Session ended

You've been signed out

Compass allows only one active session per account at a time. Another device just signed in with your credentials, so this session has been ended automatically.

Need to use Compass with colleagues? An Organization Account lets each member sign in with their own credentials, simultaneously, with either independent private workspaces or a shared collaborative one. Get in touch to upgrade.

Personal data & GDPR

Privacy Policy

Last updated: September 2026

1. Introduction

Compass Political Intelligence Platform (hereinafter “Compass”) is operated by CL Corporate Affairs Consulting E.I. (hereinafter “CL” or “CL Corporate Affairs Consulting”, used interchangeably throughout this document), headquartered at 1 avenue de l’Observatoire, 75006 Paris, France (VAT: FR58902992189), with a representation office at Avenue de Tervueren 103, B-1040 Brussels, Belgium. This Privacy Policy explains how we collect, use and protect personal data within the Compass platform, in compliance with Regulation (EU) 2016/679 (the “GDPR”) and the French Loi Informatique et Libertés.

Compass is built and operated by a working public affairs consultancy, and may be made available to fellow practitioners, such as in-house public affairs teams, trade associations, NGOs and other organisations whose activity overlaps with our own field of practice. This particular context shapes the way we have designed the platform: while CL upholds, as a foundational professional duty, a strict commitment to refusing any conflict of interest (see also section 3 of the Terms and Conditions), we believe that this contractual and ethical commitment must be matched by technical and organisational guarantees giving each user real, demonstrable control over their own data. The provisions that follow, in particular the optional end-to-end encryption (section 10.1) and our deliberate AI policy (section 9), are the practical expression of that conviction. They are not generic compliance statements: they reflect a positioning choice that we consider inseparable from the kind of platform a public affairs consultancy can responsibly offer to its peers.

2. Data controller

CL Corporate Affairs Consulting E.I.
1 avenue de l’Observatoire, 75006 Paris, France
Avenue de Tervueren 103, B-1040 Brussels, Belgium
Contact: compass.eu.com/contact

3. Roles and responsibilities under the GDPR

The allocation of data protection roles within Compass depends on the specific context of use, assessed on a case-by-case basis in accordance with Articles 4(7), 4(8), 26 and 28 of the GDPR. The determining factor is which party decides the purposes and essential means of each processing operation, not the contractual label alone.

When CL uses Compass for its own consulting activity, CL Corporate Affairs Consulting acts as sole data controller for all data processed within the platform, including reference data, stakeholder mapping, position analysis and engagement records.

When a third-party user accesses Compass in the context of their own public affairs activities, the respective roles are determined by the nature of the mission and the degree of autonomy of each party:

In all cases, CL Corporate Affairs Consulting is committed to implementing appropriate technical and organisational measures to ensure the security and confidentiality of personal data, in compliance with the GDPR. Where CL Corporate Affairs Consulting acts as data processor, the Terms and Conditions of the platform govern the obligations of each party in accordance with Article 28 GDPR.

3.1 Specific case: CL-designed analytical methodologies

The roles described in section 3 distinguish who decides what within a given processing operation. Within that framework, one nuance deserves to be stated explicitly: Compass embeds a number of analytical methodologies designed by CL Corporate Affairs Consulting: in particular the influence weighting applied to stakeholders, the urgency scoring that flags time-sensitive engagement, the activate-target detection that surfaces priority contacts, and the predictive estimation of legislative timelines derived from past procedural patterns. The user controls who is added to the platform, what data is entered, and the strategic purpose pursued; CL is the author of the methodology that turns that user-controlled data into a score, a ranking or an estimate.

As the publisher that designs the methodology, CL Corporate Affairs Consulting’s responsibility is confined to making the tool available, and it answers for that with due diligence in the light of its regulatory and legal obligations. By entering the data, by identifying the persons and institutions concerned, by prioritising those whose mobilisation matters most in view of their presumed influence, and by assuming the purpose of the processing of the data relating to them, the user consequently remains the controller of that processing within the meaning of the GDPR. Every suggested value is, moreover, visible and can be adjusted or overridden by hand. Designing the methodology gives CL Corporate Affairs Consulting no decision-making power over the purposes or the essential means of the processing of the user’s data, and therefore does not give rise to joint controllership within the meaning of Article 26 GDPR. This allocation is the one set out in section 7 of the Terms and Conditions, which constitute the Article 28 data processing agreement between the parties.

Concretely, the user remains free to disagree with a score, to override it manually, and to use Compass without relying on the suggested weighting: positions and influence values can always be set or overridden by hand. The scoring methodology CL designs rests on weightings and influence-analysis modalities derived from the relevant political-science literature. What the user is given is meaningful control over its output (every suggested value is visible and can be adjusted or overridden by hand), and CL stands by the methodology it designs. That residual methodological responsibility does not extend to the user’s overall mapping work: for the data entered, the subjects selected and the purpose pursued, the user remains the controller.

