Assay is provided by Ferrolo, referred to here as “we”, “us” and “our”. Questions about this document go to assay@ferrolo.com.
1. What this policy covers
This policy explains how we handle personal data as the controller: about the people who use Assay, visit our website, ask for access or contact us.
The conversations our customers check with Assay are handled differently. For those we act on our customer’s behalf, as their processor, under our data processing agreement. If you were a caller, customer or agent in one of those conversations, the organisation that sent it to us is responsible for it and you should contact them first.
2. What we collect
- Account details: your name, work email, organisation, role, a scrambled copy of your password, and two-factor and passkey details if you turn them on.
- How you use the service: sign-ins, actions such as reviewing a result or changing a rule, IP addresses, browser details and error logs.
- Billing details: your organisation’s billing contact, plan and invoices. Card details go straight to our payment provider, Stripe, and never reach us.
- Access requests and messages: your name, work email, company, team size, anything you write to us and the IP address it was sent from.
The public website sets no cookies and does not track you. The app sets only the cookies it needs to keep you signed in, protect forms and remember your display preference.
3. How we use it, and why we are allowed to
- To provide the service, keep your account working, bill your organisation and support you: because it is necessary for our contract with your organisation.
- To keep the service secure, prevent spam and abuse, and investigate problems: because we have a legitimate interest in running a safe service.
- To understand how Assay is used and to improve it: because we have a legitimate interest in making the product better.
- To tell you about changes to the service and, where you are a business contact, about our products. You can opt out of marketing at any time.
- To keep records and meet tax, accounting and legal duties: because the law requires it.
We do not make decisions about you that have legal or similarly significant effects based only on automated processing.
4. Conversations our customers check
We use them to check them against our customers’ rules, to show the results and evidence, and to support, secure and improve Assay, as our terms and data processing agreement set out.
We do not use them to train artificial intelligence models, and we only use AI providers who are not allowed to train on them. We do not sell them.
6. Where it is kept
Personal data may be stored and processed in the United Kingdom, the European Economic Area, the United States or other countries where we and our providers operate, and this may change over time. When it is transferred outside the United Kingdom or the European Economic Area, we rely on UK adequacy decisions or on approved safeguards such as the UK International Data Transfer Addendum and the EU standard contractual clauses.
7. How long we keep it
- Account details: while the account exists, then up to six years for our business and tax records.
- Usage and security logs: up to 12 months, unless needed longer to investigate a problem.
- Access requests and messages: up to 24 months after our last contact.
- Conversations our customers check: as set out in the data processing agreement.
- Aggregated or de-identified data that no longer identifies anyone may be kept indefinitely.
8. Your rights
Under UK data protection law you can ask to see the personal data we hold about you, correct it, delete it, restrict or object to how we use it, and receive a copy to move elsewhere. Some rights have limits, for example where we must keep records by law. Email assay@ferrolo.com and we will answer within one month.
If you are unhappy with how we handled your data, please tell us first. You can also complain to the Information Commissioner’s Office at ico.org.uk.
9. Security
We encrypt data in transit and at rest, keep each organisation’s data apart, limit who on our team can reach it, offer two-factor sign-in and passkeys, and record changes in an audit trail. No system is perfectly secure; if a breach affects you we will tell you as the law requires.
10. Children
Assay is a business service and not intended for anyone under 18.
11. Changes to this policy
We may update this policy at any time. The updated version applies from when it is published here, and the date at the top shows when it last changed.