Skip to content
Counsel Compass

Privacy Policy

Last updated:

Note: This is a working draft (v0) of the document. The final version will be published after review by a qualified attorney before 2026-06-15 (launch day). Until then, for all privacy-related questions, contact hello@thecounselcompass.com.

1. Who we are

Counsel Compass is a product of Aikon group d.o.o., with its registered office at Sremska 2A, 21000 Novi Sad, Serbia. PIB (tax ID) 103671835. MB (company registration number) 08833508.

Email for privacy questions: hello@thecounselcompass.com

2. What this document covers

This Privacy Policy describes how Counsel Compass processes YOUR personal data (as a therapist registered on the platform).

It does not cover: the processing of your clients’ data (when you, as a therapist, enter their data into Counsel Compass) - you are the data controller of that data and we are the data processor. That relationship is governed by a separate Data Processing Agreement (DPA).

3. What data we process

Account data: first name, last name, email, password (hashed), phone number (optional).

Professional data: practice name, practice address, area of specialisation.

Technical data: IP address, browser type, OS, language (legitimate interest - security and functionality).

Audit log: access to sensitive data, changes, deletions (legal obligation - Article 50 of the Law on Personal Data Protection of the Republic of Serbia (ZZPL)).

4. How we use the data

We use the data exclusively to provide the service (account, app functionality), to bill the subscription, for security (preventing abuse), for customer support, and for legal compliance. The marketing newsletter is sent only with your explicit consent, which you may withdraw at any time.

5. Who we share data with

Your data is processed by carefully selected sub-processors: hosting (EU region), email provider, payment provider, analytics. We have DPA agreements in place with all of them. The complete list is available on request.

We do not sell your data to third parties and we do not use it to train AI models outside our platform.

6. Where the data is stored

Primary hosting and backups are in the EU (West Europe region). For AI transcription we use the Deepgram EU region (eu.api.deepgram.com).

7. How long we keep it

Account data: while the account is active plus 30 days after deletion. Financial data (invoices): 10 years (legal obligation). Audit logs: 24 months. Database backups: 30-day rolling window.

8. Your rights

Under ZZPL and GDPR you have the right to:

  • Access - to know what data we hold about you
  • Rectification - to correct inaccurate data
  • Erasure - to request deletion of your account
  • Portability - to receive your data in a machine-readable format
  • Objection - to object to processing based on legitimate interest
  • Withdrawal of consent - for marketing/analytics
  • Lodge a complaint with the Commissioner - directly at poverenik.rs

Response time: 30 days from receipt of the request.

9. Data security

TLS 1.2+ for all communications, AES-256 database encryption, bcrypt/Argon2 for passwords, access logging, regular security updates, backups with a tested restore procedure. Organisational measures: NDAs, the principle of least privilege, vendor management, an incident response plan.

10. Contact and complaints

Email: hello@thecounselcompass.com
Address: Aikon group d.o.o., Sremska 2A, 21000 Novi Sad, Serbia

You have the right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection: poverenik.rs, office@poverenik.rs, +381 11 3408 900.