بوصلة | Compass

Data Processing Agreement (draft)

Version 1.0-draft · effective pending legal review

CCSIT's commitments as processor of Customer Data.

1. Scope

This DPA applies to personal data in Customer Data that CCSIT processes on the Customer's behalf to provide Compass. Subject matter: project management. Categories of data subjects: Customer staff, contractors, client contacts and client guests. Categories of data: identification and contact details, work assignments, time entries, comments and files the Customer uploads.

2. Instructions

CCSIT processes personal data only on the Customer's documented instructions (these Terms, the configuration of the workspace, and written requests), unless required by law, in which case CCSIT informs the Customer unless prohibited.

3. Confidentiality and personnel

Personnel with access are bound by confidentiality and receive security training. Production access is limited, logged and reviewed.

4. Security measures

Technical and organisational measures include: tenant isolation enforced in every query and verified by automated cross-tenant tests; role- and project-scoped access; encryption in transit and at rest; field-level encryption of authentication secrets; malware scanning of uploads; immutable audit log; least-privilege infrastructure; daily encrypted backups with tested restores; vulnerability management and annual third-party penetration testing [●].

5. Subprocessors

The Customer authorises the subprocessors on the Subprocessors page. CCSIT gives at least 30 days' notice of new subprocessors; the Customer may object on reasonable data-protection grounds and, if no solution is found, terminate the affected service.

6. Assistance

CCSIT helps the Customer respond to data-subject requests (export and deletion tools are built into the product) and with impact assessments and regulator consultations where required.

7. Personal data breaches

CCSIT notifies the Customer without undue delay and in any case within [● 48] hours of becoming aware of a personal data breach affecting Customer Data, with the information then available, and keeps the Customer updated.

8. Deletion and return

At the end of the service, Customer Data can be exported by the Customer and is then deleted as set out in the Terms of Service, with written confirmation on request.

9. Audits

CCSIT makes available its security documentation and penetration test summaries. The Customer may audit once a year on 30 days' notice at its own cost, or rely on independent reports where available.

10. International transfers

Transfers outside the workspace's data region happen only for the purposes listed (e.g. live AI) and under safeguards required by the applicable law [● standard contractual clauses / regulator approvals].

© 2026 CCSIT — Continuum Consulting Services

Compass — AI-native PMO