Privacy policy
Last updated: 11 July 2026
This policy explains how AssessHub ('we', 'us') collects and uses personal data in connection with the AssessHub website and application, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
AssessHub is fire risk assessment software. For data collected through this website and for customer account data, AssessHub is the data controller. For the content our customers put into the product — assessments, photographs, site details and reports — the customer is the controller and we act as their processor under our Data Processing Agreement.
2. Data we collect
We collect the following categories of data:
- Account data — name, work email address, organisation, role and authentication metadata, managed through our authentication provider (Clerk).
- Billing data — organisation name, billing contact and subscription details. Card details are handled solely by Stripe and never touch our servers.
- Enquiry data — information you send through the contact / book-a-demo form.
- Customer content — assessments, checklist answers, observations, photographs, voice recordings and uploaded documents created by users of the product (processed on the customer’s behalf).
- Technical data — server logs, approximate location and device information used for security (for example session and device limits) and service operation.
3. How we use data
We use personal data to:
- Provide and secure the service, including authentication, MFA and session controls (performance of contract / legitimate interests).
- Process subscriptions and seat changes via Stripe (performance of contract).
- Respond to enquiries and arrange demos (legitimate interests / pre-contract steps).
- Operate AI-assisted features: content you submit for drafting, transcription or analysis is processed by our AI infrastructure providers solely to return the result — we do not train models on customer content.
- Meet legal obligations, including accounting and tax requirements.
4. Sub-processors and transfers
We use a small number of carefully selected sub-processors: Clerk (authentication), Stripe (payments), Railway (application hosting), Cloudflare (object storage for photographs and documents) and OpenRouter (AI model routing). Where any processing occurs outside the UK, it is protected by an adequacy decision or the International Data Transfer Agreement / Standard Contractual Clauses with the UK Addendum.
5. Retention
Customer content is retained for as long as the customer’s subscription is active and is deleted or returned in line with the DPA when the contract ends. Enquiry data is kept for up to 24 months. Billing records are retained for 6 years as required by UK tax law.
6. Your rights
You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and to data portability. To exercise any right, email info@assesshub.co.uk or use the contact page. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).
Where your data appears inside a customer’s assessment (for example, you were the person consulted on site), please direct your request to that customer as the controller — we will assist them as their processor.
7. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be notified to account owners by email.