Privacy Policy

Last modified – 21st June 2021

Introduction

Your privacy is important to us !!

Compass is committed to respect your privacy while using our website and products.  This compass Privacy Policy (“Policy”) defines the requirements to ensure compliance with the applicable data privacy laws and regulations applicable to compass collection, use, and transmission of Personal Data and Sensitive Personal Data for information collected by us about you.

This website is operated by ++++, a Private Limited Company also referred as Compass (“we”,”us” or “our”). This privacy policy (“Policy”) explains how we collect, use and disclose information about our users when you use our mobile application (the “App”), our Website (the “Site”) and other online products and services that link to this Policy (collectively, the “Service”). We refer throughout this Policy to our users as “User,” “you,” or “your,” and we also refer to users as, “Potential Customers'' to denote those visiting or site or requesting information regarding our Services, “Customer Company” to denote our organizational customer, and “Employee User” to denote individual employees of Customer Company who are users of the App, the Site, and the Service through their employer. 

By using the Service, you consent to our collection, use and disclosure of your personal information as described in this Policy. Protecting the privacy rights of data subjects and safeguarding their Personal Data is now being treated as a basic right of an individual and a legal requirement in many parts of world, being a global organization, respects the privacy of data subjects and is committed to complying with the applicable data privacy laws and legislations (including but not limited to EU General Data Protection Regulation 2016/679, California Consumer Privacy Act, The Privacy Act 1988 (Australia) Data Protection Act 2018 (UK), Information Technology Act 2000 read along with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and other applicable privacy laws to the extent that they apply to compass data processing and business operations) (the “Data Privacy Laws”)

We take your privacy seriously. If you have any questions about this Policy or about privacy at Compass please contact us at hello@getcompass.ai.

This privacy policy describes:

  • The information We collect, how we do so and the purposes of our collection.
  • How We use and with whom We share such information.
  • How you can access and update such information.
  • The choices you can make about how We collect, use and share your information.
  • How We protect the information we store about you
  • Aggregate or scrape any content, data, or other information from the Website to be aggregated or shown with material from other sites or on a secondary site without our express written permission.
  • If you access our Services from a third-party site, you may be required to also read and accept the third party’s terms of service and privacy policy

Definitions

The meaning of some of the terms in use in the Policy are explained below:

  • Personal Data :
    Any information of “Data Subject” which can reasonably associate or link to an identifiable natural person or could include anyone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, economic, cultural or social identity of that natural person.

  • Personal Information (applicable only to California residents) :
    Information pertaining to residents of California that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, but does not include information that is lawfully made available from federal, state or local government records, nor does it include “deidentified” or “aggregate customer information” as those terms are defined pursuant to the California Consumer Privacy Act (CCPA).

  • Sensitive Personal Data :
    Defined as any information revealing an identified or identifiable natural person’s racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and the processing of genetic information, biometric information for the purpose of uniquely identifying a natural person, data concerning health, or information concerning an individual’s sex life or sexual orientation, and data relating to offenses, or criminal convictions.

    With respect to California residents, in addition to the preceding, the term also includes national origin or ancestry, sexual orientation, sex (including, gender, gender identity, and gender expression), pregnancy, childbirth and medical conditions related to same, age, physical or mental disability, veteran status, genetic information and citizenship.

  • Process, Processes, Processed or Processing :
    Means any operation or set of operations which is performed on Personal Data or Personal Information or Sensitive Personal Data or on sets of Personal Data or Personal Information or Sensitive Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • Consent : 
    Any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which the Processing of their Personal Data, Personal Information and/or Sensitive Personal Data via a statement or by a clear affirmative action, signifies agreement to the processing of their Personal Data, Personal Information and/or Sensitive Personal Data.

  • Data Subject : 
    Relates to a particular natural person (i.e., an identified or identifiable natural person to whom the Personal Data relates. In case of a minor/ individual with mental disabilities, the data subject would be represented by a legal representative (parent/ guardian).

    For the purpose of clarity of this Policy, “Data Subject” means compass current and previous employees, prospective candidates, current, prospective and previous customer personnel, current and previous partner/vendor personnel, website visitors, sub-contractors and visitors.

    Compass does not collect Personal Data/ Personal Information and Sensitive Personal Information from Data Subjects that are under the age of 18. For the purpose of CCPA, Data Subject shall include California residents.

  • Data Controller : 
    Means a person or organization who (either alone, or jointly, or in common) determines the purposes for which and the manner in which any Personal Data are, or are to be, Processed. For the purposes of this Policy, references to Data Controller shall mean references to compass and its affiliates, where relevant.

