Legal · Data Protection
Privacy Policy
How AssurAI collects, uses, and protects your information — GDPR and CCPA compliant.
GDPR
Compliant
+ CCPA covered
30d
Rights Response SLA
Avg. 5 days actual
0
Data Sales
We never sell your data
7
Sub-Processors
All DPA covered
Your data is never sold
AI models are never trained on your data
Delete your data any time
AES-256 encryption at rest & in transit
72-hour breach notification (GDPR)
Last Updated January 2025 · Effective: January 1, 2025
Section 01

Information We Collect

Account Information

When you create an AssurAI account, we collect your name, email address, company name, and role. This information is required to provide you with access to the platform.

Audit & Compliance Data

Controls, evidence, findings, workpapers, and projects you create within AssurAI. This data belongs entirely to you. We act as a data processor on your behalf.

Evidence Files & Uploaded Documents

When you use Evidence Intelligence, RCM Auto-Reader, Walkthrough AI, Reconciliation AI, or Prior Year Workpaper Ingestion, you upload documents for AI processing.

  • Documents are transmitted securely to Anthropic's Claude API for analysis
  • Documents are not permanently stored by AssurAI beyond what is required to display results in your session
  • SHA-256 hashes of uploaded documents are stored alongside filename, file size, and upload timestamp — the document itself is not stored
  • We do not use uploaded documents to train AI models

Usage & Technical Data

Features accessed, AI tools used, session duration, IP address, browser type, and device information — used for security, fraud prevention, and platform improvement.

Contact & Marketing

When you submit your email via our website, advisory consultation, or ROI calculator, we store your email to send relevant information about AssurAI products. You can unsubscribe at any time by emailing privacy@getassurai.com. We do not sell your data to third parties.

Section 02

How We Use Your Information

PurposeLegal Basis (GDPR)Can Opt-Out
Providing and improving AssurAIContract performanceNo (essential)
Processing AI requests on your behalfContract performanceNo (essential)
Service notifications and updatesContract performanceNo (essential)
Security monitoring and fraud preventionLegitimate interestNo
Product analyticsLegitimate interestYes
Marketing emailsConsentYes (unsubscribe anytime)
Legal complianceLegal obligationNo
Section 03

Data Sharing & Sub-Processors

🔒

We do not sell your personal data. We share data only with essential sub-processors bound by Data Processing Agreements.

Sub-ProcessorCategoryPurposeCertification
SupabaseInfrastructureDatabase & authenticationSOC 2 Type II
AnthropicAI ProcessingClaude API — no training on your dataZDR Agreement
GoogleAI ProcessingGemini API — subject to Google API TermsGoogle DPA
OpenAIAI ProcessingGPT-4o API — subject to OpenAI API TermsOpenAI DPA
NetlifyInfrastructurePlatform hostingSOC 2 Type II
StripePaymentsPayment processingPCI DSS Level 1
ResendEmailTransactional email deliveryStandard DPA
Section 04

Data Security

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Row-level security (RLS) ensures strict data isolation between organisations
  • SOC 2 compliance in progress
  • Regular security assessments and penetration testing
  • Multi-factor authentication available for all accounts
  • Breach notification within 72 hours (GDPR Article 33)

Full security details: getassurai.com/security.

Section 05

Data Retention

Data TypeRetention Period
Account data (name, email, org)Life of account + 90 days
Workpapers, findings, controls, projectsLife of account + 90 days
Evidence integrity hashes (SHA-256)Life of account
Support tickets3 years from creation
Uploaded document contentNot retained — session only
AI conversation logsSubject to Anthropic's policy
Auth / access logs90 days

Upon account closure, all personal data is deleted within 90 days except where required by law. Immediate deletion is available on request — privacy@getassurai.com.

Section 06

Your Rights (GDPR & CCPA)

Depending on your location, you have the following rights regarding your personal data. To exercise any right,

GDPR + CCPA
Right to Access
Request a copy of personal data we hold about you.
GDPR + CCPA
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
GDPR + CCPA
Right to Portability
Receive your data in a structured, machine-readable format.
GDPR
Right to Rectification
Request correction of inaccurate or incomplete data.
GDPR
Right to Object
Object to processing based on legitimate interest.
CCPA
Right to Opt-Out
Opt out of the sale of personal information (we never sell, but you may opt out of analytics).

We respond within 30 days (avg. 5 business days). EU/EEA residents may lodge a complaint with their local data protection authority.

Section 07

Cookies & Local Storage

AssurAI uses browser localStorage (not traditional cookies) to store:

  • Your authentication token (required for platform access)
  • Your active project selection and UI preferences
  • Demo data load status and dismissed banners

We do not use advertising cookies or tracking pixels. Google Ads conversion tracking may place a cookie if you arrive via a Google Ad — governed by Google's privacy policy. Manage cookie preferences via the .

Section 08

Children's Privacy

AssurAI is a professional B2B platform intended for use by individuals who are at least 18 years of age. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected information from a child, please contact privacy@getassurai.com immediately and we will promptly delete that information.

Section 09

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to all registered account holders
  • Display an in-app banner for 14 days following the change

Continued use of AssurAI after changes are posted constitutes acceptance of the updated policy. If you object to any changes, you may close your account and request data deletion.

📋

Policy version history is available on request. Email privacy@getassurai.com to request a prior version.

Section 10

Contact Us

For privacy questions, data requests, or to request our Data Processing Agreement (DPA):

Privacy Requests

privacy@getassurai.com

General Support

support@getassurai.com

Data Controller

AssurAI Inc., San Jose, California, USA

Enterprise / DPA

shakeel@getassurai.com · View DPA

© 2024–2025 AssurAI Inc. All rights reserved. AssurAI™ is a trademark of AssurAI Inc. USPTO WUID 901030615 · Terms · Security · Disclaimers

Submit a Data Rights Request
GDPR / CCPA — we respond within 30 days
Your request has been submitted. We will respond within 30 days at the email address you provided.
We will verify your identity before processing your request. Response within 30 days; typical turnaround is 5 business days.