1. Introduction
Compass Political Intelligence Platform (hereinafter “Compass”) is operated by CL Corporate Affairs Consulting E.I. (hereinafter “CL” or “CL Corporate Affairs Consulting”, used interchangeably throughout this document), headquartered at 1 avenue de l’Observatoire, 75006 Paris, France (VAT: FR58902992189), with a representation office at Avenue de Tervueren 103, B-1040 Brussels, Belgium. This Privacy Policy explains how we collect, use and protect personal data within the Compass platform, in compliance with Regulation (EU) 2016/679 (the “GDPR”) and the French Loi Informatique et Libertés.
Compass is built and operated by a working public affairs consultancy, and may be made available to fellow practitioners, such as in-house public affairs teams, trade associations, NGOs and other organisations whose activity overlaps with our own field of practice. This particular context shapes the way we have designed the platform: while CL upholds, as a foundational professional duty, a strict commitment to refusing any conflict of interest (see also section 3 of the Terms and Conditions), we believe that this contractual and ethical commitment must be matched by technical and organisational guarantees giving each user real, demonstrable control over their own data. The provisions that follow, in particular the optional end-to-end encryption (section 10.1) and our deliberate AI policy (section 9), are the practical expression of that conviction. They are not generic compliance statements: they reflect a positioning choice that we consider inseparable from the kind of platform a public affairs consultancy can responsibly offer to its peers.
2. Data controller
CL Corporate Affairs Consulting E.I.
1 avenue de l’Observatoire, 75006 Paris, France
Avenue de Tervueren 103, B-1040 Brussels, Belgium
Contact: compass.eu.com/contact
3. Roles and responsibilities under the GDPR
The allocation of data protection roles within Compass depends on the specific context of use, assessed on a case-by-case basis in accordance with Articles 4(7), 4(8), 26 and 28 of the GDPR. The determining factor is which party decides the purposes and essential means of each processing operation, not the contractual label alone.
When CL uses Compass for its own consulting activity, CL Corporate Affairs Consulting acts as sole data controller for all data processed within the platform, including reference data, stakeholder mapping, position analysis and engagement records.
When a third-party user accesses Compass in the context of their own public affairs activities, the respective roles are determined by the nature of the mission and the degree of autonomy of each party:
- If the user defines the strategy, selects the stakeholders, determines the data to be collected and controls the outputs, the user acts as data controller and CL Corporate Affairs Consulting acts as data processor (Article 4(8) GDPR), providing the technical infrastructure and processing data only on behalf of and under the instructions of the user.
- If, beyond the mere provision of the platform, CL Corporate Affairs Consulting is also retained under a consulting engagement and determines with the user the objectives and essential means of a given processing operation, both parties may be considered joint controllers (Article 26 GDPR) for that specific operation. In that case, the respective obligations are defined in the engagement agreement. Use of the platform alone, outside such an engagement, does not fall within this case: CL acts there exclusively as data processor (see section 3.1).
In all cases, CL Corporate Affairs Consulting is committed to implementing appropriate technical and organisational measures to ensure the security and confidentiality of personal data, in compliance with the GDPR. Where CL Corporate Affairs Consulting acts as data processor, the Terms and Conditions of the platform govern the obligations of each party in accordance with Article 28 GDPR.
3.1 Specific case: CL-designed analytical methodologies
The roles described in section 3 distinguish who decides what within a given processing operation. Within that framework, one nuance deserves to be stated explicitly: Compass embeds a number of analytical methodologies designed by CL Corporate Affairs Consulting: in particular the influence weighting applied to stakeholders, the urgency scoring that flags time-sensitive engagement, the activate-target detection that surfaces priority contacts, and the predictive estimation of legislative timelines derived from past procedural patterns. The user controls who is added to the platform, what data is entered, and the strategic purpose pursued; CL is the author of the methodology that turns that user-controlled data into a score, a ranking or an estimate.
As the publisher that designs the methodology, CL Corporate Affairs Consulting’s responsibility is confined to making the tool available, and it answers for that with due diligence in the light of its regulatory and legal obligations. By entering the data, by identifying the persons and institutions concerned, by prioritising those whose mobilisation matters most in view of their presumed influence, and by assuming the purpose of the processing of the data relating to them, the user consequently remains the controller of that processing within the meaning of the GDPR. Every suggested value is, moreover, visible and can be adjusted or overridden by hand. Designing the methodology gives CL Corporate Affairs Consulting no decision-making power over the purposes or the essential means of the processing of the user’s data, and therefore does not give rise to joint controllership within the meaning of Article 26 GDPR. This allocation is the one set out in section 7 of the Terms and Conditions, which constitute the Article 28 data processing agreement between the parties.
Concretely, the user remains free to disagree with a score, to override it manually, and to use Compass without relying on the suggested weighting: positions and influence values can always be set or overridden by hand. The scoring methodology CL designs rests on weightings and influence-analysis modalities derived from the relevant political-science literature. What the user is given is meaningful control over its output (every suggested value is visible and can be adjusted or overridden by hand), and CL stands by the methodology it designs. That residual methodological responsibility does not extend to the user’s overall mapping work: for the data entered, the subjects selected and the purpose pursued, the user remains the controller.
4. Categories of data processed
Compass processes three distinct categories of personal data, each with its own regime:
- Reference data: institutional and organisational information sourced from official, publicly accessible databases of the European Union (European Parliament, Council of the EU, European Commission, EU Transparency Register). This includes names, functions, mandates, committee memberships, political group affiliations, nationality and official contact details of public figures acting in their institutional capacity. CL Corporate Affairs Consulting is responsible for the collection and periodic updating of this data.
- Stakeholder mapping and position data: publicly available information aggregated by the user, with optional AI assistance: publicly declared positions, published statements, votes, press releases, public social media posts (from accounts explicitly validated by the user). The user selects the stakeholders to track, validates each position attributed, and determines how this data is used in the context of their professional activity.
- Internal notes and engagement records: free-text content entered exclusively by the user: meeting reports, phone call notes, follow-up actions, informal observations, personal assessments. This content is drafted by the user alone, accessible only to the user who created it, and is not accessed, moderated, analysed or exploited by CL Corporate Affairs Consulting in any way. The user is solely responsible for the content, accuracy and lawfulness of these notes, in the same way as for any private professional record.
User account data (name, email address, company, phone number if provided, hashed login credentials) is also processed for the purpose of providing access to the platform.
Browsing data: a single session cookie (HTTP-only, strictly functional, no tracking) is used for authentication.
Account request data: where an account is requested through the account request form, we process the identity, contact and professional details supplied, the organisation and, where applicable, the clients declared, any logos attached, how the applicant heard about Compass, and the IP address the request was sent from. This data serves one purpose: deciding on the request. If the request is accepted it becomes account data; if it is declined it is deleted, logos included.
5. Legal basis and purposes
The processing of personal data within Compass is based on the following legal grounds:
- Legitimate interest (Article 6(1)(f) GDPR): stakeholder mapping, position tracking and engagement management are recognised core functions of public affairs practice. The legitimate interest relied upon is that of the controller carrying out that activity, as identified in section 3: in the first place the user, acting in the exercise of their own regulated public affairs profession; and CL Corporate Affairs Consulting only to the extent it is itself the controller, that is, for its own consulting use of the platform (section 3). Designing the analytical methodology does not make CL a controller for a user’s processing (section 3.1). The data processed is limited to information that is publicly available or directly relevant to the professional relationship between the user and the stakeholder.
- Performance of a contract (Article 6(1)(b) GDPR): user account data is processed to provide access to the platform and deliver the agreed service.
