Compass Gateway Ltd
Privacy Policy
This policy is published at compassgateway.com/privacy. It explains how Compass Gateway Ltd handles personal data under UK data protection law, including the UK GDPR and the Data Protection Act 2018.
Contents
Who we are
Compass Gateway Ltd is the controller of the personal data described in this policy, except where section 6 says otherwise.
- Company number: 15488605 (England and Wales)
- Registered office: 27 Old Gloucester Street, London, WC1N 3AX
- Contact for privacy matters: enquiries at compassgateway dot com
We are registered with the Information Commissioner’s Office (ICO) as a data controller, registration reference ZB763883.
The personal data we collect
Clients and business contacts. Names, job titles, organisations, contact details, correspondence, and records of the work we do together.
Billing. Invoicing details, payment records and bank details you give us for payment purposes.
Training delegates. Names, contact details, attendance, and assessment or certification outcomes, usually provided to us by the organisation booking the course.
Families using childcare support. Contact details, and information you give us about your child — including health information, allergies, medication and care needs — together with emergency contacts and consents.
Website visitors. Our website does not use cookies, advertising or tracking.
We collect this data directly from you, or from the organisation that engages us.
Why we use it, and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Delivering our services and managing engagements | Performance of a contract |
| Invoicing, accounting, tax and company records | Legal obligation |
| Responding to enquiries and managing business relationships | Legitimate interests (running our business) |
| Training records and certification | Performance of a contract; legitimate interests |
| Insurance, and establishing or defending legal claims | Legitimate interests; legal obligation |
| Marketing to business contacts (occasional, relevant, easy to opt out) | Legitimate interests |
Children’s health information (childcare support). Health data is special category data. We process it only to care for your child safely, on the basis of your explicit consent, and — in an emergency — to protect your child’s vital interests. You may withdraw consent at any time, though we cannot safely provide care without this information.
Safeguarding. We may share information with appropriate authorities where we have a safeguarding concern. This is done under our legal and public-interest obligations and does not require consent.
Who we share it with
We share personal data only as needed with:
- our accountants, insurers, bankers, IT and software providers, and professional advisers;
- subcontractors helping us deliver an engagement, under confidentiality obligations;
- the organisation that engaged us, where the data relates to that engagement (for example, delegate results to the booking employer);
- regulators, HMRC, or others where the law requires.
We do not sell personal data.
Where our service providers store data outside the UK, we make sure appropriate safeguards recognised under UK law are in place (such as adequacy regulations or standard contractual clauses).
How long we keep it
- Engagement, contract and billing records: 6 years after the end of the tax year they relate to, in line with tax and limitation requirements.
- Business contact details: while the relationship is active and for a reasonable period afterwards.
- Records relating to the care of children: for longer periods in line with applicable guidance on children’s records, because legal time limits for claims involving children run from adulthood.
- Enquiries that go nowhere: up to 12 months.
When data is no longer needed, we delete it or anonymise it.
When we are not the controller
Sometimes we work inside a client’s own systems and governance — for example, clinical records made in an event medical provider’s patient record system, or data we handle on a client’s instructions. In those cases the client is the controller, we act on their instructions, and their privacy notice applies to that data. Requests about that data should go to them; we will help route them.
Your rights
You have the right to ask us for access to your personal data, correction, erasure, restriction, portability, and to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time.
To exercise any right, contact enquiries at compassgateway dot com. We will respond within one month.
If you are unhappy with how we handle your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113 — though we would appreciate the chance to sort it out first.
Security
We keep personal data secure using appropriate technical and organisational measures, including access controls, encryption in transit, and limiting access to those who need it. We will notify you and the ICO of any personal data breach where the law requires.
Changes to this policy
We may update this policy from time to time. The current version is always at compassgateway.com/privacy, with the effective date shown at the top.