4. Categories of data processed

Compass processes three distinct categories of personal data, each with its own regime:

User account data (name, email address, company, phone number if provided, hashed login credentials) is also processed for the purpose of providing access to the platform.

Browsing data: a single session cookie (HTTP-only, strictly functional, no tracking) is used for authentication.

Account request data: where an account is requested through the account request form, we process the identity, contact and professional details supplied, the organisation and, where applicable, the clients declared, any logos attached, how the applicant heard about Compass, and the IP address the request was sent from. This data serves one purpose: deciding on the request. If the request is accepted it becomes account data; if it is declined it is deleted, logos included.

5. Legal basis and purposes

The processing of personal data within Compass is based on the following legal grounds:

Account requests. An account request is processed in order to take steps at the applicant’s own request prior to entering into a contract (Article 6(1)(b) GDPR). The conflict-of-interest check described in section 3 of the Terms and Conditions, and the protection of the public form against automated abuse, rest on legitimate interest (Article 6(1)(f) GDPR).

Reminder emails. Where an account has not been signed in to for 30 days, we send its holder a short email recalling what the platform does and pointing to the contact form, then a further one 90 days after the previous message for as long as the account stays unused. This rests on legitimate interest (Article 6(1)(f) GDPR): an account exists to be used, and an unused one usually means a practical obstacle we can remove. These emails are never sent to third parties and never promote anything other than the service the holder already has. Each one carries an unsubscribe link, the preference can be changed at any time in Manage my account, and objecting has no effect on the account itself (section 13).

6. Legitimate interest assessment

In accordance with Article 6(1)(f) of the GDPR, the reliance on legitimate interest as a legal basis for the processing of stakeholder data has been assessed as follows:

7. Publicly available data and special categories

A significant portion of the personal data processed in Compass relates to public figures acting in their official capacity (Members of the European Parliament, Commissioners, Council officials, registered interest representatives). This data is sourced from official, publicly accessible institutional databases:

Where the data processed includes information that may reveal political opinions within the meaning of Article 9(1) GDPR (e.g. recorded votes, publicly declared positions on legislative files, political group affiliation), such processing is permitted under Article 9(2)(e) GDPR, as it relates exclusively to personal data which the data subject has manifestly made public through official institutional channels, parliamentary votes, public statements or voluntary publications on public social media accounts. This exception is applied strictly to data that is already in the public domain by virtue of the data subject’s own actions in their official capacity.

A distinction must be drawn between this manifestly-public underlying data and the analytical attitude rating that a user may attach to a stakeholder. That rating (the attitude score, user-assessed) is the user’s own characterisation of a political stance that the public figure has themselves manifestly made public, through recorded votes, declared positions on legislative files and public statements. Taking a prudent approach, to the extent the attitude assessment touches data revealing political opinions, CL relies on a dual basis: Article 9(2)(e) GDPR (data manifestly made public by the data subject), because the assessment characterises a stance the figure has publicly manifested in their official capacity, together with the legitimate-interest basis Article 6(1)(f) GDPR, under the assessment set out in section 6 (public figures acting in a professional or public capacity, public sources, no commercial profiling). CL does not rely on Article 6(1)(f) alone for this special-category aspect. Article 9(2)(e) remains, in any event, the basis for the genuinely manifestly-public underlying data (recorded votes, declared positions, political-group affiliation).

8. Our approach to user control and transparency

Two of the most consequential design choices of Compass, the optional end-to-end encryption of user-authored content (section 10.1) and the platform’s AI policy (section 9), are governed by the same underlying principle. Modern technologies (advanced cryptography, language models) bring real value to public affairs work, but they also raise legitimate questions about who can read what, where data flows, and what the user actually controls. Rather than answer those questions through generic reassurances, Compass is designed so that the answers are visible, verifiable and chosen by the user.

This translates into three operational rules that apply equally to encryption and to AI:

The two sections that follow apply this framework to the two specific cases of AI-assisted analysis (section 9) and end-to-end encryption (section 10.1).

9. AI services

Compass includes an AI layer that supports analytical tasks such as position classification, stakeholder analysis, strategic briefings, and suggesting positioning and rewrites on the texts under discussion. The platform is designed around a firm principle: the user always chooses which AI configuration is used, if any, and may at any time switch back to a configuration where no AI is involved.

