Legal

Privacy notice

Last updated 3 August 2026

This notice is maintained by the operator of this Assay deployment. It explains what personal data Assay processes, why, and what you can ask us to do with it. Plant data you upload is customer data, processed on your instructions, and is covered by the agreement between us rather than by this notice alone.

1. Who is responsible

For account and usage data, Assay is the controller. For the process readings, laboratory results and batch records you upload, your organisation is the controller and Assay is the processor, acting only on your documented instructions.

2. What we collect

Account data: name, work email address, organisation, site assignment and role. Collected when an account is created.

Authentication data: sign-in timestamps, session tokens and, where you use a social sign-in provider, the identifier that provider returns.

Customer plant data: tag readings, laboratory results, batch records, cost parameters, interventions and ledger entries that you or your systems upload. This is production data, not personal data, unless you choose to place personal identifiers inside it.

Usage data: pages viewed, actions taken and error reports, used to operate and improve the service. Optional analytics are only collected if you consent.

3. Why we process it

To provide the service under our contract with your organisation; to keep accounts secure and detect misuse (legitimate interests); to meet legal obligations; and, where you consent, to measure product usage.

4. Model training and separation

Models are trained per organisation, on that organisation's own data. No customer's data is ever used to train another customer's model, and no plant data is sold, licensed or shared with third parties for their own purposes.

5. Processors we use

Hosting and application delivery, managed database, authentication and storage are provided by our cloud infrastructure providers. Where an optional integration is enabled by your administrator — for example an outbound webhook or email alert — data leaves only to the destination that administrator configured.

6. Retention

Account data is kept while the account is active and for a short period afterwards for audit purposes. Customer plant data is kept for as long as your organisation's subscription runs, and is deleted or exported on request at the end of it. Ledger and intervention records are retained for the life of the subscription because they form an audit trail.

7. Security

Access is authenticated and every table is protected by organisation-scoped row-level security, so one organisation cannot read another's rows. Data is encrypted in transit and at rest by the underlying platform. See the trust and security page for the controls in place in this deployment.

8. Your rights

Depending on where you are, you may ask for access, correction, deletion, restriction, portability or to object to processing. Contact your organisation's administrator for data inside your plant workspace, or the address below for account data. If you are in the UK or EU you may also complain to your supervisory authority.

9. Contact

Privacy enquiries: the operator of this deployment, through the contact route your organisation was given at onboarding.