Deskely Privacy Policy

    Effective as of: July 3, 2025

    Your privacy is extremely important to us. This Privacy Policy explains how Deskely ("Deskely", "we", "us", "our") collects, uses, shares, and protects information when you use our websites, applications, and related services (collectively, the "Deskely Service"), including our web platform and offline-first mobile apps used for commissioning and inspection work (e.g., checksheets/ITRs, PWL, CP, walkdowns, punches, certificates, templates, tag management, master data, sign-offs, and attachments).

    This Privacy Policy relates to information collected by Compass Energy Pte Ltd (referred to in this Privacy Policy as "Deskely", "we", "us", or "our") through your use of the Deskely Service.

    If you do not agree with this Privacy Policy, do not use the Deskely Service.

    1) Scope of this Privacy Policy

    This Privacy Policy applies to information we collect when you:

    • visit our websites,
    • create or use an account,
    • use our web or mobile apps (including offline use and later sync),
    • use our APIs or integrations, or
    • otherwise interact with us (support, sales, demos, events).

    Customer Data and our role

    Deskely is typically used by organizations (e.g., project owners, EPCs, contractors). When an organization (a "Customer") subscribes to Deskely, Deskely generally processes Customer Data on the Customer's behalf. In many cases, the Customer is the controller and Deskely is the processor under applicable privacy laws.

    Our commitments to Customers regarding Customer Data (including security measures, subprocessors, and international transfers) may also be governed by a separate Data Protection Addendum (DPA). This Privacy Policy is incorporated into and governed by our Terms of Use/Service. Capitalized terms not defined here have the meaning given in those documents.

    2) What Information We Collect

    We collect information in two main categories: (A) information you provide and (B) information collected automatically or from other sources.

    A. Information you provide to us

    Account and profile information

    • name, email address, phone number (optional), job title, company/organization name
    • username, password (stored in hashed form), authentication settings
    • role/permissions and organizational membership

    Billing and commercial information (where applicable)

    • billing contact details, invoicing details
    • payment-related information (typically processed by a payment processor; we may receive limited confirmation details)

    Customer Data (content you submit or generate in Deskely)

    Depending on how Deskely is used, Customer Data may include:

    • Master Data (systems, subsystems, disciplines, locations, phases, scopes)
    • Tags and Tag Sets and related metadata
    • Templates (e.g., ITR/checksheet templates, PWL templates, CP templates, walkdown templates, certificate templates)
    • Field Work records such as checksheets/ITRs, PWL records, CP records, walkdowns, punches, certificates
    • Sign-offs/approvals, timestamps, user identifiers, and audit trail/log history associated with work execution
    • Attachments you upload (photos, documents, files) and related metadata (file name, type, size)
    • Comments and notes entered by users

    Support and communications

    • information you provide when you contact support or sales
    • content of messages and troubleshooting details you share

    B. Information we collect automatically when you use the Deskely Service

    Usage data

    • features you use, pages/screens viewed, actions taken (e.g., issuing a checksheet, completing a sign-off)
    • search terms entered within Deskely
    • interaction patterns (e.g., navigation flow), and performance metrics

    Device and connection information

    • device type, operating system, app version, browser type
    • IP address, approximate location derived from IP (e.g., country/city)
    • device identifiers, network information, language/time zone settings
    • crash logs and diagnostic data

    Offline-first behavior and local storage

    Deskely mobile apps may store data locally on your device to enable offline work and later sync. This local data may include Customer Data needed for your assigned work (e.g., templates, checksheets, punch items, attachments queued for upload) and related metadata.

    Cookies and similar technologies (web)

    We and our service providers may use cookies, SDKs, pixels, and similar technologies to:

    • keep you signed in,
    • remember preferences,
    • measure performance and usage, and
    • support analytics and (where applicable) marketing.

    C. Information we receive from other sources

    Other users / administrators

    Customer admins or other users may add you to Deskely, invite you, assign you roles, or include you in records (e.g., sign-off routing, mentions, comments).

    Integrations and third-party services

    If you (or your admin) enable integrations, we may receive data from those services as necessary to provide the integration. The data we receive depends on the integration and the permissions you grant.

    3) Why We Collect and Use Information (Purposes)

    We use information to:

    • Provide the Deskely Service (account creation, authentication, permissions, offline sync, record creation and retrieval, dashboards)
    • Operate commissioning/inspection workflows (templates, tags, master data, sign-offs, issuing/reviewing records, audit trails)
    • Enable collaboration inside Customer organizations (sharing, assignments, approvals, comments)
    • Maintain reliability and security (monitoring, preventing fraud/abuse, access control, incident response)
    • Improve and develop the Deskely Service (feature optimization, performance improvements, user experience)
    • Provide support and respond to requests
    • Manage billing and contracts (subscriptions, invoicing, account administration)
    • Communicate with you (service announcements, security notices, support responses)
    • Marketing (where permitted) (e.g., product updates; you can opt out where required)

    4) Legal Bases for Processing (EEA/UK and similar jurisdictions)

    Where applicable, we rely on one or more of the following legal bases:

    • Performance of a contract (to provide the Deskely Service)
    • Legitimate interests (e.g., service improvement, security, fraud prevention), balanced against your rights
    • Consent (e.g., certain marketing communications or optional cookies, where required)
    • Legal obligations (e.g., tax/accounting requirements, lawful requests)

    Where Deskely processes Customer Data as a processor, the Customer determines the legal basis and Deskely processes under the Customer's instructions and the DPA.

