Policy Compass
Legal

Privacy Policy

Last updated: 29 June 2026

1. Who we are

Policy Compass is operated by Meet George Limited ("Meet George", "we", "us", "our"), a company registered in England and Wales under company number 15747538, with its registered office at 18 Albert Road, Bournemouth, Dorset, BH1 1BZ.

For the personal data described in this policy, Meet George Limited is the data controller. If you have any questions or want to exercise your rights, contact us at privacy@policycompass.co.uk.

2. What this policy covers

This policy explains how we handle personal data as a controller - for visitors to policycompass.co.uk, people who contact us or request a trial, and the administration of customer accounts.

Separately, when we process personal data within the Policy Compass platform on behalf of a customer, we act as a processor under a Data Processing Agreement (DPA). That data is governed by the customer's own privacy notices and our DPA, and by the controls described in our Trust Centre.

3. The personal data we collect

Information you give us

  • When you request a trial or use our contact form: your name, work email, company, company website, what your business does, and anything you include in your message.
  • When you correspond with us by email or otherwise.
  • Account information for users of the platform: name, work email, and role.

Information collected automatically

  • Device and usage data, including IP address, collected through cookies and analytics - only where you have consented (see Cookies).
  • Technical and diagnostic data needed to operate and secure the website and service (with sensitive content and credentials removed from error reports).

We do not seek special category data, and the platform is intended for regulatory and business content rather than personal data.

4. How we use your data, and our legal bases

  • Responding to enquiries and setting up and running trials and accounts - to take steps at your request before entering a contract, and to perform a contract.
  • Providing, securing and improving the website and platform - our legitimate interests in running and protecting our service.
  • Analytics and measuring our marketing - your consent (managed through our cookie banner).
  • Meeting legal and regulatory obligations - compliance with applicable law.

We do not sell your personal data, and we do not use customer content (your questions, documents or chat history) to train AI models - by us or by our providers. See the Trust Centre for detail.

5. Marketing communications

Where you have asked to hear from us, or where we are otherwise permitted to, we may send you product updates and other marketing emails. You can opt out at any time using the unsubscribe link in any such email, or by emailing privacy@policycompass.co.uk. Service and account messages we need to send to run a trial or contract are not marketing and continue regardless.

6. Automated decision-making and profiling

Policy Compass is an AI research tool, but it does not make decisions about you. We do not use your personal data for solely automated decision-making that produces legal or similarly significant effects, and a human stays in control of how the platform is used. Where the Service analyses regulatory material, it does so to assist a person's research and judgement, not to make automated decisions about individuals.

7. Cookies and analytics

We use a consent banner to manage cookies. Strictly necessary cookies are always on; analytics and similar technologies (such as Google Analytics and Google Tag Manager) load only after you consent. You can review or change your choices at any time using the Cookies link in the website footer.

8. Who we share your data with

We share personal data with trusted service providers who process it on our instructions, including, for the website and enquiries: Airtable (storing form submissions), Resend (sending email), Vercel (website hosting), Google (analytics, with your consent), our consent-management provider (cookie consent), and Sentry (error monitoring, with prompt and response content removed).

For the Policy Compass platform, the full list of sub-processors - with each one's purpose and region - is set out in our Security & Data Handling overview, available on request and as part of any contract. We give active customers at least 30 days' notice before any material change. We do not sell personal data.

9. International transfers

Customer data within the platform is stored and processed in the EU. Some providers operate outside the UK/EEA; where they do, we rely on UK or EU adequacy or on appropriate safeguards - EU Standard Contractual Clauses and the UK ICO International Data Transfer Addendum.

10. How long we keep your data

We keep personal data only as long as we need it for the purposes above: enquiry and lead data for as long as we are in contact and a reasonable period afterwards; account and service data for the term of the contract and a defined period after it ends, after which it is deleted. Configurable retention is available on enterprise contracts.

11. How we protect your data

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256), customer data is held in EU regions and isolated per customer, and Meet George holds the UK government-backed Cyber Essentials certification. We notify affected customers of any confirmed personal-data breach without undue delay and within 72 hours of becoming aware. See the Trust Centre for the full picture.

12. Your rights

Under UK data-protection law you have the right to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent at any time. To exercise any of these, email privacy@policycompass.co.uk - we respond within 30 days.

You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113, though we'd appreciate the chance to resolve any concern first.

13. Children

Policy Compass is a business-to-business service and is not directed at children. We do not knowingly collect personal data relating to children.

14. Third-party links

The Website and Service may link to third-party websites, such as Ofgem, DESNZ and industry code bodies. We are not responsible for their content or their privacy practices; their own privacy notices apply.

15. Changes to this policy

We may update this policy from time to time. The "last updated" date above shows when it last changed, and we will notify active customers of any material change.

16. Contact

Meet George Limited, 18 Albert Road, Bournemouth, Dorset, BH1 1BZ. Data and privacy enquiries: privacy@policycompass.co.uk. General enquiries: hello@policycompass.co.uk.