Last updated: 5 July 2026
DCL (Data Compass Labz) ("we", "us") is the controller of personal data processed through datacompasslabz.com. Our headquarters is at Alt-Reinickendorf 25, 13407 Berlin, Germany, with additional offices in Helsinki, Lund, Trondheim and Hørsholm. For any privacy matter contact privacy@datacompasslabz.com. This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have.
We process: (a) contact details you submit through forms (name, email, company, message); (b) newsletter email addresses; (c) technical data such as IP address, browser type, device information and pages viewed; (d) cookie and consent data; and (e) data contained in project materials you share with us under a separate agreement. We do not knowingly collect special categories of data through this website.
We rely on the following legal bases under the GDPR:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries | Art. 6(1)(b) — pre-contract / contract |
| Newsletter | Art. 6(1)(a) — consent |
| Site security & analytics | Art. 6(1)(f) — legitimate interest |
| Cookies (non-essential) | Art. 6(1)(a) — consent |
| Legal obligations | Art. 6(1)(c) — legal obligation |
We use data to respond to enquiries, deliver contracted services, send the newsletter you requested, secure and improve the site, and comply with legal obligations. We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not sell personal data to anyone.
We share data only with vetted processors bound by data-processing agreements. The categories of sub-processor we use are:
| Category | Purpose |
|---|---|
| Hosting & infrastructure | Serving and storing the website |
| Email delivery | Sending enquiry responses and the newsletter |
| Analytics | Understanding aggregate site usage |
| Security & anti-abuse | Protecting the site from attacks and spam |
We do not share your personal data with advertisers or data brokers.
Where a processor is located outside the European Economic Area, we ensure transfers are protected by an appropriate safeguard under the GDPR — most commonly the European Commission's Standard Contractual Clauses, or reliance on an adequacy decision where one exists. We assess each such transfer and apply supplementary measures where necessary. You may request details of the safeguards applied to any specific transfer.
We keep personal data only as long as necessary:
| Data | Retention |
|---|---|
| Enquiry / contact data | Up to 24 months after last contact |
| Newsletter data | Until you unsubscribe |
| Server & security logs | Up to 12 months |
| Legally required records | The statutory period |
When data is no longer needed we delete or anonymise it.
Under the GDPR you have the right to: access; rectification; erasure; restriction of processing; data portability; objection; and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with a supervisory authority — in Germany, the Berlin Commissioner for Data Protection and Freedom of Information, or your local authority. To exercise any right, contact privacy@datacompasslabz.com.
To make a request, email privacy@datacompasslabz.com describing what you would like. We may need to verify your identity before acting. We respond to all requests within one month, as required by the GDPR; where a request is complex we may extend this by up to two further months and will tell you if so. Exercising your rights is free unless a request is manifestly unfounded or excessive.
We use cookies in four categories: strictly necessary (always on), functional, analytics and marketing. Non-essential cookies are set only with your consent, which you give through our cookie banner and can change at any time. Full detail is in our Cookie Policy.
We apply appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access: encryption in transit (TLS), access control on a least-privilege basis, logging and monitoring, and regular review of our processors' security. No system is perfectly secure, but we design to reduce risk and to detect and respond to incidents quickly.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by the GDPR. Where the breach is likely to result in a high risk to you, we will also inform you directly without undue delay.
This website is intended for business users and is not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy as our practices or the law change; the current version always applies and material changes will be noted here. Questions about this policy: privacy@datacompasslabz.com. This policy was last updated on 5 July 2026.