Skip to main content
LiveSOP by Compass Island
Watch the explainer Request a demo

Legal

Privacy Policy

This policy explains how Compass Island, LLC handles personal data collected through livesop.com. It covers visitors to this website, including anyone who requests a demonstration.

Effective August 25, 2026

Last updated August 25, 2026

1. Who we are

LiveSOP is a product of Compass Island, LLC. For personal data collected through this website, Compass Island, LLC is the data controller.

Compass Island, LLC
808 Lady Street, Suite D #57
Columbia, SC 29201, United States
privacy@compassisland.co

2. What this policy covers

This policy applies to livesop.com and to inquiries you send us through it.

It does not cover the operational content a customer puts into the LiveSOP application — missions, procedures, tasks, participants and similar records. For that content we generally act as a processor on the customer’s instructions, and the customer’s agreement with us governs how it is handled.

We also process a limited set of information for our own purposes: account administration, business contact details, billing information, security and service logs, and support correspondence. For that information we act as a controller, and this policy describes how we approach it.

3. What we collect

We keep this deliberately small. There is one form on the site, and it asks only what we need to answer you properly.

Information you give us

Your name, work email address, organization, your role, the kind of operations you would run in LiveSOP, and anything you write in the message field. If you email or call us instead, we hold that correspondence.

Technical information

Our hosting provider records standard server logs: IP address, browser and device type, the pages requested, the referring page and a timestamp.

Anti-spam signals

The demo form records how long the form was open before submission, and includes a hidden field that automated scripts tend to fill in. Both exist only to separate people from bots.

We do not ask for special category data, and we do not build profiles of visitors. No decision affecting you is made by automated means. We may also hold professional contact details obtained from a conference, a referral, a public professional profile or a business development tool, for the single purpose of getting in touch about LiveSOP. If you would rather we did not hold yours, tell us and we will delete them.

4. Why we use it, and our legal basis

Under the GDPR and UK GDPR we must have a legal basis for each purpose. Ours are as follows.

Responding to a demonstration request or inquiry, evaluating a potential customer relationship, and following up about it

Our legitimate interest in answering business inquiries and pursuing them appropriately

Keeping the site available, and preventing spam and abuse

Our legitimate interest in the security and integrity of our own systems

Measuring how the site is used, if and when we add analytics

Your consent, asked for before any such tool is introduced and withdrawable at any time

Meeting legal, tax and record-keeping obligations

Compliance with a legal obligation

5. Cookies and similar technologies

This site sets no advertising cookies and runs no third-party tracking pixels. What it uses today:

  • Strictly necessary storage. A single record of your cookie choice, held in your browser so we do not ask again. It carries no identifier and is not sent to us.
  • Analytics. None are installed at present. If we add a measurement tool, it will load only after you accept, and never before.

You can change your choice at any time using , or by clearing site data in your browser.

6. Who we share it with

We do not sell personal data, and we do not share it for advertising. We disclose it only to:

  • service providers who work on our instructions under written contract, in three categories: website hosting, email and business communications, and the tools we use to track sales inquiries;
  • professional advisers, where we need legal or accounting advice;
  • authorities, where the law requires it, and any acquirer if the business is sold.

Write to privacy@compassisland.co and we will tell you which providers we currently use.

7. International transfers

We are based in the United States and our infrastructure is hosted there, so information you send us is stored in the United States. Where privacy law requires a transfer mechanism for personal data leaving the EEA or the UK, we use an appropriate one, such as standard contractual clauses or a provider’s certification under a recognized transfer framework. If you want to know which mechanism applies to a particular transfer, ask us.

8. How long we keep it

  • Demonstration requests and related correspondence that do not lead to a customer relationship: up to 36 months from your last contact with us, then deleted.
  • Server logs: up to 12 months.
  • Records we must keep for tax or legal reasons: for the period the relevant law requires.

9. Security

The site is served over TLS. Access to inquiry data is limited to the people who need it to respond to you, and is protected by individual accounts and multi-factor authentication. No transmission over the internet is completely secure, so we collect as little as we can and hold it no longer than we need to.

10. Your rights in the EEA and the UK

If the GDPR or UK GDPR applies to you, you have the right to:

  • ask what personal data we hold about you, and get a copy of it;
  • have inaccurate data corrected, or incomplete data completed;
  • have your data deleted, or its use restricted;
  • object to processing we carry out on the basis of legitimate interests;
  • receive the data you gave us in a portable format;
  • withdraw consent at any time, where we rely on consent.

Email privacy@compassisland.co. We answer within one month, and will tell you if we need longer. Exercising these rights is free, and we will not treat you differently for doing so. We may ask for enough information to confirm who you are before we act.

11. California privacy rights

If the CCPA, as amended by the CPRA, applies to us, California residents may ask us to disclose the personal information we have collected about them, to correct it, or to delete it. The categories involved are identifiers, professional and employment information, internet activity from server logs, and the contents of messages you send us, collected for the business purposes described in section 4.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. You may use an authorized agent to make a request. We will not treat you differently for exercising these rights. Write to privacy@compassisland.co.

12. Canada

If you are in Canada, applicable Canadian privacy law, including PIPEDA where it applies, gives you the right to access the personal information we hold about you and to challenge its accuracy. Requests go to the same address. If you are not satisfied with our response, you may be able to complain to the Office of the Privacy Commissioner of Canada.

13. Children

LiveSOP is sold to organizations and this site is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us information, write to us and we will delete it.

14. Changes to this policy

When this policy changes we update the date at the top of the page. If a change materially affects how we use personal data we already hold, we will tell affected people directly where we have a way to reach them.

15. Contact and complaints

For anything in this policy, including a request about your own data, write to privacy@compassisland.co or to Compass Island, LLC, 808 Lady Street, Suite D #57, Columbia, SC 29201, United States.

We are based in the United States. Where applicable law requires us to appoint a representative in the EEA or the UK, we will appoint one and publish the details here. Until then, requests from either region come to us directly at the address above.

If you are in the EEA or the UK and you are unhappy with how we have handled your data, you may also complain to your national data protection authority, or to the Information Commissioner's Office in the United Kingdom.