“The right to be let alone is the most comprehensive of rights, and the right most valued by civilised people.”

Louis Brandeis

CompHolis Privacy Policy


Last Updated: 5th of January 2026

At CompHolis, we take privacy seriously. We believe that trust is built through openness, clarity, and respect for personal data. This Privacy Policy explains how we collect, use, store, and protect information when you visit our website or use the CompHolis platform.

We aim to be clear and upfront at all times. If anything in this policy is unclear, we encourage you to contact us.

1. Who We Are

CompHolis is a compliance management platform designed to help organisations manage security, risk, and regulatory requirements in a clear and practical way.

For the purposes of data protection laws, CompHolis is the data controller for personal data collected through this website and, depending on the service arrangement, a data processor for client data stored within the platform.

2. The Information We Collect

We collect only the information we genuinely need to operate our website and provide our services.

This may include:

  • Website information, such as IP address, browser type, device type, pages visited, and usage patterns
  • Contact information, such as name, email address, and organisation details when you contact us or request information
  • Account and platform data, provided by clients and their users when using the CompHolis platform
  • Support communications, including emails and messages sent to us

We do not knowingly collect data from children.


3. How We Use Your Information

We use personal data for the following purposes:

  • To operate, maintain, and improve our website and services
  • To respond to enquiries and provide customer support
  • To manage user accounts and platform access
  • To meet legal, regulatory, and contractual obligations
  • To monitor website performance and usage trends using anonymised analytics

We do not use personal data for purposes that are incompatible with these aims.


4. Use of Artificial Intelligence (AI)

CompHolis uses AI-assisted processing features to support functionality within the platform, such as analysis, categorisation, or automation.

We are very clear about how this works:

  • AI processing is used only to deliver platform functionality
  • No client data is ever used to train AI models
  • No client data is made available to external AI providers for retention or training
  • Data processed by AI remains within the CompHolis controlled environment and is handled in line with this policy

AI is used as a tool to assist users - not as a mechanism to extract, reuse, or monetise their data.


5. Data Storage Locations and Geographical Controls

We recognise that data residency matters.

Client data is stored in geo-fenced data centres, selected by the client. Available locations include:

  • United Kingdom
  • European Union (Ireland)
  • European Union (Germany)
  • United States of America
  • Singapore

Client data remains within the selected geographic region unless the client explicitly requests otherwise.


6. Data Retention and Deletion

We retain personal data only for as long as it is needed to fulfil its purpose and meet legal or contractual requirements.

Retention periods are aligned with:

  • The laws and regulations applicable to the geographic location where the data is stored
  • Contractual obligations with our clients

Permanent deletion:

All client data can be permanently deleted upon request. Once deleted, data is removed from active systems and backups in line with secure deletion procedures.

7. Cookies and Similar Technologies
Our website uses cookies to ensure it functions correctly and to understand how visitors use it.
Cookies may include:
  • Essential cookies, required for the website to operate
  • Analytics cookies, used to understand website performance and usage
Analytics data is fully anonymised and cannot be used to identify individuals.
You can control or disable cookies through your browser settings.
8. Analytics and Anonymised Data

We use analytics tools to understand how our website is used and how we can improve it.

  • Analytics data is anonymised
  • We do not collect personally identifiable analytics data
  • We do not sell or share analytics data for advertising purposes
  • This information helps us improve usability, performance, and content - nothing more.

9. Data Sharing and Third Parties

We do not sell personal data.

We may share limited data with trusted third parties only where necessary, such as:

  • Hosting and infrastructure providers
  • Security, monitoring, and support services
  • Analytics providers (anonymised data only)

All third parties are required to handle data securely and in accordance with applicable data protection laws.

10. International Data Protection and GDPR

We comply with applicable data protection laws, including:

  • UK GDPR
  • EU GDPR
  • Relevant local privacy laws in other jurisdictions

Where required, we use appropriate safeguards for international data transfers, including contractual protections and technical controls.

11. Your Rights

Unless local laws of your country of residence or business require otherwise, you will always have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent where applicable

We respect these rights and respond to requests promptly.

12. Security

We take security seriously and apply appropriate technical and organisational measures to protect data, including:

  • Access controls
  • Encryption
  • Monitoring and logging
  • Secure development and operational practices

No system is ever completely risk-free, but we work continuously to protect data against unauthorised access, loss, or misuse.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our services.

Any updates will be published on this page, with the “last updated” date clearly shown.

14. Contact Us

If you have any questions about this Privacy Policy or how we handle data, please contact us:

Email: privacy@compholis.com

Company: CompHolis


We believe privacy should be handled with care, clarity, and respect - and we welcome questions at any time.