Privacy Policy

Last updated: June 16, 2026

1. Introduction

This Privacy Policy explains how Assenture ("Assenture", "we", "us", "our") collects, uses, shares, retains, and protects personal data when you visit our website at assenture.app, use the Assenture web or mobile applications, communicate with us, or otherwise interact with the Service (as defined in our Terms of Service). It applies to personal data we process as a controller. Where we process personal data on behalf of a customer (for example information that customer uploads about its own employees, suppliers, or contacts), we act as a processor and our Data Processing Addendum applies.

The Service is intended for individuals who are at least 18 years of age. We do not knowingly collect personal data from anyone under 18.

2. Who we are and how to contact us

Assenture is the controller of personal data described in this Privacy Policy. You can reach our data protection team at business@assenture.app. For general legal enquiries write to business@assenture.app.

3. Personal data we collect

3.1 Data you provide

  • Account data: name, email address, password (hashed), profile photo, language and time zone, organisation name, role, and any other information you choose to add.
  • Billing data: billing name and address, country, tax identification number, plan, transaction history, and last four digits and brand of your payment card. Full payment card details are handled by our payment processors, not by us.
  • Content data: information you upload to or generate within the Service, including assets, contacts, invoices, bills, expenses, contracts, files, comments, prompts, and AI outputs.
  • Communications: messages you send to us by email, chat, or support tools, and the metadata of those messages.
  • Survey, research, and event data: responses you give if you take part in research or attend an event we organise.

3.2 Data we collect automatically

  • Device and connection data: IP address, device identifier, browser type and version, operating system, screen size, referring URL, language settings.
  • Usage data: pages and features used, actions taken, timestamps, performance metrics, crash logs, search queries, and feature flags.
  • Cookies and similar technologies: as described in our Cookies Policy.
  • Security telemetry: sign in attempts, IP reputation signals, and other information used to detect and prevent abuse.

3.3 Data from third parties

  • Identity providers: if you sign in with Google or another identity provider, we receive the data you authorise that provider to share with us (typically name, email, and profile picture).
  • Integrations you enable: data from accounting, banking, payment, storage, or AI services you connect to the Service, in accordance with your configuration.
  • Service providers: our payment processors, fraud prevention providers, and analytics providers may share data with us about transactions and risk signals.
  • Publicly available sources: company registries, social networks where you have made information public, and similar sources, used for business verification and marketing.

4. How we use personal data and our legal bases

We process personal data only where we have a legal basis to do so. The table below summarises the main purposes and legal bases. Where we rely on legitimate interests we have carried out a balancing assessment to ensure your rights and interests are not overridden.

PurposeCategoriesLegal basis (GDPR / UK GDPR)Legal basis (PDPA, Singapore)
Creating and operating your account, providing the Service, customer supportAccount, content, communications, device, usagePerformance of a contract; legitimate interests in operating our businessConsent; necessary for the provision of the Service requested
Billing, fraud prevention, tax complianceBilling, device, usagePerformance of a contract; legal obligation; legitimate interests in preventing fraudNecessary for performance of the contract; legal obligation
Security, abuse prevention, audit logsDevice, usage, security telemetry, contentLegitimate interests in protecting the Service and our users; legal obligationLegitimate interests; necessary for security
Improving and developing the Service, including aggregated analyticsUsage, device, content (aggregated and de identified)Legitimate interests in improving the ServiceConsent or legitimate interests, as applicable
Marketing communications about our products and offersAccount, communicationsConsent, or legitimate interests for existing customers within the limits of the soft opt inConsent or deemed consent where permitted, with an opt out
Compliance with law, response to lawful requests, defence of legal claimsAll categories as requiredLegal obligation; legitimate interests in establishing or defending claimsLegal obligation; legitimate interests

5. AI features

Some features of the Service use artificial intelligence. When you use these features, prompts and selected content you submit are sent to our AI provider on your behalf in order to generate the output you requested. We do not permit our AI providers to use your content to train their general purpose foundation models. We may store prompts and outputs to provide history, support, abuse prevention, and product improvement. AI outputs may be inaccurate and must be reviewed by you before use. See our Financial Information Disclaimer. We do not use automated decision making that produces legal or similarly significant effects on you without meaningful human involvement.

