Free trial: all features unlocked.

Privacy Policy

Automate Fire Door Management OS

Last updated: 18 August 2026

Automate Works Limited ("Automate", "we", "us", "our") operates the Automate Fire Door Management OS, associated applications, websites, services and related technology (together, the "Service").

We are committed to protecting personal data and handling it responsibly, securely and transparently.

This Privacy Policy explains how personal data is collected, used, stored, disclosed and protected when you:

  • visit our website
  • create or manage an Automate account
  • use the Automate platform
  • use our mobile or web applications
  • communicate with us
  • receive communications from us
  • interact with features, services or integrations provided by Automate

Automate operates primarily as a business-to-business software provider. Depending on the circumstances and the particular processing activity, Automate may act as a data controller, data processor, or, where applicable, another legally recognised role under applicable data protection law.

This distinction is important and is explained below.

1. Who we are

The Service is operated by
Automate Works Limited
Trading as
Automate
Registered company details
16865956
Registered office
1 Faviell Gardens, Featherstone, Wakefield WF7 6FF

If you have questions about this Privacy Policy or the way we handle personal data, contact us using the details above.

Where legally required, Automate will appoint and identify a Data Protection Officer or other appropriate privacy contact.

2. The data protection laws that apply

Depending on the circumstances, our processing may be subject to:

  • UK General Data Protection Regulation ("UK GDPR")
  • Data Protection Act 2018
  • Privacy and Electronic Communications Regulations ("PECR")
  • other applicable UK data protection and privacy legislation
  • applicable legislation concerning electronic communications, marketing and cookies
  • applicable contractual and regulatory requirements

We aim to apply appropriate technical and organisational measures to protect personal data and maintain accountability for our processing activities.

3. Automate's different data protection roles

The role Automate performs depends on the particular data and processing activity.

3.1 When Automate is a Data Processor

When an organisation subscribes to Automate and uses the platform to manage its own operational information, that organisation will generally determine why its operational data is collected and how it should be used.

Examples may include:

  • fire door records
  • project information
  • inspection records
  • evidence photographs
  • installation records
  • maintenance records
  • remedial work
  • certificates
  • compliance documentation
  • door schedules
  • employee or contractor information
  • client information
  • site information
  • QR-linked records
  • quotation information
  • other information entered into the organisation's Automate workspace

In these circumstances, the subscribing organisation will generally act as the Data Controller and Automate will generally act as its Data Processor.

Automate processes that information on the organisation's documented instructions and in accordance with the applicable agreement between Automate and that organisation.

A separate Data Processing Agreement ("DPA") may apply to this processing.

The controller/processor relationship does not mean Automate has no responsibilities under data protection law. Processors have their own obligations under the UK GDPR and must implement appropriate safeguards.

4. When Automate is a Data Controller

Automate will act as a Data Controller where it determines the purposes and means of processing personal data.

This may include:

  • account registration
  • customer relationship management
  • billing and subscription administration
  • payment administration
  • customer support
  • service communications
  • security monitoring
  • fraud prevention
  • website operation
  • marketing
  • cookie and analytics management
  • product improvement
  • business administration
  • maintaining appropriate business records
  • responding to legal obligations
  • handling enquiries
  • managing demonstrations and trials
  • protecting Automate's systems and legitimate business interests

Where Automate acts as controller, we determine the relevant lawful basis and purposes for processing.

5. Information we may collect

The precise information collected depends upon how you interact with Automate.

5.1 Account and identity information

This may include:

  • name
  • business email address
  • telephone number
  • job title
  • organisation
  • organisation role
  • username
  • account credentials
  • workspace membership
  • user permissions
  • profile information
  • account status

6. Organisational and business information

When an organisation uses Automate, we may process information concerning the organisation, including:

  • company name
  • trading information
  • business address
  • contact information
  • branding assets
  • company logos
  • billing information
  • subscription information
  • workspace configuration
  • user and team structures
  • supplier information
  • customer information
  • project information
  • operational configuration

7. Fire door and operational data

Automate is designed to manage detailed fire door lifecycle information.

Depending on how the Service is configured and used, this may include:

  • door references
  • door locations
  • building and site information
  • floor information
  • door dimensions
  • structural openings
  • door configurations
  • fire ratings
  • frame specifications
  • leaf specifications
  • glazing information
  • hardware
  • ironmongery
  • seals
  • manufacturing information
  • installation information
  • inspection findings
  • maintenance information
  • remedial work
  • photographs
  • videos
  • certificates
  • technical documents
  • quotations
  • purchase orders
  • delivery records
  • signatures and approvals
  • client sign-offs
  • shipping information
  • compliance evidence
  • QR-linked records
  • Golden Thread information
  • project information
  • other information entered by customers into the Service

Where this information contains personal data belonging to individuals, the relevant customer will generally determine the purpose for which that information is processed.

