01Who we are
Assureid is operated by Avacote Ltd, a company registered in England and Wales ("Avacote", "we", "us"). Avacote is the data controller for personal data processed to provide Assureid, and this policy is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Assureid is mostly used by businesses to verify and onboard their employees, customers and suppliers. If a business uses Assureid to collect your details (for example, by asking you to complete an onboarding form), that business also decides what it asks for and how it uses your answers, and its own privacy notice applies to that use. We process that information on the business's behalf and only to provide Assureid.
02What we collect
- Account details
- Your first and last name, email address, mobile number, a unique user ID, the companies you belong to and your role in each.
- Sign-in and verification data
- Data used to sign you in without a stored password (a cryptographic salt and verifier, never the password itself), short-lived one-time codes sent by SMS, device attestation data, and records of identity verifications you take part in — who verified whom, how (QR code or code entry) and when.
- Company and onboarding information
- Company name, registration and VAT numbers, trading name, address and contact person. When you complete an onboarding form, whatever that form asks for — which can include your address, date of birth or other custom fields, answers to security questions, and bank details (bank name, account holder, account number and sort code).
- Contacts and connections
- Names, email addresses, mobile numbers and notes for the people and companies in a business's network, and the verification status of each.
- Invoices and documents
- Invoice files uploaded through the web app (PDF or image), and the details read from them, such as the companies involved, invoice number, date and amounts.
- Web sign-in requests
- When you use the phone app to approve a sign-in to the web app, we record the browser name, user agent, IP address and the approximate city, region and country derived from that IP address.
- Device and diagnostic data
- Your device's push notification token and platform, the app version, crash reports and error details, and app event logs linked to your user ID, used to keep the service working and fix problems.
What we do not collect
- We do not collect precise location (GPS).
- We do not scan identity documents or take photos or selfies. The camera is used only to read QR codes, and camera images are not stored or uploaded.
- Face ID and Touch ID are handled entirely by your device. We never receive your fingerprint or face data — only a yes/no result from your phone.
- We do not upload your address book. When you choose a contact from your phone, only the contact you pick is used, to fill in a form.
- We do not use advertising identifiers or third-party analytics or advertising SDKs.
03How we collect it
- From you, when you register, sign in, complete forms, add contacts, verify someone or upload invoices.
- From other users, for example when a business, employer or supplier adds you as a contact, invites you to verify your identity, or enters your details to set up your account. Details entered this way are copied to your account when you register.
- From your device, with your permission: the camera (to scan QR codes), your contacts (only the contact you select), Face ID or Touch ID (checked on the device) and notifications.
- Automatically, as you use the service: push tokens, device attestation, crash reports, app event logs and, for web sign-in requests, browser and IP address details.
04How we use it
We use personal data only to run Assureid, and for these purposes:
- Creating and managing your account, signing you in, and approving sign-ins to the web app. (Performance of our contract with you or your business.)
- Verifying identities between people and businesses, onboarding employees, customers and suppliers, and managing contacts and connections. (Contract; and the business's legitimate interest in knowing who it deals with.)
- Sending, reading, approving and routing invoices. (Contract.)
- Sending sign-in codes, invitations, activation emails and notifications about verifications and tasks. (Contract.)
- Keeping the service secure: detecting tampered apps and compromised devices, rate-limiting and preventing fraud. (Legitimate interests in protecting users and the service.)
- Diagnosing crashes and fixing faults. (Legitimate interests in a reliable service.)
- Meeting legal obligations, such as responding to lawful requests. (Legal obligation.)
We do not use your data for advertising, we do not sell it, and we do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
05Who we share it with
We share personal data only with the service providers below, and only what each needs to do its job. They act as our processors under written data processing agreements that require them to use the data only on our instructions, keep it confidential and secure, and give it the same or equal protection as this policy.
Google (Firebase & Google Cloud)
Data · Account records, company and contact records, uploaded invoices, push notification tokens, crash reports and service logs.
Purpose · Hosting, database, file storage, sign-in tokens, push notifications (Firebase Cloud Messaging) and crash reporting (Firebase Crashlytics).
Apple
Data · Push notification tokens and message content; device attestation data.
Purpose · Delivering notifications to iPhones and confirming requests come from a genuine copy of the app (App Attest).
