PRIVACY STATEMENT — COMPLI PLATFORM
For workers and visitors.
About this Privacy Statement
Compli provides an online platform that helps principal contractors and their chain partners comply with laws and regulations regarding external workers and presence at project sites. This Privacy Statement explains which personal data is processed via the Compli platform, why this happens, who is responsible for it, and what rights you have. This Privacy Statement is intended for three groups of individuals whose data is processed in the Compli platform:
· Workers in the chain — employees of a principal contractor or a subcontractor who work on a project where chain liability applies.
· Visitors to project sites — individuals who are not an employee of a principal or subcontractor but who do visit a project site (such as inspectors, suppliers, guests, or client representatives).
· Workers of ancillary contractors — individuals who work at a project site by virtue of employment with an organization that is not part of the chain, but to whom safety and qualification requirements nonetheless apply.
Below you will find what applies per situation. General information (about Geofencing, security, sub-processors, your rights, and contact) is provided at the bottom and applies to all three groups.
Who is responsible for your data
Under the General Data Protection Regulation (GDPR), there is always one party that is the data controller for your data. This is the party that determines why and how your data is processed. Compli is in all cases the processor. We carry out the processing according to the controller’s instructions and on the basis of a data processing agreement.
Situation
Data Controller
Compli’s Role
You are a worker in the chain
Your employer (the principal contractor or the subcontractor who registered you)
Processor
You are a visitor at a project site
The project’s principal contractor (Compli’s Customer)
Processor
You are an employee of an ancillary contractor
The project’s principal contractor (Compli’s Customer)
Processor
Want to know exactly who your controller is in a specific situation? Ask the person who invited or registered you in Compli, or send an email to privacy@compli.nl.
A. If you are a worker in the chain
What data do we process about you?
· Name
· Company name of your employer
· Mobile phone number
· Email address
· Home address
· Residential address (if different from your home address)
· Citizen Service Number (BSN)
· Details from your identity document (type, document number, expiry date, date of birth, photo)
· Copy of your identity document
· Copy of your residence permit, work permit, Posted Workers notification, A1 certificate, or
Certificate of Coverage — where applicable
· Copies of professional competence, safety, and examination certificates
· Date and time of your check-in and check-out at a project site
· Location data from your mobile device at the moment of check-in and check-out (see the Geofencing section below)
Why do we process this data?
The law obliges your employer and the principal contractor in the chain to keep track of who works where and when, and whether that person is permitted to. Compli supports this technically. The relevant legal obligations include the Chain Liability scheme, the Hirer’s Liability scheme, the Foreign Nationals Employment Act (Wav), the Bogus Self-Employment Act (WAS), the Terms of Employment (Posted Workers) Act (WagwEU), the Placement of Personnel by Intermediaries Act (Waadi), the Assessment of Employment Relationships (Deregulation) Act (Wet DBA), the Minimum Wage and Minimum Holiday Allowance Act (WML), and the Working Conditions Act (Arbowet).
In addition, your presence on the project is recorded for the purpose of safety at the project site.
On what legal basis?
Article 6(1)(c) GDPR (legal obligation) and Article 6(1)(f) GDPR (legitimate interest of your employer and of the principal contractor in the chain in keeping track of presence and qualifications).
How long do we retain this data?
In accordance with the statutory tax retention periods: up to seven years after the end of the tax year to which the data relates. A shorter period is permitted if your employer instructs so, except insofar as a statutory retention obligation requires the data to be kept longer.
B. If you are a visitor at a project site
What data do we process about you?
· Name
· Company or organization name on whose behalf you are visiting
· Mobile phone number
· Email address
· Reason or purpose of your visit
· Date and time of your check-in and check-out
· Location data from your mobile device at the moment of check-in and check-out (see the Geofencing section below)
We do not process your Citizen Service Number, no copy of your identity document, and no copies of permits or certificates if you are a visitor.
Why do we process this data?
Under the Working Conditions Act, the project’s principal contractor must know who is present at its project site — for safety, to be able to give safety instructions, and to be able to reconstruct an incident should one occur.
