# Privacy at KeyCompass

> What KeyCompass collects, why, and how long it is kept. The short version: as little as
> possible, and never your recovery phrase, private keys, or funds.

**Last updated:** 8 September 2026

Simon Geils, trading as KeyCompass, is a sole trader and the data controller for the
personal data described here, and is registered with the Information Commissioner's Office.
Contact: [hello@keycompass.co.uk](mailto:hello@keycompass.co.uk).

## The one thing worth saying first

KeyCompass never asks for, receives, or stores your recovery phrase, your private keys, or
your wallet passwords. Not the words, not a photo, not "just the first four". During a
session, screen sharing runs on the practitioner's side only and everything sensitive stays
on your side of the call. There is no situation in which KeyCompass would need this
information, and anyone asking you for it — including someone claiming to be KeyCompass —
is not acting for KeyCompass.

## This website

The site is a set of static files. It sets no cookies of its own, runs no analytics, and
loads no third-party trackers or advertising scripts.

The site is hosted by Netlify, which keeps standard server access logs (including IP
address and user agent) for security and operational purposes as part of delivering the
site. This is Netlify's processing as a hosting provider.

The "Book a session" buttons open a booking window served by **Cal.com**. That window is
Cal.com's, not KeyCompass's, and anything you enter into it is handled under Cal.com's own
privacy policy in addition to this one.

## Sessions

Onboarding sessions and reviews run over **Google Meet**, on KeyCompass's Google Workspace
account. **Calls are not recorded** — there is no recording, no transcript, and no copy of
the call kept afterwards. Screen sharing runs on the practitioner's side only: you are never
asked to share your screen, and everything sensitive stays on your side of the call.

The only record of a session is the written notes described below, and those never contain
a recovery phrase, a private key, a password, a device serial number, a wallet address, or
a balance.

## What is collected, and why

| What | When | Why | Lawful basis |
|---|---|---|---|
| Name, email, timezone, and your answers to the intake questions | When you book a call via Cal.com | To schedule and hold the call | Steps taken at your request prior to a contract |
| Email correspondence | When you email KeyCompass | To answer you and run the engagement | Legitimate interests / performance of a contract |
| Your name, voice, and anything you choose to show on camera | During a session on Google Meet | To hold the session | Performance of a contract |
| Working notes about your setup — for example whether backups are redundant, or whether a passphrase is in use | During an onboarding session or security review | To write your summary or review report, and to answer follow-up questions | Performance of a contract |
| Your written summary or review report | After the engagement | So you have a record, and so follow-up questions can be answered accurately | Performance of a contract |

Working notes never include recovery phrases, private keys, passwords, device serial
numbers, wallet addresses, or balances.

## Who it is shared with

KeyCompass does not sell personal data and does not share it for marketing. Data is
processed by a small number of service providers acting on KeyCompass's behalf:

- **Cal.com** — booking and scheduling
- **Google Workspace** — email, and video calls via Google Meet
- **Netlify** — website hosting

Data may also be disclosed where the law requires it.

## Transfers outside the UK

Cal.com, Google, and Netlify are US-headquartered, so personal data handled by them may be
transferred outside the United Kingdom. Those transfers rely on the safeguards in each
provider's data processing terms — the UK Addendum to the EU Standard Contractual Clauses,
or the UK Extension to the EU–US Data Privacy Framework where the provider is certified
under it. No personal data is transferred anywhere else.

## How long it is kept

- **Booking records** (name, email, timezone, intake answers): 12 months from the booking.
- **Email correspondence:** 24 months from the last message in the thread.
- **Session notes and your written summary or review report:** 24 months from the
  engagement. Reviews include a re-assessment once you have made the changes, and returning
  clients are common, so the notes have to outlive the session itself.

If you would like your records deleted sooner, ask and they will be.

## Your rights

Under UK data protection law you have the right to ask for a copy of your personal data, to
have it corrected or deleted, to restrict or object to how it is used, and to receive it in
a portable form. To exercise any of these, email
[hello@keycompass.co.uk](mailto:hello@keycompass.co.uk).

If you are not satisfied with the response, you can complain to the Information
Commissioner's Office at [ico.org.uk](https://ico.org.uk), the UK supervisory authority for
data protection.

## Security

Correspondence and notes are held on encrypted devices and in access-controlled accounts
protected by multi-factor authentication. Because no keys, phrases, or funds are ever held,
a compromise of KeyCompass cannot move your assets.

## Changes

Any material change to this notice will be reflected in the "last updated" date above.

## Related pages

- [Services and booking](https://keycompass.co.uk/)
- [About](https://keycompass.co.uk/about)
- [Contact](https://keycompass.co.uk/contact)