Twilio
Data · Mobile number and the text of the message.
Purpose · Sending SMS sign-in codes, account deletion codes, registration codes and verification invitations.
Amazon Web Services (Amazon SES)
Data · Email address and the content of the email.
Purpose · Sending account activation and registration emails.
Microsoft (Azure AI Document Intelligence)
Data · Invoice files you or your business upload.
Purpose · Reading invoice details (such as invoice number, date and amounts) so they don't have to be typed in.
ip-api.com
Data · The IP address of a browser asking to sign in to the web app.
Purpose · Showing the approximate city and country of that sign-in request so you can recognise it before approving it.
Talsec (freeRASP)
Data · Device security signals, such as whether the device is jailbroken or the app has been tampered with.
Purpose · Protecting your account from compromised devices and modified copies of the app.
Within Assureid, information is also visible to other users where that is the point of the service — for example, a business you are verified with can see your verified details, and the answers you give on a business's onboarding form are shared with that business.
We may also disclose data if required by law, to protect the rights, safety or property of our users or others, or to a successor if Avacote's business is reorganised or sold, in which case this policy will continue to apply.
06Where it is stored
Our servers and databases run on Google Cloud, primarily in London (United Kingdom), with supporting services in the European Union (Belgium and Ireland). Some of our providers, such as Twilio, Apple, Amazon and Talsec, may process data in other countries, including the United States. Where personal data leaves the UK, we rely on UK adequacy regulations or on safeguards approved by the UK Information Commissioner, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
07How we protect it
- All connections are encrypted in transit, and the app pins our API's certificates to block interception.
- Sign-in uses the Secure Remote Password protocol: our servers store only a verifier, never your password. Sign-in credentials are kept in your device's secure Keychain.
- Registration data is additionally end-to-end encrypted between the app and our API.
- Apple App Attest and on-device integrity checks help ensure only genuine, untampered copies of the app on uncompromised devices can reach your account.
- Data is encrypted at rest by our cloud providers, and access is limited to authorised staff.
- Deletion and registration codes are hashed, expire within minutes, and are rate-limited.
No system is perfectly secure, but we work to protect your data and will notify you and the regulator of a personal data breach where the law requires.
08How long we keep it
- Account, company, contact and onboarding data — while your account, or the business account it belongs to, is active.
- One-time codes and sign-in sessions — minutes; they expire automatically, typically within 5 to 10 minutes.
- Crash reports — up to 90 days. Service logs — kept for a limited period for security and troubleshooting, normally no longer than 30 days.
- After you delete your account — your personal data is permanently removed within 7 days. Business records you took part in, such as invoices and verification audit trails, are anonymised so they no longer identify you, unless we are legally required to keep them for longer (for example, for tax or accounting), in which case we keep them only for as long as that obligation lasts.
09Deleting your account
You can delete your Assureid account at any time from inside the app:
- Open Settings, then Profile, then tap Delete Account.
- Confirm with Face ID or Touch ID.
- Enter the 6-digit code we send by SMS to your registered mobile number.
You will be signed out and your account is scheduled for deletion. Your personal data is permanently removed within 7 days. If you change your mind, sign back in within those 7 days and tap Cancel deletion.
If you can't use the app, or you want data deleted that a business entered about you without you having an account, email privacy@avacote.com from the email address linked to the data. We will verify your request and respond within one month.
10Your rights and choices
Under UK data protection law you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it, including processing based on legitimate interests;
- receive your data in a portable format; and
- withdraw consent at any time, where we rely on consent.
Revoking permissions: you can turn off camera, contacts, Face ID and notification access for Assureid at any time in your device's Settings. Some features, such as scanning QR codes, won't work without them.
To exercise any right, email privacy@avacote.com. We respond within one month. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to put things right first.
11This website
The assureid.ai website does not use analytics, advertising or tracking cookies. It remembers your light or dark theme choice in your browser's local storage, which never leaves your device. Fonts are loaded from Google Fonts, which receives your IP address to deliver them.
12Changes to this policy
We may update this policy as Assureid changes. The effective date at the top shows when it was last revised. If we make significant changes, we will tell you in the app or by email before they take effect.
13Contact us
Questions, requests or concerns about privacy:
Avacote Ltd (Assureid)privacy@avacote.com