  • Data Processor :
    Is a person or organization who Processes the Personal Data on behalf of and under the instruction of the Data Controller.

  • Third Party :
  • In relation to Personal Data or Personal Information or Sensitive Personal Data means any person other than the Data Subject, the Data Controller, or any Data Processor or other person authorized to process data for the Data Controller.

Personal Information we collect and process and how we use it

Information we collect from customer company

When a Customer Company indicates interest in our Service, we collect the following information via our sign-up form: full name, email address, company name and phone number. We collect this information through a landing page which an interested Customer Company might access through forms on various directory services detailed in our Third-Party Provider. When a Customer Company indicates interest in our Service, we collect the following information via our sign-up form: full name, email address, company name and phone number. We collect this information through a landing page which an interested Customer Company might access through forms on various directory services detailed in our Third-Party Provider.

Personal data we collect from employee users

We collect certain human resource (“HR”) information, and other information about Employee Users, from the Customer Company, and at the Customer Company’s option, such as: full name, email address, phone number or any other information that may be required from time to time. This Data is provided by the Customer Company’s HR department directly or indirectly by allowing compass to connect customer systems like HRMS, Single sign on systems etc, and is loaded and maintained in our system to allow for analytics. As noted above, we collect certain HR information about Employee Users directly from the Customer Company. 

When Employee Users answer surveys or engage in conversations with peers on the App, Site, or System by voting on surveys or engaging in text conversations between peers, we collect employee opinions from Employee Users. Employee User votes or comments are connected to their authors. When a User visits our Site, we use certain tracking data (“Tracking Information”). We use Google Analytics and Freshdesk for Tracking Information.

The following Tracking Information is collected: email address, device ID, IP address. We collect your email address, IP addresses and device information, directly through inclusion of their sdk/pixel or any other information which may be required from time to time. Tracking Information is collected via the Site and our web-applications, as well as via our iOS and android implementations.

Payment information

If a third party is not paying for the service on your behalf, We will collect the billing and financial information necessary to process your charges for compass services which require payment, which may include your postal and e-mail addresses. Compass may also receive the billing and payment information that you provide when your purchase is processed by another party, such as Paypal etc. Our Terms of Service explain our policies and terms relevant to our charges and billing practices. Please note that establishing an account with a third-party payment processor, like PayPal etc, may also be subject to additional policies.

Technical and usage information

When you access our websites or use our Services, we collect -

  1. Certain technical information about your mobile device or computer system, including IP Address and mobile device ID; and
  2. Usage statistics about your interactions with the Service. This information is typically collected using server log files or web log files (“Log Files”), mobile device software development kits and tracking technologies like browser cookies to collect and analyse certain types of technical information. Some of the cookies the Service places on your computer are linked to your user ID number(s).


Cookies and automated information collection

When you access the Service, we collect certain technical information in order to -

  1. Analyze the usage of our sites and services;
  2. Provide a more personalized experience; and 
  3. Manage testimonials.
  4. You can set your web browser to warn you about attempts to place cookies on your computer or limit the type of cookies you allow.

 

Other sources

We may collect or receive information from other sources including third party information providers. This information will be used to supplement your profile - primarily to help you and your friends connect. It will be combined with other information We collect.

How we use the information we collect

In general, we collect, store, and use your information to provide you with a safe, smooth, efficient, and customized experience. For example, we may use information collected from you in any one or more of the following ways:

  • Provide, maintain, and improve our Service.
  • Provide and deliver the Service Customer Company requests and configures, process transactions and send you related information, including confirmations.
  • Investigate system issues that impact our ability to provide the Service to Users.
  • Send you technical notices, updates, confirmations, security alerts and support and administrative messages.
  • Respond to your comments, questions and requests and provide customer service.
  • Communicate to Customer Companies with you about products, services, offers, promotions, rewards, and events offered by compassand others, and provide news and information we think will be of interest to you.
  • Monitor and analyze trends, usage, and activities in connection with our Service and improve and personalize the Service.
  • Personalize and improve the Service, content or features that match user profiles or interests.
  • Link or combine with information we get from others to help understand your needs and provide you with better service.
  • Connect you with other users in your Contacts.

We will not sell, rent, or share Personal Data with third parties outside of our company without your consent, except in the following ways:

Law enforcement and internal operations

Personal Data may be provided where we are required to do so by law, or if we believe in good faith that it is reasonably necessary.