    5) How We Share Information

    We do not sell personal information.

    We may share information as follows:

    Within a Customer organization

    Customer admins and authorized users may access information in the Customer's Deskely environment, subject to permissions.

    Service providers (subprocessors)

    We use vendors to help provide the Deskely Service (e.g., hosting, storage, monitoring, analytics, error tracking, customer support tools, payment processing). They may access information only as needed to perform services for us and are bound by confidentiality and data protection obligations.

    Integrations at your direction

    If you enable an integration, we may share or receive information with the integration provider as configured by you/your admin.

    Legal and safety reasons

    We may disclose information if we believe in good faith it is necessary to comply with law, respond to lawful requests, protect rights and safety, investigate fraud, or enforce our terms.

    Business transfers

    If Deskely is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality and continuity protections.

    Affiliates

    We may share information with affiliates under common control, consistent with this Privacy Policy.

    6) International Transfers

    Your information may be transferred to, stored, and processed in countries other than where you live. Where required, we use appropriate safeguards for international transfers (such as contractual protections) and apply security measures designed to protect your data.

    For Customer Data, transfer terms and safeguards may be described in the DPA.

    7) Data Retention

    We retain personal information only as long as necessary for the purposes described in this Privacy Policy, including to:

    • provide the Deskely Service,
    • comply with legal obligations,
    • resolve disputes, and
    • enforce agreements.

    Customer Data is typically retained for the duration of the Customer's subscription and as instructed by the Customer, subject to contractual and legal requirements. Some data may remain in backups for a limited period after deletion, consistent with backup and disaster recovery practices.

    Because Deskely supports offline use, Customer Data may also remain cached locally on user devices until it is synced and/or removed through app controls, account removal, or device management.

    8) Security

    We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No security system is perfect, and you are responsible for safeguarding your credentials and devices, especially where offline data may be stored locally.

    9) Your Rights and Choices

    Depending on your location and applicable law, you may have rights such as:

    • Access to your personal information
    • Correction of inaccurate information
    • Deletion (erasure) in certain circumstances
    • Portability of your data
    • Restriction of processing in certain circumstances
    • Objection to certain processing (including some legitimate-interest processing)
    • Withdraw consent where we rely on consent

    How to exercise rights

    If you are an end user in a Customer organization, your request may need to be handled by your organization's admin (because the Customer controls Customer Data).

    You can also contact us using the details in Section 16. We may need to verify your identity before fulfilling requests.

    Marketing choices

    You can opt out of marketing emails using the unsubscribe link in those messages. Service and security communications are not optional because they are necessary to provide the Deskely Service.

    Cookies

    Where required, you can manage cookie preferences through consent tools (if available) and browser settings.

    10) Children Under 16

    The Deskely Service is not directed to children under 16 and is intended for professional/enterprise use. We do not knowingly collect personal information from children under 16.

    11) Sensitive Information

    Please do not submit sensitive personal data (e.g., government IDs, health information, biometrics, criminal background) through the Deskely Service unless your organization has determined it is necessary and lawful for the intended use. If sensitive data is included in Customer Data, the Customer is responsible for establishing a lawful basis and providing any required notices.

    12) Third-Party Links and Services

    The Deskely Service may link to third-party sites or services (including integrations). Their privacy practices are governed by their own policies. This Privacy Policy applies only to information collected by Deskely.

    13) Do Not Track

    Some browsers offer "Do Not Track" signals. The Deskely Service may not respond to Do Not Track signals in a uniform way because there is no consistent industry standard.

    14) U.S. State Privacy Disclosures (including California)

    Where applicable, you may have rights under laws such as the CCPA/CPRA and other state privacy laws. Deskely does not sell personal information. We may share personal information with service providers and for the business purposes described above.

    You (or an authorized agent) may request access, correction, or deletion, subject to verification and legal exceptions.

    15) Changes to this Privacy Policy

    We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the Deskely Service, email, or other appropriate means. Continued use of the Deskely Service after an update means you accept the revised Privacy Policy.

    16) Contact Us

    For privacy questions or requests, contact:

    By email: oscar@compass-digital.com

    By postal mail:
    ATTN: Privacy
    Compass Energy Pte Ltd (Org. nr: 200302890M)
    12 Tuas Ave 1
    Singapore 639497

    We use cookies to improve your experience.
    You can opt out of certain cookies.
    Find out more in our privacy policy.