Privacy Policy
Privacy is not a feature at Compeas — it is the foundation. We are a Swedish company, we host on Ploi Cloud in Sweden, and your data stays in the EU.
Last updated: July 22, 2026
Compeas ("Compeas", "we", "us", or "our") respects your privacy. This Privacy Policy explains what information we collect when you use our website and platform (the "Service"), how we use it, and the rights you have in relation to it.
In short: we are a Swedish company, the Service is hosted on Ploi Cloud in Sweden, and we do not transfer your data outside the EEA.
1. Who We Are — and Our Roles
The Service is operated by Compeas AB, org. no. 559590-5703, Östra långgatan 35, 731 30 Köping, Sweden ("Compeas").
- Compeas as controller. For data we collect through this website, your account, billing, and our own marketing, Compeas is the data controller under the GDPR.
- Compeas as processor. For the compliance data you or your organisation enter into the platform, your organisation is the controller and Compeas is the processor. That processing is governed by our Data Processing Addendum (see section 11).
Privacy contact and Data Protection Officer: Martin Karlsson (CEO), privacy@compeas.com.
2. Information We Collect
Information you provide to us
- Account information — name, work email, company name, and password when you create an account.
- Billing information — billing address and payment details, processed by our payment provider (we do not store full card numbers).
- Communications — messages you send us via forms, email, or support channels.
- Compliance data — information you connect to or enter into the platform for monitoring and evidence purposes.
Information collected automatically
- Usage data — pages visited, features used, and interactions with the Service.
- Device data — browser type, operating system, IP address, and approximate location derived from it.
- Cookies — see the "Cookies" section below.
3. How We Use Information
- To provide, operate, and maintain the Service.
- To process transactions and manage your account.
- To respond to inquiries and provide support.
- To monitor the security of the Service and prevent abuse.
- To improve and develop the Service.
- To send product updates and marketing communications where you have opted in (you can unsubscribe at any time).
4. Legal Bases (EEA/UK)
Where the GDPR applies, we process personal data on the basis of: performance of a contract (Art. 6(1)(b)), our legitimate interests (Art. 6(1)(f)) — securing and improving the Service, compliance with legal obligations (Art. 6(1)(c)), and your consent (Art. 6(1)(a)) where required — for example for non-essential cookies and marketing emails.
5. How We Share Information
We do not sell personal data. We share information only with:
- Service providers / subprocessors who help us operate the Service (hosting, payment processing, email delivery), each bound by a data processing agreement. Our current list is published at Subprocessors.
- Professional advisors (lawyers, auditors) under confidentiality obligations.
- Authorities where required by law or to protect rights and safety.
- Successors in connection with a merger, acquisition, or sale of assets, subject to this Policy.
6. Where We Process Your Data
The Service, including all customer data and backups, is hosted on Ploi Cloud in a Swedish datacenter. Website form submissions are processed within the EU. Backups are stored in a separate location within the EU and are not transferred outside the EEA. We do not transfer personal data outside the EEA as a matter of course.
If a future subprocessor would require processing outside the EEA, we will first update our subprocessor list and ensure an appropriate safeguard under Chapter V GDPR (such as Standard Contractual Clauses) is in place.
7. Cookies and Similar Technologies
This website sets no marketing or advertising cookies. We use one strictly necessary browser storage entry to remember your cookie choice, and — only if you accept — privacy-friendly analytics (Plausible) hosted in the EU. You can change or withdraw your choice at any time via the "Cookie settings" link in the footer.
| Name | Type | Purpose | Duration |
|---|---|---|---|
compeas-cookie-consent |
Local storage (strictly necessary) | Remembers your cookie consent choice | Until you clear browser data or change your choice |
| None — Plausible is cookieless | Analytics (consent required) | EU-hosted, privacy-friendly usage statistics (Plausible Insights OÜ, Estonia) | — |
Our analytics provider is Plausible Insights OÜ (Estonia). Plausible collects no personal data and sets no cookies or other identifiers: page views are measured using only the page URL, referrer, browser, operating system, device type, and country derived from your IP address — the IP address itself is never stored. Data is hosted in the EU and is not shared with or sold to third parties; see Plausible's data policy. The measurement script is served through our own domain (a first-party proxy), so your browser never contacts Plausible directly.
8. Data Retention
| Data category | Retention |
|---|---|
| Account data | Duration of the account, deleted within 30 days of closure |
| Billing records | 7 years, as required by the Swedish Accounting Act (bokföringslagen) |
| Contact & signup form submissions | 24 months |
| Support conversations | 24 months |
| Compliance data (processed for customers) | Duration of the contract; exportable at any time; deleted within 30 days after termination on request |
| Server and security logs | 90 days |
You may request earlier deletion at any time (see "Your Rights" below).
9. Security
We protect personal data with encryption in transit (TLS 1.2+) and at rest (AES-256), strict access controls with mandatory multi-factor authentication, and continuous monitoring. Details — including our responsible disclosure programme and compliance roadmap — are published in our Trust Centre. No method of transmission or storage is 100% secure; if you believe your account has been compromised, contact us immediately.
10. Your Rights
Under the GDPR you have the right to:
- Access, correct, or delete your personal data.
- Object to or restrict certain processing.
- Data portability.
- Withdraw consent at any time (without affecting prior processing).
- Lodge a complaint with a supervisory authority — in Sweden, the Integritetsskyddsmyndigheten (IMY).
To exercise these rights, email privacy@compeas.com. We respond within one month, as required by the GDPR.
11. Data Processing Addendum (DPA)
When Compeas processes personal data on your behalf as a processor (for example, compliance data you enter into the platform), our Data Processing Addendum applies. It describes our technical and organisational measures, our subprocessors, audit rights, and the safeguards that apply to any processing outside the EEA.
To request a countersigned DPA, email privacy@compeas.com.
12. Children's Privacy
The Service is not directed at children under 18, and we do not knowingly collect their personal data.
13. Changes to This Policy
We may update this Policy from time to time. We will post the updated version here and, for material changes, notify account holders by email or in-product notice.
14. Contact Us
Compeas AB, org. no. 559590-5703
Östra långgatan 35, 731 30 Köping, Sweden
Email: privacy@compeas.com