Legal

Privacy policy

Effective 14 August 2026 · Version 1.0. This policy explains what personal data Assay Technologies Private Limited (“Assay”, “we”) collects, why, and what rights you have.

The short version. The analysis tool runs entirely in your browser and sends us nothing. The website sets no cookies and runs no analytics or advertising trackers. The only personal data we hold is what you type into the contact form or send us by email, and what we need to run a paid engagement. We never sell personal data.

1. Who we are

Assay Technologies Private Limited, H. No. 438, Sr. No. 179, Pandharkar Wasti, Akurdi, Pune 411035, Maharashtra, India is the controller of personal data described in this policy. Contact us at privacy@theassayco.com for any data protection matter.

2. The analysis tool

Our browser-based analysis tool parses the file you select inside your own browser. The file is not transmitted to us or to any third party, is not stored on any server, and is discarded when you close the tab. We receive no copy, no metadata and no record that you used it.

Okta strips connection credentials during export, so a Workflows export contains configuration structure rather than secrets. It may still contain names of folders, flows, connections and tables that identify your organisation or its systems.

3. What we collect

CategoryWhatWhyLawful basis (UK/EU)
Enquiry dataName, work email, organisation, topic, estate size, message To respond to your enquiryConsent, and legitimate interests in responding to business enquiries
Engagement dataContact details of your named personnel; the export files you supply To perform an agreed engagementPerformance of a contract
CorrespondenceEmails you send us and our replies To maintain a record of the engagementLegitimate interests, and legal obligation where applicable
Billing dataEntity name, billing address, tax identifiers To invoice and meet accounting obligationsContract and legal obligation
Referral dataPartner name, referred organisation, engagement valueTo administer the referral programme and pay feesPerformance of a contract
Server logsIP address, user agent, timestamp, page requested Security and availability of the siteLegitimate interests in operating a secure service

We do not collect special category data, and we ask you not to send it. Please do not include credentials, secrets, or personal data about third parties in the contact form.

Messaging apps

If you contact us via the WhatsApp link on our contact page, that conversation is carried by WhatsApp and is subject to WhatsApp’s own privacy terms as well as ours. We use it only to respond to your enquiry. Please do not send export files, credentials or personal data about others over WhatsApp.

4. Cookies and tracking

This website sets no cookies. We run no analytics, no advertising pixels, no session recording and no third-party trackers. Web fonts are loaded from Google Fonts, which receives your IP address as part of that request; if you prefer to avoid this, we can supply a self-hosted build of the site.

Because we set no cookies, no cookie banner is required and there is nothing to consent to or refuse.

5. How long we keep things

  • Enquiries that do not become engagements — deleted within 12 months.
  • Export files supplied for an engagement — held only as long as needed to produce and support the attestation, and deleted within 90 days of delivery unless you ask us to hold them longer for the next attestation cycle.
  • Derived records (control results, counts, scores, file hash, dates, with folder and connection names redacted) — retained for the life of the engagement plus 6 years, so that an attestation chain remains verifiable.
  • Billing records — retained as required by applicable tax and accounting law.
  • Server logs — retained no longer than 30 days.

6. Who we share with

We do not sell personal data, and we do not share it for advertising. We use a small number of processors to run the business: Netlify for website hosting, [EMAIL PROVIDER] for email, and [ACCOUNTING PROVIDER] for invoicing. Each is bound by a data processing agreement. A current list is available on request.

We may disclose data where required by law, or to establish or defend legal claims.

7. International transfers

Assay operates from India. If you are in the United Kingdom, the European Economic Area or another region with transfer restrictions, your personal data will be transferred outside that region when you engage us.

Where required, such transfers rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical measures including encryption in transit and at rest and minimisation of what is retained. A copy of the relevant clauses is available on request.

8. Your rights

Depending on where you are, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting prior processing.

United Kingdom and European Economic Area

Under the UK GDPR and EU GDPR you have all the rights above and the right to lodge a complaint with your supervisory authority — the Information Commissioner’s Office in the UK, or your national authority in the EEA.

California

Under the CCPA as amended by the CPRA you may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising. We will not discriminate against you for exercising any right.

India

Under the Digital Personal Data Protection Act 2023 you may access and correct your data, request erasure, nominate another person to exercise rights on your behalf, and raise a grievance with us before approaching the Data Protection Board. Our grievance contact is privacy@theassayco.com.

Other regions

We extend equivalent access, correction and deletion rights to everyone, wherever you are, including under Brazil’s LGPD, Canada’s PIPEDA, Australia’s Privacy Act and South Africa’s POPIA.

To exercise any right, email privacy@theassayco.com. We respond within 30 days, and will tell you if we need to verify your identity first.

9. Security

Client-side analysis means most data never reaches us at all, which is the strongest control we have. Where we do hold data we apply encryption in transit and at rest, least-privilege access limited to personnel who need it, multi-factor authentication on all administrative accounts, and deletion on the schedule above. No method of transmission or storage is completely secure, and we do not claim otherwise.

If you believe you have found a security issue, please contact security@theassayco.com. We will acknowledge within two working days and will not pursue good-faith security research.

10. Children

This is a business service not directed at children. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will delete it.

11. Changes

If we change this policy we will update the effective date above and, for material changes affecting existing clients, notify you by email. Previous versions are available on request.

12. Contact

Assay Technologies Private Limited, H. No. 438, Sr. No. 179, Pandharkar Wasti, Akurdi, Pune 411035, Maharashtra, India
General: hello@theassayco.com · +91 76663 74674
Data protection and grievances: privacy@theassayco.com
Security: security@theassayco.com