Privacy policy

Last updated: 11 July 2026

This policy explains how AssessHub ('we', 'us') collects and uses personal data in connection with the AssessHub website and application, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

AssessHub is fire risk assessment software. For data collected through this website and for customer account data, AssessHub is the data controller. For the content our customers put into the product — assessments, photographs, site details and reports — the customer is the controller and we act as their processor under our Data Processing Agreement.

2. Data we collect

We collect the following categories of data:

  • Account data — name, work email address, organisation, role and authentication metadata, managed through our authentication provider (Clerk).
  • Billing data — organisation name, billing contact and subscription details. Card details are handled solely by Stripe and never touch our servers.
  • Enquiry data — information you send through the contact / book-a-demo form.
  • Customer content — assessments, checklist answers, observations, photographs, voice recordings and uploaded documents created by users of the product (processed on the customer’s behalf).
  • Technical data — server logs, approximate location and device information used for security (for example session and device limits) and service operation.

3. How we use data

We use personal data to:

  • Provide and secure the service, including authentication, MFA and session controls (performance of contract / legitimate interests).
  • Process subscriptions and seat changes via Stripe (performance of contract).
  • Respond to enquiries and arrange demos (legitimate interests / pre-contract steps).
  • Operate AI-assisted features: content you submit for drafting, transcription or analysis is processed by our AI infrastructure providers solely to return the result — we do not train models on customer content.
  • Meet legal obligations, including accounting and tax requirements.

4. Sub-processors and transfers

We use a small number of carefully selected sub-processors: Clerk (authentication), Stripe (payments), Railway (application hosting), Cloudflare (object storage for photographs and documents) and OpenRouter (AI model routing). Where any processing occurs outside the UK, it is protected by an adequacy decision or the International Data Transfer Agreement / Standard Contractual Clauses with the UK Addendum.

5. Retention

Customer content is retained for as long as the customer’s subscription is active and is deleted or returned in line with the DPA when the contract ends. Enquiry data is kept for up to 24 months. Billing records are retained for 6 years as required by UK tax law.

6. Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your personal data, and to data portability. To exercise any right, email info@assesshub.co.uk or use the contact page. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

Where your data appears inside a customer’s assessment (for example, you were the person consulted on site), please direct your request to that customer as the controller — we will assist them as their processor.

7. Changes

We will post any changes to this policy on this page and update the date above. Material changes will be notified to account owners by email.