CL Corporate Affairs Consulting has made a deliberate choice to limit Compass’s AI scope to Mistral, the European AI provider headquartered in Paris (France). No other third-party AI provider (neither OpenAI, nor Anthropic, nor any non-European model) is integrated into the platform, and none is contemplated for future integration. Compass relies on a single AI configuration: Mistral’s European commercial API, described below. AI processing stays on European infrastructure, with no transfer of data to non-European providers.

9.1 Mistral’s European commercial API

In this configuration, AI requests are sent to Mistral AI’s commercial API (api.mistral.ai). Mistral AI is a French company; per Mistral’s representation, API data is hosted in the European Union by default. Depending on the features used, Mistral may rely on the sub-processors listed in its Trust Center; any transfer within Mistral’s own sub-processing chain is governed by its Data Processing Addendum (adequacy decisions or Standard Contractual Clauses). This configuration operates in a single modality:

The following safeguards apply:

Reference documentation: Mistral terms: legal.mistral.ai/terms · Data Processing Addendum: legal.mistral.ai/terms/data-processing-addendum.

9.2 AI-assisted research of public sources

Upon explicit user action, the AI layer may consult publicly accessible sources (an organisation’s official website, public position statements, position papers) to help characterise the positioning of an organisation or a client, or to identify the declared clients of a consultancy. This consultation is never automatic: it results from an explicit user command, is logged, and its output is presented to the user for validation before any storage. The European Union Transparency Register, for its part, is consulted locally from data already integrated into Compass, with no external request.

9.3 No AI provider is ever imposed on the user

Activation of the AI configuration requires a deliberate user action in Manage my account. The default state of every Compass account is “no AI”: the AI-assisted features are simply absent until the user explicitly enables Mistral’s European API. The user may revert to “no AI” at any time, with no data persistence between configurations.

AI-generated content, produced via Mistral’s European API, is provided for informational purposes only and should always be reviewed and validated by the user before being acted upon or shared externally. CL Corporate Affairs Consulting does not guarantee the accuracy, completeness or reliability of AI-generated outputs.

9.4 eTranslation — machine translation by the European Commission

Compass offers an optional translation of texts you have produced within the platform — an analysis of tabled amendments, a draft message to a stakeholder — into any of the 24 official languages of the Union. Practitioners regularly need to address a national delegation or a rapporteur in their own language, and source documents themselves arrive in many languages.

This translation is performed by eTranslation, the machine-translation service of the European Commission, operated by its Directorate-General for Translation under the Digital Europe Programme. It is therefore a public European service run by an institution of the Union, not a private provider, and not a non-European one: the alternatives commonly used for this purpose would have meant transferring your work to a processor established outside the Union, which CL has declined to do.

10. Data security and hosting

All data processed by Compass is stored on private, dedicated servers located within the European Union, under the physical control of CL Corporate Affairs Consulting; no third-party public-cloud host stores that data. Public access is routed to them through a reverse proxy located within the European Union, over an encrypted private network; the relay stores no personal data, and no personal data is stored outside the European Union.

Where CL Corporate Affairs Consulting processes personal data on a user’s behalf, it relies on a deliberately limited set of sub-processors, each bound by a data-processing agreement within the meaning of Article 28 GDPR, currently two: the European Commission (Directorate-General for Translation), for the optional eTranslation feature described in section 9.4, which runs on credentials held by CL and processes only the text a user explicitly submits for translation, on European Commission infrastructure within the Union; and OVHcloud (France), which carries our outbound transactional email — account creation, password reset, security notices — and therefore handles the recipient’s name, address and the secure links those messages contain. We send no marketing email. By contrast, the optional Mistral AI feature described in section 9.1, disabled by default, runs under the user’s own Mistral account and API key, where Mistral acts as the user’s own processor and not as CL’s sub-processor. CL maintains an up-to-date list of its sub-processors and will inform users of any material change, in particular before a new sub-processor begins processing personal data. Users may object to such an addition or replacement, on legitimate data-protection grounds, within fifteen (15) days of the notice.

In-browser assets are self-hosted on EU infrastructure. All assets loaded in the visitor’s browser, including the web fonts (Cormorant Garamond, Vollkorn and Montserrat) and the JavaScript visualisation library (D3.js) used on the stakeholder-mapping page, are served directly from CL Corporate Affairs Consulting’s own EU-hosted servers. No page loads assets from Google, Cloudflare or any other non-EU content-delivery network, and no visitor IP address or browser details are transmitted to such providers in the course of rendering. Accordingly, the only transfer of personal data associated with the platform is the optional, opt-in Mistral AI feature (disabled by default), the processing of which remains within the European Union (see section 9.1).

The platform implements the following security measures:

Emails related to account management (password creation, reset, change notifications) are sent via SMTP with TLS encryption.