On what legal basis?
Article 6(1)(c) GDPR (legal obligation under the Working Conditions Act) and Article 6(1)(f) GDPR (legitimate interest of the principal contractor).
Legitimate interests:
· presence registration at a Project;
· increasing safety awareness through examination, the provision of certificates, and the demonstrable acceptance of project-specific rules and safety instructions (such as site rules and codes of conduct).
How long do we retain this data?
90 days after the date of your check-out. Longer only if there is an ongoing incident investigation that justifies this.
C. If you are an employee of an ancillary contractor
What data do we process about you?
· Name
· Company name of the ancillary contractor you work for
· Your role or activity on the project
· Mobile phone number
· Email address
· Copies of your certificates (including VCA and other professional competence certificates)
· Date and time of your check-in and check-out
· Location data from your mobile device at the moment of check-in and check-out (see the Geofencing section below)
We do not process your Citizen Service Number, no copy of your identity document, and no copies of residence or work permits if you are an employee of an ancillary contractor.
Why do we process this data?
Under the Working Conditions Act, the principal contractor must be able to demonstrate that everyone working at its project site has the correct qualifications (such as a valid VCA) and must register your presence for safety and any incident reconstruction.
On what legal basis?
Article 6(1)(c) GDPR (legal obligation under the Working Conditions Act) and Article 6(1)(f) GDPR (legitimate interest of the principal contractor).
Legitimate interests:
· presence registration at a Project;
· increasing safety awareness through examination, the provision of certificates, and the demonstrable acceptance of project-specific rules and safety instructions (such as site rules and codes of conduct).
How long do we retain this data?
Up to one year after the end of the project for which you were present at the site. Longer only if there is an ongoing incident investigation or a statutory retention obligation that justifies this.
Location verification (Geofencing)
For check-in and check-out, the Compli platform uses Geofencing: a virtual boundary around the project site. Below we explain exactly what this means in your case.
How does it work?
At the moment you check in or check out, the Compli app compares the current location of your mobile device with the coordinates of the project site as recorded by the principal contractor.
Between your check-in and your check-out, the Compli app uses the native geofencing function of iOS or Android on your phone. Your operating system monitors at the system level whether you leave the geofence, and only sends a signal to the Compli app at the moment you enter or leave the geofence. The Compli app does not receive a continuous stream of location data and does not process any interim coordinates. We do this explicitly to protect your privacy.
What do we store?
We only store:
· Date and time of your check-in;
· Date and time of your check-out.
The actual location coordinates of your phone are not stored.
What if you do not give permission on your phone?
When the app first asks you for location permission, you can choose “Only this once”, “While using the app”, or “Don’t allow”. If you do not give permission, you cannot check in at a project site yourself using the app. In that case, you can only be checked in and out by a colleague or other authorized user who is present at the project site and who has the appropriate rights in the Compli platform to do so. A check-in from outside the geofence is not possible. The system refuses it and does not register it.
Compliance check at check-in
At the moment of your check-in, the Compli platform checks whether the documents and certificates recorded in the system are still valid at that time for the work on the relevant project. This includes your identity document, residence or work permit, A1 certificate, or certificates such as VCA.
The outcome of that check is shown to you and to the platform’s authorized users. On the basis of that check, the Compli platform does not make an automated decision that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR. The final decision on whether or not you are admitted to the work is always made by a human — your employer or the principal contractor.
Acceptance of project-specific rules
The principal contractor of a project may require you to agree to project-specific rules and instructions — for example safety instructions, codes of conduct, or site rules — before you are given access to the project site. When you click “I agree” via the Compli app or via checkin.compli.nl, the Compli platform records your acceptance with: your name or identifier, the date and time, and the version of the document you agreed to.
The content and versions of these rules are determined by the principal contractor. Compli acts as processor for this record-keeping.
Security of your data
Compli works in accordance with the ISO 27001 information security management system. This means we work systematically on security risks, including through the following measures:
· Access to your data is limited to those who genuinely need it for their work (role-based access control, multi-factor authentication where appropriate).