- Legal obligation (Article 6(1)(c) GDPR): where applicable, compliance with transparency obligations (EU Transparency Register, HATVP declarations under French law).
Account requests. An account request is processed in order to take steps at the applicant’s own request prior to entering into a contract (Article 6(1)(b) GDPR). The conflict-of-interest check described in section 3 of the Terms and Conditions, and the protection of the public form against automated abuse, rest on legitimate interest (Article 6(1)(f) GDPR).
Reminder emails. Where an account has not been signed in to for 30 days, we send its holder a short email recalling what the platform does and pointing to the contact form, then a further one 90 days after the previous message for as long as the account stays unused. This rests on legitimate interest (Article 6(1)(f) GDPR): an account exists to be used, and an unused one usually means a practical obstacle we can remove. These emails are never sent to third parties and never promote anything other than the service the holder already has. Each one carries an unsubscribe link, the preference can be changed at any time in Manage my account, and objecting has no effect on the account itself (section 13).
6. Legitimate interest assessment
In accordance with Article 6(1)(f) of the GDPR, the reliance on legitimate interest as a legal basis for the processing of stakeholder data has been assessed as follows:
- Legitimacy of the interest: monitoring legislative processes, mapping stakeholder positions and managing institutional engagement are lawful and well-established professional activities in the field of public affairs and institutional representation, activities that are themselves framed by transparency regimes such as the EU Transparency Register. They serve the legitimate interest of the controller carrying them out: primarily the user, in the exercise of their own public affairs profession, and CL Corporate Affairs Consulting only to the extent it acts as controller under section 3, that is, for its own consulting use of the platform.
- Necessity: the processing is necessary to achieve these objectives. Understanding who the relevant decision-makers are, what positions they hold and how the legislative balance of power evolves cannot be achieved without processing personal data relating to these public figures.
- Balancing of interests: the data processed relates overwhelmingly to individuals acting in their official public capacity (elected representatives, senior civil servants, registered lobbyists). These persons have a reduced expectation of privacy with respect to their institutional activities, which are by nature public. The data is sourced from official institutional databases or from statements the data subjects have themselves made public. The processing does not involve profiling for commercial purposes, does not seek to predict private behaviour, does not target vulnerable individuals, and is limited to what is necessary for legitimate public affairs activities. The data subjects retain at all times their right to object under Article 21 GDPR.
7. Publicly available data and special categories
A significant portion of the personal data processed in Compass relates to public figures acting in their official capacity (Members of the European Parliament, Commissioners, Council officials, registered interest representatives). This data is sourced from official, publicly accessible institutional databases:
- European Parliament website, Legislative Observatory (OEIL) and EU Who is Who directory
- EU Transparency Register and LobbyFacts.eu
- Council of the EU public registers
- European Commission organigrammes and press corner
- Public social media accounts (X/Twitter, LinkedIn): only accounts explicitly validated by the user
Where the data processed includes information that may reveal political opinions within the meaning of Article 9(1) GDPR (e.g. recorded votes, publicly declared positions on legislative files, political group affiliation), such processing is permitted under Article 9(2)(e) GDPR, as it relates exclusively to personal data which the data subject has manifestly made public through official institutional channels, parliamentary votes, public statements or voluntary publications on public social media accounts. This exception is applied strictly to data that is already in the public domain by virtue of the data subject’s own actions in their official capacity.
A distinction must be drawn between this manifestly-public underlying data and the analytical attitude rating that a user may attach to a stakeholder. That rating (the attitude score, user-assessed) is the user’s own characterisation of a political stance that the public figure has themselves manifestly made public, through recorded votes, declared positions on legislative files and public statements. Taking a prudent approach, to the extent the attitude assessment touches data revealing political opinions, CL relies on a dual basis: Article 9(2)(e) GDPR (data manifestly made public by the data subject), because the assessment characterises a stance the figure has publicly manifested in their official capacity, together with the legitimate-interest basis Article 6(1)(f) GDPR, under the assessment set out in section 6 (public figures acting in a professional or public capacity, public sources, no commercial profiling). CL does not rely on Article 6(1)(f) alone for this special-category aspect. Article 9(2)(e) remains, in any event, the basis for the genuinely manifestly-public underlying data (recorded votes, declared positions, political-group affiliation).
8. Our approach to user control and transparency
Two of the most consequential design choices of Compass, the optional end-to-end encryption of user-authored content (section 10.1) and the platform’s AI policy (section 9), are governed by the same underlying principle. Modern technologies (advanced cryptography, language models) bring real value to public affairs work, but they also raise legitimate questions about who can read what, where data flows, and what the user actually controls. Rather than answer those questions through generic reassurances, Compass is designed so that the answers are visible, verifiable and chosen by the user.
This translates into three operational rules that apply equally to encryption and to AI:
- Explicit user choice over any non-trivial processing. Sensitive options (turning on end-to-end encryption, activating an external AI provider) are never enabled by default and never imposed: each requires a deliberate, informed action by the user. The default configuration is the most privacy-preserving one (no external AI, no transmission outside the EU; encryption available but not forced).
- Transparency on what actually happens, including limitations. We document not only what the platform does, but also what it does not do, and where the boundaries of each guarantee lie. Section 10.1 explicitly lists which fields are encrypted and which are not, and why; section 9 explains what would be transmitted to Mistral’s European API if the user chooses to activate AI. We avoid wording that would suggest stronger guarantees than the technology actually delivers.
- Technical guarantees as a complement to ethical and contractual commitments, not a substitute for them. Our refusal of conflicts of interest, our contractual commitment never to read user-authored content, and the technical impossibility we offer through end-to-end encryption operate at three different levels and reinforce one another. Where technology can make a guarantee unbreakable, we deploy it; where it cannot, we say so plainly and rely on the contractual and ethical commitments that govern our profession.
The two sections that follow apply this framework to the two specific cases of AI-assisted analysis (section 9) and end-to-end encryption (section 10.1).
9. AI services
Compass includes an AI layer that supports analytical tasks such as position classification, stakeholder analysis, strategic briefings, and suggesting positioning and rewrites on the texts under discussion. The platform is designed around a firm principle: the user always chooses which AI configuration is used, if any, and may at any time switch back to a configuration where no AI is involved.
CL Corporate Affairs Consulting has made a deliberate choice to limit Compass’s AI scope to Mistral, the European AI provider headquartered in Paris (France). No other third-party AI provider (neither OpenAI, nor Anthropic, nor any non-European model) is integrated into the platform, and none is contemplated for future integration. Compass relies on a single AI configuration: Mistral’s European commercial API, described below. AI processing stays on European infrastructure, with no transfer of data to non-European providers.
9.1 Mistral’s European commercial API
In this configuration, AI requests are sent to Mistral AI’s commercial API (api.mistral.ai). Mistral AI is a French company; per Mistral’s representation, API data is hosted in the European Union by default. Depending on the features used, Mistral may rely on the sub-processors listed in its Trust Center; any transfer within Mistral’s own sub-processing chain is governed by its Data Processing Addendum (adequacy decisions or Standard Contractual Clauses). This configuration operates in a single modality:
- A personal key, provided by a user (never by CL): AI features run exclusively on a Mistral API key supplied by a user: independent capacity, billed to and governed by that user’s own Mistral account. CL Corporate Affairs Consulting holds no shared key and provides no AI capacity of its own. In a collaborative workspace, a member who has not added a key of their own uses the key of their account manager: usage is then billed to the manager’s Mistral account and governed by the manager’s plan and settings, only the standard model is used, and the member is told so explicitly in Manage my account. Every user is invited to add their own key, for independent capacity under their own account and settings; outside a collaborative workspace a personal key is required, and without one the AI features remain unavailable. That use is governed by the terms the user has accepted with Mistral (including their plan and their account’s privacy and training settings), and users are invited to review them. The key is encrypted at rest and decrypted only for the duration of a call, including where the user has not enabled end-to-end encryption. Requests are strictly partitioned per user: no user has access to another user’s prompts or responses. What this means for end-to-end encryption. AI is optional and off by default, and it is the one operation in which encrypted content is momentarily handled in the clear. To issue a request, the content is decrypted in the user’s browser and transmitted to Mistral through the platform’s server, which relays it: for the duration of that relay the content is readable by Mistral, under the account whose key is used, and, in memory only, by the platform’s server. The technical impossibility described in section 10.1 does not extend to that moment. Nothing, however, is written to disk. The platform’s server neither stores nor logs the content of prompts or responses; only technical metadata (timestamp, user identifier, task type, model and token volume) is retained, solely for usage accounting.