8. Photographs, video and evidence

Automate allows users to capture and upload evidence associated with fire doors, projects and inspections.

This may include photographs or videos showing:

  • doors
  • buildings
  • components
  • installations
  • defects
  • labels
  • certificates
  • QR codes
  • surrounding environments
  • workers
  • contractors
  • inspectors
  • other individuals

Customers are responsible for ensuring they have an appropriate lawful basis and authority to upload personal data to Automate.

Automate processes such evidence in accordance with the customer's instructions and applicable contractual arrangements.

Users should avoid uploading unnecessary personal information into evidence fields.

9. Technical and usage information

We may automatically collect technical information when users access the Service, including:

  • IP address
  • device type
  • operating system
  • browser
  • application version
  • session information
  • login information
  • authentication events
  • approximate location derived from technical information where appropriate
  • network information
  • error reports
  • performance information
  • security events
  • feature usage
  • diagnostic information
  • audit events

This information helps us operate, secure, monitor and improve the Service.

10. Logs, audit trails and security information

Because Automate is designed for operational and compliance environments, the Service may maintain records of actions performed within the platform.

These may include:

  • account creation
  • authentication
  • login events
  • changes to records
  • record creation
  • record deletion
  • document uploads
  • inspections
  • approvals
  • sign-offs
  • administrative changes
  • permission changes
  • exports
  • system events
  • security events

These records may be required to operate the Service, maintain security, investigate incidents and provide traceability.

11. Artificial intelligence and automated processing

Automate incorporates artificial intelligence and machine-learning technologies into certain features.

Depending on the Service and functionality being used, AI may assist with:

  • document and door schedule extraction
  • project creation
  • information classification
  • inspection assistance
  • image or evidence analysis
  • recommendations
  • information retrieval
  • workflow assistance
  • quotation preparation
  • data organisation
  • administrative assistance
  • natural-language interaction
  • other platform functionality

AI-generated information may be probabilistic and is not guaranteed to be correct.

Automate will not represent AI-generated information as a substitute for professional judgement, statutory requirements, certification, inspection or technical assessment where those things are required.

Where Automate uses third-party AI providers, relevant data may be processed by those providers as sub-processors or other appropriate service providers, subject to the applicable contractual, security and data protection arrangements.

Automate should not send personal data to an AI provider unless that processing is authorised and appropriately protected.

Where AI processing involves customer operational data, the applicable customer agreement and DPA will govern the processing.

12. How we use personal data

Where Automate acts as controller, we may use personal data to:

  • provide and administer accounts
  • provide customer support
  • provide demonstrations and trials
  • process subscriptions
  • process payments
  • communicate with customers
  • provide service notifications
  • maintain security
  • prevent fraud and abuse
  • investigate incidents
  • monitor performance
  • troubleshoot problems
  • improve the Service
  • develop new features
  • understand how customers use the Service
  • maintain business records
  • comply with legal obligations
  • establish, exercise or defend legal claims
  • protect our rights, property and systems

Where Automate acts as processor, we process customer data according to the customer's documented instructions and applicable contractual terms.

13. Lawful bases for processing

Where Automate acts as controller, we rely on one or more lawful bases under applicable data protection law.

These may include:

Contract

Where processing is necessary to provide the Service or perform our contractual obligations.

Legitimate Interests

Where processing is necessary for legitimate business purposes and those interests are not overridden by the individual's rights and interests.

Examples may include:

  • maintaining platform security
  • preventing fraud
  • improving reliability
  • responding to customer enquiries
  • managing business relationships
  • maintaining appropriate records
  • protecting our legal rights

Legal Obligation

Where we are required to process information to comply with a legal or regulatory obligation.

Consent

Where consent is required by law or where we choose to rely on consent.

Where processing relies on consent, individuals may withdraw consent at any time, although this will not affect processing that occurred before withdrawal.

14. Marketing communications

We may send service-related communications where necessary to operate your account.

These may include:

  • account notifications
  • security alerts
  • billing notifications
  • service announcements
  • operational messages
  • important changes to the Service

Where required by law, we will obtain appropriate consent before sending electronic direct marketing.

You may opt out of marketing communications at any time.

Service and legally necessary communications may continue where appropriate.

15. Payment information

Payments and subscriptions may be processed through third-party payment providers.

Automate does not ordinarily need to store complete payment card numbers.

Payment providers may process:

  • name
  • billing information
  • email
  • subscription information
  • transaction information
  • payment status
  • payment identifiers
  • limited payment-related information

The relevant payment provider's own privacy terms will also apply.

16. Third-party service providers

Automate relies on specialist technology providers to operate the Service.

