Compass Gateway

Compass Gateway Ltd

Privacy Policy

Effective
27 July 2026
Version
1.0

This policy is published at compassgateway.com/privacy. It explains how Compass Gateway Ltd handles personal data under UK data protection law, including the UK GDPR and the Data Protection Act 2018.

Contents
  1. 1Who we are
  2. 2The personal data we collect
  3. 3Why we use it, and our lawful bases
  4. 4Who we share it with
  5. 5How long we keep it
  6. 6When we are not the controller
  7. 7Your rights
  8. 8Security
  9. 9Changes to this policy

Who we are

Compass Gateway Ltd is the controller of the personal data described in this policy, except where section 6 says otherwise.

We are registered with the Information Commissioner’s Office (ICO) as a data controller, registration reference ZB763883.

The personal data we collect

Clients and business contacts. Names, job titles, organisations, contact details, correspondence, and records of the work we do together.

Billing. Invoicing details, payment records and bank details you give us for payment purposes.

Training delegates. Names, contact details, attendance, and assessment or certification outcomes, usually provided to us by the organisation booking the course.

Families using childcare support. Contact details, and information you give us about your child — including health information, allergies, medication and care needs — together with emergency contacts and consents.

Website visitors. Our website does not use cookies, advertising or tracking.

We collect this data directly from you, or from the organisation that engages us.

Why we use it, and our lawful bases

PurposeLawful basis
Delivering our services and managing engagementsPerformance of a contract
Invoicing, accounting, tax and company recordsLegal obligation
Responding to enquiries and managing business relationshipsLegitimate interests (running our business)
Training records and certificationPerformance of a contract; legitimate interests
Insurance, and establishing or defending legal claimsLegitimate interests; legal obligation
Marketing to business contacts (occasional, relevant, easy to opt out)Legitimate interests

Children’s health information (childcare support). Health data is special category data. We process it only to care for your child safely, on the basis of your explicit consent, and — in an emergency — to protect your child’s vital interests. You may withdraw consent at any time, though we cannot safely provide care without this information.

Safeguarding. We may share information with appropriate authorities where we have a safeguarding concern. This is done under our legal and public-interest obligations and does not require consent.

Who we share it with

We share personal data only as needed with:

  • our accountants, insurers, bankers, IT and software providers, and professional advisers;
  • subcontractors helping us deliver an engagement, under confidentiality obligations;
  • the organisation that engaged us, where the data relates to that engagement (for example, delegate results to the booking employer);
  • regulators, HMRC, or others where the law requires.

We do not sell personal data.

Where our service providers store data outside the UK, we make sure appropriate safeguards recognised under UK law are in place (such as adequacy regulations or standard contractual clauses).

How long we keep it

  • Engagement, contract and billing records: 6 years after the end of the tax year they relate to, in line with tax and limitation requirements.
  • Business contact details: while the relationship is active and for a reasonable period afterwards.
  • Records relating to the care of children: for longer periods in line with applicable guidance on children’s records, because legal time limits for claims involving children run from adulthood.
  • Enquiries that go nowhere: up to 12 months.

When data is no longer needed, we delete it or anonymise it.

When we are not the controller

Sometimes we work inside a client’s own systems and governance — for example, clinical records made in an event medical provider’s patient record system, or data we handle on a client’s instructions. In those cases the client is the controller, we act on their instructions, and their privacy notice applies to that data. Requests about that data should go to them; we will help route them.

Your rights

You have the right to ask us for access to your personal data, correction, erasure, restriction, portability, and to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time.

To exercise any right, contact enquiries at compassgateway dot com. We will respond within one month.

If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113 — though we would appreciate the chance to sort it out first.

Security

We keep personal data secure using appropriate technical and organisational measures, including access controls, encryption in transit, and limiting access to those who need it. We will notify you and the ICO of any personal data breach where the law requires.

Changes to this policy

We may update this policy from time to time. The current version is always at compassgateway.com/privacy, with the effective date shown at the top.

Back to Compass Gateway