Privacy Policy
Last updated: 9 July 2026
1. Introduction
This privacy policy explains how Compfeed B.V. (“Compfeed”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use our design system governance platform available at https://www.compfeed.com and https://app.compfeed.com (the “Platform”).
Compfeed is a business-to-business (B2B) software-as-a-service (SaaS) platform that helps design and engineering teams manage component libraries, design systems, and related documentation. This policy applies to users of the Platform, including individuals who access the Platform through their organization’s account.
We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and Dutch data protection law (Uitvoeringswet AVG).
2. Controller Information
The controller responsible for processing your personal data is:
Compfeed B.V. KvK: 96147075 Rotterdam, The Netherlands Email: support@compfeed.com
For privacy-related inquiries, you may contact us at support@compfeed.com.
3. Categories of Personal Data We Collect
3.1 Account and Authentication Data
When you create an account or sign in, we collect:
- Email address
- Name (if provided)
- Profile picture (if using social sign-in)
- Authentication identifiers and session data
3.2 Organization and Workspace Data
When your organization uses Compfeed, we process:
- Organization name and settings
- Team membership and role assignments
- Invitation data (email addresses of invitees)
3.3 User-Generated Content
Content you and your team create within the Platform:
- Component documentation and descriptions
- Checklist items and process documentation
- Activity history and contribution records
- Comments and annotations
- Uploaded images and files (such as organization logos)
3.4 Integration Data
When you enable integrations, we process data from connected services:
- Integration authorization data and access permissions
- Content and metadata from connected services (such as design files or project management data)
The personal data within these integrations depends on what your organization chooses to connect. You control which integrations are enabled.
3.5 AI Assistant Data
When you use AI-powered features, we process:
- Text content submitted for AI generation or enrichment
- AI-generated outputs
- Usage metrics for AI features
We do not use your content to train Compfeed-owned AI models, and we configure third-party AI service providers not to use your content for model training where this is available under their terms. See Section 7 for information about our AI service providers.
3.6 Technical and Usage Data
We automatically collect:
- IP address
- Browser type and version
- Device information
- Pages visited and features used
- Error logs and diagnostic information
- Referral URLs
3.7 Billing Data
Payment processing is handled by Paddle, our Merchant of Record. Paddle may process billing details, payment method information, tax information, invoices, transaction records, and related customer-support data as needed to process payments, manage subscriptions, handle taxes, and comply with applicable legal obligations.
We do not directly store your payment card details.
3.8 Communication Data
When you contact us for support:
- Email address and message content
- Support ticket history
4. Sources of Personal Data
We collect personal data from the following sources:
- Directly from you: When you create an account, use the Platform, or contact us
- From your organization: When your employer or team administrator adds you to a workspace
- From identity providers: When you sign in via social authentication
- From connected integrations: When you authorize connections to third-party services
- Automatically: Through your use of the Platform (technical data, cookies)
5. Purposes and Legal Bases for Processing
We process your personal data for the following purposes, each with a corresponding legal basis under GDPR Article 6(1):
5.1 Contract Performance (Article 6(1)(b))
- Creating and managing your account
- Providing access to the Platform and its features
- Processing authentication and maintaining sessions
- Enabling collaboration within your organization
- Providing AI-assisted features when enabled by your organization
- Processing subscription billing
- Providing customer support
5.2 Legitimate Interests (Article 6(1)(f))
- Security and fraud prevention: Protecting the Platform and users from unauthorized access, abuse, and security threats
- Service improvement: Analyzing usage patterns to improve the Platform
- Error monitoring: Identifying and fixing technical issues
- Business communications: Sending service-related announcements and updates to organizational contacts
- Enforcing our terms: Investigating and addressing violations of our terms of service
We have balanced these interests against your rights and determined that processing is necessary and proportionate. You may object to processing based on legitimate interests (see Section 11).
5.3 Consent (Article 6(1)(a))
- Optional analytics: Where we use analytics that require consent under applicable law
You may withdraw consent at any time (see Section 11).
5.4 Legal Obligation (Article 6(1)(c))
- Retaining billing and transaction records for tax and accounting purposes
- Responding to valid legal requests from authorities
- Complying with data protection law requirements
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account plus the applicable recovery period after deletion request, then deleted or anonymized unless retention exceptions apply |
| Organization content | Duration of organization subscription, deleted upon organization account closure (subject to backup retention) |
| Activity/contribution history | Retained as part of organizational audit trail while organization is active |
| AI Assistant data | Duration of feature enablement, plus a limited period after disabling (subject to backup retention and legal obligations) |
| Billing records | 7 years (legal requirement for tax/accounting) |
| Error and diagnostic logs | Up to 90 days |
| Security logs | Up to 12 months |
| Backups | Up to 30 days after data deletion |
When you request account deletion, we delete or anonymize your personal data without undue delay, except where:
- We are legally required to retain certain records
- Data forms part of organizational audit trails and your organization has not requested deletion
- Technical backup cycles require additional time
Note on organizational content: When you contribute to documentation within an organization, your contributions may be retained as part of your organization’s historical records. If your personal account is deleted while your organization remains active, your past contributions may be attributed to “Former Member” rather than fully deleted, as they form part of the organization’s business records.
