Free trial: all features unlocked.
Automate Fire Door Management OS
Last updated: 18 August 2026
Automate Works Limited ("Automate", "we", "us", "our") operates the Automate Fire Door Management OS, associated applications, websites, services and related technology (together, the "Service").
We are committed to protecting personal data and handling it responsibly, securely and transparently.
This Privacy Policy explains how personal data is collected, used, stored, disclosed and protected when you:
Automate operates primarily as a business-to-business software provider. Depending on the circumstances and the particular processing activity, Automate may act as a data controller, data processor, or, where applicable, another legally recognised role under applicable data protection law.
This distinction is important and is explained below.
If you have questions about this Privacy Policy or the way we handle personal data, contact us using the details above.
Where legally required, Automate will appoint and identify a Data Protection Officer or other appropriate privacy contact.
Depending on the circumstances, our processing may be subject to:
We aim to apply appropriate technical and organisational measures to protect personal data and maintain accountability for our processing activities.
The role Automate performs depends on the particular data and processing activity.
When an organisation subscribes to Automate and uses the platform to manage its own operational information, that organisation will generally determine why its operational data is collected and how it should be used.
Examples may include:
In these circumstances, the subscribing organisation will generally act as the Data Controller and Automate will generally act as its Data Processor.
Automate processes that information on the organisation's documented instructions and in accordance with the applicable agreement between Automate and that organisation.
A separate Data Processing Agreement ("DPA") may apply to this processing.
The controller/processor relationship does not mean Automate has no responsibilities under data protection law. Processors have their own obligations under the UK GDPR and must implement appropriate safeguards.
Automate will act as a Data Controller where it determines the purposes and means of processing personal data.
This may include:
Where Automate acts as controller, we determine the relevant lawful basis and purposes for processing.
The precise information collected depends upon how you interact with Automate.
This may include:
When an organisation uses Automate, we may process information concerning the organisation, including:
Automate is designed to manage detailed fire door lifecycle information.
Depending on how the Service is configured and used, this may include:
Where this information contains personal data belonging to individuals, the relevant customer will generally determine the purpose for which that information is processed.
Automate allows users to capture and upload evidence associated with fire doors, projects and inspections.
This may include photographs or videos showing:
Customers are responsible for ensuring they have an appropriate lawful basis and authority to upload personal data to Automate.
Automate processes such evidence in accordance with the customer's instructions and applicable contractual arrangements.
Users should avoid uploading unnecessary personal information into evidence fields.
We may automatically collect technical information when users access the Service, including:
This information helps us operate, secure, monitor and improve the Service.
Because Automate is designed for operational and compliance environments, the Service may maintain records of actions performed within the platform.
These may include:
These records may be required to operate the Service, maintain security, investigate incidents and provide traceability.
Automate incorporates artificial intelligence and machine-learning technologies into certain features.
Depending on the Service and functionality being used, AI may assist with:
AI-generated information may be probabilistic and is not guaranteed to be correct.
Automate will not represent AI-generated information as a substitute for professional judgement, statutory requirements, certification, inspection or technical assessment where those things are required.
Where Automate uses third-party AI providers, relevant data may be processed by those providers as sub-processors or other appropriate service providers, subject to the applicable contractual, security and data protection arrangements.
Automate should not send personal data to an AI provider unless that processing is authorised and appropriately protected.
Where AI processing involves customer operational data, the applicable customer agreement and DPA will govern the processing.
Where Automate acts as controller, we may use personal data to:
Where Automate acts as processor, we process customer data according to the customer's documented instructions and applicable contractual terms.
Where Automate acts as controller, we rely on one or more lawful bases under applicable data protection law.
These may include:
Where processing is necessary to provide the Service or perform our contractual obligations.
Where processing is necessary for legitimate business purposes and those interests are not overridden by the individual's rights and interests.
Examples may include:
Where we are required to process information to comply with a legal or regulatory obligation.
Where consent is required by law or where we choose to rely on consent.
Where processing relies on consent, individuals may withdraw consent at any time, although this will not affect processing that occurred before withdrawal.
We may send service-related communications where necessary to operate your account.
These may include:
Where required by law, we will obtain appropriate consent before sending electronic direct marketing.
You may opt out of marketing communications at any time.
Service and legally necessary communications may continue where appropriate.
Payments and subscriptions may be processed through third-party payment providers.
Automate does not ordinarily need to store complete payment card numbers.
Payment providers may process:
The relevant payment provider's own privacy terms will also apply.
Automate relies on specialist technology providers to operate the Service.
These may include providers for:
A current list of material sub-processors should be maintained separately and made available to customers where appropriate.
The list must reflect Automate's actual production infrastructure.
Where Automate acts as a processor, we may engage carefully selected sub-processors to provide elements of the Service.
Appropriate contractual arrangements and data protection safeguards will be maintained.
Where required, customers will receive appropriate information regarding material changes to sub-processors and applicable rights to object.
UK GDPR processor contracts require appropriate provisions concerning sub-processors, security, confidentiality, assistance with data-subject rights and other matters.
Automate may use service providers whose operations or infrastructure are located outside the United Kingdom.
Where personal data is transferred outside the UK, Automate will implement appropriate safeguards required by applicable data protection law.
Depending on the destination and circumstances, safeguards may include:
The actual countries and transfer mechanisms applicable to Automate's production infrastructure should be documented and reflected in the relevant Data Processing Agreement or sub-processor information.
Automate takes the security of personal data seriously.
