AssetWRX Privacy Policy

Last updated: 19 July 2026 Effective: 19 July 2026 Version: 1.1.0

This Privacy Policy explains how AssetWRX (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you use our mobile applications, web application, and related services (collectively, the “Service”). It is written to comply with the EU General Data Protection Regulation, the UK GDPR and the Data Protection Act 2018, the California Consumer Privacy Act / California Privacy Rights Act, and platform requirements set by Apple and Google.

1. Who is responsible for your data

AssetWRX is operated by Cogniforma Ltd, a company registered in England & Wales with company number 16176541, whose registered office is at 17 Quaves Road, Slough, SL3 7NX, UK (“Cogniforma”, “we”, “us”). For privacy matters you can contact us at privacy@assetwrx.com.

Our supervisory authority in the UK is the Information Commissioner’s Office (ICO). Our Data Protection Officer, where one is appointed, is reachable at dpo@assetwrx.com; otherwise privacy enquiries are handled by our privacy team at the same address.

1.1 Our role — controller and processor

  • When we act as a controller. We are the controller for the personal data we determine the purposes of: your account and identity data, billing data, device and diagnostic data, and marketing preferences. This policy governs that data.
  • When we act as a processor. For the content you and your organisation put into the Service — your assets, inspections, jobs, photos, videos, documents, and the contact, requester and contractor records you create (“Customer Content”) — you (or your organisation) are the controller and we act as your processor, processing that content only on your documented instructions to provide the Service. Our processing of Customer Content is governed by our Data Processing Agreement, which forms part of your agreement with us. As the controller of Customer Content, you are responsible for having a lawful basis and for meeting transparency obligations towards the individuals whose data it contains (see section 5).

2. Scope

This policy applies to personal data processed when you:

  • create an account, sign in, or use any feature of the Service;
  • contact our support team;
  • receive transactional or, where you have opted in, marketing communications from us; or
  • visit our public website at assetwrx.com.

If your organisation has its own data processing agreement with us, that agreement controls in the event of any conflict for data processed on behalf of your organisation.

2.1 Global standard and your local law

We engineer the Service to a single, high data-protection standard equivalent to the EU/UK GDPR, and apply it globally. Where you use the Service in a jurisdiction with its own data-protection law — including the Kingdom of Saudi Arabia (Personal Data Protection Law) and the United Arab Emirates (Federal Decree-Law No. 45 of 2021) — you are responsible for ensuring that your use of the Service, and your processing of Customer Content, complies with the law applicable to you and to your data subjects. We will provide reasonable assistance to help you meet those obligations.

3. Categories of personal data we process

3.1 Data you provide directly

  • Account data: first and last name, email address, password (hashed), language and time-zone preferences, default workspace currency.
  • Workspace data: workspace name, branding, billing email, team membership, contractor and contact records you create.
  • Content data (Customer Content): assets, inspections, jobs, photos, videos, voice notes, dictated text, documents, signatures, QR scan results, location coordinates you elect to capture, and any other content you create in the Service. See section 5 for our role in processing this.
  • Billing data: name, billing address, VAT/tax identifier, and payment instrument details. Payment instruments themselves are processed by Stripe (see section 6); we never store full card numbers.
  • Support correspondence: the contents of any tickets, chat sessions, or emails you send us.

3.2 Data we collect automatically

  • Device and technical data: device model, operating system, app version, IP address, preferred language, time-zone offset, screen size, and crash diagnostics.
  • Usage data: features you use, screens you visit, errors encountered, and timing metrics (only after you have granted analytics consent — see section 9).
  • Cookies and similar technologies: see our Cookie Policy.

3.3 Data from third parties

  • Authentication providers (Google, Apple, Microsoft) — if you sign in via one of these providers, we receive your name, email, and a stable provider identifier. We do not receive your password.
  • Stripe — billing status, subscription state, invoice metadata.

