Privacy Policy

Last updated: 14 September 2026

Introduction

Automate ("we", "our", "the Service") is a fire door management and compliance platform used by installers, surveyors, contractors, and building owners. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our application, including when connecting a Google Workspace, Gmail, Microsoft 365, or SMTP email provider.

We comply fully with the UK GDPR, Data Protection Act 2018, and Google API Services User Data Policy.

Contact Details

Data Controller: Automate

Email: hello@automateapp.co.uk

Registered domain: automateapp.co.uk

What Data We Collect

We only collect data necessary for account management, app functionality, compliance workflows, and optional email provider integrations.

We may collect:

  • Name, email address, phone number, business name, job role
  • Project data, inspection records, photos, evidence logs
  • QR code scan history (non-sensitive)
  • IP address and device information (security purposes)
  • Audit logs and usage information
  • Information you provide when completing forms or requesting access to public inspection records

Google Workspace / Gmail Data

When you choose to connect your Google account, we ONLY request the minimum necessary scopes:

Required Gmail Scopes:

  • gmail.send
  • gmail.compose
  • gmail.modify
  • email
  • openid
  • profile

These are used ONLY for:

  • Sending transactional business emails (reports, updates, quotes)
  • Associating your email account with your organisation
  • Placing the sent email into your "Sent" folder
  • Verifying the identity of the connected account

WE DO NOT:

  • Read incoming emails
  • Access inbox contents
  • Download, store, or analyse email bodies
  • Access attachments
  • Access contacts or calendars
  • Share any Google user data with third parties
  • Use Gmail data for advertising, profiling, or marketing

All OAuth tokens are encrypted, stored securely, and used exclusively for sending emails on your behalf.

Microsoft 365 (Outlook) Data

When connecting a Microsoft 365 account, we request the minimal mail-sending scope via Microsoft Graph API.

We ONLY use this for:

  • Sending transactional email on your behalf
  • Adding the message to your "Sent Items" folder
  • Identifying your connected email account

We do NOT access inbox data or read emails.

SMTP Server Data

If you connect a custom SMTP server:

  • Credentials are stored encrypted
  • Used only for sending emails triggered by your app actions
  • Not shared with third parties

How We Use Your Data

We use your data to:

  • Create and manage your Automate account
  • Process inspections, installations and compliance evidence
  • Maintain golden-thread audit trails
  • Send business emails (only when YOU trigger them)
  • Improve safety, reliability and usability
  • Provide customer support
  • Ensure platform security and fraud prevention

Sharing of Data

We do NOT sell or share personal data with third parties for marketing.

Data may be shared only with:

  • Cloud infrastructure providers (secure, encrypted, UK/EU-compliant)
  • Law enforcement if legally required
  • Organisations you explicitly collaborate or share data with via built-in collaboration features

Your Rights

Under UK GDPR, you have the right to:

  • Access your data
  • Correct inaccurate information
  • Request deletion
  • Restrict processing
  • Export your data (data portability)
  • Object to certain processing
  • Withdraw consent at any time

To exercise these rights: hello@automateapp.co.uk

Data Retention

We retain records only for as long as required for:

  • Project history
  • Legal compliance
  • Safety auditing
  • Evidence documentation

You may request deletion at any time.

Deleting Connected Email Data

At any time, users may navigate to:

Business Profile → Company Email & Notifications → Disconnect

This permanently removes:

  • OAuth tokens
  • Email provider configuration
  • Any linked mail authentication data

This ensures we no longer have access to your email provider.

Security Measures

We implement:

  • Encrypted HTTPS
  • Encrypted database storage
  • Encrypted OAuth token storage
  • Access controls & authenticated API endpoints
  • Minimal data retention
  • Regular audits, monitoring, and compliance reviews

Public Inspection Records Data

When you request access to view public inspection records for doors, we collect limited information such as:

  • Name
  • Email
  • Organisation
  • Job role

This is used strictly for:

  • Auditing access
  • Security
  • Logging who has viewed compliance records
  • Occasional follow-up on compliance solutions

Changes to This Privacy Policy

We may update this Privacy Policy when required. The latest version will always be available on this page.

Contact

For privacy questions or data requests:
Email: hello@automateapp.co.uk