Introduction
Automate ("we", "our", "the Service") is a fire door management and compliance platform used by installers, surveyors, contractors, and building owners. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our application, including when connecting a Google Workspace, Gmail, Microsoft 365, or SMTP email provider.
We comply fully with the UK GDPR, Data Protection Act 2018, and Google API Services User Data Policy.
What Data We Collect
We only collect data necessary for account management, app functionality, compliance workflows, and optional email provider integrations.
We may collect:
- • Name, email address, phone number, business name, job role
- • Project data, inspection records, photos, evidence logs
- • QR code scan history (non-sensitive)
- • IP address and device information (security purposes)
- • Audit logs and usage information
- • Information you provide when completing forms or requesting access to public inspection records
Google Workspace / Gmail Data
When you choose to connect your Google account, we ONLY request the minimum necessary scopes:
Required Gmail Scopes:
- • gmail.send
- • gmail.compose
- • gmail.modify
- • email
- • openid
- • profile
These are used ONLY for:
- • Sending transactional business emails (reports, updates, quotes)
- • Associating your email account with your organisation
- • Placing the sent email into your "Sent" folder
- • Verifying the identity of the connected account
WE DO NOT:
- • Read incoming emails
- • Access inbox contents
- • Download, store, or analyse email bodies
- • Access attachments
- • Access contacts or calendars
- • Share any Google user data with third parties
- • Use Gmail data for advertising, profiling, or marketing
All OAuth tokens are encrypted, stored securely, and used exclusively for sending emails on your behalf.
Microsoft 365 (Outlook) Data
When connecting a Microsoft 365 account, we request the minimal mail-sending scope via Microsoft Graph API.
We ONLY use this for:
- • Sending transactional email on your behalf
- • Adding the message to your "Sent Items" folder
- • Identifying your connected email account
We do NOT access inbox data or read emails.
SMTP Server Data
If you connect a custom SMTP server:
- • Credentials are stored encrypted
- • Used only for sending emails triggered by your app actions
- • Not shared with third parties
How We Use Your Data
We use your data to:
- • Create and manage your Automate account
- • Process inspections, installations and compliance evidence
- • Maintain golden-thread audit trails
- • Send business emails (only when YOU trigger them)
- • Improve safety, reliability and usability
- • Provide customer support
- • Ensure platform security and fraud prevention
Sharing of Data
We do NOT sell or share personal data with third parties for marketing.
Data may be shared only with:
- • Cloud infrastructure providers (secure, encrypted, UK/EU-compliant)
- • Law enforcement if legally required
- • Organisations you explicitly collaborate or share data with via built-in collaboration features
Your Rights
Under UK GDPR, you have the right to:
- • Access your data
- • Correct inaccurate information
- • Request deletion
- • Restrict processing
- • Export your data (data portability)
- • Object to certain processing
- • Withdraw consent at any time
To exercise these rights: hello@automateapp.co.uk
Data Retention
We retain records only for as long as required for:
- • Project history
- • Legal compliance
- • Safety auditing
- • Evidence documentation
You may request deletion at any time.
Deleting Connected Email Data
At any time, users may navigate to:
Business Profile → Company Email & Notifications → Disconnect
This permanently removes:
- • OAuth tokens
- • Email provider configuration
- • Any linked mail authentication data
This ensures we no longer have access to your email provider.
Security Measures
We implement:
- • Encrypted HTTPS
- • Encrypted database storage
- • Encrypted OAuth token storage
- • Access controls & authenticated API endpoints
- • Minimal data retention
- • Regular audits, monitoring, and compliance reviews
Public Inspection Records Data
When you request access to view public inspection records for doors, we collect limited information such as:
- • Name
- • Email
- • Organisation
- • Job role
This is used strictly for:
- • Auditing access
- • Security
- • Logging who has viewed compliance records
- • Occasional follow-up on compliance solutions
Changes to This Privacy Policy
We may update this Privacy Policy when required. The latest version will always be available on this page.