Legal

Privacy Policy

Last updated: 29 April 2026

This Privacy Policy explains how Compass Innovation Limited (“we”, “us”), trading as AssuranceLens, collects, uses, stores and protects personal data when you use the AssuranceLens platform at www.assurancelens.com.

We are the data controller for personal data you provide directly. When your organisation uploads regulatory documents that contain personal data of third parties (e.g. patient identifiers in a clinical evaluation report), we act as a data processor on your behalf under a Data Processing Agreement.

1. What data we collect

2. Lawful basis (UK / EU GDPR Art. 6)

3. Where data is stored

All customer documents, account data, audit logs and database records are stored in the EU/EEA:

Where Anthropic Claude is used as an AI inference provider, prompts may be transferred to the United States under Standard Contractual Clauses and Anthropic's zero-retention enterprise commitments. Customers who require strict EU residency can elect the Ollama on-premise deployment, in which no data leaves the cluster.

4. How long we keep data

5. Your rights (UK / EU GDPR Art. 15–22)

You have the right to:

To exercise any of these rights, email sales@virtualinspector.uk. Logged-in users can also export or delete their account directly from Settings → Privacy.

6. AI transparency (EU AI Act Art. 13)

AssuranceLens uses large language models to generate gap-analysis output. Each analysis is tagged with the model version and timestamp. AI output is always advisory; a qualified human reviewer must confirm findings before export, in line with EU AI Act Art. 14. We do not use customer documents to train AI models.

7. Sub-processors

A current list of sub-processors is available on request. Material changes to sub-processors are notified at least 30 days before they take effect.

8. Security

We follow the controls of ISO 27001 Annex A and SOC 2 Common Criteria. Highlights: AES-256-GCM at rest, TLS 1.3 in transit, MFA on all privileged accounts, immutable audit log, default-deny network policy, annual penetration test.

9. Cookies

We use only strictly-necessary cookies for authentication and session management. We do not use advertising cookies, third-party trackers, or cross-site profiling. See our Cookie Policy for details.

10. Complaints

You can complain to your local supervisory authority. In the UK, this is the Information Commissioner's Office at ico.org.uk. In the EU, your national DPA is listed at edpb.europa.eu.

11. Contact

Compass Innovation Limited (AssuranceLens)
United Kingdom
Email: sales@virtualinspector.uk

Back to home