Depending on the nature of the processing and risk involved, our technical and organisational measures may include:
Security measures evolve as the Service develops.
We do not claim that any system can be completely secure.
Automate is designed as a multi-tenant SaaS platform.
Customer information is logically separated according to the organisation, workspace and permissions applicable to the Service.
Access controls are designed to ensure that users can only access information for which they have appropriate permissions.
Customers are responsible for:
Automate supports QR-linked fire door records.
A QR code may provide access to information associated with a particular door or record, depending upon the customer's configuration.
Customers are responsible for determining what information should be made accessible through QR-linked records.
Automate will use appropriate access controls and technical restrictions configured within the Service.
QR-linked information should not be assumed to be private merely because it is associated with a physical asset.
Customers should therefore avoid placing unnecessary personal or sensitive information into publicly accessible QR-linked records.
Automate does not apply a single universal retention period to all customer data.
Retention depends upon:
Where Automate acts as processor, the customer's retention instructions will generally determine how long customer operational data is retained, subject to applicable contractual and legal requirements.
Where an account is terminated, customer data may be retained for a limited period to allow:
Specific deletion and return arrangements should be governed by the customer's contract and DPA.
Automate may maintain backups to support:
Backups may remain temporarily available after production data has been deleted because of backup retention cycles.
Backup retention periods should be documented within Automate's internal retention and disaster-recovery procedures.
Automate maintains procedures for identifying, assessing and responding to suspected security incidents.
Where Automate acts as a processor, we will notify the relevant customer of a personal-data breach in accordance with the applicable contractual and Data Processing Agreement requirements.
Where Automate acts as controller, we will assess incidents in accordance with applicable data protection law and notify the ICO or affected individuals where legally required.
Depending upon the circumstances and applicable law, individuals may have rights including:
These rights are subject to applicable legal exemptions and limitations.
Where Automate acts as a processor, customers are generally responsible for responding to requests from individuals whose personal data they control.
Automate will provide reasonable assistance where required under the applicable contract and UK GDPR.
This may include helping with:
If you believe Automate is processing your personal data as a controller, you may contact us at hello@automateapp.co.uk.
We may need sufficient information to verify your identity before responding.
We will respond within the timescales required by applicable law.
If you have concerns about our use of your personal data, please contact us first so that we can investigate the issue.
You also have the right to complain to the UK's data protection regulator:
The ICO provides information about data protection rights and how to raise a concern.
Automate's marketing website and applications may use cookies and similar technologies.
These may include technologies used for:
Non-essential cookies or storage technologies will be handled in accordance with applicable PECR requirements, including consent where required.
The ICO states that organisations must provide clear information about cookies and obtain consent for non-essential cookies where required; strictly necessary technologies may fall within an exemption.
Automate maintains a separate Cookie Policy identifying the actual cookies and similar technologies currently used.
Automate may use analytics and performance technologies to understand:
Analytics information is configured so that it is collected and processed in accordance with applicable privacy and cookie requirements.
Automate is a business-to-business service and is not directed towards children.
We do not knowingly seek to provide accounts to children where doing so would be inappropriate or prohibited by applicable law.
If you believe a child has provided personal data to Automate without appropriate authorisation, please contact us.
Automate is not intended to require users to upload special category personal data unless it is necessary for a customer's legitimate operational purpose and appropriate lawful conditions apply.
Customers should avoid uploading unnecessary sensitive personal information.
Where customer workflows require processing of special category data, the customer remains responsible for determining the appropriate lawful basis and applicable Article 9 condition where the customer acts as controller.
Automate will process such information only in accordance with the applicable contract and documented instructions where acting as processor.
Automate provides tools that allow customers to create, import, edit and maintain operational information.
Customers remain responsible for the accuracy and completeness of information they enter into the Service.
AI-assisted extraction and automation may assist users but should be reviewed where accuracy is important.
Automate does not guarantee that automatically extracted or AI-generated information is error-free.
Automate may use automated processing and AI-assisted systems to provide recommendations, classifications, extraction or workflow assistance.
Unless expressly stated otherwise, these features are intended to assist users rather than make legally significant decisions about individuals.
Where applicable law gives individuals rights relating to solely automated decision-making, Automate will comply with those requirements.
Subject to the customer's subscription and contractual terms, Automate may provide functionality allowing customers to export information from the Service.
Customers are responsible for maintaining appropriate copies of information where they require independent archival records.
The specific export formats and available functionality may change as the Service evolves.
Where appropriate and subject to contractual and legal requirements, customers may request deletion of customer data.
Deletion may not immediately remove every copy from:
Such information will be retained only for as long as necessary for the applicable purpose and protected appropriately.
The Service may contain links or integrations to third-party websites and services.
Automate is not responsible for the privacy practices of third parties.
Users should review the privacy notices of those third parties before providing personal data to them.
Automate is continuously developing its platform.
New functionality may introduce new categories of processing or new technology providers.
Where such changes materially affect how personal data is processed, Automate will update this Privacy Policy and, where legally or contractually required, provide appropriate notice.
We may update this Privacy Policy from time to time.
The latest version will be published on the relevant Automate website or application.
The "Last Updated" date will indicate when the policy was most recently revised.
Where changes are material, we may provide additional notice through:
This Privacy Policy is governed by the laws of England and Wales, unless applicable law requires otherwise.
For privacy and data protection enquiries:
Automate uses essential cookies to keep the website working and optional cookies to provide enhanced functionality. You can choose which optional cookies to allow at any time. Privacy Policy · Cookie Policy