  1. To respond to claims asserted against compass or to comply with the legal process (for example, discovery requests, subpoenas or warrants);
  2. To enforce or administer our policies and agreements with users.
  3. For fraud prevention, risk assessment, investigation, customer support, product development and de-bugging purposes; or
  4. To protect the rights, property, or safety of ............, its users or members of the general public. 
  5. We will use commercially reasonable efforts to notify users about law enforcement or court ordered requests for data unless otherwise prohibited by law.
  6. However, nothing in this Privacy Policy is intended to limit any legal defences or objections that you may have to any third-party request to compel disclosure of your information.

Data recipients, transfer, and disclosure of Personal Information

Compass does not share your Personal Information with third parties for their direct marketing purposes

We share your Personal Information within ............, Business partners, Service vendors, Authorized third-party agents or Contractors as per the law.

We reserve the right to use or disclose your Personal Information if required by law or if we reasonably believe that use or disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or comply with a law, court order, or legal process.

Business transfer

Compass may sell, transfer, or otherwise share some or all of its assets, including your Personal Data, in connection with a merger, acquisition, reorganization or sale of assets or in the event of bankruptcy. Under such circumstances, compass will use commercially reasonable efforts to notify its users if their personal information is to be disclosed or transferred and/or becomes subject to a different privacy policy.

Third – parties 

We sometimes contract with other companies and individuals to perform functions or services on our behalf, such as software maintenance, data hosting, sending email messages, etc. We necessarily have to share your Personal Data with such third parties as may be required to perform their functions. We take necessary steps to ensure that these parties take protecting your privacy as seriously as we do, including entering into Data Processing Addendum(s), EU Model Clauses and/or ensuring these third-parties have EU-U.S. and Swiss-US Privacy Shield certification.

How is my data protected?

We have implemented reasonable administrative, technical, and physical security measures to protect your personal information against unauthorized access, destruction, or alteration. For example:

  • SSL encryption (https) where we deal with personal data. Personal Data is encrypted in transit using https/ssl/tls and encrypted at rest. Our database is encrypted, and data transferred via sftp is encrypted using PGP.
  • Password protection on your account.
  • Rotating verification codes to access by some parties.
  • Data is kept on secure, encrypted servers.
  • Restricting staff access to Personal Data, protected by password logs and two factor authentications.
  • Non-Disclosure Agreements with vendors
  • Regular staff privacy and security training

Retention and Disposal of Personal Data or Personal Information

How long we continue to hold your Personal Data/ Personal Information will vary depending principally on:

  • Purposes identified in this Policy for using the Personal Data/ Personal Information/ Sensitive Personal Information – we will need to keep the information for as long as is necessary for the relevant purpose; and
  • Legal obligations – laws or regulation may set a minimum period for which we will have to keep your Personal Data/ Personal Information/ Sensitive Personal Information
  • Disposal of Personal Data/ Personal Information/ Sensitive Personal Information shall be handled with utmost care and shall be governed in accordance with reasonable data security practices as detailed by its internal policies governing data disposal.
  • Personal Data/ Personal Information/ Sensitive Personal Data shall only be Processed for the period necessary for the purposes for which it was originally collected as per the compass Retention Policy.

Children’s Personal Information

We do not knowingly collect any personal information from children under the age of 16. If you are under the age of 16, please do not submit any personal information through our Websites or Services. 

We encourage parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide personal information through the Websites or Services without their permission. If you have reason to believe that a child under the age of 16 has provided personal information to us through the Websites or Services, please contact us at hello@getcompass.ai, and we will use commercially reasonable efforts to delete that information.

Access & Control Your Personal Data

Individual can review, correct, and remove your Personal Information.

  • You can request access, correction, updates, or deletion of your personal information.
  • You can object to processing of your personal information, ask us to restrict processing of your personal information or request portability of your personal information.
  • If we have collected and process your personal information with your consent, then you can withdraw your consent at any time.
  • Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
  • You have the right to complain to a data protection authority about our collection and use of your personal information.

To exercise any of these rights, please email us at hello@getcompass.ai

Complaints and Grievances

Any complaints or grievances received about our use of Personal Data, Personal Information or Sensitive Personal Data and any communications regarding enforcement of your privacy rights should be promptly directed to our Data Protection Officer Complaints.

Contact - 

Attn: Data Protection Officer

Email ID - hello@getcompass.ai

Updates to Our Policy

We may amend or update our Privacy Policy. We will provide you notice of amendments to this Privacy Policy, as appropriate, and update the “Last modified” date at the top of this Privacy Policy. Please review our Privacy Policy from time to time.