platform; the written access-review procedure and evidence schedule are being documented for client review. |
| Logging | Audit record of access, refusals, report release, export and print | Being formalised | Recorded by the platform; the retention window and the client extract format are being documented. |
| Retention | Client-directed retention with a documented default | Being formalised | Default of 24 months stated in Section 4.4; per-engagement schedules are being written into engagement agreements. |
| AI use | Draft-only AI use with recorded human verification | Being formalised | Section 4.5 states the operating rule; the provenance record and verification sign-off are being standardised across every AI-assisted artifact. |
| Incident response | 72-hour notification to the client system owner | Being formalised | Section 8 states the commitment; the tested runbook is being written. |
| Subcontractors | Written processing terms with each provider; notice before a new one is used | Being formalised | Provider list published in the Personal Data Notice; the change-notice step is being formalised. |
| Business continuity | Provider backup plus an independent document record of truth | Being formalised | Backups run at the provider; restore testing is being scheduled. |
Incident response
Access to client material is restricted by role and logged. If a breach affecting personal data occurs, Compass notifies the relevant supervisory authority within 72 hours of becoming aware, notifies the client system owner within the same window, and informs affected people without undue delay where the risk to them is high.
Report a suspected vulnerability, exposure or misdirected record to skopecky@compassperformanceinc.com. Include what you observed and when; do not include the affected personal data in the message.
Contact
Security questions, IT review requests, subprocessor queries and incident reports go to one address.
- Email skopecky@compassperformanceinc.com
- Telephone 224.307.0912
- 500 West Silver Spring Drive, Suite K-200, Glendale, Wisconsin 53217, United States
This document is Compass's standard operating position, not legal advice. Compass is not your counsel. Have your own legal and IT functions review it before execution, and where an executed master agreement exists, that agreement controls.
Not sure where to start?
Three questions, and we point you to the right instrument.
Under a minute. From this page, most leaders begin with The organization.
