Privacy policy
Last updated: 15 September 2026
EmberSuite Fire is job-management software for fire-safety professionals, operated by Shayaan Ahmed, trading as EmberSuite Fire (a sole trader, not a registered company), of 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England ("we", "us"). This policy explains what personal data we collect, why, how long we keep it, and your rights under the UK GDPR and Data Protection Act 2018. It should be read alongside our Terms of Service.
Who is the data controller
For the account of the person who signs up (your name, email and billing), we are the data controller.
For the business data you put into the app about your own clients and the buildings you work on (client contact details, job records, photographs, and the people named in your Documents), you are the data controller and we act as your data processor, processing that data only to provide the Service to you and on your instructions. Our Data Processing Agreement sets out those terms; it applies automatically as part of the Terms of Service, with no signature needed, and a countersigned copy is available on request.
What we collect
- Account data: your name, email address, and a securely hashed password (managed by our authentication provider: we never see your password in plain text).
- Billing data: subscription status and history, and a customer identifier from our payment processor. Card details are handled by the payment processor; we do not store your full card number.
- Your business data: client records, certificates, fire risk assessments, invoices, service records, assessment and logbook evidence photographs, and company branding you create in the app.
- Support and contact data: messages you send us via the contact form, support chat, or email.
- Technical data: basic security and operational logs (such as request metadata) generated by our hosting providers. We set no advertising or analytics cookies and use no trackers.
Why we use it, and our lawful bases
- To provide the Service (host your data, generate and send Documents you approve, manage your account), lawful basis: performance of a contract.
- To take payment and manage subscriptions: performance of a contract.
- To send compliance reminders and service emails: performance of a contract / legitimate interests.
- To provide support and respond to enquiries: legitimate interests.
- To secure the Service and prevent abuse: legitimate interests.
- To meet legal and accounting obligations: legal obligation.
Where your data lives, and who processes it
All primary data is stored in a PostgreSQL database hosted in the EU and protected by row-level security: each account's records are isolated at the database level and cannot be read by any other account. Two kinds of photograph are treated differently. Loose site photos from the Job photos tab are never uploaded: the app renames them by client and job and hands them straight back to your own device, and we keep no copy. Assessment and logbook evidence photographs are stored, because they form part of the compliance record: they are embedded in the issued Document and held in private storage, served only via short-lived signed links to the account (or team) they belong to. We use the following sub-processors, each only for the purpose shown:
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication and file storage | EU |
| Stripe | Payment processing and subscription billing | EU / US |
| Cloudflare | Website hosting, security, and inbound email routing | Global / EU |
| PDFShift | Converting a Document to PDF at the moment you generate or send it | EU |
| Anthropic | AI features (support chat and voice-fill): processes the text you enter, then does not retain it for training | US |
| n8n (Autoshworks) | Automation of compliance reminders | EU |
| Resend | Sending account emails and the Documents you approve in the Outbox | EU |
Where a provider is outside the UK/EU (for example Stripe or Anthropic in the US), transfers are protected by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses.
We do not sell your data or share it with anyone else for their own marketing.
AI features
If you use voice-fill or the support chat, the text you enter is sent to our AI provider to generate a response, and is not used to train their models. Because this text is processed by a third party, do not enter anything into AI features that you would not be willing to share for that purpose.
Emails
The Service sends two kinds of email: compliance reminders (to you and, where you have configured them, your clients) and Documents that you have personally reviewed and approved in the Outbox. Nothing is emailed to your clients without a human pressing Send.
Cookies and local storage
We set no advertising or analytics cookies and use no trackers. The only browser storage used is a login token kept in your browser so you stay signed in, strictly necessary for the Service to function, which is why there is no cookie-consent banner.
How long we keep it
We keep your account and business data for as long as your account is active. If you delete a record (such as a client) it is permanently removed, along with its linked records and photos. If you close your account, we delete or anonymise your personal data within 90 days, except where we must retain certain records (for example billing records for tax purposes) for the period required by law.
Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. You can export or delete much of your data in the app directly; to exercise any right, or to delete your entire account, contact us at the address below. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Where you are the controller and we are your processor (your client data), we will assist you in responding to requests from your own data subjects, as set out in our Data Processing Agreement.
How we handle rights requests
- How to ask. Email [email protected] with the subject "Data request", or write to the postal address below. Tell us which right you are exercising and, for access requests, what you are looking for if it is not everything.
- Checking it is you. We may ask you to confirm your identity before we act, for example by replying from the email address on the account. We will not ask for more than we need.
- How long it takes. We respond within one month of receiving the request. For a complex request, or several at once, we may take up to two further months, in which case we tell you within the first month and explain why.
- Cost. Free, unless a request is manifestly unfounded or excessive (for example, repeated requests for the same thing), in which case we may charge a reasonable fee or decline and tell you why.
- Your own account data. We are the controller, so we answer directly. You can already export and delete most of your data in the app; to delete the whole account, ask us.
- Data about your clients. We are the processor and you are the controller, so the decision is yours. If one of your clients or their occupants contacts us directly, we forward the request to you within 5 working days and help you respond. You can view, export or delete any client, Document or record yourself in the app.
Changes to this policy
We may update this policy from time to time. Material changes will be notified by email or in-app notice, and the "last updated" date above will change.
Contact
Data protection questions or requests: [email protected]
Postal: 27 Beaumont Road, Slough, Berkshire, SL2 1NQ, England
ICO registration number: [pending — ICO registration in progress]