10.1 Optional end-to-end encryption

Why this feature exists. Compass is built and operated by a working public affairs consultancy whose users are often, themselves, public affairs professionals working on sensitive matters, sometimes on dossiers that touch the same policy areas as engagements pursued by CL itself or by its other clients. Even though CL Corporate Affairs Consulting upholds, as a foundational professional duty, a strict policy of refusing any conflict of interest (see also section 3 of the Terms and Conditions) and contractually commits never to read user-authored content (see section 11 of the Terms and Conditions), we believe that users should not be required to take that commitment on trust alone. End-to-end encryption is the technical translation of that conviction: it gives users a way to ensure, by the design of the platform itself, that their analytical work is mathematically out of reach of CL operators, of any third party gaining access to the servers, and of any authority seeking compelled disclosure. It is, in our view, a natural consequence of building a tool for one’s own profession.

What it is, in practical terms. In addition to the baseline security measures above, Compass offers an optional end-to-end encryption mode that users may activate at any time in Manage my account. This feature is not enabled by default; it is an explicit opt-in, intended for users who handle particularly sensitive material and who wish to add a technical guarantee on top of CL’s contractual commitments. Users who do not activate it are, of course, fully covered by the contractual non-consultation commitment, which applies regardless of encryption status; the feature is offered as an additional layer for users who want it, not as a prerequisite to use the platform.

What is encrypted. When end-to-end encryption is enabled on an account, the following data is encrypted in the user’s browser before being stored on the server: personal notes, the user-authored content of the stakeholder mapping (attributed position summaries, supporting arguments, private comments and curated sources), watch keywords (in Secure Search mode), topic names, user-authored biographies and profile notes, engagement log entries (meeting records, takeaways, signals), the user’s personal radar cache, and any other content authored personally by the user. The scope of encryption is deliberately broad and aims to prevent any observer of the server (including CL operators) from profiling the user’s activity, interests or analytical positions.

What is not encrypted, and why. The following categories remain unencrypted, by design: the list of dossiers a user tracks (the procedure reference is the key through which the server retrieves and refreshes each file from the EU’s public sources — OEIL, votes, delegated acts, institutional calendars — and through which alerts are matched; encrypting it would sever that automated enrichment, which is the substance of the service. The reference is itself a public EU procedure number. This is stated identically in section 11 of the Terms and Conditions); public reference data shared across all users (Members of the European Parliament, Commissioners, Commission staff, Council staff, Transparency Register organisations, institutional calendar events, all sourced from official EU databases); account information required for authentication and notifications (first name, last name, email, phone number, organisation); technical identifiers required for SQL joins (primary keys, foreign keys, user identifiers); audit timestamps (creation, modification, login times); cryptographic lookup hashes (irreversible SHA-256 digests of watch keywords in Secure Search mode, used for server-side matching without revealing the keyword); and the analytical scores and the rankings derived from them (the influence, urgency, involvement and attitude scores attached to each stakeholder, together with the priority quadrant and activate-target flags computed from them). These last are not free text authored by the user but values produced by the analytical methodologies designed by CL (influence weighting, urgency and activate-target scoring), which the server computes and re-computes; keeping the numeric scores legible to the engine is precisely what lets the platform position stakeholders on the map, rank them and recompute their quadrant. The written reasoning that justifies each score is itself encrypted, and a bare figure (an influence of 80, say) is in any event far less revealing than the analyst’s rationale, which stays protected. These categories are either already public by nature, or necessary to the technical operation of the service. We list them here, rather than mention encryption in vague terms, because we consider that an honest description of the boundaries of the guarantee is part of the guarantee itself.

How it works: in plain language. When a user activates end-to-end encryption, two things happen inside their browser, both invisible to the server. First, a new master key is generated locally: this is the key that will actually encrypt the user’s content. Second, this master key is itself put inside a sealed envelope whose lock is opened only by the user’s login password. The server stores the sealed envelope, but never the master key in clear form, and never the password. Each time the user logs in, the password unlocks the envelope locally in the browser, the master key is recovered for the duration of the session, and the encrypted fields can be read; when the user logs out, everything goes back inside its sealed envelope on the server side. CL never holds the master key and cannot reconstruct it: the cryptographic guarantee is that what is stored on our servers, in encrypted form, is unreadable to us by construction.

