Privacy Policy
Last updated: 7 July 2026
This policy explains how the Greyguard Compass web application (the “Compass App”, accessible at compass.greyguardconsulting.com) collects, uses, stores, and protects personal data. It is maintained by SERED CONSULTING LTD (the “App Owner”) and applies only to the Compass App, not to the marketing website at greyguardconsulting.com or any other Greyguard service.
1. Who we are (Data Controller)
SERED CONSULTING LTD is the data controller for personal data processed through the Compass App. We are registered in the United Kingdom at:
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United KingdomFor any privacy request, contact us at info@greyguardconsulting.com.
2. What data we collect
- Account data: email address used for the one-time magic-link sign-in and the Supabase authentication identifier.
- Assessment answers: your responses to the governance questionnaire, including any free-text notes and optional file attachments you upload as evidence.
- Organisation context: company name, sector, size and role information you provide inside the assessment.
- Payment metadata: if you engage us for a tailored verified report and pay through Stripe, Stripe receives your card details directly; we store only the Stripe customer/session identifier, amount, currency, and status. We never see or store card numbers.
- Email delivery data: transactional email logs (submission confirmations, report-ready notifications, unsubscribe tokens) and suppression list entries.
- Technical data: minimal server-side request logs (IP, user-agent, timestamps) needed for security and abuse prevention. The Compass App does not use third-party marketing or analytics cookies.
- Local browser storage: your in-progress assessment is cached in
localStorageon your device so you can resume it, and a Supabase auth token is kept there for the session.
3. Why we process it (legal basis)
- Contract (GDPR Art. 6(1)(b)): to run the assessment, generate your report, and deliver the paid report you purchased.
- Legitimate interest (Art. 6(1)(f)): security, fraud prevention, service reliability, and internal quality review of anonymised aggregate scoring.
- Legal obligation (Art. 6(1)(c)): tax and accounting records for paid purchases.
- Consent (Art. 6(1)(a)): for any optional follow-up communications; you can withdraw at any time via the one-click unsubscribe link.
4. Where your data is stored (data residency)
The Compass App’s primary database, authentication service, file storage, and encrypted secrets are hosted on Supabase running on AWS in the eu-west-2 region (London, United Kingdom). Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
Under GDPR, the UK is a third country covered by an EU adequacy decision (currently in force, with a proposed extension to December 2028), so EU→UK transfers of your personal data are lawful without additional safeguards while that decision remains valid.
5. Sub-processors
| Processor | Purpose | Region |
|---|---|---|
| Supabase (on AWS) | Database, auth, storage, secrets | UK (eu-west-2) |
| Cloudflare | Edge/CDN, TLS termination, DDoS/WAF, serverless SSR | Global (EU-first routing) |
| Stripe | Payment processing for full-report purchases | EU / US (SCCs) |
| Lovable AI Gateway (Google Gemini / OpenAI) | AI-assisted report drafting; contractual no-training clauses | EU / US (SCCs) |
| Lovable Emails | Transactional email delivery | EU |
All sub-processors are bound by Data Processing Agreements. Onward transfers outside the UK/EEA rely on the EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum.
6. How long we keep it
- Assessments & reports: kept while your account is active, so you can return to them. Deleted within 30 days of account deletion.
- Paid purchase records: retained for 7 years to meet tax and accounting obligations.
- Email suppression list: kept indefinitely so we continue to honour your unsubscribe request.
- Server/security logs: retained for up to 90 days.
7. Security
- TLS 1.2+ everywhere; AES-256 encryption at rest.
- Postgres Row-Level Security enforces per-user access; service role access is limited to verified server functions.
- Passwordless magic-link sign-in - no passwords to leak.
- Stripe webhooks are HMAC-signature verified.
- Automated encrypted backups of the primary database.
8. Your rights
Under GDPR / UK GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent at any time. To exercise any of these rights, email info@greyguardconsulting.com. You may also lodge a complaint with your local supervisory authority (in the UK, the ICO).
9. Cookies & tracking
The Compass App uses only strictly necessary storage: a Supabase authentication token and a local cache of your in-progress assessment, both stored in your browser. We do not use advertising cookies, cross-site trackers, or third-party analytics.
10. Changes to this policy
We will update this page when our processing changes materially. The “Last updated” date at the top reflects the current version.
