Privacy policy
Last updated: 9 July 2026
EmberSuite Fire is job-management software for fire-safety professionals, operated by Shayaan Ahmed, trading as EmberSuite Fire (a sole trader, not a registered company), of 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England ("we", "us"). This policy explains what personal data we collect, why, how long we keep it, and your rights under the UK GDPR and Data Protection Act 2018. It should be read alongside our Terms of Service.
Who is the data controller
For the account of the person who signs up (your name, email and billing), we are the data controller.
For the business data you put into the app about your own clients and the buildings you work on (client contact details, job records, photographs, and the people named in your Documents), you are the data controller and we act as your data processor, processing that data only to provide the Service to you and on your instructions. If you need a data processing agreement (DPA) for your own compliance, contact us at the address below and we will provide one.
What we collect
- Account data: your name, email address, and a securely hashed password (managed by our authentication provider — we never see your password in plain text).
- Billing data: subscription status and history, and a customer identifier from our payment processor. Card details are handled by the payment processor; we do not store your full card number.
- Your business data: client records, certificates, fire risk assessments, invoices, service records, job photographs, and company branding you create in the app.
- Support and contact data: messages you send us via the contact form, support chat, or email.
- Technical data: basic security and operational logs (such as request metadata) generated by our hosting providers. We set no advertising or analytics cookies and use no trackers.
Why we use it, and our lawful bases
- To provide the Service (host your data, generate and send Documents you approve, manage your account) — lawful basis: performance of a contract.
- To take payment and manage subscriptions — performance of a contract.
- To send compliance reminders and service emails — performance of a contract / legitimate interests.
- To provide support and respond to enquiries — legitimate interests.
- To secure the Service and prevent abuse — legitimate interests.
- To meet legal and accounting obligations — legal obligation.
Where your data lives, and who processes it
All primary data is stored in a PostgreSQL database hosted in the EU and protected by row-level security: each account's records are isolated at the database level and cannot be read by any other account. Job photos are held in a private storage bucket and served only via short-lived signed links to the account (or team) they belong to. We use the following sub-processors, each only for the purpose shown:
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and file storage | EU |
| Stripe | Payment processing and subscription billing | EU / US |
| Cloudflare | Website hosting, security, and inbound email routing | Global / EU |
| PDFShift | Converting a Document to PDF at the moment you generate or send it | EU |
| Anthropic | AI features (support chat and voice-fill) — processes the text you enter, then does not retain it for training | US |
| n8n (Autoshworks) | Automation of reminders and the review-and-send email queue | EU |
Where a provider is outside the UK/EU (for example Stripe or Anthropic in the US), transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
We do not sell your data or share it with anyone else for their own marketing.
AI features
If you use voice-fill or the support chat, the text you enter is sent to our AI provider to generate a response, and is not used to train their models. Because this text is processed by a third party, do not enter anything into AI features that you would not be willing to share for that purpose.
Emails
The Service sends two kinds of email: compliance reminders (to you and, where you have configured them, your clients) and Documents that you have personally reviewed and approved in the Outbox. Nothing is emailed to your clients without a human pressing Send.
Cookies and local storage
We set no advertising or analytics cookies and use no trackers. The only browser storage used is a login token kept in your browser so you stay signed in — strictly necessary for the Service to function, which is why there is no cookie-consent banner.
How long we keep it
We keep your account and business data for as long as your account is active. If you delete a record (such as a client) it is permanently removed, along with its linked records and photos. If you close your account, we delete or anonymise your personal data within 90 days, except where we must retain certain records (for example billing records for tax purposes) for the period required by law.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. You can export or delete much of your data in the app directly; to exercise any right, or to delete your entire account, contact us at the address below. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Where you are the controller and we are your processor (your client data), we will assist you in responding to requests from your own data subjects.
Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or in-app notice, and the "last updated" date above will change.
Contact
Data protection questions or requests: [email protected]
Postal: 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England
ICO registration number: [pending — ICO registration in progress]