Assisto logo
Legal homeTermsPrivacyCookiesAcceptable useFAQ

Assisto legal

Privacy Policy

This policy explains what personal data we collect, why we use it, who we share it with, and the choices and rights available to you.

Last updated: 15 July 2026

1. Who we are

Assisto is a Business OS and AI-assisted business workflow service for small businesses operated by WEBISITY STUDIO LTD. For privacy questions, contact info@assistocrm.com.

WEBISITY STUDIO LTD is registered in England and Wales with company number 16924225. Registered office: 3rd Floor, 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.

Where we decide why and how personal data is used, we act as controller. Where a business user uploads or sends personal data about its own customers, suppliers, workers, or contacts for us to process on its behalf, that business may be the controller and Assisto may act as processor.

Our Terms of Service include a data processing addendum for customer data, invoices, receipts, chat messages, payment data, and bank/Open Banking data processed through Assisto.

2. Personal data we collect

  • Account data, such as email address, password hash, account status, and login/session information.
  • Business profile data, such as business name, contact name, business type, company number, address, phone, country, currency, and language preferences.
  • Chat and app data, such as web/mobile messages, onboarding replies, uploaded notes, and message metadata.
  • CRM data, such as customers, suppliers, contact details, notes, quotes, invoices, tasks, reminders, contract schedules, and payment records.
  • Document and receipt data, such as uploaded files, extracted text, OCR results, summaries, classifications, and accountant exports.
  • Open Banking and payment data, such as bank connection records, transaction data, payment watch records, Stripe customer or subscription identifiers, and billing events.
  • AI workflow data, such as prompts, tool results, assistant replies, translations, extracted fields, and limited context needed to complete your requested workflow.
  • Legal consent records, such as the version of the terms or privacy policy accepted, timestamp, and related account identifiers.
  • Technical and security data, such as IP address, user agent, rate-limit records, audit logs, errors, and service diagnostics.
  • Support and communication data, such as messages you send to us and notes from support interactions.

3. Where data comes from

We collect data directly from you, from your use of Assisto, from payment and billing providers, from TrueLayer or Plaid where you connect an Open Banking or bank-data account, from third-party app connectors where you choose to connect them, and from files or messages you choose to upload or send.

When you use AI-assisted features, we may send the minimum relevant message, document, CRM, quote, invoice, payment, or task context to AI gateway, model, transcription, OCR, or document processing providers so they can process your request and return a result.

4. Why we use personal data

  • To create, secure, and manage your account.
  • To provide CRM, AI, document, payment, billing, and reminder features.
  • To process instructions you send through the web app or mobile app.
  • To generate, classify, extract, summarise, and organise business records.
  • To provide support, troubleshoot issues, and improve reliability.
  • To prevent fraud, abuse, spam, unauthorised access, and misuse of paid or high-cost features.
  • To comply with legal, tax, accounting, regulatory, and dispute obligations.
  • To send service messages and, where permitted, product updates or marketing communications, including unsubscribe controls and a valid postal address where required by law.

5. Lawful bases

Depending on the context, we rely on one or more lawful bases under UK GDPR, including:

  • Contract, where processing is needed to provide Assisto to you.
  • Legitimate interests, such as service security, abuse prevention, product improvement, and business-to-business communications.
  • Legal obligation, where we must keep or disclose information to comply with law.
  • Consent, where we ask for consent for a specific activity, such as optional marketing or optional non-essential cookies.

6. Google Workspace data

If you connect Gmail, Google Drive, Google Calendar, Google Docs, Google Sheets, or Google Contacts, Assisto requests read-only access and uses Google data only to provide the feature you ask for, such as finding an email, event, file, document, spreadsheet, or contact and answering or preparing an internal draft from it. Assisto does not send, edit, delete, or otherwise change content in your Google account.

Google content returned for a connector request is processed as transient context and is not saved as durable business memory; the generic connector-memory tool rejects Google Workspace content. Assisto may keep connection metadata, security and audit records that identify the connector and tool used without storing the returned content. An answer or draft you choose to create from Google data remains in a provenance-tagged Assisto chat. During this read-only release, Google-derived chat content cannot be converted into a separate customer, supplier, quote, invoice, task, note, document, or other business record. Deleting a tagged Google chat permanently removes its messages, conversation state, and correlated AI workflow records from the active database. A verified support request can also remove an exact legacy Google chat and Google connector metadata.

Google connector content is processed through Composio to operate the connection and may be sent to Google Cloud Vertex AI only when needed to answer your current request. Assisto forces live Google connector results and provenance-tagged Google chat history to that Vertex AI route and fails closed if it is unavailable, even if the default model-provider configuration changes. Assisto does not use Google user data to train or improve general-purpose AI models.

Raw Google data may include requested message content and attachments, Drive file content and metadata, event details, document text, spreadsheet cells, and contact details. Assisto does not build aggregated or anonymized datasets from that content. Content-free operational metrics may record connector attempts, outcomes, service names, and read-only tool names. Google data is sent over HTTPS; OAuth credentials are held by Composio rather than in Assisto's application database; and connected-app content is treated as untrusted evidence, separated from application instructions, and checked for prompt-injection language.