The following safeguards apply:
- Use of data for model training: whether Mistral may use API inputs and outputs to improve its models depends on Mistral’s own terms and on the plan and privacy settings of the user’s own Mistral account. Users should review (and may disable) that setting in their Mistral account; where a Mistral account has that setting enabled, Mistral states that the data used is anonymised.
- Retention: Mistral retains API inputs and outputs for up to 30 rolling days for abuse-monitoring purposes (a processing Mistral carries out as an autonomous controller under its own terms), then deletes them. A Zero Data Retention (ZDR) option may be requested from Mistral on certain paid plans, subject to Mistral’s approval, directly under the user’s own account.
- Contractual safeguards: a Data Processing Addendum (DPA) and GDPR-aligned terms apply by default. As both CL Corporate Affairs Consulting and Mistral AI are established within the European Union, the Compass→Mistral leg itself involves no transfer outside the EEA; any transfers within Mistral’s own sub-processing chain are governed by Mistral’s DPA, as noted above. (All in-browser assets, web fonts and the D3.js visualisation library, are self-hosted on CL’s EU servers, so no transfer outside the EU arises from page rendering; see section 10.)
- Sub-processing: since AI runs on the user’s own key, the user is Mistral’s direct customer and Mistral acts as the user’s own processor under the agreement the user has accepted with Mistral; CL Corporate Affairs Consulting merely relays the user’s requests as a processor acting on the user’s documented instructions, and is not a party to the user’s agreement with Mistral.
Reference documentation: Mistral terms: legal.mistral.ai/terms · Data Processing Addendum: legal.mistral.ai/terms/data-processing-addendum.
9.2 AI-assisted research of public sources
Upon explicit user action, the AI layer may consult publicly accessible sources (an organisation’s official website, public position statements, position papers) to help characterise the positioning of an organisation or a client, or to identify the declared clients of a consultancy. This consultation is never automatic: it results from an explicit user command, is logged, and its output is presented to the user for validation before any storage. The European Union Transparency Register, for its part, is consulted locally from data already integrated into Compass, with no external request.
9.3 No AI provider is ever imposed on the user
Activation of the AI configuration requires a deliberate user action in Manage my account. The default state of every Compass account is “no AI”: the AI-assisted features are simply absent until the user explicitly enables Mistral’s European API. The user may revert to “no AI” at any time, with no data persistence between configurations.
AI-generated content, produced via Mistral’s European API, is provided for informational purposes only and should always be reviewed and validated by the user before being acted upon or shared externally. CL Corporate Affairs Consulting does not guarantee the accuracy, completeness or reliability of AI-generated outputs.
9.4 eTranslation — machine translation by the European Commission
Compass offers an optional translation of texts you have produced within the platform — an analysis of tabled amendments, a draft message to a stakeholder — into any of the 24 official languages of the Union. Practitioners regularly need to address a national delegation or a rapporteur in their own language, and source documents themselves arrive in many languages.
This translation is performed by eTranslation, the machine-translation service of the European Commission, operated by its Directorate-General for Translation under the Digital Europe Programme. It is therefore a public European service run by an institution of the Union, not a private provider, and not a non-European one: the alternatives commonly used for this purpose would have meant transferring your work to a processor established outside the Union, which CL has declined to do.
- Nothing is sent unless you ask. The feature is never automatic. Text leaves the platform only when you select a target language and press Translate, and only the text you have chosen is sent — never your dossiers, your stakeholder mapping or your account data.
- Role of each party. Unlike the AI feature described in section 9.1, which runs on your own Mistral account, translation runs on credentials held by CL. The European Commission therefore acts here as a sub-processor engaged by CL within the meaning of Article 28 GDPR, and is listed as such in section 12.
- Where the data goes. The processing takes place on European Commission infrastructure within the Union. No transfer outside the EEA arises from this feature.
- How long we keep it. A translation job is held on our server only for as long as it takes to deliver the result to your browser, and in any event for no more than 30 minutes, after which it is deleted. The European Commission’s own conditions of use govern what it does with the text on its side.
- End-to-end-encrypted content. If you have enabled encryption, the text on your screen has already been decrypted in your browser. Sending it for translation is therefore a deliberate act on your part, and it leaves the protection of end-to-end encryption for the duration of that request. Compass never decrypts anything on its own initiative in order to translate it.
10. Data security and hosting
All data processed by Compass is stored on private, dedicated servers located within the European Union, under the physical control of CL Corporate Affairs Consulting; no third-party public-cloud host stores that data. Public access is routed to them through a reverse proxy located within the European Union, over an encrypted private network; the relay stores no personal data, and no personal data is stored outside the European Union.
Where CL Corporate Affairs Consulting processes personal data on a user’s behalf, it relies on a deliberately limited set of sub-processors, each bound by a data-processing agreement within the meaning of Article 28 GDPR, currently two: the European Commission (Directorate-General for Translation), for the optional eTranslation feature described in section 9.4, which runs on credentials held by CL and processes only the text a user explicitly submits for translation, on European Commission infrastructure within the Union; and OVHcloud (France), which carries our outbound transactional email — account creation, password reset, security notices — and therefore handles the recipient’s name, address and the secure links those messages contain. We send no marketing email. By contrast, the optional Mistral AI feature described in section 9.1, disabled by default, runs under the user’s own Mistral account and API key, where Mistral acts as the user’s own processor and not as CL’s sub-processor. CL maintains an up-to-date list of its sub-processors and will inform users of any material change, in particular before a new sub-processor begins processing personal data. Users may object to such an addition or replacement, on legitimate data-protection grounds, within fifteen (15) days of the notice.
In-browser assets are self-hosted on EU infrastructure. All assets loaded in the visitor’s browser, including the web fonts (Cormorant Garamond, Vollkorn and Montserrat) and the JavaScript visualisation library (D3.js) used on the stakeholder-mapping page, are served directly from CL Corporate Affairs Consulting’s own EU-hosted servers. No page loads assets from Google, Cloudflare or any other non-EU content-delivery network, and no visitor IP address or browser details are transmitted to such providers in the course of rendering. Accordingly, the only transfer of personal data associated with the platform is the optional, opt-in Mistral AI feature (disabled by default), the processing of which remains within the European Union (see section 9.1).
