بوصلة | Compass

Privacy Policy (draft)

Version 1.0-draft · effective pending legal review

How CCSIT handles personal data — aligned with Egypt's PDPL (Law 151/2020), Saudi PDPL, UAE PDPL (Federal Decree-Law 45/2021) and GDPR principles.

1. Roles

For Customer Data inside a workspace, the Customer is the controller and CCSIT is the processor (see the Data Processing Agreement). For account, billing, website and security data, CCSIT is the controller and this policy applies.

2. What we collect

Account data: name, work email, job title, role, language and time-zone preferences.

Security data: sign-in times, IP addresses, browser user agent, two-step verification events, kept to protect accounts.

Billing data: company name, billing contact and invoices (card details are handled by our payment provider, never stored by Compass).

Usage data: feature usage and AI credit consumption, to operate plans and improve the Service.

3. Why we use it (lawful bases)

To provide the Service under our contract with your organisation; to secure accounts and prevent abuse (legitimate interest and legal obligation); to bill (contract, legal obligation); to send service emails you can control in your notification settings.

4. Where data is stored

Each workspace chooses a data region when it is created (UAE, Saudi Arabia or Egypt, or your own data centre for on-premises deployments). Customer Data is stored and processed in that region, except when live AI is enabled and data is sent to the AI provider listed on the Subprocessors page with appropriate safeguards [● cross-border transfer mechanism per jurisdiction].

5. Retention

Account data: while the account exists plus [●] months. Security logs: 12 months. Billing records: as required by tax law. Customer Data: as set out in section 10 of the Terms of Service.

6. Your rights

You may request access, correction, deletion, restriction or a copy of your personal data, and object to processing, by writing to privacy@ccsit.co. If your data is in a customer's workspace, we will pass the request to that customer as controller. You may also complain to the competent data protection authority (e.g. Egypt's Personal Data Protection Centre, SDAIA in Saudi Arabia, the UAE Data Office).

7. Security

Encryption in transit (TLS) and at rest, bcrypt password hashing, optional and enforceable two-step verification, role-based access with client isolation, antivirus scanning of uploads, audit and security logs, and regular penetration testing.

8. Cookies

Compass uses strictly necessary cookies only: the session cookie, a CSRF protection cookie, and a language preference cookie. No advertising or third-party tracking cookies are used in the application.

9. Contact

Data protection contact: privacy@ccsit.co. [● Data Protection Officer name and registration where required.]

© 2026 CCSIT — Continuum Consulting Services

Compass — AI-native PMO