Assisto's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See How Assisto uses Google data for scope purposes, retention, revocation, and deletion instructions.

7. AI and automation

Assisto uses AI to interpret messages, draft or suggest actions, extract information from documents, classify records, and assist with business workflows. AI outputs are not final professional advice and should be reviewed by you before use.

AI providers need to process the useful business facts in a prompt to produce an answer, so AI prompts cannot be fully encrypted from the model while still remaining useful. Instead, we use safeguards such as TLS in transit, encryption at rest where appropriate, access controls, prompt minimisation, and backend tools for sensitive matching or calculations where possible.

In production, AI requests are routed through a shared backend model client. Where configured, Google Cloud Vertex AI Gemini is the primary model provider and OpenRouter may be used as an explicit fallback. The client minimises prompts, records operational telemetry, and uses provider data controls where available. OpenRouter fallback requests are configured to request no provider data collection, zero data retention routing, and no provider fallbacks. These controls are designed to prevent prompts and completions from being retained or used to train third-party AI models, but the providers still process the content transiently to deliver the service and may handle limited metadata, security, abuse, or operational logs under their own terms.

We do not intentionally use your chat messages, CRM records, documents, bank data, or other customer content to create, train, or improve general-purpose AI models.

We minimise sensitive data sent to AI providers. For example, backend systems should handle bank tokens, raw Open Banking payloads, full account details, API keys, and sensitive reconciliation logic where possible, and the AI layer should receive only the summary or candidate information needed to complete the workflow.

We do not use AI to make solely automated decisions about you that produce legal or similarly significant effects without appropriate human involvement.

8. Who we share data with

We share personal data only where needed to run, secure, support, or improve Assisto:

  • Hosting, database, storage, and infrastructure providers.
  • AI gateways, model providers, transcription providers, OCR providers, and document processing providers used to interpret messages and files.
  • Payment, billing, and subscription providers such as Stripe.
  • Open Banking and bank-data providers such as TrueLayer and Plaid where you choose to connect bank data.
  • Connector brokers and third-party app providers such as Composio and connected app platforms where you choose to connect app context.
  • Authentication, app-store, bot-prevention, error-monitoring, and operational-monitoring providers where those features are configured.
  • Professional advisers, insurers, auditors, and authorities where legally required or necessary to protect rights.

The subprocessor list below reflects providers Assisto may use where the relevant feature or infrastructure is enabled in production.

If Plaid is enabled for a bank connection, Plaid may process end-user bank data under its own notices, including the Plaid End User Privacy Policy.

ProviderCategoryPurposeLocationSafeguards
VercelHosting and application deliveryHosting, deployments, routing, runtime services, and operational logs where used in production.US, EU, and global infrastructureDPA, SCCs/UK Addendum, DPF where applicable, and region/account controls where configured.
SupabaseDatabase, storage, and backend servicesPostgres database, private file storage, edge functions, signed URLs, and related backend services where used in production.Configured production project region, with provider support operations in the US/EUDPA, SCCs/UK Addendum, DPF where applicable, encryption, private buckets, and tenant-scoped access controls.
StripePayments and billingCheckout, subscriptions, billing portal, invoices, payment status, and webhook processing where billing is enabled.US, UK, EU, and global infrastructureStripe data processing terms, SCCs/UK Addendum, DPF where applicable, and payment-security controls.
RevenueCatMobile subscription managementGoogle Play subscription entitlement checks and billing webhook processing where Android in-app subscriptions are enabled.US and global infrastructureProvider data processing terms, SCCs/UK Addendum or equivalent safeguards where required, and limited billing metadata.
AppleAuthentication and app distributionSign in with Apple and App Store/TestFlight account or distribution services where enabled for iOS users.US, UK, EU, and global infrastructureProvider platform terms, SCCs/UK Addendum or equivalent safeguards where required, and limited authentication/app metadata.
Google Identity Services and Google PlayAuthentication and app distributionGoogle sign-in, Android app distribution, and Google Play billing flows where enabled.US, UK, EU, and global infrastructureProvider platform terms, SCCs/UK Addendum, DPF where applicable, and limited authentication/app metadata.
OpenAIAI and transcriptionVoice transcription or AI processing where OpenAI features are configured. API data controls are used where available and business data is not intentionally used by Assisto to train general AI models.US and global infrastructureProvider data processing terms, SCCs/UK Addendum, DPF where applicable, prompt minimisation, and provider data controls.
Google Cloud Vertex AIAI model processingPrimary Gemini model inference for chat, planning, extraction, summarisation, and agent governance. Business prompts are sent only as needed to deliver the requested service.Configured Google Cloud region and global support operationsGoogle Cloud data processing terms, SCCs/UK Addendum, DPF where applicable, prompt minimisation, and provider data controls.
OpenRouterAI gateway and model fallbackFallback-only AI gateway used when the primary Vertex AI path is unavailable. Production requests use no data collection, zero data retention routing, disabled provider fallbacks, and restricted provider routing where available.US, EU routing where configured, and provider-dependent locationsProvider terms, restricted routing, zero-retention routing where available, SCCs/UK Addendum or equivalent safeguards where required.
Selected model providers via OpenRouterAI model processingModel inference for AI-assisted workflows where routed through OpenRouter, such as selected Google/Vertex endpoints where configured. Providers process limited prompt context needed to return a result under the configured routing and data controls.Provider-dependentOpenRouter routing controls, provider data controls, prompt minimisation, and SCCs/UK Addendum or equivalent safeguards where required.
TrueLayerOpen BankingUK and EU Open Banking account connection, connection-state handling, transaction sync, and payment matching where TrueLayer is enabled.UK and EU, with provider operations as described in TrueLayer termsOpen Banking regulatory controls, provider data processing terms, SCCs/UK Addendum or equivalent safeguards where required, and token encryption.
PlaidOpen Banking and bank dataBank account connection and transaction data where Plaid is enabled, including US bank-data flows.US, UK, EU, and global infrastructurePlaid terms and end-user privacy notices, SCCs/UK Addendum or equivalent safeguards where required, and token encryption.
ComposioConnector broker and third-party app contextRead-only connector sessions, third-party OAuth credential brokerage, and app-context retrieval where connectors are enabled.US and global infrastructureProvider data processing terms, SCCs/UK Addendum or equivalent safeguards where required, scoped connector sessions, and view-only product policy.
CloudflareSecurity and abuse preventionTurnstile signup bot checks, security challenge tokens, DNS, or edge-security services where configured.Global infrastructureProvider data processing terms, SCCs/UK Addendum, DPF where applicable, and use limited to security and abuse prevention.
SentryError monitoringCrash, error, and diagnostic event capture where Sentry is configured for application or worker observability.US and EU infrastructureProvider data processing terms, SCCs/UK Addendum or equivalent safeguards where required, and minimised diagnostic payloads.
Healthchecks.io or equivalent heartbeat providerOperational monitoringDead-man's-switch heartbeat checks for background workers where a heartbeat URL is configured.Provider-dependentProvider terms, limited operational metadata, and no intentional customer content in heartbeat pings.