4. Purposes and lawful bases

For the personal data we process as controller, we rely on the following lawful bases:

Purpose Lawful basis (GDPR Art. 6)
Create and maintain your account; provide the core Service Contract (Art. 6(1)(b))
Bill you for paid plans; collect taxes Contract + legal obligation (Art. 6(1)(b), (c))
Send service notifications (incident, security, billing, inspection reminders) Contract + legitimate interests (Art. 6(1)(b), (f))
Detect, investigate, and prevent fraud, abuse, or unauthorised access; secure the Service Legitimate interests (Art. 6(1)(f))
Crash reporting and stability monitoring (Sentry — PII-scrubbed) Legitimate interests (Art. 6(1)(f))
Product analytics (PostHog) Consent (Art. 6(1)(a))
Marketing email and push notifications Consent (Art. 6(1)(a))
Comply with legal obligations (tax, accounting, lawful requests) Legal obligation (Art. 6(1)(c))
Defend or assert legal claims Legitimate interests (Art. 6(1)(f))

For Customer Content you upload, you are the controller and are responsible for establishing the lawful basis for that processing. If Customer Content includes special category data (Art. 9) — for example health-related photographs in an inspection — you are responsible for ensuring an Article 9 condition is met (such as the explicit consent of the individual concerned) before you upload it. We do not solicit special category data and provide tools to help you avoid capturing it unnecessarily.

5. How we handle Customer Content

Your inspections, assets, jobs, photos, voice notes, documents and other Customer Content remain yours. We act as your processor and use it solely to provide the Service to you and your workspace on your instructions, including:

  • showing, indexing, and searching your content in the app;
  • generating reports, summaries, and AI-assisted suggestions that you request;
  • backing up your data to ensure durability;
  • enabling sharing within teams or with collaborators you invite.

We do not use your Customer Content to train our own AI models. Specific AI features (asset report generation, inspection summarisation, image analysis) send the relevant Content to Google (Gemini API) as a sub-processor, under Google’s applicable API data-processing terms. AI features are optional and can be avoided by not invoking them.

Because you are the controller of Customer Content, you are responsible for providing any notice required to the individuals it concerns (for example your own contacts, contractors, requesters, or inspection subjects), and for having a lawful basis for including their data. Our processing of Customer Content is governed by our Data Processing Agreement.

6. Sub-processors and recipients

We share personal data with the following sub-processors, each under a data processing agreement that imposes confidentiality and security obligations consistent with the GDPR. A current list is also published at assetwrx.com/legal/subprocessors.

Sub-processor Purpose Region
Supabase (database, auth, storage, edge functions) Core infrastructure EU / US (configurable)
Stripe Payments Europe Ltd / Stripe Inc. Subscription and credit-pack billing EU + US
Resend, Inc. Transactional and (with consent) marketing email delivery US
PostHog Inc. Product analytics — only when you have consented EU (EU Cloud)
Functional Software, Inc. (Sentry) Error and crash monitoring US
Google LLC (Gemini API) AI features you invoke US
Komoot GmbH (Photon geocoding, OpenStreetMap data) Address autocomplete and geocoding EU
Apple Push Notification Service Delivery of iOS push notifications US
Google Firebase Cloud Messaging Delivery of Android push notifications US
Cloudflare R2 (where enabled) Object storage for large media EU + US

We may also disclose personal data:

  • to professional advisers (legal, accounting, audit) under confidentiality obligations;
  • in connection with a corporate transaction (merger, acquisition, restructuring), in which case you will be notified before personal data becomes subject to a different privacy policy;
  • when required by law, regulation, court order, or to enforce our Terms of Service or protect the rights, property, or safety of the Service, our users, or others.

We do not sell personal data and we do not share personal data for cross-context behavioural advertising as defined by the CCPA / CPRA.

7. International transfers

Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on:

  • the European Commission’s Standard Contractual Clauses (2021/914) and, for UK transfers, the UK International Data Transfer Addendum;
  • Supplementary measures as described in our Transfer Impact Assessment (available on request);
  • For transfers to providers in countries benefiting from an adequacy decision (e.g. UK→EEA), that adequacy decision.

