Your Business Information, Protected
You've worked hard to build your business. We've built OwnerCompass so that information stays safe, private, and completely under your control.
Our Promise to You
AES-256 Encryption standard
Every document you upload is encrypted using the same standard used by leading financial services — unreadable without the encryption keys.
UK & EU Data residency
Your data is stored on servers within the UK and EU, keeping it firmly under UK GDPR and European data protection law.
0
Data sold to third parties
Your business information belongs to you. We don't sell it, share it, or use it for advertising. Full stop.
How We Protect Your Data
Multiple layers of security working together
Encryption in Transit
All data transferred between your browser and our servers is encrypted using TLS — the industry standard that protects information as it travels across the internet. Nobody can intercept or read your data in transit.
Encryption at Rest
Your documents and data are encrypted when stored on our servers using AES-256 encryption — the same standard used by leading financial services. Your information is unreadable to anyone without the correct encryption keys.
UK & EU Data Storage
Your documents and data are stored on servers within the UK and EU, keeping them firmly under UK GDPR and European data protection law. A small number of trusted service providers — such as AI document analysis and email delivery — may process limited data outside these regions, always under UK GDPR safeguards, as set out in our Privacy Policy.
Secure Access Controls
Your account is protected by password sign-in with secure session management, and you can add two-factor authentication (2FA) for an extra layer of security. Successful sign-ins to your account are recorded.
Automated Backups
Your account data is automatically backed up by our infrastructure provider. Uploaded documents are stored with built-in redundancy, protecting against hardware failures and ensuring your information remains available.
Access Records
Sign-in activity on your account is recorded, and access for trusted people only works once you've approved it — so it's always possible to establish who could see your information, and to investigate anything unusual.
Our Privacy Promises
Some things we'll never do with your data
We never sell your data
Your business information is yours. We will never sell, rent, or share it with third parties for marketing purposes.
We don't mine your data
We don't analyse your documents for our own benefit. We don't build profiles. Our AI partners do not train their models on your sensitive business information.
No unexpected access
Only you can grant access to your information. You choose exactly what each person can see. You can remove their access at any time, instantly.
No advertising or tracking
We don't use advertising cookies or tracking pixels. We don't share your information with ad networks. Our business model is simple: you pay for the service, we provide the value.
Frequently Asked Questions
Straight answers to the things business owners actually want to know.
Who can see my documents and business information?
Only you — and anyone you explicitly invite. When you add a trusted person, you choose what they can see. You can remove their access at any time.
What happens to my data if I cancel my subscription?
Nothing is deleted. Your account is paused and everything you've stored is kept safe, so you can pick up where you left off if you resubscribe. If you want your data gone, request account deletion in Settings — after a 14-day grace period (in case you change your mind), everything is permanently removed from our systems in line with UK GDPR.
Is OwnerCompass compliant with UK data protection law?
Yes. Built in compliance with UK GDPR and the Data Protection Act 2018. OwnerCompass Limited is the data controller and is registered with the Information Commissioner's Office under reference ZC212374. Your data is stored in the UK and EU; a small number of trusted providers may process limited data outside the UK under UK GDPR safeguards, as set out in our Privacy Policy. You have the right to access, correct, or delete your data at any time.
What if something goes wrong — a data breach, for example?
In the unlikely event of a security incident, we follow our UK GDPR obligations: we notify the ICO within 72 hours where required, and we'll contact you directly without undue delay if your data is affected. We'd explain what happened and what steps we've taken. We believe in complete transparency.
Security is an ongoing commitment, not a one-time achievement. We continuously monitor threats, update our systems, and improve our practices to stay ahead of risks.
Your trust is everything to us. We'll keep earning it every day.
Questions about security? Get in touch — we're happy to talk through any concerns.