Data protection
Access Compass · accesscompass.uk · last reviewed July 2026
Access Compass is built local-first. There are no accounts and no user database: your settings, access profile and saved items stay on your own device and are not sent to us. That is true for every edition of the app, wherever it's used. This statement sets out, plainly, what that means under UK data-protection law and, for our Victoria (Australia) edition, Australian privacy law, the services the app relies on, your rights, and what an organisation needs to know before offering Access Compass to the people it serves.
1. Who is responsible for your data
Access Compass is provided by ADAI Digital Ltd ("we", "our", "us"), a company based in Kettering, United Kingdom. For anything you do inside the app on your own device, you remain in control of that information: it is held on your device, not by us. Where we act as a data controller (for example, for a feedback report or email you choose to send us, or the standard server logs of the website that serves the app), our contact point is admin@adaidigital.co.uk.
2. Which law applies to you
Access Compass is offered in different regional editions, and the same local-first, no-personal-data design applies to all of them. Which specific privacy law and regulator applies depends on where you are:
- UK editions (Northamptonshire, the Bedfordshire family, Rutland, the seed packs and Accessible Air Travel): UK GDPR and the Data Protection Act 2018, regulated by the Information Commissioner's Office (ICO).
- Victoria, Australia edition: the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), regulated by the Office of the Australian Information Commissioner (OAIC).
Because the app does not collect personal data from you in ordinary use unless you choose to submit feedback, the practical protection is the same everywhere: the difference below is mainly which law and regulator's name applies, not a difference in what we actually do with your information.
Our ICO registration reference, named data-protection contact, company registration number and a signed Data Processing Agreement are available to organisations on request as part of due diligence.
3. What the app stores, and where it lives
Everything you set or save in Access Compass is stored in your own browser's local storage on your device. It is not transmitted to us and there is no login that could link it to you.
| Information | Where it is stored | Who can see it |
|---|---|---|
| Items you save from the directory | Your device only (browser local storage) | Only you, on your device |
| Your access profile | Your device only | Only you, on your device |
| Journey support plans, assistance requests, mobility-aid details and booking references | Your device only | Only you, on your device, unless you choose to share a plan |
| Display choices (text size, theme, contrast, reading font) | Your device only | Only you, on your device |
Because this data lives on your device, you can remove all of it at any time by clearing the site's storage in your browser, or by uninstalling the app. There is nothing for us to delete on your behalf, because we never held it.
4. What we, and our website host, actually receive
Like any website, when your device loads Access Compass, the servers involved automatically receive standard technical information such as your device's IP address and the request being made. This is a normal part of how the internet works and is used to deliver the page and to keep the service secure and reliable. We do not use this to build a profile of you, we do not run advertising or tracking scripts, and we do not combine it with anything you set in the app.
5. Lawful basis for processing
For the small amount of processing we do carry out (serving the website securely, and reviewing feedback or messages you choose to send us), our lawful basis under UK GDPR is our legitimate interests in running a safe, working service and in replying to you. Where you email us, you are also giving your information to us directly so that we can respond. Under the Australian Privacy Principles, this same handling is the minimum reasonably necessary to run the service and to respond to you, collected directly from you.
6. Access needs and other sensitive information
Some of what you may enter, such as your access profile, could relate to health or disability. Under UK GDPR this would be special-category data; under the Australian Privacy Principles it would be sensitive information, both of which carry extra protection. This is exactly why the app keeps it on your device and never sends it to us, wherever you are. We do not receive it, store it, or share it. If you choose to share a journey support plan, the previewed text goes directly from your device to the recipient you choose. Booking references, contact details and private notes are excluded by default.
7. Services the app relies on
Access Compass is a static Progressive Web App. To deliver the site to your device, it relies on the website host below. This request carries the standard technical information described in section 3. It does not carry your saved items or access profile.
| Service | Purpose | What is sent |
|---|---|---|
| Google Firebase Hosting | Serving the website securely | Standard server request data (section 3) |
| ADAI Feedback Control | Receiving a correction or suggestion you choose to submit for review | Only the bounded form fields you enter, the referenced public item and an opaque receipt |
Where you choose to follow a link out to a listed service's own website, that takes you to a third party whose terms and privacy practices then apply, as set out in our Terms of Service.
8. International transfers
Some technical services operate outside the UK and outside Australia. Because no identifying personal data is sent to them from the app in ordinary use, the transfer of personal data is minimal. Where any transfer of personal data does occur (for example, in a feedback report or email you send us), it relies on appropriate safeguards, such as adequacy decisions or standard contractual clauses under UK GDPR, or the equivalent overseas-disclosure protections under the Australian Privacy Principles where relevant.
9. How long data is kept
Data you set or save in the app stays on your device until you remove it. We do not hold copies, so we do not set a retention period for it. Emails you send us are kept only as long as needed to deal with your enquiry, and then deleted.
10. Your rights
If you are in the UK, under UK GDPR you have rights over your personal data, including the right to access it, correct it, erase it, restrict or object to its processing, and to data portability. If you are in Australia, the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) give you broadly equivalent rights to access and correct your personal information. Because your app data is on your own device, many of these you can exercise directly and immediately: you can view, edit and delete it yourself, without asking us. For anything we do hold, such as a feedback report or email exchange, contact admin@adaidigital.co.uk and we will respond within one month.
11. Children
Access Compass lists support services for children as well as adults, and is intended to be used by families, carers and professionals. It does not create accounts or ask for personal details in ordinary use. The optional feedback form asks reporters not to include children’s, safeguarding, health or other sensitive personal information.
12. Security
The app is served over an encrypted connection, holds no central store of user data to breach, and runs no user accounts or passwords. Our approach is set out in full in our security overview.
13. Data breaches
Because we do not hold a central database of user data, the most common cause of a personal-data breach does not apply. If a reportable breach affecting personal data we do control ever occurred, we would assess and, where required, report it to the ICO within 72 hours and inform anyone affected.
14. For organisations considering Access Compass
Access Compass is designed to be straightforward for a local authority, NHS body, Australian state or NDIS provider, charity or other statutory organisation to offer to the people it serves. The local-first design means that, in normal use, no resident, patient, participant or staff personal data flows to ADAI Digital, which is deliberately assessment-friendly, whether your process is a UK Data Protection Impact Assessment (DPIA) or an Australian Privacy Impact Assessment (PIA).
- Roles. In ordinary use we do not act as your data processor (UK) or your contracted service provider handling personal information (Australia), because the app does not send us your people's data. Where a formal arrangement is needed, we will enter an agreement that reflects the actual data flows.
- Assessment support. We will support your DPIA or PIA and provide the data-flow information above in the format your information-governance team needs.
- Scope. Access Compass is an information and signposting directory. It is not a medical device and does not provide clinical, legal or financial advice.
- Accessibility. We design to WCAG 2.1 level AA as our target and keep improving. Our full position, and how we test, is in our accessibility and inclusion statement.
- On request. An ICO registration reference (UK), named data-protection contact, security questionnaire responses and a signed data-handling agreement are available for procurement and assurance.
15. Changes and how to reach us
We will update this statement as the app develops and note the review date at the top. For any data-protection question, contact ADAI Digital Ltd at admin@adaidigital.co.uk. If you are in the UK, you also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. If you are in Australia, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. Wherever you are, we would appreciate the chance to put things right first.
All policies · Privacy · Cookies · Security · Back to Access Compass