9. International transfers

Assisto is operated from the UK, but some suppliers may process data outside the UK or European Economic Area. The provider locations and transfer safeguards are summarised in the subprocessor table because cloud hosting, support, security, model routing, billing, and connector services may involve UK, EEA, US, or other global infrastructure depending on the feature and provider.

Where a restricted transfer takes place, we use an appropriate transfer mechanism where required. These may include UK adequacy regulations, EU adequacy decisions, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, the UK-US Data Bridge or EU-US Data Privacy Framework where applicable, or another lawful transfer mechanism.

10. Retention

We keep personal data only for as long as needed for the purposes described in this policy. Account and CRM records are generally kept while your account is active, unless you delete them or ask us to delete them. Billing, tax, accounting, dispute, and security records may be kept for longer where required by law or legitimate business need.

Backups and logs may take additional time to expire from our systems. We may retain limited information where needed to prevent abuse, resolve disputes, enforce terms, or comply with legal obligations.

AI providers and connected services may retain limited request metadata, security logs, abuse monitoring logs, or operational records under their own terms. Our production AI routing is configured to reduce prompt and completion retention and to avoid providers that collect customer prompts for training.

The Google-specific retention criteria, permanent chat deletion path, disconnect behavior, verified erasure process, and backup-restore rule are set out in How Assisto uses Google data.

11. UK and EEA privacy rights

Depending on the data and lawful basis, you may have rights to access, correct, delete, restrict, object to processing, and receive a copy of your personal data. Where we rely on consent, you may withdraw that consent at any time.

You can contact info@assistocrm.com to exercise these rights. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

12. US state privacy rights

If a US state privacy law applies to our processing of your personal information, you may have rights to know or access personal information, receive a portable copy, correct inaccurate personal information, delete personal information, opt out of sale, sharing for cross-context behavioural advertising, targeted advertising, or certain profiling, limit certain sensitive personal information uses where applicable, and appeal a denied request.

We do not sell personal information, share it for cross-context behavioural advertising, or use it for targeted advertising. We also do not currently use advertising cookies or profiling cookies.

To exercise a US privacy right, contact info@assistocrm.com. We may need to verify your request and your authority to act for the relevant account or business. If we deny a request and your state law gives you an appeal right, reply with "appeal" and explain what you want us to review.

13. Security

We use technical and organisational measures designed to protect personal data, including access controls, encryption where appropriate, private storage for sensitive files, rate-limits, and monitoring for abuse. No online service can be guaranteed completely secure, so you should also protect your devices, passwords, and email account.

14. Children

Assisto is intended for business users and is not directed at children under 18. Do not use Assisto to intentionally collect children's data unless you have a lawful basis and all required safeguards.

15. Changes

We may update this Privacy Policy as the product, suppliers, or legal requirements change. If we make material changes, we will take reasonable steps to bring them to your attention.