How it works: in technical terms. The scheme is zero-knowledge: the keys that decrypt user data never leave the user’s device and are not stored on the server in any retrievable form. More specifically:

What this means in everyday use. The two-key design has a direct, practical benefit for users:

Consequences for CL. Because the key that protects the master key is derived from the user’s password and never leaves their browser, CL Corporate Affairs Consulting and its administrators cannot, by construction, read the encrypted fields of an account that has end-to-end encryption turned on. This property is enforced technically, not merely contractually, and applies even in the face of an internal investigation, a security incident or a legal order: CL does not hold the key, cannot reconstruct it, and cannot be compelled to produce the clear-text content of encrypted fields. This limitation applies equally to CL itself and is assumed as a deliberate consequence of the zero-knowledge design (see also section 11 of the Terms and Conditions).

Fields that are not encrypted remain technically accessible to CL operators. In the absence of end-to-end encryption, this includes the content of notes, stakeholder mapping, attributed positions, private comments and all other user-authored content. The non-consultation of these fields by CL is governed exclusively by the contractual commitment set out in section 11 of the Terms and Conditions and is not, in the absence of end-to-end encryption, enforced by a technical impossibility. We consider that this distinction must be stated explicitly: it is the difference between a guarantee that we promise to honour and a guarantee that the platform itself enforces.

Even when end-to-end encryption is activated, certain operational metadata remain technically visible to CL operators, as an unavoidable consequence of running a web service. These metadata do not allow reconstruction of encrypted content, but may allow inference of certain usage characteristics:

These structural metadata fall within the same contractual non-consultation commitment as any other non-encrypted data (section 11 of the Terms and Conditions). CL Corporate Affairs Consulting commits not to exploit them for any purpose other than the technical supervision of the service (security monitoring, debugging, capacity planning). We document them here, rather than omit them, because the credibility of the broader guarantee depends on a transparent description of its boundaries.

Conversely, fields that have been encrypted with end-to-end encryption cannot be read by anyone other than the user, including CL itself. This is a property of the cryptographic design, not a contractual promise: the key that unlocks it is derived from the user’s password inside their own browser and never leaves the user’s device. CL does not hold the key, cannot reconstruct it, and cannot be compelled to produce the clear-text content of encrypted fields: neither in response to a legal order, nor in the course of a security investigation, nor at the request of a third party who would gain access to the servers. This limitation applies equally to CL Corporate Affairs Consulting and is assumed as a deliberate consequence of the zero-knowledge design.

10.2 Separation between the Compass platform and CL Corporate Affairs consulting practice

CL Corporate Affairs Consulting operates two distinct activities through a single legal entity: the publication of Compass and a public-affairs consulting practice. This dual role may, in some cases, create a conflict-of-interest risk that the contractual non-consultation commitment (section 11 of the Terms and Conditions) and the optional end-to-end encryption (section 10.1) already address. The following provisions complete that framework with practical commitments that do not require any formal compliance apparatus to honour.

(a) Non-reuse of user data in CL consulting engagements. CL Corporate Affairs Consulting commits never to use, in its own consulting engagements, any data, analysis, position, mapping, comment, draft amendment, watchlist or insight entered by a Compass user, whether end-to-end encryption is activated or not. This commitment covers the identity of the dossiers tracked by the user, the substance of their analytical work, and even the simple fact that the user takes an interest in a given topic. Where end-to-end encryption is activated, the commitment is additionally enforced by cryptographic impossibility (section 10.1).

(b) Three-tier data taxonomy. Compass processes three distinct categories of data, each with its own protection regime:

(c) Access policy. Access to the production database is limited to the technical functions required to operate the service and is not routine: it occurs for operation, maintenance and support, not to consult user content; privileged actions are recorded in the security and accountability log referenced in section 10, which serves to detect and investigate incidents and support accountability rather than as an internal-control mechanism. The platform runs on private servers located in the EU and under the physical control of CL Corporate Affairs, without reliance on a public-cloud provider or on any third party with access to user content; public access is routed through a reverse proxy in the European Union that stores no user content. The partitioning between accounts is enforced at the application level by user-scoped queries, and reinforced (for accounts with end-to-end encryption activated) by per-user encryption envelopes: no user can access another user’s analytical content.

(d) Reinforced confidentiality commitment. Beyond the GDPR, CL Corporate Affairs Consulting voluntarily aligns its practice with the professional confidentiality standards applicable to public-affairs practitioners: the EU Transparency Register Code of Conduct annexed to the 2021 Interinstitutional Agreement between Parliament, Council and Commission (in particular its provisions on the honest obtaining, handling and release of EU information); the values of integrity, transparency, accuracy and confidentiality set out in the SEAP (Society of European Affairs Professionals) Code of Conduct; and the deontological standards of the French High Authority for Transparency in Public Life (HATVP) for declared interest representatives: notably the prohibition on obtaining information through fraudulent means and on selling information obtained from public officials. When accepting a new consulting engagement, CL Corporate Affairs checks in good faith for any obvious overlap with the known activity of a Compass user, and declines the engagement where one is found.