The platform implements the following security measures:
- Authentication by email and password, with passwords hashed using PBKDF2-HMAC-SHA256 (600,000 iterations, in line with current OWASP recommendations) and a unique salt per user;
- Sessions managed via HTTP-only, SameSite=Lax secure cookies;
- Per-session CSRF tokens, verified on every state-changing request;
- Automatic account lockout after 5 failed login attempts (15-minute cooldown), and IP-level rate limiting (30-minute block after repeated failures from the same source);
- HTTPS encryption in transit (TLS via Let’s Encrypt certificate);
- Defence-in-depth HTTP response headers (
X-Frame-Options,X-Content-Type-Options,Referrer-Policy,Content-Security-Policy); - A basic security and accountability log of authentication events, privileged actions and security-relevant failures, kept to detect and investigate security incidents and to support breach response and external accountability (for example to the CNIL or before a court), rather than as an internal-control mechanism; proportionate to the risk under Article 32 GDPR, it is not held in tamper-evident or off-server form, and records only the fact and time of an action with limited technical metadata (such as email and IP address), never user-authored content;
- No indexation of the authenticated area by search engines: only the public-facing pages (home page, Privacy Policy, Terms & Conditions) are indexable; every other path (dashboards, account management, administrative interfaces, API endpoints) is explicitly blocked via
robots.txtandnoindexdirectives; - By default no AI is enabled, and no data is sent for AI processing. When the user activates the Mistral European commercial API (section 9.1, on their own API key), inputs and outputs transit to Mistral’s infrastructure (hosted in the European Union by default, per Mistral’s representation); retention by Mistral is limited to 30 rolling days for abuse-monitoring purposes; whether the data may be used for model training depends on the settings of the user’s own Mistral account, and the platform itself stores no prompt or response content.
Emails related to account management (password creation, reset, change notifications) are sent via SMTP with TLS encryption.
10.1 Optional end-to-end encryption
Why this feature exists. Compass is built and operated by a working public affairs consultancy whose users are often, themselves, public affairs professionals working on sensitive matters, sometimes on dossiers that touch the same policy areas as engagements pursued by CL itself or by its other clients. Even though CL Corporate Affairs Consulting upholds, as a foundational professional duty, a strict policy of refusing any conflict of interest (see also section 3 of the Terms and Conditions) and contractually commits never to read user-authored content (see section 11 of the Terms and Conditions), we believe that users should not be required to take that commitment on trust alone. End-to-end encryption is the technical translation of that conviction: it gives users a way to ensure, by the design of the platform itself, that their analytical work is mathematically out of reach of CL operators, of any third party gaining access to the servers, and of any authority seeking compelled disclosure. It is, in our view, a natural consequence of building a tool for one’s own profession.
What it is, in practical terms. In addition to the baseline security measures above, Compass offers an optional end-to-end encryption mode that users may activate at any time in Manage my account. This feature is not enabled by default; it is an explicit opt-in, intended for users who handle particularly sensitive material and who wish to add a technical guarantee on top of CL’s contractual commitments. Users who do not activate it are, of course, fully covered by the contractual non-consultation commitment, which applies regardless of encryption status; the feature is offered as an additional layer for users who want it, not as a prerequisite to use the platform.
What is encrypted. When end-to-end encryption is enabled on an account, the following data is encrypted in the user’s browser before being stored on the server: personal notes, the user-authored content of the stakeholder mapping (attributed position summaries, supporting arguments, private comments and curated sources), watch keywords (in Secure Search mode), topic names, user-authored biographies and profile notes, engagement log entries (meeting records, takeaways, signals), the user’s personal radar cache, and any other content authored personally by the user. The scope of encryption is deliberately broad and aims to prevent any observer of the server (including CL operators) from profiling the user’s activity, interests or analytical positions.
What is not encrypted, and why. The following categories remain unencrypted, by design: the list of dossiers a user tracks (the procedure reference is the key through which the server retrieves and refreshes each file from the EU’s public sources — OEIL, votes, delegated acts, institutional calendars — and through which alerts are matched; encrypting it would sever that automated enrichment, which is the substance of the service. The reference is itself a public EU procedure number. This is stated identically in section 11 of the Terms and Conditions); public reference data shared across all users (Members of the European Parliament, Commissioners, Commission staff, Council staff, Transparency Register organisations, institutional calendar events, all sourced from official EU databases); account information required for authentication and notifications (first name, last name, email, phone number, organisation); technical identifiers required for SQL joins (primary keys, foreign keys, user identifiers); audit timestamps (creation, modification, login times); cryptographic lookup hashes (irreversible SHA-256 digests of watch keywords in Secure Search mode, used for server-side matching without revealing the keyword); and the analytical scores and the rankings derived from them (the influence, urgency, involvement and attitude scores attached to each stakeholder, together with the priority quadrant and activate-target flags computed from them). These last are not free text authored by the user but values produced by the analytical methodologies designed by CL (influence weighting, urgency and activate-target scoring), which the server computes and re-computes; keeping the numeric scores legible to the engine is precisely what lets the platform position stakeholders on the map, rank them and recompute their quadrant. The written reasoning that justifies each score is itself encrypted, and a bare figure (an influence of 80, say) is in any event far less revealing than the analyst’s rationale, which stays protected. These categories are either already public by nature, or necessary to the technical operation of the service. We list them here, rather than mention encryption in vague terms, because we consider that an honest description of the boundaries of the guarantee is part of the guarantee itself.
How it works: in plain language. When a user activates end-to-end encryption, two things happen inside their browser, both invisible to the server. First, a new master key is generated locally: this is the key that will actually encrypt the user’s content. Second, this master key is itself put inside a sealed envelope whose lock is opened only by the user’s login password. The server stores the sealed envelope, but never the master key in clear form, and never the password. Each time the user logs in, the password unlocks the envelope locally in the browser, the master key is recovered for the duration of the session, and the encrypted fields can be read; when the user logs out, everything goes back inside its sealed envelope on the server side. CL never holds the master key and cannot reconstruct it: the cryptographic guarantee is that what is stored on our servers, in encrypted form, is unreadable to us by construction.
How it works: in technical terms. The scheme is zero-knowledge: the keys that decrypt user data never leave the user’s device and are not stored on the server in any retrievable form. More specifically:
- Key derivation. A first key is derived in the browser from the user’s login password using PBKDF2-HMAC-SHA256 with 600,000 iterations (in line with current OWASP recommendations) and a 16-byte random salt generated at activation. The salt is stored server-side (it is not secret); the password itself, and the key derived from it, are not.
- Two-key (key-wrapping) design. The key derived from the password is not used directly to encrypt the user’s data. Instead, it serves to protect a separate, randomly generated master key, which is the key that actually encrypts the user’s content. Only the master key, in its protected (“wrapped”) form, is stored on the server. This two-key design is the same approach used by reputable zero-knowledge applications (such as professional password managers and end-to-end encrypted messengers). It has one important practical consequence, described in the next paragraph: it allows users to change their login password without re-encrypting any of their stored data.
- Authenticated encryption. User data is encrypted with AES-256-GCM, a 96-bit nonce drawn from a cryptographically secure random source for each write, and an authentication tag verified on read. The same algorithm protects the master key inside its envelope.
- Storage format. Encrypted payloads are stored as base64url-encoded strings prefixed with a short version tag, so the server can distinguish encrypted from plaintext fields without ever being able to decrypt them.
- Browser requirements. The feature uses the standard Web Crypto API available in all modern browsers over HTTPS. It does not depend on any external service or third-party library.
What this means in everyday use. The two-key design has a direct, practical benefit for users:
- Changing your password is safe and instantaneous. Through the normal Change password flow (which requires the current password), the master key is briefly recovered with the current password and immediately re-protected with the new one. The user’s stored data is never re-encrypted, never re-uploaded, and there is no risk of losing access; this is structurally the same as in a professional password manager.
