Legal · Compliance

GDPR & data processing

Effective 27 May 2026. This page explains, in plain English, where every piece of data on Assesr lives, where AI processing happens, who else touches the data, and how we meet UK GDPR and EU GDPR. It is intended to answer the questions lenders, borrowers, compliance teams and DPOs actually ask before signing up.

See also our Privacy Policy (the formal legal notice) and Security (controls, certifications and architecture).

1. Plain-English summary

  • Your deal data is stored in a managed relational database in the EU/UK, encrypted at rest with AES-256 and in transit with TLS 1.2+.
  • AI credit papers are generated using paid commercial LLM APIs (see section 5 for details). On paid API tiers, your data is not used to train any model — this is a contractual commitment from each provider, not a setting we toggle.
  • Our application runs on global edge infrastructure. HTTPS terminates at the nearest edge node, then connects to the EU/UK database.
  • You can access, correct, export, restrict or delete your data at any time by emailing privacy@assesr.com.
  • Assesr is the data controller for your account and deal data. Lenders who receive a deal become independent controllers for the data they then process for credit-decisioning.

2. End-to-end data flow

Here is exactly what happens when you submit a deal:

  1. Upload — your browser sends documents over an encrypted TLS connection to the nearest edge node, then on to our application.
  2. Storage — the original document is written to secure file storage in an EU/UK data centre. Extracted fields are written to the database in the same region.
  3. AI extraction — text extracted from the document (not the raw file) is sent over TLS to our AI processing pipeline, which routes it to a commercial LLM provider. The response is returned in seconds and written back to the database.
  4. Credit-paper generation — structured deal fields are sent to the LLM to generate a comprehensive credit paper. Same encrypted path as step 3.
  5. Lender matching — the credit paper is shared, with your explicit consent, with lenders whose published mandate fits the deal. No data is shared with lenders until you click "Submit to marketplace".
  6. Audit log — every read, write and lender access event is recorded in an append-only log for forensics and your own visibility.

3. Where data is stored (at rest)

Data typeWhere it livesEncryption
Account profile (name, email, role)Managed database — EU/UK data centreAES-256 at rest, TLS 1.2+ in transit
Deal fields (site, GDV, costs, structure)Managed database — EU/UK data centreAES-256 at rest, TLS 1.2+ in transit
Uploaded documents (PDFs, images)Secure file storage — EU/UK data centreAES-256 at rest, TLS 1.2+ in transit
Generated credit papersManaged database — EU/UK data centreAES-256 at rest, TLS 1.2+ in transit
Audit / access logsManaged database — EU/UK data centreAES-256 at rest, append-only
Authentication credentialsManaged auth service — EU/UK data centreIndustry-standard hashing; signed session tokens
Backups (daily snapshots)Encrypted snapshots — same regionAES-256, retained per our backup policy
LLM prompts & responsesNot retained by Assesr beyond the request lifecycle (the generated paper is kept). Not retained by the model provider — see section 5.TLS 1.2+ end-to-end

Encryption at rest is provided by the infrastructure provider's server-side encryption and cannot be disabled. Backups are encrypted before they leave the database host.

4. Data in transit

  • All public endpoints enforce HTTPS with TLS 1.2 or higher. HTTP requests are automatically redirected.
  • HSTS is enabled with a long max-age; browsers refuse to downgrade.
  • All internal service-to-service communication uses TLS 1.2+.
  • Authentication cookies are flagged Secure, HttpOnly and SameSite=Lax.

5. Where AI / LLM processing happens

This is the question lenders ask most often, so it gets its own section. Assesr does not host or train its own large language models. We send specific, structured data to commercial LLM APIs and write the response back into your deal.

5.1 Which providers are used

  • Google (paid commercial Gemini API) — used for extraction and credit-paper drafting.
  • OpenAI (paid commercial API) — used for selected analysis steps.

In both cases we use paid enterprise API tiers, not free consumer products. This distinction matters for GDPR because the data-use terms are materially different on paid tiers.

5.2 Where the inference physically runs

LLM requests leave our application over TLS and are executed in the model provider's own data centres. Both providers operate globally and route to the nearest healthy region.

  • Google (paid API): typically processed in Google Cloud regions, which include EU regions. Google publishes Zero Data Retention support for eligible models on the paid tier.
  • OpenAI (paid API): default processing region is the United States. OpenAI also offers EU data residency for eligible endpoints.
  • Our application layer executes at the nearest edge node — for an EU/UK user, that means an EU/UK location.

5.3 Training & retention by the model providers

  • OpenAI (paid API): since 1 March 2023 OpenAI does not use API inputs or outputs to train its models by default — this is contractual, not an opt-in. Limited abuse-monitoring logs may be held for up to 30 days, then deleted.
  • Google (paid API): data is not used to train Google models. Eligible models additionally support Zero Data Retention — prompts and responses are not stored after the API call completes.
  • Assesr: we do not retain the raw input after the response is written. We do retain the generated output (your credit paper) because that is the product you asked us to build.

5.4 What the LLM actually sees

We minimise what is sent to the model. The LLM receives only the extracted text and structured fields relevant to a single deal. It does not receive other users' data, your authentication tokens, your payment details, or data from any other deal.

