Privacy Policy
Version 1.0 · Last updated August 8, 2026
Prepared under the EU General Data Protection Regulation (GDPR) and Spanish data-protection law (LOPDGDD).
This Privacy Policy explains what personal data Comppound processes, why, on what legal basis, and what rights apply, covering the comppound.com website, the discovery-call and sales process, active client engagements, and any associated tools (invoicing, analytics, outreach, hosting).
1. Controller
2. Overview of Processing Operations
Categories of Data Processed
- Identity Data: name, email address, job title
- Contact Data: email address, phone number, company name
- Company Data: company name, industry, size, ARR band, website URL
- Billing Data: invoicing details, VAT/tax ID, payment records (via payment processor; card details never touch Comppound directly)
- Platform Access Data: where an engagement is active, credentials or scoped access to client platforms (e.g., Google Search Console, Google Analytics, CMS) as needed to deliver the Services
- Communications Data: content of emails, discovery-call notes, and messages exchanged in the course of the relationship
- Technical & Usage Data: IP address, browser type, pages visited, and timestamps, collected via the Site
Categories of Data Subjects
- Prospects: individuals who request a proposal or otherwise inquire about the Services
- Clients: individuals at companies with an active or completed Service Agreement
- Website Visitors: individuals browsing comppound.com who have not otherwise contacted Comppound
- Communication Partners: individuals who email or message Comppound for any reason
Purposes of Processing
- Operating the Site and responding to inquiries
- Delivering the Services under an active Service Agreement, including accessing client platforms per the agreed scope
- Invoicing and payment processing
- Producing case studies and marketing materials (only per the opt-out terms in the Service Agreement)
- Compliance with tax, accounting, and other legal obligations
3. Legal Bases for Processing
- Performance of a Contract (Art. 6(1)(b) GDPR): processing necessary to deliver the Services under an executed Service Agreement, or to take pre-contractual steps at a Prospect’s request (e.g., scoping a proposal).
- Legitimate Interests (Art. 6(1)(f) GDPR): responding to inquiries and reasonable business-development follow-up, balanced against the individual’s rights as described per activity below.
- Consent (Art. 6(1)(a) GDPR): any future non-essential analytics or marketing cookies, withdrawable at any time. See Section 9.
- Legal Obligation (Art. 6(1)(c) GDPR): retention of invoicing and accounting records per Spanish tax law.
4. Recipients and Service Providers
Personal data may be shared with the following categories of service providers, each acting under a data-processing agreement consistent with Article 28 GDPR:
| Category | Provider | Purpose |
|---|---|---|
| Invoicing / payments | A third-party payment processor | Invoice generation, payment collection and processing |
| Website hosting | The Site's hosting provider | Hosting comppound.com |
| Client communication | Standard email and business communication tools | Responding to inquiries and coordinating discovery calls |
| Client SEO platforms | Google Search Console, Google Analytics (client-owned) | Delivering the Services; accessed under client authorization, not owned by Comppound |
| Production system / workspace | Internal production tooling and cloud storage | Storing engagement content, drafts, and reporting |
Comppound does not sell personal data to third parties, and does not share client platform data across clients.
5. International Data Transfers
Some service providers may process data outside the European Economic Area. Where this occurs, transfers are made only: to countries covered by a European Commission adequacy decision; under the European Commission’s Standard Contractual Clauses; or with explicit consent where required. A list of current cross-border transfers can be requested at the contact address in Section 15.
6. Retention Periods
| Data category | Retention period |
|---|---|
| Active client data | Duration of the engagement, plus 3 years after it ends |
| Invoicing / accounting records | 10 years (Spanish legal obligation) |
| Prospect data (no engagement resulted) | 3 years after last contact |
| General inquiries / contact form | 2 years after the inquiry is resolved |
| Website technical / log data | 12 months maximum |
| Client platform access | Revoked at the end of the engagement; any locally retained exports deleted within 30 days of termination |
At the end of the applicable period, data is deleted or irreversibly anonymized, unless a longer period is required by law.
7. Website Hosting and Log Files
The Site is hosted by a third-party hosting provider. In the ordinary course of serving the Site, that provider processes server log data, which may include IP address, browser type, referring page, and timestamp, for security and stability purposes (e.g., preventing abuse and DDoS activity). Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
8. Specific Processing Activities
8.1 Discovery Calls and Proposals
When a Prospect gets in touch via the contact form or by email on the Site, Comppound collects identity, contact, and company data to scope and price a proposal. Legal basis: pre-contractual steps at the data subject’s request (Art. 6(1)(b) GDPR).
8.2 Active Client Engagements
For an active client, Comppound processes contact, billing, communications, and (where granted) platform access data to perform the Service Agreement. Where platform access exposes the client’s own end-customer data (e.g., in analytics), Comppound processes that data solely as a processor acting on the client’s instructions, per the Service Agreement, not for Comppound’s own purposes. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
8.3 Invoicing and Payment
Billing details are processed to issue invoices and collect payment via a third-party payment processor. Card and bank details are handled directly by the payment processor and are not stored by Comppound. Legal basis: performance of a contract (Art. 6(1)(b) GDPR); legal obligation for accounting records (Art. 6(1)(c) GDPR).
8.4 Case Studies and Testimonials
Where a client has not opted out under the Service Agreement, company name, and high-level, non-confidential results may be used in marketing materials. This does not involve processing of individual personal data beyond a named point of contact’s public professional details, where used in a testimonial with that individual’s separate consent.
8.5 Outreach and Business Development
Comppound may process publicly available professional contact information (e.g., from LinkedIn or a company website) to make warm-intro or direct outreach to prospective clients. Legal basis: legitimate interests (Art. 6(1)(f) GDPR), balanced against the individual’s right to object at any time (Section 12).
9. Cookies and Analytics
10. Social Media Profiles
11. Changes to This Policy
This Policy may be updated as data-processing practices change. Material changes affecting active clients or requiring fresh consent will be communicated directly, not only by posting an updated version on the Site.
12. Your Rights as a Data Subject
- Right of Access (Art. 15 GDPR): confirmation of whether your data is processed, and access to it.
- Right to Rectification (Art. 16 GDPR): correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17 GDPR): deletion of your data where legally applicable.
- Right to Restriction of Processing (Art. 18 GDPR)
- Right to Data Portability (Art. 20 GDPR): receiving your data in a structured, machine-readable format.
- Right to Object (Art. 21 GDPR): including to processing based on legitimate interests or for direct marketing, at any time.
- Right to Withdraw Consent (Art. 7(3) GDPR): at any time, without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: with the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid, Spain (www.aepd.es).
To exercise any of these rights, contact hello@comppound.com. Comppound will respond within one month of a verified request, extendable by two further months for complex requests, with notice given within the first month.
13. Data Security
- Access to client platforms and communications restricted to Comppound only (single-operator practice, no third-party staff access without disclosure)
- Strong authentication on tools holding client data
- Encryption in transit for all data exchanged with third-party processors
- Platform access scoped to the minimum necessary and revoked promptly at engagement end
- Regular review of connected tools and access lists
14. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person. “Controller” means the entity that determines the purposes and means of processing. “Processor” means an entity that processes data on the controller’s behalf and instructions. “Processing” means any operation performed on personal data, whether automated or not.
Comppound maintains a presence on LinkedIn and Instagram (@comppoundhq). Interactions on these platforms (comments, messages) are processed to communicate with users and are also subject to each platform’s own privacy policy. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).