Legal
Privacy Policy
Last updated: 29 April 2026
This Privacy Policy explains how Compass Innovation Limited (“we”, “us”), trading as AssuranceLens, collects, uses, stores and protects personal data when you use the AssuranceLens platform at www.assurancelens.com.
We are the data controller for personal data you provide directly. When your organisation uploads regulatory documents that contain personal data of third parties (e.g. patient identifiers in a clinical evaluation report), we act as a data processor on your behalf under a Data Processing Agreement.
1. What data we collect
- Account data: name, work email, hashed password, MFA status, organisation, role.
- Customer documents: regulatory submissions, design inputs, technical files, and any text these contain. Encrypted at rest (AES-256-GCM) and in transit (TLS 1.3).
- Usage data: audit log of authentication, analyses run, gaps generated, exports, and access events. Required for SOC 2 and ISO 27001 audit evidence.
- Billing data: handled by Stripe; we receive only the customer ID and subscription state, never card numbers.
- Error monitoring data: uncaught errors and stack traces sent to Sentry (EU region). Personally-identifying information is suppressed by default.
2. Lawful basis (UK / EU GDPR Art. 6)
- Contract performance — to deliver the service you have subscribed to.
- Legitimate interests — security monitoring, fraud prevention, audit logging, product improvement.
- Legal obligation — tax, accounting, response to lawful requests from supervisory authorities.
- Consent — optional product analytics and marketing communications. Consent is freely revocable at any time.
3. Where data is stored
All customer documents, account data, audit logs and database records are stored in the EU/EEA:
- Application + database hosted in the EU on EU-resident infrastructure.
- Database: Neon Postgres, eu-west-2 (London).
- Error monitoring: Sentry, Frankfurt (DE) region.
- Email delivery: Resend, EU region.
- Payment processing: Stripe Payments Europe Ltd, Ireland.
Where Anthropic Claude is used as an AI inference provider, prompts may be transferred to the United States under Standard Contractual Clauses and Anthropic's zero-retention enterprise commitments. Customers who require strict EU residency can elect the Ollama on-premise deployment, in which no data leaves the cluster.
4. How long we keep data
- Customer documents: until you delete them, or 30 days after subscription end.
- Audit log: 6 years (SOC 2 / ISO 27001 retention requirement).
- Account record: until you request deletion under Art. 17.
- Backups: 7 days rolling point-in-time-restore.
5. Your rights (UK / EU GDPR Art. 15–22)
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Port your data to another provider
- Object to processing based on legitimate interests
- Restrict processing
- Withdraw consent at any time
To exercise any of these rights, email sales@virtualinspector.uk. Logged-in users can also export or delete their account directly from Settings → Privacy.
6. AI transparency (EU AI Act Art. 13)
AssuranceLens uses large language models to generate gap-analysis output. Each analysis is tagged with the model version and timestamp. AI output is always advisory; a qualified human reviewer must confirm findings before export, in line with EU AI Act Art. 14. We do not use customer documents to train AI models.
7. Sub-processors
A current list of sub-processors is available on request. Material changes to sub-processors are notified at least 30 days before they take effect.
8. Security
We follow the controls of ISO 27001 Annex A and SOC 2 Common Criteria. Highlights: AES-256-GCM at rest, TLS 1.3 in transit, MFA on all privileged accounts, immutable audit log, default-deny network policy, annual penetration test.
9. Cookies
We use only strictly-necessary cookies for authentication and session management. We do not use advertising cookies, third-party trackers, or cross-site profiling. See our Cookie Policy for details.
10. Complaints
You can complain to your local supervisory authority. In the UK, this is the Information Commissioner's Office at ico.org.uk. In the EU, your national DPA is listed at edpb.europa.eu.
11. Contact
Compass Innovation Limited (AssuranceLens)
United Kingdom
Email: sales@virtualinspector.uk
