For company.

Create a company,

Add company inside user

Also inside companie add belong_to (user)
Also inside companie employees_ ( list of user)

Now privacy

this company employees contain current user

There are many ways.