- Forgetting your password is, by contrast, irrecoverable for encrypted data. If the password is forgotten, the envelope that protects the master key cannot be opened by anyone: not by CL, not by the user. The Forgot password flow can reset the password, but it cannot recover the master key, and the existing encrypted fields therefore become permanently unreadable. This trade-off is the price of the zero-knowledge design and is the reason the feature is strictly opt-in. Users who activate end-to-end encryption are strongly encouraged to store their password in a password manager and to keep at least one secure backup of it.
Consequences for CL. Because the key that protects the master key is derived from the user’s password and never leaves their browser, CL Corporate Affairs Consulting and its administrators cannot, by construction, read the encrypted fields of an account that has end-to-end encryption turned on. This property is enforced technically, not merely contractually, and applies even in the face of an internal investigation, a security incident or a legal order: CL does not hold the key, cannot reconstruct it, and cannot be compelled to produce the clear-text content of encrypted fields. This limitation applies equally to CL itself and is assumed as a deliberate consequence of the zero-knowledge design (see also section 11 of the Terms and Conditions).
Fields that are not encrypted remain technically accessible to CL operators. In the absence of end-to-end encryption, this includes the content of notes, stakeholder mapping, attributed positions, private comments and all other user-authored content. The non-consultation of these fields by CL is governed exclusively by the contractual commitment set out in section 11 of the Terms and Conditions and is not, in the absence of end-to-end encryption, enforced by a technical impossibility. We consider that this distinction must be stated explicitly: it is the difference between a guarantee that we promise to honour and a guarantee that the platform itself enforces.
Even when end-to-end encryption is activated, certain operational metadata remain technically visible to CL operators, as an unavoidable consequence of running a web service. These metadata do not allow reconstruction of encrypted content, but may allow inference of certain usage characteristics:
- Approximate data volume: the number of encrypted rows stored in each of the user’s personal tables is visible to the server (for instance, that a user has 47 tracked dossiers or 312 engagement log entries), without the content itself being readable;
- Activity timestamps: logins, writes and reads are timestamped for audit purposes;
- IP address: required by the TCP/IP protocol, allowing inference of approximate geographic location;
- Correlated activity patterns: if multiple users modify related records at similar times, a collaborative relationship may be inferred.
These structural metadata fall within the same contractual non-consultation commitment as any other non-encrypted data (section 11 of the Terms and Conditions). CL Corporate Affairs Consulting commits not to exploit them for any purpose other than the technical supervision of the service (security monitoring, debugging, capacity planning). We document them here, rather than omit them, because the credibility of the broader guarantee depends on a transparent description of its boundaries.
Conversely, fields that have been encrypted with end-to-end encryption cannot be read by anyone other than the user, including CL itself. This is a property of the cryptographic design, not a contractual promise: the key that unlocks it is derived from the user’s password inside their own browser and never leaves the user’s device. CL does not hold the key, cannot reconstruct it, and cannot be compelled to produce the clear-text content of encrypted fields: neither in response to a legal order, nor in the course of a security investigation, nor at the request of a third party who would gain access to the servers. This limitation applies equally to CL Corporate Affairs Consulting and is assumed as a deliberate consequence of the zero-knowledge design.
10.2 Separation between the Compass platform and CL Corporate Affairs consulting practice
CL Corporate Affairs Consulting operates two distinct activities through a single legal entity: the publication of Compass and a public-affairs consulting practice. This dual role may, in some cases, create a conflict-of-interest risk that the contractual non-consultation commitment (section 11 of the Terms and Conditions) and the optional end-to-end encryption (section 10.1) already address. The following provisions complete that framework with practical commitments that do not require any formal compliance apparatus to honour.
(a) Non-reuse of user data in CL consulting engagements. CL Corporate Affairs Consulting commits never to use, in its own consulting engagements, any data, analysis, position, mapping, comment, draft amendment, watchlist or insight entered by a Compass user, whether end-to-end encryption is activated or not. This commitment covers the identity of the dossiers tracked by the user, the substance of their analytical work, and even the simple fact that the user takes an interest in a given topic. Where end-to-end encryption is activated, the commitment is additionally enforced by cryptographic impossibility (section 10.1).
(b) Three-tier data taxonomy. Compass processes three distinct categories of data, each with its own protection regime:
- Public reference data: MEPs, Commissioners, Council and Commission staff, EU Transparency Register, institutional calendars; sourced from official EU databases and shared across all users; not encrypted in any configuration (the data is publicly available by nature).
- Account data: first name, last name, email, phone, organisation. Required for authentication and notifications; stored in clear; protected by the GDPR baseline plus the contractual non-consultation commitment; not affected by end-to-end encryption (which would prevent login and contact).
- User-authored analytical content: stakeholder mapping, positions, notes, engagement log, draft amendments, internal observations, watch keywords. (The list of dossiers a user tracks and the analytical scores derived from this content are not encrypted, for the functional reasons set out in section 10.1.) When end-to-end encryption is OFF (default), stored in clear server-side; protection rests on the contractual non-consultation commitment plus (a) above. When end-to-end encryption is ON (opt-in), encrypted in the browser before storage with a random master key, itself sealed by a key derived from the user’s password (section 10.1); CL cannot read the content by construction.
(c) Access policy. Access to the production database is limited to the technical functions required to operate the service and is not routine: it occurs for operation, maintenance and support, not to consult user content; privileged actions are recorded in the security and accountability log referenced in section 10, which serves to detect and investigate incidents and support accountability rather than as an internal-control mechanism. The platform runs on private servers located in the EU and under the physical control of CL Corporate Affairs, without reliance on a public-cloud provider or on any third party with access to user content; public access is routed through a reverse proxy in the European Union that stores no user content. The partitioning between accounts is enforced at the application level by user-scoped queries, and reinforced (for accounts with end-to-end encryption activated) by per-user encryption envelopes: no user can access another user’s analytical content.
(d) Reinforced confidentiality commitment. Beyond the GDPR, CL Corporate Affairs Consulting voluntarily aligns its practice with the professional confidentiality standards applicable to public-affairs practitioners: the EU Transparency Register Code of Conduct annexed to the 2021 Interinstitutional Agreement between Parliament, Council and Commission (in particular its provisions on the honest obtaining, handling and release of EU information); the values of integrity, transparency, accuracy and confidentiality set out in the SEAP (Society of European Affairs Professionals) Code of Conduct; and the deontological standards of the French High Authority for Transparency in Public Life (HATVP) for declared interest representatives: notably the prohibition on obtaining information through fraudulent means and on selling information obtained from public officials. When accepting a new consulting engagement, CL Corporate Affairs checks in good faith for any obvious overlap with the known activity of a Compass user, and declines the engagement where one is found.
(e) Simple conflict signalling, in both directions.
- From a user to CL. A Compass user who has reason to believe that a CL consulting engagement may overlap with their own work in a conflicting way may signal it via the contact form. CL commits to investigate in good faith and, where a genuine overlap is identified, to suspend the conflicting consulting engagement and to confirm to the user that the situation has been resolved. End-to-end encryption substantially mitigates this risk at source: when encryption is on, CL has no technical way of even noticing such an overlap.
- From CL to itself. Symmetrically, when CL identifies through its own consulting practice that a potential engagement intersects with the known activity of a Compass user (to the limited extent technically detectable, and effectively only when encryption is OFF), CL commits to decline the engagement before any work begins, without disclosing the user’s identity to the prospective consulting client.
- External recourses remain available, independently of CL. Any person retains the recourses that already exist for them under French and EU law: the CNIL (cnil.fr) for data-protection matters, the HATVP (hatvp.fr) for matters within the lobbying transparency framework, or the competent judicial authorities in case of suspected criminal conduct. These are not channels designated by CL; they exist on their own and CL simply notes their availability to anyone who may want to use them.
