1. Who we are and what this notice covers
AssurSight Ltd (“AssurSight”, “we”, “us” or “our”) is responsible for the personal information described in this notice when it determines why and how that information is used. In data-protection terms, AssurSight Ltd is the controller for information collected through the public AssurSight website, business enquiries, demonstration requests, direct communications and our own sales and marketing activities.
This notice applies to the website at https://assursight.com and related public web pages, forms and communications. It does not replace the privacy notice of an MSP, MSSP, customer or other organisation that uses the AssurSight platform.
Where AssurSight processes personal information contained in customer or provider data on behalf of another organisation through the AssurSight platform, the applicable customer agreement and data processing addendum govern that processing. In those circumstances, the relevant provider or customer may be the controller and AssurSight may act as its processor.
The website and AssurSight's business services are intended for organisations and business users. They are not directed to children, and we do not knowingly invite anyone under 18 to submit personal information through the website.
2. Personal information we collect
We may collect the following categories of information:
- Identity and contact information: name, business email address, telephone number and preferred contact details.
- Professional and organisation information: employer, job title, role, business sector, number of managed customers, areas of interest and information about your service-delivery model.
- Enquiry and correspondence information: demonstration requests, questions, survey responses, feedback, support enquiries, meeting notes and other messages you send to us.
- Marketing information: communication preferences, consent records, unsubscribe status and engagement with permitted business communications.
- Technical and usage information: IP address, browser type and version, device type, operating system, referring page, pages viewed, timestamps, approximate location derived from an IP address, cookie identifiers and interactions with the website and embedded forms.
- Security and administration information: logs used to protect the website, detect abuse, diagnose faults, record consent choices and investigate suspected misuse.
- Business-relationship information: where an enquiry progresses, information required to evaluate, contract for, deliver, support or administer AssurSight products or services.
Please do not provide special-category personal information, criminal-offence information or other highly sensitive information through a public website form unless we have specifically asked for it and explained why it is required.
2.1 How we collect information
We may collect information:
- directly from you when you complete a form, request a demonstration, subscribe to communications, respond to a survey, email us or speak with us;
- automatically when your browser or device interacts with the website, subject to applicable cookie and consent requirements;
- from your employer, a colleague, a referral partner or another business contact who reasonably believes that our services may be relevant to you or your organisation;
- from publicly available professional sources, such as company websites, business directories or professional networking services, where permitted by law; and
- from service providers that help us operate our website, forms, communications, CRM, security and business systems.
3. How and why we use personal information
We only use personal information where we have a lawful basis. The basis depends on the purpose and the circumstances.
| Purpose | Typical information | Lawful basis |
|---|---|---|
| Respond to enquiries, arrange demonstrations and provide requested information. | Contact, organisation, role, interests and message content. | Taking steps at your request before entering into a contract; and our legitimate interests in responding to business enquiries. |
| Manage prospective and existing business relationships, meetings, service discussions, support and account administration. | Contact, organisation, correspondence and relationship records. | Performance of a contract or steps before a contract; and our legitimate interests in managing our business relationships. |
| Operate, secure, troubleshoot and protect the website, forms and business systems. | Technical, usage, security and administration information. | Our legitimate interests in providing a secure and reliable website; and compliance with legal obligations where applicable. |
| Understand website use and improve our website, products, content and customer experience. | Usage data, form interactions, feedback and aggregated analytics. | Consent where required for non-essential cookies or similar technologies; and our legitimate interests in improving our services once collection is permitted. |
| Send relevant business-to-business product, service, event or company communications. | Contact, organisation, interests, preferences and communication engagement. | Consent where required, or our legitimate interests in relevant B2B marketing where permitted by law. You can object or unsubscribe at any time. |
| Comply with law, protect rights, prevent fraud or misuse, and establish, exercise or defend legal claims. | Information relevant to the legal, security or compliance issue. | Legal obligation and our legitimate interests in protecting AssurSight, our customers and others. |
When we rely on legitimate interests, we consider whether the use is necessary and whether your interests, rights or freedoms override those interests.
3.1 Marketing communications
Where permitted, we may send relevant business communications about AssurSight, events, product updates and related services. You can unsubscribe using the link in an email or contact us at any time. We will maintain a suppression record where necessary to respect an opt-out.
6. How long we keep information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including business, legal, regulatory, accounting, security and dispute-resolution requirements.
As a general rule, website enquiry, prospect and relationship information will be retained for no longer than 18 months from the last recorded meaningful contact or the end of the relevant contract, whichever is later. We may retain particular records for longer where a legal obligation, tax or accounting rule, limitation period, security need, complaint, dispute or contractual requirement justifies it.
Cookie and technical-data retention depends on the technology and purpose. Security logs may be retained for a period appropriate to investigation and protection needs. Backup copies may remain until overwritten through normal backup cycles and will remain protected from routine use.
7. How we protect information
We use administrative, technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction. Measures may include role-based access, authentication controls, encryption in transit, supplier due diligence, monitoring, logging, secure development and incident-management processes.
No website, network or storage system can be guaranteed completely secure. If you believe that information supplied to AssurSight may have been compromised, contact us promptly using the details below.
8. Your data-protection rights
Depending on the circumstances, UK data-protection law may give you rights to:
- be informed about how your personal information is used;
- request access to your personal information and obtain a copy;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information where the right applies;
- ask us to restrict processing in certain circumstances;
- receive certain information in a portable format;
- object to processing based on legitimate interests;
- object at any time to the use of your information for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing; and
- receive safeguards in relation to certain solely automated decisions with legal or similarly significant effects.
These rights are not absolute and exemptions may apply. We may need to verify your identity and clarify a request. We normally respond to valid rights requests within one month, subject to permitted extensions.
8.1 Automated processing
We may use CRM tools to organise business contacts, record engagement or help prioritise follow-up. We do not use information collected through the public website to make solely automated decisions that produce legal or similarly significant effects about you.
AI-assisted processing performed within the AssurSight platform for providers or customers is governed by the relevant customer agreement, data processing terms and provider/customer privacy information rather than this website notice.
9. Third-party websites
The website may link to third-party websites or services. We do not control those sites and are not responsible for their content, security or privacy practices. Their own terms and privacy notices apply when you use them.
10. Changes to this notice
We may update this notice to reflect changes in law, our website, services, suppliers or data use. We will post the updated notice on this page and revise the “Last updated” date. Where appropriate, we will take additional steps to bring a material change to your attention.
11. Contacting us and making a complaint
- Controller: AssurSight Ltd
- Website: https://assursight.com
- Email: info@assursight.com
Please use the subject “Data Protection Enquiry” when contacting us about this notice or exercising a data-protection right.
We would appreciate the opportunity to resolve a concern first. You also have the right to complain to the UK Information Commissioner's Office. More information is available at https://ico.org.uk/make-a-complaint/.