· Encryption of your data in transit (TLS 1.2 or higher) and at rest (AES-256).
· Specific encryption of your Citizen Service Number and encrypted storage of copies of identity and work documents.
· Periodic risk assessments, audits, and awareness training for our staff.
· An incident and data breach procedure that ensures we can respond quickly if something unexpectedly goes wrong.
Noticed something suspicious? Let us know.
If you notice something that could be a data breach — for example, that someone else appears to be able to see your data, a misdirected confirmation, or access from an unfamiliar device — please let us know as soon as possible via privacy@compli.nl. The sooner we know, the sooner we can act.
Sub-processors
For certain parts of our services, Compli works together with specialized suppliers. We have entered into data processing agreements with all of these parties, under which at least the same security and privacy obligations apply as Compli itself upholds.
Party
Purpose
Country
Transfer outside the EEA
Amazon Web Services (AWS)
Hosting of the Compli platform
Processing within the EEA (Frankfurt, Germany)
No
Didit.me
Verification of identity documents (only for workers in the chain)
Spain
No
BulkSMS
Sending SMS messages with verification codes for login
United Kingdom and South Africa
Yes — with EU Standard Contractual Clauses and additional safeguards
HubSpot
Customer support and CRM
United States (EU data center where possible)
Yes — under the EU-U.S. Data Privacy Framework, with additional Standard Contractual Clauses
Transfer of your data to countries outside the EEA
As described above, a limited part of your data — only your phone number and SMS text (BulkSMS), or contact details and support messages (HubSpot) — is transferred to countries outside the European Economic Area. This is done exclusively on the basis of a valid transfer mechanism under Chapter V GDPR: the EU-U.S. Data Privacy Framework for HubSpot, and the European Commission’s Standard Contractual Clauses plus additional safeguards for BulkSMS, in accordance with the Court of Justice’s Schrems II case law.
Identification data, copies of identity documents, BSN, permits, and certificates remain within the EEA.
Your rights
Under the GDPR, you have the following rights with regard to your personal data:
· Access — you have the right to know what data about you is being processed and to receive a copy of it.
· Rectification — if your data is incorrect or incomplete, you can request that it be corrected or completed.
· Erasure — under certain conditions, you can request the deletion of your data. Note: statutory retention periods may preclude deletion for as long as that period runs.
· Restriction — you can request that processing be temporarily halted, for example while a rectification request is being assessed.
· Objection — you can object to the processing, in particular to processing based on legitimate interest.
· Data portability — insofar as the processing is based on consent or a contract and is carried out automatically, you can request to receive your data in a common format or to have it transferred.
· Withdrawing consent — if you have given consent for a specific processing activity (such as sharing your location via the app), you can withdraw that consent at any time via your phone’s settings.
How do you exercise your rights?
You can primarily exercise your rights with the data controller — that is your employer (if you are a worker in the chain) or the principal contractor (if you are a visitor or an employee of an ancillary contractor). If you do not know who that is in your case, or if you wish to exercise your rights via Compli, send an email to privacy@compli.nl. We will then forward your request to the correct controller without delay and keep you informed.
We apply a response period of a maximum of one month, in line with Article 12(3) GDPR.
Complaints
Do you have a complaint about the way your data is processed? First contact the data controller (your employer or the principal contractor) or us via privacy@compli.nl. If we are unable to resolve this together, you always have the right to lodge a complaint with the Dutch supervisory authority:
Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
Postbus 93374, 2509 AJ The Hague, the Netherlands
https://www.autoriteitpersoonsgegevens.nl
Changes to this Privacy Statement
We may amend this Privacy Statement from time to time, for example if laws and regulations change or if we add new functionality to the Compli platform. The most current version is always available at compli.nl/yourprivacy. We will announce material changes in advance via the app and/or via the email address or phone number known to us.
Contact
Do you have questions about this Privacy Statement or about how we handle your data?
Compli B.V.
John M. Keynesplein 10, Amsterdam
KvK 88171833
Email: privacy@compli.nl
Version 2.0 — last updated: 29 May 2026