(e) Simple conflict signalling, in both directions.

Each signal is taken seriously. Every report received (from a user, from CL itself, or from a third party) is examined with ethical and legal diligence. We treat this as a core condition of the platform’s credibility, not as an optional courtesy: in a profession where discretion is part of the deliverable, a tool that mishandled conflict-of-interest signals would lose what makes it worth using in the first place.

11. Data retention

In line with the storage-limitation principle (Article 5(1)(e) GDPR), personal data is kept only for as long as necessary for the purposes for which it is processed. While an account is active, the data is retained on the legal basis of performance of the contract (Article 6(1)(b) GDPR): a user’s own dossiers, stakeholder mappings, positions, notes and engagement logs are the very content the service exists to store and make available, and are kept for as long as the user maintains the account. The user controls this content directly: individual dossiers, notes and other items can be deleted from within the platform at any time.

Discontinuation of the platform. Should the platform cease to operate, users will be notified in advance and will be able to download their data. The terms and limits of that undertaking are set out in section 10.1 of the Terms and Conditions.

Transfer of the platform. Should Compass be transferred, users will be informed within two weeks of the agreement with the acquirer being concluded, the acquirer ascertaining the legal obligations incumbent upon it. During that period, anyone may export their data and request deletion of their account if they do not wish to continue under the new operator (section 10.2 of the Terms and Conditions).

Account requests. A declined request is deleted immediately upon the decision, together with any logo supplied. Where a request is accepted, the information supplied becomes account data and follows the rules above; the record of the decision itself is kept without its attachments. A request that receives no decision within 30 days expires and is deleted on the same terms, and the applicant is told.

12. Recipients of data

Personal data processed within Compass is accessible only to authorised users of the platform. Each user accesses only the data relevant to their own activity. Internal notes and engagement records are visible only to the user who created them.

Alerts from the European Parliament. Compass can subscribe you to the alert service of the Parliament’s Legislative Observatory for a procedure you track. If you ask for it, and only then, your email address is transmitted to the European Parliament so that it can create the subscription and send you its own confirmation. The subscription becomes active only when you click that confirmation, and at that moment you accept the Parliament’s terms rather than ours. Compass does not send these alerts, does not receive them, and keeps no record of what you are notified about. You can unsubscribe at any time directly with the Parliament.

This is a contractual undertaking binding on CL Corporate Affairs Consulting and on every administrator acting for it, and not merely a description of how the software behaves. Where the user has enabled end-to-end encryption, that undertaking is reinforced by a technical impossibility: the content is not merely off-limits to us, it is unreadable to us. The two operate together: the commitment covers what we could technically read, and the encryption removes the question for the rest.

Administration of the platform. Compass is administered by CL Corporate Affairs Consulting. Its founder holds the master administrator account, and is the only person who can create, alter or withdraw administration rights : that power is not delegable to anyone, by design and not merely by policy.

Alongside it, CL may grant a delegated administrator account to a person assisting in the operation of the platform. Such an account holds only the specific capabilities it has been granted, one by one, and nothing else: for example restarting the server, or managing accounts, or reading the contact@compass.eu.com mailbox. A delegated administrator can never grant itself a further capability, create another administrator, or act on the master administrator’s own account. Every action taken under a delegated account is recorded in the audit log, identified as such.

Two limits apply to every administrator, master or delegated, and they are technical rather than contractual. No administrator can read end-to-end-encrypted content (your written notes, your reasoning, your position papers) because it is encrypted with your password and the server never holds the key (section 10.1). And where an administrator has a copy of an account’s data prepared for its holder, the download link is never shown to them: it is generated by the server and sent directly to the account holder (section 11). We state this here because delegated administration is a real capability of the platform, and we would rather describe it before it is used than afterwards.

No data is shared with third parties, except:

What a lawful request can and cannot obtain. Where a judicial, police or administrative authority makes a request that is binding on us, we comply with it. It is worth being precise about what compliance can produce, so that no one, user or authority, is misled about it.

For data held in the clear, compliance is unremarkable: account details, the list of dossiers a user tracks, stakeholder mappings and the analytical scores attached to them are all readable by the platform and can be produced. For content the user has protected with end-to-end encryption, what we hold is ciphertext, and that is what we are able to produce. We cannot produce the plaintext, because we do not have the key: it is derived from the user’s password, which we never receive and never store, and the design that makes this so is described in section 10.1 and was in place before any request could be made.