These may include providers for:

  • cloud infrastructure
  • databases
  • authentication
  • storage
  • email delivery
  • payment processing
  • artificial intelligence
  • analytics
  • monitoring
  • error reporting
  • communications
  • document generation
  • hosting
  • security
  • customer support
  • other infrastructure required to operate the Service

A current list of material sub-processors should be maintained separately and made available to customers where appropriate.

The list must reflect Automate's actual production infrastructure.

17. Sub-processors

Where Automate acts as a processor, we may engage carefully selected sub-processors to provide elements of the Service.

Appropriate contractual arrangements and data protection safeguards will be maintained.

Where required, customers will receive appropriate information regarding material changes to sub-processors and applicable rights to object.

UK GDPR processor contracts require appropriate provisions concerning sub-processors, security, confidentiality, assistance with data-subject rights and other matters.

18. International data transfers

Automate may use service providers whose operations or infrastructure are located outside the United Kingdom.

Where personal data is transferred outside the UK, Automate will implement appropriate safeguards required by applicable data protection law.

Depending on the destination and circumstances, safeguards may include:

  • UK adequacy regulations
  • UK International Data Transfer Agreements
  • UK Addendum to EU Standard Contractual Clauses
  • appropriate contractual protections
  • transfer risk assessments where required
  • another legally recognised transfer mechanism

The actual countries and transfer mechanisms applicable to Automate's production infrastructure should be documented and reflected in the relevant Data Processing Agreement or sub-processor information.

19. Data security

Automate takes the security of personal data seriously.

Depending on the nature of the processing and risk involved, our technical and organisational measures may include:

  • encryption in transit
  • encryption at rest where supported by the relevant infrastructure
  • role-based access control
  • organisation/workspace isolation
  • authentication controls
  • database access controls
  • row-level security where applicable
  • least-privilege access
  • audit logging
  • secure credential handling
  • infrastructure monitoring
  • vulnerability management
  • backup procedures
  • disaster recovery measures
  • incident response procedures
  • access reviews
  • secure development practices
  • environment separation

Security measures evolve as the Service develops.

We do not claim that any system can be completely secure.

20. Organisation and workspace isolation

Automate is designed as a multi-tenant SaaS platform.

Customer information is logically separated according to the organisation, workspace and permissions applicable to the Service.

Access controls are designed to ensure that users can only access information for which they have appropriate permissions.

Customers are responsible for:

  • managing their users
  • protecting login credentials
  • assigning appropriate permissions
  • removing access when users leave
  • ensuring users are authorised
  • configuring their organisation appropriately

21. QR codes and Golden Thread records

Automate supports QR-linked fire door records.

A QR code may provide access to information associated with a particular door or record, depending upon the customer's configuration.

Customers are responsible for determining what information should be made accessible through QR-linked records.

Automate will use appropriate access controls and technical restrictions configured within the Service.

QR-linked information should not be assumed to be private merely because it is associated with a physical asset.

Customers should therefore avoid placing unnecessary personal or sensitive information into publicly accessible QR-linked records.

22. Data retention

Automate does not apply a single universal retention period to all customer data.

Retention depends upon:

  • the customer's instructions
  • contractual requirements
  • the type of data
  • the purpose of processing
  • legal requirements
  • security requirements
  • regulatory obligations
  • technical requirements

Where Automate acts as processor, the customer's retention instructions will generally determine how long customer operational data is retained, subject to applicable contractual and legal requirements.

Where an account is terminated, customer data may be retained for a limited period to allow:

  • account closure
  • data export
  • dispute resolution
  • security investigation
  • legal compliance
  • backup management
  • fulfilment of contractual obligations

Specific deletion and return arrangements should be governed by the customer's contract and DPA.

23. Backups

Automate may maintain backups to support:

  • disaster recovery
  • service continuity
  • data integrity
  • security
  • restoration following technical incidents

Backups may remain temporarily available after production data has been deleted because of backup retention cycles.

Backup retention periods should be documented within Automate's internal retention and disaster-recovery procedures.

24. Data breaches and security incidents

Automate maintains procedures for identifying, assessing and responding to suspected security incidents.

Where Automate acts as a processor, we will notify the relevant customer of a personal-data breach in accordance with the applicable contractual and Data Processing Agreement requirements.

Where Automate acts as controller, we will assess incidents in accordance with applicable data protection law and notify the ICO or affected individuals where legally required.

25. Your data protection rights

Depending upon the circumstances and applicable law, individuals may have rights including:

  • the right to be informed
  • the right of access
  • the right to rectification
  • the right to erasure
  • the right to restrict processing
  • the right to data portability
  • the right to object
  • rights relating to automated decision-making and profiling where applicable
  • the right to withdraw consent where processing relies on consent

These rights are subject to applicable legal exemptions and limitations.

26. Customer requests concerning their users' data

Where Automate acts as a processor, customers are generally responsible for responding to requests from individuals whose personal data they control.