7. Service Providers and Data Sharing
We use service providers to deliver the Platform. These include:
- Cloud infrastructure providers for hosting, database, and file storage
- Authentication providers for social sign-in options
- Email service providers for transactional communications
- Payment processors for subscription billing and invoicing
- Error monitoring and analytics providers for service reliability and improvement
- AI service providers for optional AI-assisted features
- Document and collaboration infrastructure providers for real-time editing features
For customer-enabled integrations (such as design tools or project management services), data is shared with those services only when your organization enables the integration. Those services operate under their own terms and privacy policies.
We enter into data processing agreements with our service providers and require appropriate safeguards for international data transfers.
A detailed list of subprocessors is available upon request for customers with a Data Processing Agreement.
8. International Data Transfers
Some of our service providers may process personal data outside the European Economic Area, including in the United States and other locations where they operate. When we transfer personal data from the EEA, United Kingdom, or Switzerland to countries without an adequacy decision, we rely on:
- Standard Contractual Clauses (SCCs): Where required, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, data processing agreements, and supplementary measures
- Supplementary measures: Including encryption in transit and at rest, access controls, and contractual commitments
For transfers to the United Kingdom, we rely on the UK’s adequacy decision for the EEA and the UK International Data Transfer Agreement where applicable.
9. Cookies and Similar Technologies
9.1 Essential Cookies and Storage
We use strictly necessary cookies and local storage for:
- Authentication and session management
- Security (CSRF protection)
- Remembering your preferences
- Core Platform functionality
These technologies are required for authentication, security, and core Platform functionality. Disabling them in your browser may prevent the Platform from working properly.
9.2 Analytics
We use privacy-focused analytics to understand how the Platform is used. This data is aggregated and does not track individual users across sites.
10. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit and at rest
- Access controls and authentication requirements
- Security monitoring
- Employee access limited to those who need it
- Subprocessor security requirements
No method of transmission or storage is completely secure. If you discover a security vulnerability, please report it to support@compfeed.com.
11. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data (subject to legal retention requirements)
- Restriction: Request that we limit processing of your data
- Data portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interests
- Withdraw consent: Withdraw consent where processing is based on consent
- Automated decision-making: We do not make solely automated decisions with legal or significant effects
How to Exercise Your Rights
You can exercise many of these rights directly in your account settings. For requests that require our assistance, contact us at support@compfeed.com.
We will respond to your request without undue delay and in any event within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receiving your request.
We may ask you to verify your identity before processing your request.
Right to Lodge a Complaint
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with a supervisory authority. For users in the Netherlands, this is:
Autoriteit Persoonsgegevens Website: https://autoriteitpersoonsgegevens.nl Postal address: Postbus 93374, 2509 AJ Den Haag
12. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware of the breach, where feasible
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
13. Children and Minors
Compfeed is a B2B platform designed for use by professionals within organizations. We do not knowingly collect personal data from children.
Under Dutch law, individuals under 16 years of age require parental or guardian consent for consent-based processing of their personal data in online services. If we become aware that we have collected personal data from a person under 16 without appropriate consent or authorization, we will take steps to delete that data.
14. Your Organization as Customer
When you access Compfeed through your organization (employer, client, or team), your organization is typically the “customer” that has agreed to our terms of service. In this relationship:
- Compfeed as processor: For content your organization creates and stores in the Platform (component documentation, checklists, uploaded files), Compfeed acts as a data processor on behalf of your organization, which acts as the data controller
- Compfeed as controller: For account data, authentication, billing, and Platform operations, Compfeed is the data controller
Your organization is responsible for:
- Ensuring it has a lawful basis to share your data with Compfeed
- Determining what content is uploaded to the Platform
- Managing access to organizational workspaces
- Informing you about its data processing practices
If you have questions about how your organization uses your data within Compfeed, please contact your organization’s administrator.
15. No Sale of Personal Data
We do not sell your personal data to third parties. We do not share your personal data with third parties for their own marketing purposes.
16. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or applicable law. When we make significant changes, we will notify you by:
- Posting a notice on the Platform
- Sending an email to account holders (for material changes)
- Updating the “Last updated” date at the top of this policy
We encourage you to review this policy periodically.
17. Contact Us
If you have questions about this privacy policy or our data practices, please contact us:
Email: support@compfeed.com