- No retaliation. CL Corporate Affairs commits to take no retaliatory action against a Compass user who, in good faith, signals a suspected conflict or breach: including no termination of their subscription, no degradation of service, and no disclosure of their identity to third parties beyond what is strictly necessary to investigate.
Each signal is taken seriously. Every report received (from a user, from CL itself, or from a third party) is examined with ethical and legal diligence. We treat this as a core condition of the platform’s credibility, not as an optional courtesy: in a profession where discretion is part of the deliverable, a tool that mishandled conflict-of-interest signals would lose what makes it worth using in the first place.
11. Data retention
In line with the storage-limitation principle (Article 5(1)(e) GDPR), personal data is kept only for as long as necessary for the purposes for which it is processed. While an account is active, the data is retained on the legal basis of performance of the contract (Article 6(1)(b) GDPR): a user’s own dossiers, stakeholder mappings, positions, notes and engagement logs are the very content the service exists to store and make available, and are kept for as long as the user maintains the account. The user controls this content directly: individual dossiers, notes and other items can be deleted from within the platform at any time.
- User account data: retained for the duration of the account and deleted when the account is removed (see below). The account holder can rectify their own account details at any time and can delete individual content items themselves whenever they wish.
- Exporting your data: while the account is active, the holder can at any time obtain a complete copy of their own content including any end-to-end-encrypted content, which is decrypted inside the holder’s own browser, through the self-service export described in section 13 (right to data portability, Article 20 GDPR). That export is available only while signed in. We still recommend using it before deactivating or requesting removal — not because you would otherwise be left without a copy (see the next point), but because it is the only route that can include your encrypted notes and reasoning. Anything protected by end-to-end encryption is encrypted with your password and unreadable to us, so no copy we prepare on our side can ever contain it. That is the guarantee working as described, not a service limitation.
- The copy we prepare for you, and how long we keep it. When an account is deactivated or deleted, whoever initiates it, the platform automatically prepares an archive of everything CL is technically able to read: your account details, your tracked dossiers, and the full list of your stakeholder mapping with each entry’s organisation, role, influence, attitude, involvement and urgency scores and priority quadrant. A download link is sent to your registered address. You do not need to have anticipated anything, and you do not need to be able to sign in.
How that link is protected. It carries a single-use random token; where your account used two-factor authentication, one of your backup codes is also required, because a code sent by email would reach the same mailbox as the link and would add nothing. The archive is deleted from our servers as soon as it has been downloaded, and in any event after 30 days, after which the link stops working. Each download, and each rejected code, raises an alert on our side. If you no longer have your backup codes, write to us from your registered address: we verify the request ourselves and send a fresh link. Neither the administrator who triggers a copy nor anyone else at CL is shown that link, which is generated and sent by the server directly to you. - Deactivating your account. You may deactivate your account at any time from Manage my account. This blocks sign-in immediately and ends every active session, but it is a suspension, not a deletion: your account and its content are kept as they are, for as long as you wish, and nothing is erased by the passage of time. You may ask us to reopen it whenever you like — that request carries no expiry date. The archive described above is prepared and sent to you automatically at that moment; if you use end-to-end encryption, export from within the platform first (see the first point above), since that is the only copy that can include your encrypted content.
- Deleting your account (right to erasure, Article 17 GDPR). A request for erasure may be made at any time through our contact form, including from an account you have already deactivated, and is actioned within the time-limits set out in section 13 (as a rule, one month, extendable by up to two further months for complex requests). Deletion places the account in a restorable state for 30 days, during which it can be fully restored on request and during which you retain access to a copy of your data; after that window the account and all content created under it — dossiers, stakeholder mappings, positions, notes, drafts, keywords and derived caches — are permanently and irreversibly purged. This 30-day window applies to every deletion path, whoever initiates it.
- Accounts that were never used. An account whose holder has never signed in is deleted outright, with no 30-day window. That window exists to give the holder time to export their data; an account that was never activated holds nothing to export and no one has relied on it.
- Accounts never finalised. An account whose holder has not accepted the Terms and the Privacy Policy at first sign-in is not operational and holds no content. The administrator answerable for it is reminded after 30 days and again after 60 days, and the account is deleted automatically 90 days after its creation or approval, in application of the storage-limitation principle. Refusing the Terms, or withdrawing an account request, deletes the account and everything supplied with it at once, with no 30-day window. The reminders carry the holder’s name, address and organisation and the date of creation, and no content; they rest on the legitimate interest of administering the accounts opened at that administrator’s request (Article 6(1)(f) GDPR). See section 2 of the Terms and Conditions.
- Reminder emails. For the emails described in section 5 we keep only the date the last one was sent, how many have been sent and your preference. Nothing else is retained for that purpose, and the record is deleted with the account.
- Deletion or deactivation at CL’s initiative. CL Corporate Affairs Consulting may, at its own discretion, deactivate or permanently delete an account — deactivation being the reversible measure and deletion the final one. The grounds are stated on request. Where the ground is a conflict of interest, the account is deactivated and never deleted, and the holder is notified as promptly as circumstances allow; deletion is reserved for an unlawful use of the platform. This is a termination of the service on the basis of article 3 of the Terms and Conditions, not a decision taken over the content you entrusted to us: where CL acts on its own initiative, the holder is notified and the same 30-day window applies before anything is erased.
- Organisation accounts. In a collaborative organisation, the account manager may deactivate or delete each sub-account individually. A member asks their manager rather than acting alone, since the account belongs to the organisation’s subscription. Deleting a manager’s own account does not delete the accounts of its members: those survive, and the manager’s own purge is deferred for as long as any account remains attached to the organisation, so that no member is left orphaned.
- What we keep separately. Entries in the security and accountability log are retained separately from the account, on the legitimate-interest and legal-obligation bases of detecting and investigating security incidents and supporting breach response and accountability (Article 6(1)(c) and 6(1)(f) GDPR), for a bounded period of twelve months rather than indefinitely; they record only the fact and time of administrative actions, together with limited technical metadata (such as the email address and IP address associated with an action), not your analytical content. The log is proportionate to the risk under Article 32 GDPR and is not held in tamper-evident form.
- End-to-end-encrypted content: where the user has enabled end-to-end encryption, content is stored only as ciphertext (prefixed
cv1:orco1:) that CL cannot decrypt. Deleting the account removes both the ciphertext and the encryption parameters (salt and wrapped master key) held server-side; once these are gone the content is unrecoverable by anyone, including CL. The same is true if the user loses the password that protects their key, independently of deletion (see section 8). - Reference data (institutional, sourced from official EU databases): updated periodically, retained for as long as the platform is in operation. Outdated entries are overwritten on refresh. This is public reference data and is not tied to any individual account.
- Stakeholder mapping and position data: retained for as long as the account exists, and deleted with it. This content belongs to the user, who is its controller; CL processes it on their instructions and has no independent retention right over it. It is therefore not archived, and no administrative or evidentiary retention period applies to it: on removal of the account it follows the deletion model described above, and is permanently purged after the 30-day restoration window.
- Internal notes and engagement logs: retained for as long as the account exists, and deleted with it, on the same basis and with no archival. The user may delete their own notes at any time.
- CL’s own contractual and accounting records (engagement letters, invoices, related correspondence): retained for up to 6 years, the standard professional retention period under French commercial law. This period concerns only the records CL holds as controller of its own business relationship, and never the content created inside the platform, which is covered by the two entries above.
Discontinuation of the platform. Should the platform cease to operate, users will be notified in advance and will be able to download their data. The terms and limits of that undertaking are set out in section 10.1 of the Terms and Conditions.
