Compasa

Privacy Policy

Effective: 13 August 2026

[email protected]

This notice explains how Compasa handles personal data about website visitors, waitlist applicants, operators, and guests.

1. Who is responsible for your data?

Széll Máté Csongor e.v. (H-4032 Debrecen, Kosztolányi Dezső utca 4., Hungary) is the controller. For privacy questions, a copy of applicable transfer safeguards, or to exercise your rights, email [email protected]. We have not designated a data protection officer; as an EU-established controller, we do not use an Article 27 representative.

2. What we collect and why

Waitlist

Data
Name, work email address, optional company name, property-count band, language, and consent details.
Purpose
To manage your waitlist registration, send related early-access updates, and document your consent.
Legal basis
Consent (GDPR Article 6(1)(a)).

Operator account and customer relationship

Data
Name, email address, organization membership, sign-in and security events, and support-request content.
Purpose
To provide access, operate and secure the service, and provide support.
Legal basis
Performance of a contract and our legitimate interests in protecting the service (GDPR Article 6(1)(b) and (f)).

Content uploaded to the service

Data
Property information, documents, images, manuals, notes, knowledge items, and any personal or security-sensitive information they contain.
Purpose
To create and maintain a property knowledge base and provide operator-approved guest information.
Legal basis
Performance of a contract (GDPR Article 6(1)(b)). The operator is responsible for lawfully sharing uploaded content with us.

Guest portal and questions

Data
A guest’s question, answer, feedback, and technical data associated with the guest link.
Purpose
To answer property-specific questions, maintain quality and security, and identify missing information.
Legal basis
Performance of a contract and legitimate interests (GDPR Article 6(1)(b) and (f)).

Website, security, and measurement

Data
Short-lived IP-address and request metadata, Turnstile verification, short-lived pseudonymous abuse-prevention identifiers, and anonymous waitlist events.
Purpose
To protect the website and form, prevent abuse, and understand whether the waitlist flow works.
Legal basis
Legitimate interests (GDPR Article 6(1)(f)).

3. Service providers and transfers

We share only the data a provider needs to perform its role. Our main current providers are:

Cloudflare

Public website delivery, DNS, TLS/CDN, DDoS and abuse protection, Turnstile, and transient waitlist-request processing. A waitlist request and network metadata, including IP address, may be processed transiently through Cloudflare’s global edge infrastructure; Cloudflare is not our persistent waitlist database.

Brevo

Storage of waitlist contact details in our selected EU-region account and delivery of waitlist and transactional email. The applicable Brevo DPA, subprocessor information, and transfer safeguards are available on request at [email protected].

PostHog Cloud EU

Limited cookieless waitlist-funnel measurement through the verified PostHog EU project and EU ingestion host. We send only four allowlisted funnel events and do not send form fields or identified people. A network connection can still provide PostHog with technical metadata; the project is configured to discard raw IP addresses processor-side.

DigitalOcean

EU-region hosting for the application, PostgreSQL database, document storage, and backups.

Google Gemini

Within the product, narrowly scoped text or image processing, embeddings, and answer generation. We send only the excerpts needed for the task and do not use provider-hosted conversation, file, or vector stores.

Some providers may process personal data outside the European Economic Area. We use the safeguards recorded for the relevant provider in our founder evidence log. To request a copy of applicable safeguards, contact [email protected].

4. How long we keep data

Waitlist and consent evidence

Until you unsubscribe or for 24 months from your latest valid waitlist signup. We do not treat email opens, clicks, or browsing as engagement that extends this period. After expiry or unsubscribe, only the minimum suppression evidence needed to prevent renewed outreach may remain.

Operator profile and membership

For the customer relationship; on its end, we normally delete personal profiles within 30 days unless law requires otherwise.

Sources and property knowledge

While the property is active; on deletion, we remove it from active use immediately and delete it within 30 days.

Guest questions, answers, and retrieval traces

90 days, then we delete or anonymize raw content and linkable identifiers.

Security and application logs

Normally 30 days; security and administration audit events for up to 12 months.

Anonymous analytics

Up to 12 months.

5. AI-assisted processing

Compasa may use AI to organize uploaded information and answer guest questions. We first retrieve approved, relevant knowledge on our own EU infrastructure, then send only the necessary text excerpts to the AI provider. We do not send email addresses, guest links, IP addresses, or booking identifiers, and we redact personal contact details where practical. Operators remain responsible for ensuring that uploaded content is lawful and appropriate to share.

6. Cookies and local storage

We do not use analytics cookies or browser persistence on the public waitlist site. Cloudflare Turnstile processes technical signals only to protect the form from abuse. PostHog receives the limited cookieless funnel events described above; it does not receive form values or identifiers. Your browser may store only a local language preference. In the signed-in product, we use cookies necessary for session and security functions.

7. Your rights

You may ask for access to, correction, deletion, restriction, or portability of your data, and object to processing based on legitimate interests. You may withdraw consent at any time; this does not affect processing before withdrawal. You can also unsubscribe from waitlist email using the link in the email. Send requests to [email protected]. You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH; naih.hu), or to the supervisory authority where you live, work, or believe an infringement occurred.

8. Security and changes

We use proportionate technical and organizational safeguards, including access controls, encrypted transmission, permission separation, and logging. No online system is entirely risk-free. If this notice materially changes, we will update its effective date on this page.