8. Retention

We retain personal data for as long as necessary to provide the Service and to comply with our legal obligations. Specifically:

  • Account and content data: until you delete your account. Upon deletion, business records are retained for up to 30 days in a soft-deleted state to enable recovery; thereafter they are hard-deleted or irreversibly anonymised. See the Data Deletion Policy.
  • Billing records: retained for the statutory period required by tax authorities in our operating jurisdictions (typically 6–10 years).
  • Audit logs (security and consent): retained for up to 7 years for legal-defence purposes.
  • Marketing consent records: retained for as long as you are subscribed plus 3 years after withdrawal, to evidence the lawful basis of past sends.

9. Cookies, analytics, and tracking

The mobile apps do not use tracking that links to advertising identifiers. We do not request the iOS App Tracking Transparency prompt for advertising purposes.

Within the app and on our website you can independently consent to:

  • Analytics — product usage data captured by PostHog, used to understand which features are used and where they break. Off by default; you may grant or withdraw consent at any time in Profile → Privacy & Data → Communication preferences (in-app) or via the cookie banner (web).
  • Marketing — see section 11.

Crash and security telemetry (Sentry) is processed under legitimate interests and is not controllable via a consent toggle. We strip directly identifying information (email, names, authentication headers) from crash payloads before transmission.

10. Your rights

If you are in the EEA, UK, Switzerland, or California, you have the right to:

  • Access your personal data and obtain a copy in a portable format.
  • Rectify inaccurate or incomplete data.
  • Erase (“be forgotten”) your data, subject to lawful retention exceptions.
  • Restrict or object to certain processing (in particular, processing based on legitimate interests, including profiling).
  • Withdraw consent at any time, where processing is based on consent — without affecting the lawfulness of processing before withdrawal.
  • Data portability — receive your data in a structured, machine-readable format.
  • Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our AI features generate suggestions for your review and do not make such decisions about you without human involvement.

Where we act as processor of Customer Content, we will refer a request we receive from one of your data subjects to you (the controller) and assist you in responding.

You can exercise most of these rights directly:

  • Access / portability: Profile → Privacy & Data → Export My Data.
  • Erase: Profile → Privacy & Data → Delete Account.
  • Marketing withdrawal: Profile → Privacy & Data → Communication preferences.
  • Other requests: privacy@assetwrx.com.

We respond within 30 days (extendable by a further 60 days for complex requests, in which case we will notify you).

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with a supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). In other EEA states, you can find your local authority via the European Data Protection Board (edpb.europa.eu).

11. Marketing

We send marketing communications (product updates, tips, promotions) only when you have given us explicit opt-in consent. Marketing consent is collected separately from acceptance of these Terms and Privacy Policy; we never treat acceptance of either as marketing consent.

Each marketing email contains a one-click unsubscribe link. You can also manage marketing preferences in Profile → Privacy & Data → Communication preferences. Withdrawal is recorded immediately and we will not send marketing email or push for the channel(s) you withdraw.

See the Marketing Consent Policy for further detail.

12. Security

We implement technical and organisational measures appropriate to the risk, including:

  • TLS 1.2+ in transit for all client-server communication;
  • AES-256 at rest for all object storage and database backups;
  • role-based access controls and database-level row-level security;
  • audit logging of administrative actions;
  • periodic penetration tests and dependency scanning;
  • least-privilege access for engineering staff.

No system is perfectly secure. We will notify affected users and supervisory authorities of a personal data breach within the timescales required by Art. 33 / 34 GDPR. Where a breach affects Customer Content, we will notify you (as controller) without undue delay so that you can meet your own notification obligations.

13. Children

The Service is not directed to children under 16, and we do not knowingly collect personal data from children. Where we operate in the United States, we do not knowingly collect personal data from children under 13 (COPPA). If you become aware that a child has provided us with personal data, please contact privacy@assetwrx.com and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. When changes are material we will:

  • update the version and effective date at the top of this document;
  • post the updated policy in the Service;
  • if you have an account, present the updated policy when you next open the app and require acknowledgement before continued use.

15. Contact