Transfer of the platform. Should Compass be transferred, users will be informed within two weeks of the agreement with the acquirer being concluded, the acquirer ascertaining the legal obligations incumbent upon it. During that period, anyone may export their data and request deletion of their account if they do not wish to continue under the new operator (section 10.2 of the Terms and Conditions).
Account requests. A declined request is deleted immediately upon the decision, together with any logo supplied. Where a request is accepted, the information supplied becomes account data and follows the rules above; the record of the decision itself is kept without its attachments. A request that receives no decision within 30 days expires and is deleted on the same terms, and the applicant is told.
12. Recipients of data
Personal data processed within Compass is accessible only to authorised users of the platform. Each user accesses only the data relevant to their own activity. Internal notes and engagement records are visible only to the user who created them.
Alerts from the European Parliament. Compass can subscribe you to the alert service of the Parliament’s Legislative Observatory for a procedure you track. If you ask for it, and only then, your email address is transmitted to the European Parliament so that it can create the subscription and send you its own confirmation. The subscription becomes active only when you click that confirmation, and at that moment you accept the Parliament’s terms rather than ours. Compass does not send these alerts, does not receive them, and keeps no record of what you are notified about. You can unsubscribe at any time directly with the Parliament.
This is a contractual undertaking binding on CL Corporate Affairs Consulting and on every administrator acting for it, and not merely a description of how the software behaves. Where the user has enabled end-to-end encryption, that undertaking is reinforced by a technical impossibility: the content is not merely off-limits to us, it is unreadable to us. The two operate together: the commitment covers what we could technically read, and the encryption removes the question for the rest.
Administration of the platform. Compass is administered by CL Corporate Affairs Consulting. Its founder holds the master administrator account, and is the only person who can create, alter or withdraw administration rights : that power is not delegable to anyone, by design and not merely by policy.
Alongside it, CL may grant a delegated administrator account to a person assisting in the operation of the platform. Such an account holds only the specific capabilities it has been granted, one by one, and nothing else: for example restarting the server, or managing accounts, or reading the contact@compass.eu.com mailbox. A delegated administrator can never grant itself a further capability, create another administrator, or act on the master administrator’s own account. Every action taken under a delegated account is recorded in the audit log, identified as such.
Two limits apply to every administrator, master or delegated, and they are technical rather than contractual. No administrator can read end-to-end-encrypted content (your written notes, your reasoning, your position papers) because it is encrypted with your password and the server never holds the key (section 10.1). And where an administrator has a copy of an account’s data prepared for its holder, the download link is never shown to them: it is generated by the server and sent directly to the account holder (section 11). We state this here because delegated administration is a real capability of the platform, and we would rather describe it before it is used than afterwards.
No data is shared with third parties, except:
- Where required by law (judicial, police or administrative authorities);
- Only where CL is the controller within the meaning of section 3 β that is, for its own use of the platform in its consulting engagements: with a client of CL Corporate Affairs Consulting, where the sharing is strictly necessary for the execution of that engagement and contractually defined. This case never concerns another user's data, for which CL acts as processor and has no right to share anything;
- With Mistral AI, only where the user has explicitly activated the Mistral European commercial API described in section 9.1. No data is transmitted to any AI service when no AI is activated (the default).
What a lawful request can and cannot obtain. Where a judicial, police or administrative authority makes a request that is binding on us, we comply with it. It is worth being precise about what compliance can produce, so that no one, user or authority, is misled about it.
For data held in the clear, compliance is unremarkable: account details, the list of dossiers a user tracks, stakeholder mappings and the analytical scores attached to them are all readable by the platform and can be produced. For content the user has protected with end-to-end encryption, what we hold is ciphertext, and that is what we are able to produce. We cannot produce the plaintext, because we do not have the key: it is derived from the user’s password, which we never receive and never store, and the design that makes this so is described in section 10.1 and was in place before any request could be made.
This is not a refusal to cooperate, and not a claim of privilege. It is an absence of technical means, disclosed in advance, applying uniformly and to us as much as to anyone else. We hold no master key, no recovery key and no escrow copy, and we are not able to create one retroactively for content already encrypted — a key that does not exist cannot be surrendered. An authority seeking the plaintext of such content would need to address the person who holds the key, that is the user. We will say exactly this, and produce everything we do hold, whenever we are lawfully required to. It nevertheless remains the responsibility of users, as the principal controllers of their own content, to cooperate fully with judicial requests; CL Corporate Affairs Consulting assists as best it can, within the obligations incumbent upon it and within the latitude of the technical means at its disposal.
We would rather state the limit of that position than let it be read as more than it is. What we describe here is an inability to decrypt content already encrypted. It is not a claim that no order could ever require anything of us going forward: a court may lawfully compel measures for the future, and we would be bound by them like any other operator. Two consequences follow, which we prefer to set out, for the sake of complete transparency and diligence. Encryption protects what is already sealed, not what has not yet been written. And the one moment in which encrypted content is handled in the clear is the optional AI relay described in section 9.1, which is off by default, runs only on a key the user has supplied, writes nothing to disk, and is the reason that section describes it in such detail. If we were ever compelled to alter substantial elements of this policy, we would amend it in strict compliance with our regulatory obligations, taking account of the technical limits within which such future amendments could fall, and of any other legal obligations we are likewise bound to observe.
The full list of sub-processors, together with confirmation that all in-browser assets (web fonts and the D3.js visualisation library) are self-hosted on CL’s EU servers and our commitment to notify users of new sub-processors, is set out in section 10.
Cloudflare (Turnstile). The public account request form is protected against automated abuse by Cloudflare Turnstile. To perform that check, Cloudflare receives the IP address, the browser user agent and technical signals from the browser. It runs on that single public page, never on a page where a user is signed in, and is not used for advertising or behavioural profiling. Cloudflare, Inc. is established in the United States; its involvement is limited to this one check on this one page, and no content held in Compass is exposed to it.
13. Your rights
The GDPR grants specific rights to individuals whose personal data is processed. Within Compass, these rights apply differently depending on the category of person concerned:
Platform users (account holders) may at any time:
- Access their account data and obtain information about its processing (Article 15 GDPR);
- Rectify inaccurate or incomplete account data (Article 16 GDPR);
- Delete their account and all associated data (right to erasure, Article 17 GDPR), as described in section 11;
- Restrict processing in the cases provided for by Article 18 GDPR;
- Object to processing based on legitimate interest (Article 21 GDPR);
- Withdraw consent at any time for the optional AI feature, which is off by default and relies on the user’s consent (Article 7(3) GDPR); withdrawal does not affect the lawfulness of processing carried out before it;
- Change their password from the dashboard;
- Opt out of the reminder emails described in section 5, from the link in any of them or from Manage my account, at any time and with no effect on the account;
- Export the content they have authored (including end-to-end-encrypted content) through a dedicated self-service export in Manage my account, available only to the account holder. Because encrypted content can only be decrypted with the user’s password inside their own browser, the export is generated client-side while the user is signed in and unlocked; CL never has access to the decrypted content, and the export therefore includes material that is, by construction, unreadable to CL (data portability, Article 20 GDPR). The export covers the content the user has authored, including the full stakeholder mapping list with its scores and priority quadrants. Correction of the account email address is not yet available in-app and is handled on request via our contact form. The scope of an export depends on whether the holder can still sign in: performed from an active session, it contains everything, encrypted material included, since the browser decrypts it locally; requested from CL after sign-in has been disabled, it can only contain what CL is technically able to read — account details, tracked dossiers and the stakeholder mapping list, all unencrypted by design — and never end-to-end-encrypted content. In a collaborative organisation account, each member exports the content they have personally authored; organisation-wide data is handled by the account manager.
