Privacy notice
How Be Assured Ltd collects, uses and protects personal information. Last updated 7 October 2026.
1. Who we are
Be Assured Ltd (“Be Assured”, “we”, “us”) is a company registered in England and Wales, company number [company number], registered office [registered address]. We provide software that helps social housing providers, consultants and oversight bodies assess, evidence and improve performance against the Regulator of Social Housing’s standards.
For personal information collected through this website, our marketing and our dealings with customers, we are the controller. For information our customers upload into the Be Assured platform, we are usually a processor acting on our customer’s instructions (see section 8).
Questions about this notice or your information: privacy@beassured.co.uk, or write to the Data Protection Lead at the address above.
2. Information we collect
- Contact and enquiry details you give us, for example when you book a demo, subscribe to updates or email us: name, job title, organisation, work email, phone number and what you tell us in your message.
- Account details for platform users: name, work email, role, organisation, login records and user settings.
- Customer and supplier records: contract, billing and correspondence details for the people we deal with.
- Technical and usage data: IP address, browser and device type, pages visited and actions taken on our website and platform, collected through logs and cookies (see our Cookie policy).
- Event and webinar data: registration and attendance details if you join one of our events.
We do not intentionally collect special category data (such as health or ethnicity) through this website. Please don’t include it in enquiry forms.
3. How we use it, and our lawful basis
| Purpose | Lawful basis under UK GDPR |
|---|---|
| Responding to enquiries and arranging demos | Legitimate interests in responding to people who contact us, or steps before entering a contract |
| Providing the platform and supporting users | Performance of a contract with our customer, and our legitimate interests in running the service |
| Sending regulatory updates and marketing emails | Consent, or legitimate interests for existing business contacts, as allowed by PECR. You can opt out at any time |
| Keeping our website and platform secure, and improving them | Legitimate interests in running a safe, reliable service |
| Billing, accounting and record keeping | Legal obligation and performance of a contract |
| Handling complaints, disputes and legal claims | Legitimate interests and legal obligation |
4. Who we share it with
We never sell personal information. We share it only where needed, with:
- Service providers who host, support or run our systems for us, such as cloud hosting, email, CRM, analytics and customer support tools, under contracts that require them to protect it.
- Consultants or partners, only where a customer has invited them into its workspace.
- Professional advisers such as lawyers, accountants and insurers.
- Regulators, law enforcement or courts, where the law requires it.
- A buyer or investor, if all or part of our business is sold or restructured, under confidentiality terms.
5. International transfers
We aim to keep personal information in the UK. Where a provider processes it outside the UK, we make sure there is a lawful transfer mechanism in place, such as a UK adequacy decision or the ICO’s International Data Transfer Agreement or Addendum, with appropriate safeguards.
6. How long we keep it
- Enquiries and demo requests that don’t lead to a contract: up to 24 months after our last contact.
- Marketing preferences: until you unsubscribe, then a suppression record so we don’t contact you again.
- Customer and contract records: for the length of the contract plus 6 years.
- Platform data: as set out in the customer’s contract, then deleted or returned.
- Website and security logs: normally up to 12 months.
7. How we protect it
We use technical and organisational measures suited to the risk, including access controls by role, encryption, logging of access and changes, staff confidentiality obligations and supplier due diligence. No system is completely secure, so if we become aware of a breach that affects you we will tell you and the ICO where the law requires.
8. Data inside the Be Assured platform
Our customers, such as housing associations, councils and consultancies, decide what information goes into their workspace. This can include personal information about staff and, in some cases, tenants. For that information the customer is the controller and Be Assured is the processor, acting under a written data processing agreement.
If you are a tenant or member of staff and want to use your rights over information held in a customer’s workspace, please contact that organisation directly. We will help them respond.
9. Your rights
Under UK data protection law you have the right to:
- access the personal information we hold about you
- have inaccurate information corrected
- have information deleted in some circumstances
- restrict or object to how we use it, including objecting to direct marketing at any time
- receive your information in a portable format, where processing is based on consent or contract
- withdraw consent at any time, where we rely on consent
To use any of these rights, email privacy@beassured.co.uk. We will reply within one month. There is normally no charge.
10. Complaints
If you’re unhappy with how we’ve handled your information, please tell us first so we can put it right. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113.
11. Changes to this notice
We may update this notice from time to time. The date at the top shows when it was last changed. Significant changes will be flagged on our website or emailed to customers.