5.5 No automated decision-making

The credit paper is a drafting aid for human credit teams. The LLM does not make a lending decision and we do not perform automated decision-making with legal or similarly significant effects on you within the meaning of Article 22 GDPR. A human underwriter at the lender always makes the final call.

6. Sub-processors

The following third parties process personal data on our behalf under Article 28 GDPR. Each is bound by a Data Processing Agreement with appropriate safeguards.

Sub-processorPurposeRegion
SupabaseManaged database, file storage, authenticationEU/UK
Amazon Web ServicesUnderlying infrastructure for database providerEU
CloudflareEdge hosting, DNS, DDoS protectionGlobal; EU/UK for EU/UK traffic
Google (paid Gemini API)LLM inference for AI featuresGoogle Cloud, EU regions where available
OpenAI (paid API)LLM inference for AI featuresUS default; EU residency where supported
StripePayment processingEU & US
ResendTransactional email deliveryEU

We will notify customers in advance of material changes to this list. Email privacy@assesr.com to subscribe to sub-processor change notices.

7. International data transfers

Your primary deal data stays in the EU/UK. Where data is transferred outside the UK / EEA — primarily to the United States for some LLM inference, payments, and edge networking — we rely on the following safeguards:

  • EU-US Data Privacy Framework (and UK Extension) — for transfers to certified US recipients including AWS, Google LLC and Cloudflare. The DPF is the adequacy decision that replaced Privacy Shield in July 2023.
  • Standard Contractual Clauses (Module 2 or 3, EU Commission Decision 2021/914) plus the UK ICO Addendum — used as a fallback and for transfers to recipients not on the DPF list.
  • Transfer Impact Assessments — completed for each material sub-processor and reviewed annually.

8. Retention & deletion

DataRetention
Active account & dealsUntil you delete the account, or 24 months after last activity
Deals that reached drawdown6 years from drawdown (UK FCA / accounting record-keeping); PII fields are then automatically purged
Uploaded documentsSame as parent deal; a grace period applies after deletion, then permanently removed from storage
Audit logs12 months rolling; aggregated metrics retained longer with no PII
LLM inputsNot retained after the response is written
BackupsEncrypted snapshots, retained per our backup policy then automatically deleted
Marketing emailsUntil you unsubscribe; suppression list kept indefinitely so we don't email you again

9. Your GDPR rights

Under UK GDPR and EU GDPR you have the right to:

  • Access (Article 15) — get a copy of the personal data we hold about you.
  • Rectification (Article 16) — correct anything inaccurate.
  • Erasure (Article 17) — "right to be forgotten", subject to legal record-keeping duties.
  • Restriction (Article 18) — pause processing while a dispute is resolved.
  • Portability (Article 20) — receive your data in a machine-readable format (we export to JSON/CSV).
  • Object (Article 21) — object to processing based on legitimate interests, and to direct marketing at any time.
  • Not be subject to solely automated decisions (Article 22) — see section 5.5.
  • Complain to a supervisory authority — the UK ICO at ico.org.uk, or your local EU DPA.

To exercise any right, email privacy@assesr.com. We respond within 30 days (usually within 72 hours).

10. Lawful basis for processing

ProcessingLawful basis (Article 6)
Creating your account, generating credit papers, matching to lendersPerformance of a contract — Art. 6(1)(b)
Sharing a deal with a specific lenderYour explicit consent at submission — Art. 6(1)(a)
Fraud prevention, audit logs, security monitoringLegitimate interests — Art. 6(1)(f)
AML, KYC and FCA-related record retentionLegal obligation — Art. 6(1)(c)
Product marketing emailsConsent (you can withdraw at any time) — Art. 6(1)(a)

11. Security controls

  • Data-level isolation — each user can only access their own data; lenders only see deals they were explicitly sent.
  • Role-based access control enforced at the database level — application code cannot bypass it.
  • Re-authentication required for sensitive actions (submitting to marketplace, deleting data).
  • Append-only audit log of every lender access event.
  • Automated backups, monitored, with documented restore procedures.
  • Vulnerability scanning on every deploy.
  • Principle of least privilege for staff access; admin actions are logged.
  • Full detail on the Security page.

12. Breach notification

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the UK ICO within 72 hours of becoming aware of it (Article 33 GDPR) and notify affected users without undue delay where the risk is high (Article 34).

13. DPO & contact

Assesr is the data controller for personal data processed on the platform. For all privacy, GDPR or data-protection matters:

Enterprise / institutional customers can request our signed Data Processing Agreement, Transfer Impact Assessment and up-to-date sub-processor notice by emailing privacy@assesr.com.

14. Frequently asked questions

The questions lenders, borrowers, compliance teams and DPOs ask most often — answered plainly without revealing proprietary implementation details.

General

Data residency

AI & LLMs

Your rights

For lenders

For borrowers

Security

Cookies & marketing

For partners

For compliance teams

This page is informational and forms part of our broader Privacy Policy. Where a specific clause in the Privacy Policy or a signed DPA differs from a description on this page, the Privacy Policy or DPA prevails.