Persons referenced as stakeholders (public figures, institutional actors) whose publicly available data is processed in Compass may:
- Access data held about them and obtain information about the purposes of processing;
- Rectify inaccurate data;
- Object to processing based on legitimate interest (Article 21 GDPR), in which case the data controller will assess whether compelling legitimate grounds override the objection;
- Request erasure of their data, subject to any overriding legitimate interest or legal obligation.
Who to contact: requests relating to user account data should be addressed to CL Corporate Affairs Consulting. Where a third-party user acts as data controller for stakeholder data they have entered, requests from stakeholders relating to that data should be directed to the relevant user (data controller). CL Corporate Affairs Consulting will assist in routing such requests where appropriate.
To exercise any of these rights, please contact us via our contact form. Where we have reasonable doubt about the identity of the person making a request, we may ask for information needed to confirm that identity before acting. We respond to requests within one month of receipt; this period may be extended by up to two further months where the request is complex or where we receive a number of requests, in which case we will inform the requester within the first month. You may also lodge a complaint with the CNIL (cnil.fr) or any competent supervisory authority.
14. Cookies
Compass uses one strictly necessary first-party session cookie (compass_session) required for authentication. It is HTTP-only and Secure, set with SameSite=Lax, and stores only a session identifier: no personal data beyond that identifier and no cross-site tracking. Its lifetime corresponds to the user’s session; it is extended when the user selects “remember me” and is otherwise short-lived.
On the public pages (the home page and the other pages outside the application), Compass also sets two purely functional first-party preference cookies that contain no personal data, no identifier and perform no tracking: compass_lang remembers the visitor’s chosen interface language (EN/FR/DE/IT) so it does not have to be re-selected on each visit, and compass_intro_seen records that the brief introductory animation has already been shown so that it is not replayed on every visit. Both are first-party, expire after approximately 7 days and store only a basic preference value.
No tracking, profiling or advertising cookies are used, and no audience-measurement tool is deployed on the Compass platform. Because the session cookie is strictly necessary to provide the service requested by the user (authentication) and the two preference cookies are purely functional, limited to remembering choices the user has actively made and storing no personal data, they fall within the “strictly necessary / functional” exemption of the ePrivacy Directive (Article 5(3) of Directive 2002/58/EC, as transposed into French law) and therefore require no consent banner. Authentication relies solely on the session cookie and not on browser storage; any data held in the browser’s local storage consists only of non-personal interface preferences.
The public account request form loads Cloudflare Turnstile (section 12), which may place a short-lived technical token in the browser for the sole purpose of validating the anti-robot check. It carries no advertising or tracking function, is present on no other page, and falls within the same strictly necessary exemption, being required to secure a service the visitor has actively requested.
15. Personal-data-breach notification
CL Corporate Affairs Consulting operates the Compass infrastructure and is responsible, as controller at platform level, for detecting, assessing and responding to personal-data breaches. If we become aware of a personal-data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the CNIL without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR). Where a breach is likely to result in a high risk to affected individuals, we will inform those individuals without undue delay (Article 34 GDPR) so that they can take protective measures.
If a user suspects a security incident or breach affecting their data, they may report it to us through our contact form; CL will investigate and, where the thresholds above are met, carry out the required notifications. Content for which a user has enabled the optional end-to-end encryption (section 10.1) is stored only as ciphertext that CL cannot read, which materially reduces the impact such a breach would have on that content.
16. Records of processing (Article 30)
Although CL Corporate Affairs Consulting is a small organisation, the Article 30(5) exemption for organisations with fewer than 250 staff does not apply here, because the processing is regular and may involve data revealing political opinions (a special category under Article 9 GDPR). CL therefore maintains a record of its processing activities, available to the CNIL on request.
17. Data protection impact assessment (Article 35)
Because Compass involves the systematic scoring of identifiable individuals (the influence, attitude and urgency ratings) on data that may reveal political opinions, CL Corporate Affairs Consulting treats these features as requiring a data protection impact assessment under Article 35 GDPR and has carried one out. That assessment documents the safeguards relied upon: the public-capacity nature of the figures concerned, the exclusive use of public sources, the legitimate-interest assessment set out in section 6, the availability of optional end-to-end encryption, the user’s ability to override every value, and the absence of any commercial profiling of private individuals. The scoring of public figures rests on legitimate interest (Article 6(1)(f) GDPR), supported by that assessment, which is kept under review. The full assessment is set out in our Data Protection Impact Assessment.
18. Data Protection Officer (Article 37) and privacy contact
The Article 37 question follows the allocation of roles set out in sections 3 and 3.1: as the CJEU has held in Wirtschaftsakademie (C-210/16) and Fashion ID (C-40/17), data-protection responsibility (and with it the data-protection-officer and contact role) attaches to the real scope of each processing operation and to the party that determines its means and purposes, not to a single label. Compass involves two distinct operations, and the answer differs for each.
First, for the data of third parties processed within the interface, the stakeholders a user maps and assesses, the determining choices (which persons are processed, which data, for what purpose) rest predominantly with the user. The user is therefore the controller for that processing and, where their own activity makes a designation mandatory under Article 37 GDPR, the party who designates the data protection officer for it. CL Corporate Affairs provides the platform, the methodology and the technical safeguards.
Second, for the data of the users themselves, their account and identification data, CL Corporate Affairs Consulting is the controller and, through its legal representative, acts as the data protection officer and point of contact. It is reachable through our contact form, overseeing compliance for the platform-level processing, handling requests on account data and liaising with the CNIL. As this account-data processing is limited and is not, in itself, large-scale monitoring or large-scale special-category processing, CL is not required to appoint a separate formal Article 37 officer for it, and keeps that assessment under review.
CL’s designation of its data-protection referent is recorded in writing: see our Designation of the data-protection referent.
19. Information provided to stakeholders (Article 14)
Some of the personal data processed in Compass concerns third parties, the public figures that users map, and is obtained not from those persons themselves but from public sources (the official institutional databases and registers listed in sections 4 and 7). Where personal data is not obtained from the data subject, Article 14 GDPR applies. Because it is the user who selects the stakeholders to map and determines the data entered and the purpose pursued (sections 3 and 3.1), the Article 14 information duty falls primarily on the user, as controller of that analysis; CL Corporate Affairs Consulting, as the platform provider, facilitates compliance: including by making the general information below publicly available and by enabling the persons concerned to exercise their rights (section 13).
Individually notifying every such person would, given the number of public figures referenced across the platform, involve a disproportionate effort and would seriously impair the objectives of the processing. In these circumstances the exemption in Article 14(5)(b) GDPR applies. As the safeguard required by that provision, this information is made publicly available through this very Privacy Policy, which describes the categories of data, the sources, the purposes and lawful bases, and the rights available to the persons concerned (see in particular sections 4, 6, 7 and 13).
A user’s own analysis of a stakeholder, the positions attributed, the assessed ratings and the accompanying reasoning, is confidential professional work product, and whether it is ever published or disclosed is a decision for that user alone. Accordingly, a request for access to such data under Article 15 GDPR is subject to the limit recognised in Article 15(4) GDPR and Recital 63, under which the right to obtain a copy must not adversely affect the rights and freedoms of others: including the confidentiality of a user’s analytical work product and any applicable trade secrets.
20. Changes to this policy
This policy may be updated to reflect changes in the platform’s features, applicable legislation or regulatory guidance. Changes will be published on this page with an updated date. Where changes materially affect the processing of personal data, users will be notified upon their next login.