This is not a refusal to cooperate, and not a claim of privilege. It is an absence of technical means, disclosed in advance, applying uniformly and to us as much as to anyone else. We hold no master key, no recovery key and no escrow copy, and we are not able to create one retroactively for content already encrypted — a key that does not exist cannot be surrendered. An authority seeking the plaintext of such content would need to address the person who holds the key, that is the user. We will say exactly this, and produce everything we do hold, whenever we are lawfully required to. It nevertheless remains the responsibility of users, as the principal controllers of their own content, to cooperate fully with judicial requests; CL Corporate Affairs Consulting assists as best it can, within the obligations incumbent upon it and within the latitude of the technical means at its disposal.

We would rather state the limit of that position than let it be read as more than it is. What we describe here is an inability to decrypt content already encrypted. It is not a claim that no order could ever require anything of us going forward: a court may lawfully compel measures for the future, and we would be bound by them like any other operator. Two consequences follow, which we prefer to set out, for the sake of complete transparency and diligence. Encryption protects what is already sealed, not what has not yet been written. And the one moment in which encrypted content is handled in the clear is the optional AI relay described in section 9.1, which is off by default, runs only on a key the user has supplied, writes nothing to disk, and is the reason that section describes it in such detail. If we were ever compelled to alter substantial elements of this policy, we would amend it in strict compliance with our regulatory obligations, taking account of the technical limits within which such future amendments could fall, and of any other legal obligations we are likewise bound to observe.

The full list of sub-processors, together with confirmation that all in-browser assets (web fonts and the D3.js visualisation library) are self-hosted on CL’s EU servers and our commitment to notify users of new sub-processors, is set out in section 10.

Cloudflare (Turnstile). The public account request form is protected against automated abuse by Cloudflare Turnstile. To perform that check, Cloudflare receives the IP address, the browser user agent and technical signals from the browser. It runs on that single public page, never on a page where a user is signed in, and is not used for advertising or behavioural profiling. Cloudflare, Inc. is established in the United States; its involvement is limited to this one check on this one page, and no content held in Compass is exposed to it.

13. Your rights

The GDPR grants specific rights to individuals whose personal data is processed. Within Compass, these rights apply differently depending on the category of person concerned:

Platform users (account holders) may at any time:

Persons referenced as stakeholders (public figures, institutional actors) whose publicly available data is processed in Compass may:

Who to contact: requests relating to user account data should be addressed to CL Corporate Affairs Consulting. Where a third-party user acts as data controller for stakeholder data they have entered, requests from stakeholders relating to that data should be directed to the relevant user (data controller). CL Corporate Affairs Consulting will assist in routing such requests where appropriate.

To exercise any of these rights, please contact us via our contact form. Where we have reasonable doubt about the identity of the person making a request, we may ask for information needed to confirm that identity before acting. We respond to requests within one month of receipt; this period may be extended by up to two further months where the request is complex or where we receive a number of requests, in which case we will inform the requester within the first month. You may also lodge a complaint with the CNIL (cnil.fr) or any competent supervisory authority.

14. Cookies

Compass uses one strictly necessary first-party session cookie (compass_session) required for authentication. It is HTTP-only and Secure, set with SameSite=Lax, and stores only a session identifier: no personal data beyond that identifier and no cross-site tracking. Its lifetime corresponds to the user’s session; it is extended when the user selects “remember me” and is otherwise short-lived.

On the public pages (the home page and the other pages outside the application), Compass also sets two purely functional first-party preference cookies that contain no personal data, no identifier and perform no tracking: compass_lang remembers the visitor’s chosen interface language (EN/FR/DE/IT) so it does not have to be re-selected on each visit, and compass_intro_seen records that the brief introductory animation has already been shown so that it is not replayed on every visit. Both are first-party, expire after approximately 7 days and store only a basic preference value.

No tracking, profiling or advertising cookies are used, and no audience-measurement tool is deployed on the Compass platform. Because the session cookie is strictly necessary to provide the service requested by the user (authentication) and the two preference cookies are purely functional, limited to remembering choices the user has actively made and storing no personal data, they fall within the “strictly necessary / functional” exemption of the ePrivacy Directive (Article 5(3) of Directive 2002/58/EC, as transposed into French law) and therefore require no consent banner. Authentication relies solely on the session cookie and not on browser storage; any data held in the browser’s local storage consists only of non-personal interface preferences.

The public account request form loads Cloudflare Turnstile (section 12), which may place a short-lived technical token in the browser for the sole purpose of validating the anti-robot check. It carries no advertising or tracking function, is present on no other page, and falls within the same strictly necessary exemption, being required to secure a service the visitor has actively requested.

15. Personal-data-breach notification

CL Corporate Affairs Consulting operates the Compass infrastructure and is responsible, as controller at platform level, for detecting, assessing and responding to personal-data breaches. If we become aware of a personal-data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the CNIL without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR). Where a breach is likely to result in a high risk to affected individuals, we will inform those individuals without undue delay (Article 34 GDPR) so that they can take protective measures.