Automate will provide reasonable assistance where required under the applicable contract and UK GDPR.

This may include helping with:

  • access requests
  • correction
  • deletion
  • restriction
  • portability
  • objection
  • security enquiries
  • other applicable rights

27. Data subject requests to Automate

If you believe Automate is processing your personal data as a controller, you may contact us at hello@automateapp.co.uk.

We may need sufficient information to verify your identity before responding.

We will respond within the timescales required by applicable law.

28. Complaints

If you have concerns about our use of your personal data, please contact us first so that we can investigate the issue.

You also have the right to complain to the UK's data protection regulator:

Regulator
Information Commissioner's Office (ICO)
Official website
https://ico.org.uk/

The ICO provides information about data protection rights and how to raise a concern.

29. Cookies and similar technologies

Automate's marketing website and applications may use cookies and similar technologies.

These may include technologies used for:

  • essential functionality
  • authentication
  • security
  • preferences
  • analytics
  • performance
  • marketing
  • other functionality

Non-essential cookies or storage technologies will be handled in accordance with applicable PECR requirements, including consent where required.

The ICO states that organisations must provide clear information about cookies and obtain consent for non-essential cookies where required; strictly necessary technologies may fall within an exemption.

Automate maintains a separate Cookie Policy identifying the actual cookies and similar technologies currently used.

30. Analytics

Automate may use analytics and performance technologies to understand:

  • website usage
  • traffic sources
  • page performance
  • feature usage
  • application performance
  • errors
  • conversion
  • service reliability

Analytics information is configured so that it is collected and processed in accordance with applicable privacy and cookie requirements.

31. Children

Automate is a business-to-business service and is not directed towards children.

We do not knowingly seek to provide accounts to children where doing so would be inappropriate or prohibited by applicable law.

If you believe a child has provided personal data to Automate without appropriate authorisation, please contact us.

32. Sensitive or special category data

Automate is not intended to require users to upload special category personal data unless it is necessary for a customer's legitimate operational purpose and appropriate lawful conditions apply.

Customers should avoid uploading unnecessary sensitive personal information.

Where customer workflows require processing of special category data, the customer remains responsible for determining the appropriate lawful basis and applicable Article 9 condition where the customer acts as controller.

Automate will process such information only in accordance with the applicable contract and documented instructions where acting as processor.

33. Data accuracy

Automate provides tools that allow customers to create, import, edit and maintain operational information.

Customers remain responsible for the accuracy and completeness of information they enter into the Service.

AI-assisted extraction and automation may assist users but should be reviewed where accuracy is important.

Automate does not guarantee that automatically extracted or AI-generated information is error-free.

34. Automated decision-making

Automate may use automated processing and AI-assisted systems to provide recommendations, classifications, extraction or workflow assistance.

Unless expressly stated otherwise, these features are intended to assist users rather than make legally significant decisions about individuals.

Where applicable law gives individuals rights relating to solely automated decision-making, Automate will comply with those requirements.

35. Data export

Subject to the customer's subscription and contractual terms, Automate may provide functionality allowing customers to export information from the Service.

Customers are responsible for maintaining appropriate copies of information where they require independent archival records.

The specific export formats and available functionality may change as the Service evolves.

36. Data deletion

Where appropriate and subject to contractual and legal requirements, customers may request deletion of customer data.

Deletion may not immediately remove every copy from:

  • backups
  • security logs
  • legally required records
  • fraud-prevention records
  • other systems where retention is legally justified

Such information will be retained only for as long as necessary for the applicable purpose and protected appropriately.

37. Third-party websites and services

The Service may contain links or integrations to third-party websites and services.

Automate is not responsible for the privacy practices of third parties.

Users should review the privacy notices of those third parties before providing personal data to them.

38. Changes to the Service

Automate is continuously developing its platform.

New functionality may introduce new categories of processing or new technology providers.

Where such changes materially affect how personal data is processed, Automate will update this Privacy Policy and, where legally or contractually required, provide appropriate notice.

39. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

The latest version will be published on the relevant Automate website or application.

The "Last Updated" date will indicate when the policy was most recently revised.

Where changes are material, we may provide additional notice through:

  • email
  • in-product notification
  • account notification
  • another appropriate communication method

40. Governing law

This Privacy Policy is governed by the laws of England and Wales, unless applicable law requires otherwise.

41. Contact

For privacy and data protection enquiries:

Company
Automate Works Limited
Registered office
1 Faviell Gardens, Featherstone, Wakefield WF7 6FF
Company number
16865956

Questions about your data?

We take privacy seriously. Contact us anytime.

hello@automateapp.co.uk

Your privacy matters

Automate uses essential cookies to keep the website working and optional cookies to provide enhanced functionality. You can choose which optional cookies to allow at any time. Privacy Policy · Cookie Policy