Confirm Action
Are you sure?
Replace Project

Currently bound to:

Privacy Policy

Last updated: September 2026

This Privacy Policy explains how ASC Portal collects, uses, stores, and protects information when ASC staff, contractors, and other authorised users access the portal. ASC Portal is an internal business system used for account access, task management, timesheets, logbook workflows, notifications, team support, reporting, and selected administrative functions.

1. Information We Collect

We collect account and access data needed to run the portal, such as your name, email address, password hash for local sign-in, role and permission assignments, team visibility, terms acceptance, email verification status, security preferences, and active session records.

If you use Google sign-in, we receive the basic Google account data required to authenticate you and match you to an ASC Portal user, such as your Google account email address, display name, and Google account identifier. We do not request access to Google Drive, Gmail content, Google Calendar, or other Google data through the sign-in flow.

While you use the portal, we may store profile and operational data that you create or update, including profile pictures, project and site details, assignments, timesheet entries, approvals, unlock requests, logbook records, support tickets, attachments, reports, and related audit or activity history.

Depending on which features your organisation has enabled, we may also collect: your date of birth (used for optional birthday recognition messages); a cached copy of your Slack profile photo and Slack member ID (used to display your avatar and deliver optional Slack notifications); employment and performance data such as skill ratings, skill assessments, responsibility assignments, and attendance/leave records; a record of which internal pages you have accessed and when; and, if you use the optional AI chatbox feature, a log of your questions, which data categories they touched, and associated usage cost. See sections 4 and 5 below for how AI chatbox and Slack data specifically are handled.

Separately, if your organisation has connected Simpro, ASC Portal imports business data such as leads, quotes, jobs, and staff activity logs from Simpro into the portal for reporting. This is operational business data flowing into the portal, not personal data we send out to Simpro about you.

2. Employee Onboarding and Candidate Data

When ASC hires a new employee, the portal sends the candidate a secure, single-use, time-limited link by email to complete an onboarding form. Candidates do not need a portal account to use this link.

Through this form, we may collect the candidate's name, date of birth, contact details, gender, marital status, religion, national ID number, tax ID number, home address, bank account details, social-security numbers, government ID or contract documents, and a profile photo. A manager assigned to review the candidate may also submit related employment details as part of the same workflow.

This information is used to assess the candidate and, if approved, to create their employee account and HR record. Access to submitted onboarding data is restricted to administrators holding the onboarding-review permission and the specific manager assigned to that candidate.

Onboarding records and uploaded documents, including those for candidates who are not progressed, are retained as part of ASC's personnel records until deletion is specifically requested.

3. How We Use Information

We use collected information to authenticate users, manage accounts, enforce role-based access, operate task-management and timesheet workflows, render reports and dashboards, maintain notifications, and support normal business administration and troubleshooting.

We also use account and security data to send verification emails, password-reset messages, email one-time passcodes when enabled, live notification updates, and session-activity information such as logged-in devices.

Google account data obtained through sign-in is used only for authentication, account linking, secure access control, and related account administration. It is not used for advertising or sold to third parties.

Where enabled, we use your Slack member ID to send you automated Slack direct messages, such as timesheet reminders or an optional birthday greeting, and to sync your Slack profile photo for display in the portal. We use page-access and handbook-article-read history to support accountability, security review, and content usage insight for administrators with the relevant permission.

4. Third-Party Services and Data Sharing

We do not sell personal data or Google sign-in data. We may use third-party services where needed to operate ASC Portal, including:

  • Google for optional Google sign-in
  • SMTP or email delivery providers for verification, OTP, reset, and backup emails
  • OpenStreetMap, Nominatim, and Photon for site address lookup and map previews
  • Google Drive when authorised administrators configure backup delivery to Google Drive
  • Slack, for optional profile photo sync and for sending reminder/notification direct messages when your organisation enables that feature
  • Anthropic (the maker of Claude), when you use the optional AI chatbox feature - see section 5 below

Information is shared with those services only as needed to provide the relevant feature. We may also disclose information where required by law, to protect ASC Portal, or to investigate security or misuse issues.

Separately, if your organisation has connected Simpro, business data (leads, quotes, jobs, staff activity) flows into ASC Portal from Simpro for reporting purposes. We do not send your personal account data to Simpro as part of this integration.

5. AI Chatbox (Optional Feature)

ASC Portal includes an optional AI-assisted chatbox powered by Anthropic's Claude models. When you ask the chatbox a question, that question and the specific business data needed to answer it are sent to Anthropic to generate a response.

Access is controlled by data category ("dataset"). An administrator must explicitly grant you access to a dataset before the chatbox can use it to answer your questions - by default, a dataset is not accessible to anyone until that grant exists. Datasets containing especially sensitive personal data, such as employee HR and performance records, are blocked from the chatbox entirely, for every user including administrators, until someone holding the required compliance permission has reviewed and documented the basis for enabling it. Certain individual data fields (for example, bank account details, national ID numbers, religion, and marital status) are excluded from the chatbox's reach at the database level regardless of dataset access.

We log each chatbox question, the data categories it touched, and associated token/cost usage, for monitoring, audit, and cost-control purposes. This usage log is retained for 90 days and then automatically deleted.

6. Cookies, Sessions, and Security Controls

ASC Portal uses essential cookies and server-side session storage to keep users signed in, secure the authentication flow, and prevent misuse of the service. These cookies are required for the portal to function correctly and are not used as advertising trackers.

The application also uses security controls such as role-based permissions, CSRF protections, rate limits on sensitive auth flows, and security headers. Session activity may be shown to users so they can review and revoke active sessions.

Credentials and secrets that the portal manages on your organisation's behalf, such as the Slack bot token and the Anthropic API key used by the optional AI chatbox, are encrypted at rest. Other personal and HR data is protected through authentication, role-based access control, and audit logging rather than field-level encryption. Technical and audit logs may also capture IP address and browser/device (user-agent) information for security and troubleshooting purposes.

7. Files, Backups, and Retention

Profile pictures, support-ticket attachments, and site attachments are stored on the server and served through authenticated routes. Direct public access to protected upload locations is blocked.

Authorised administrators may generate backup exports in SQL, CSV, or XLSX format and deliver them by download, email, or Google Drive depending on the configured backup workflow. Backup history and related administrative activity may also be retained.

Account, operational, audit, notification, and backup-related data may be retained for business, administrative, legal, and security reasons. Retention periods can vary depending on operational needs and administrator actions.

8. Your Choices

Users can review or update certain account details from the portal, including profile name, profile picture, password, email OTP preference, and active sessions. Some account data, such as email address, role assignments, or access scope, may only be changed by administrators or related security workflows.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected on this page and the "Last updated" date above. When you are logged in and a material change has not yet been acknowledged for your account, ASC Portal shows a brief notice linking to the updated Privacy Policy and Terms of Service. Continuing to use ASC Portal after that notice constitutes agreement to the updated terms.

10. Contact

If you have questions about this Privacy Policy or data handling in ASC Portal, please contact your system administrator.

← Back to Register