If a user suspects a security incident or breach affecting their data, they may report it to us through our contact form; CL will investigate and, where the thresholds above are met, carry out the required notifications. Content for which a user has enabled the optional end-to-end encryption (section 10.1) is stored only as ciphertext that CL cannot read, which materially reduces the impact such a breach would have on that content.

16. Records of processing (Article 30)

Although CL Corporate Affairs Consulting is a small organisation, the Article 30(5) exemption for organisations with fewer than 250 staff does not apply here, because the processing is regular and may involve data revealing political opinions (a special category under Article 9 GDPR). CL therefore maintains a record of its processing activities, available to the CNIL on request.

17. Data protection impact assessment (Article 35)

Because Compass involves the systematic scoring of identifiable individuals (the influence, attitude and urgency ratings) on data that may reveal political opinions, CL Corporate Affairs Consulting treats these features as requiring a data protection impact assessment under Article 35 GDPR and has carried one out. That assessment documents the safeguards relied upon: the public-capacity nature of the figures concerned, the exclusive use of public sources, the legitimate-interest assessment set out in section 6, the availability of optional end-to-end encryption, the user’s ability to override every value, and the absence of any commercial profiling of private individuals. The scoring of public figures rests on legitimate interest (Article 6(1)(f) GDPR), supported by that assessment, which is kept under review. The full assessment is set out in our Data Protection Impact Assessment.

18. Data Protection Officer (Article 37) and privacy contact

The Article 37 question follows the allocation of roles set out in sections 3 and 3.1: as the CJEU has held in Wirtschaftsakademie (C-210/16) and Fashion ID (C-40/17), data-protection responsibility (and with it the data-protection-officer and contact role) attaches to the real scope of each processing operation and to the party that determines its means and purposes, not to a single label. Compass involves two distinct operations, and the answer differs for each.

First, for the data of third parties processed within the interface, the stakeholders a user maps and assesses, the determining choices (which persons are processed, which data, for what purpose) rest predominantly with the user. The user is therefore the controller for that processing and, where their own activity makes a designation mandatory under Article 37 GDPR, the party who designates the data protection officer for it. CL Corporate Affairs provides the platform, the methodology and the technical safeguards.

Second, for the data of the users themselves, their account and identification data, CL Corporate Affairs Consulting is the controller and, through its legal representative, acts as the data protection officer and point of contact. It is reachable through our contact form, overseeing compliance for the platform-level processing, handling requests on account data and liaising with the CNIL. As this account-data processing is limited and is not, in itself, large-scale monitoring or large-scale special-category processing, CL is not required to appoint a separate formal Article 37 officer for it, and keeps that assessment under review.

CL’s designation of its data-protection referent is recorded in writing: see our Designation of the data-protection referent.

19. Information provided to stakeholders (Article 14)

Some of the personal data processed in Compass concerns third parties, the public figures that users map, and is obtained not from those persons themselves but from public sources (the official institutional databases and registers listed in sections 4 and 7). Where personal data is not obtained from the data subject, Article 14 GDPR applies. Because it is the user who selects the stakeholders to map and determines the data entered and the purpose pursued (sections 3 and 3.1), the Article 14 information duty falls primarily on the user, as controller of that analysis; CL Corporate Affairs Consulting, as the platform provider, facilitates compliance: including by making the general information below publicly available and by enabling the persons concerned to exercise their rights (section 13).

Individually notifying every such person would, given the number of public figures referenced across the platform, involve a disproportionate effort and would seriously impair the objectives of the processing. In these circumstances the exemption in Article 14(5)(b) GDPR applies. As the safeguard required by that provision, this information is made publicly available through this very Privacy Policy, which describes the categories of data, the sources, the purposes and lawful bases, and the rights available to the persons concerned (see in particular sections 4, 6, 7 and 13).

A user’s own analysis of a stakeholder, the positions attributed, the assessed ratings and the accompanying reasoning, is confidential professional work product, and whether it is ever published or disclosed is a decision for that user alone. Accordingly, a request for access to such data under Article 15 GDPR is subject to the limit recognised in Article 15(4) GDPR and Recital 63, under which the right to obtain a copy must not adversely affect the rights and freedoms of others: including the confidentiality of a user’s analytical work product and any applicable trade secrets.

20. Changes to this policy

This policy may be updated to reflect changes in the platform’s features, applicable legislation or regulatory guidance. Changes will be published on this page with an updated date. Where changes materially affect the processing of personal data, users will be notified upon their next login.