PRIVACY NOTICE · 9 OCTOBER 2026
How Compass handles personal and assessment data.
Blue Top Consulting, of <registered address>, is the responsible party or controller for Compass account and service-operation data. For customer-controlled target content, the customer may also determine why the assessment is run.
Data we process
- Account and authentication data, including email address, user identifier, login events and current legal acceptance.
- Invitation and organisation data, including invited email, organisation membership, role, expiry, redemption and revocation records.
- Assessment data, including submitted public targets, sampled page URLs, public technical signals, bounded check evidence, findings, screenshots when enabled, report provenance and status.
- Security and operations data, including audit events, quotas, worker/provider outcomes and error diagnostics. Compass avoids storing secret values in evidence and logs where its controls identify them.
Why we process it
We use data to authenticate invited testers, provide assessments and reports, manage organisations, enforce limits, prevent abuse, troubleshoot failures, secure Compass, communicate about the service, comply with law and establish or defend legal claims. Depending on the context, the basis is performance of our agreement, legitimate interests in operating and securing the beta, consent where required, or legal obligation.
Public target data and screenshots
Compass observes publicly reachable targets selected by a user. A target may still contain personal or confidential material, so users must have authority to assess it. Screenshots and sampled URLs can reveal page content and are treated as private assessment artefacts. Screenshot capture can be disabled operationally and may use a hosted-browser provider.
Providers, sharing and international processing
We use service providers for cloud hosting, database, authentication, transactional email and isolated browser sessions, currently including Supabase and configured hosting and hosted-browser providers. We share only data reasonably needed for those services, security, professional advice, corporate transactions or legal compliance. Providers may process data outside South Africa; we use contractual and other safeguards appropriate to the arrangement. Current provider facts are maintained in our internal subprocessor register.
Retention
Completed and failed free-tier scans and their reports are scheduled for deletion after the configured period, currently 90 days. Security and audit events are scheduled for deletion after a separate period, currently 180 days. Pending/running work is handled through recovery controls. Invitation records are retained for access security and audit history. Some data may remain longer where required for an active account, dispute, legal duty, incident investigation or bounded backup cycle.
Security and incidents
Measures include invitation-gated access, authentication, server-side authorisation, tenant boundaries, row-level security, private artefact storage, short-lived access URLs where used, target validation, quotas, audit events and deletion jobs. No internet service is completely secure. We investigate suspected compromise and notify affected people and regulators where applicable law requires it.
Cookies and analytics
Compass uses necessary cookies for authentication and invitation continuity. The raw invitation token is moved out of the address bar into an HTTP-only cookie. Compass does not currently use third-party advertising cookies on invitation pages. If analytics changes materially, this notice and consent controls will be updated where required.
Your rights and requests
Subject to applicable law, you may ask for access, correction, deletion, objection, restriction or information about processing. Account closure does not require deletion where retention is legally necessary. Contact admin@bluetop.co.za; we may verify identity and authority before acting.
Children
Compass is a business service and is not directed to children. Do not invite or submit personal information about a child unless you have a lawful basis and appropriate authority.
South African privacy contact and regulator
Information Officer: Jonathan Nel. Contact: admin@bluetop.co.za. You may also lodge a POPIA complaint with the Information Regulator (South Africa) at POPIAComplaints@inforegulator.org.za or 010 023 5200.
United States privacy rights
Some US state laws may provide rights to know, correct, delete or obtain a copy of personal information and to appeal a refused request. Compass does not sell personal information or use it for cross-context behavioural advertising. Submit requests through the privacy contact above; applicability depends on the relevant law and circumstances.
Changes
We may update this notice as Compass and its providers change. We will publish the new effective date and provide additional notice where required.