6. How we share personal data

We share personal data only in the following circumstances:

  • With our service providers (sub-processors): hosting and content delivery, database, authentication, email and notifications, customer support, analytics, error monitoring, payment processing, fraud prevention, and AI providers. A current list is available on request and is published in or linked from this policy. We bind sub-processors by written contract to standards no less protective than those in our Data Processing Addendum.
  • With other users of the Service in your organisation or with whom you choose to share content (for example through a share link or invitation).
  • With integrations you enable in accordance with your configuration.
  • With professional advisers such as lawyers, accountants, auditors, bankers, and insurers, where reasonably necessary.
  • In connection with a corporate transaction such as a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
  • To comply with law or protect rights where we believe in good faith that disclosure is necessary to comply with a legal obligation, lawful request from a public authority, or to protect the rights, property, or safety of Assenture, our users, or others.

We do not sell personal data and we do not share it for cross context behavioural advertising as those terms are defined under the CCPA.

7. International transfers

Assenture operates globally and personal data may be transferred to, and processed in, countries other than the country in which you are located. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision, we use the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss equivalent, as applicable. Where we transfer personal data out of Singapore we take steps required by the PDPA to ensure overseas recipients provide a comparable standard of protection. You can request a copy of the safeguards we use by writing to business@assenture.app.

8. Retention

We retain personal data only for as long as needed for the purposes set out in this Privacy Policy or as required by law. The main retention periods are:

  • Account data: for as long as your account is active, plus up to 90 days after closure for backup and audit purposes.
  • Customer content: as set out in your subscription and in our Terms of Service; available for export for 30 days after termination, then deleted within 90 days, subject to backup rotation.
  • Billing and tax records: typically 5 to 7 years after the end of the tax year, in line with applicable law.
  • Security and audit logs: typically 12 to 24 months, longer where required for investigations.
  • Marketing data: until you withdraw consent or object, and for a reasonable period afterwards to demonstrate compliance.
  • Support communications: typically up to 3 years after the matter is closed.

When personal data is no longer needed we will delete or anonymise it. Anonymised data may be retained without time limit.

9. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, role based access control, multi factor authentication for administrative access, vulnerability scanning, penetration testing, secure software development practices, vendor risk management, and an incident response plan. No system is perfectly secure; we cannot guarantee absolute security but we work hard to protect your data. In the event of a personal data breach affecting you, we will notify you and the relevant authorities where required by law.

10. Your rights

Depending on where you live, you may have the following rights in relation to your personal data, subject to limits and exceptions in law:

  • Access: obtain confirmation that we process your personal data and a copy of it.
  • Correction: have inaccurate or incomplete data corrected.
  • Deletion: have personal data erased in certain circumstances.
  • Restriction: have processing restricted in certain circumstances.
  • Objection: object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
  • Portability: receive personal data in a structured, commonly used, machine readable format and transmit it to another controller.
  • Withdraw consent: where we rely on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.
  • Not to be subject to solely automated decisions producing legal or similarly significant effects.
  • Lodge a complaint with a supervisory authority (for example the Personal Data Protection Commission of Singapore, the UK Information Commissioner's Office, your local EU data protection authority, or the California Privacy Protection Agency).

California residents also have the right not to receive discriminatory treatment for exercising privacy rights, and the right to designate an authorised agent. Residents of certain other US states (such as Colorado, Connecticut, Virginia, Utah, and Texas) have similar rights under their respective laws. To exercise any right, write to business@assenture.app. We will respond within the time required by law (typically 30 days, extendable where permitted).

11. Cookies

We use cookies and similar technologies as described in our Cookies Policy. You can manage non-essential cookies through our cookie preference centre.

12. Marketing

We may send you marketing communications about products and services we think you will find useful, where permitted by law. You can opt out at any time by clicking the unsubscribe link in any marketing email or by writing to business@assenture.app. Opting out of marketing does not stop service or transactional messages.

13. Third party links

The Service may contain links to third party websites and services. We are not responsible for the privacy practices of those third parties. Please read their privacy notices before submitting personal data to them.

14. Children

The Service is not intended for, and we do not knowingly collect personal data from, anyone under 18. If you believe a child has provided personal data to us, please write to business@assenture.app and we will take steps to delete it.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes we will notify you by email or through the Service. The "Last updated" date at the top of this policy indicates when it was most recently revised.

16. Contact

For privacy enquiries or to exercise your rights, write to business@assenture.app. For legal matters, write to business@assenture.app.