Privacy Policy
Last Updated: August 6, 2026
Introduction
Welcome to Assistemia Ltd (“Assistemia,” “we,” “us,” or “our”). We are committed to protecting your personal information and your right to privacy. This privacy policy explains how we collect, use, store, share and protect your information when you use our website at https://assistemia.com (“Site”) and our AI-powered academic research platform (“Services”).
Assistemia Ltd is a company registered in England and Wales, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the data controller for the personal data we process about you.
This privacy policy is written in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
If you have any questions about this policy, please contact us at info@assistemia.com.
1. Age and Eligibility
1.1 Minimum Age
You must be at least 16 years old (or the age of majority in your jurisdiction) to access and use the Services. For users under 16, parental or guardian consent is required.
1.2 Territorial Scope
The Services are operated from the United Kingdom. Although accessible worldwide, it is your responsibility to comply with local laws that may apply to your use of our Services. Assistemia complies with the UK GDPR, the Data Protection Act 2018, and applicable international data protection frameworks.
2. Information We Collect
2.1 Personal Information You Provide
We collect personal information that you voluntarily provide to us when registering, using our Services, or contacting us. This includes:
- Account Data: Name (first and last), email address, organisation, country, job title, fields of interest, account type, acceptance records for the Terms and Fair Usage Policy, and password (hashed).
- Group or Institutional Account Data: Where applicable, organisation name, administrator and billing contacts, authorised-user or seat assignments, and related account-management information.
- Google OAuth Data: If you sign in via Google, we receive your Google email, name, and profile picture.
- Payment Data: Name, email, and billing information processed securely by Stripe. We do not store your card details.
- Research Content: Documents you upload (stored in Supabase for 2 years to enable search history and re-use), text queries, and AI-generated research outputs.
- Contact Data: Name, email, subject, and message when you use our contact form.
- Communication Preferences: Email marketing opt-in status.
2.2 Information Collected Automatically
When you use our Site, we automatically collect:
- Device, Browser and Session Information: IP address (anonymised when used for analytics), approximate country or region derived from IP address, browser type, operating system, device type, screen resolution, pseudonymous device or session identifiers, login and logout times, forced session termination, device or session changes, and account-verification events.
- Usage and Fair-Usage Data: Pages visited, features used, session duration, interaction data, successful tool-operation counts and timestamps, processing and error status, and patterns reasonably required to identify security issues or possible breaches of the Individual Account and Fair Usage Policy.
- Cookies: Essential cookies for site functionality and optional analytics cookies (see Section 9).
2.3 Information from Third-Party Sources
Our platform indexes publicly available academic data from the following sources for use in our research tools:
- OpenAlex — Academic article metadata, author names, affiliations, and ORCID IDs.
- Public patent databases (USPTO, EPO, WIPO) — Patent metadata, inventor names, and abstracts.
This data is publicly available and is processed under our legitimate interest to provide academic research services.
3. How We Use Your Information
We use your information for the following purposes, each supported by a lawful basis under UK GDPR Article 6:
3.1 Performance of Contract (Article 6(1)(b))
- Creating and managing Individual, Group or Institutional accounts, including named-user access and account acceptance records.
- Authenticating you via email/password or Google OAuth.
- Delivering AI-powered research services (literature review, summarisation, topic discovery, patent search, article proofreading, reference formatting and conversion).
- Processing subscription payments via Stripe.
3.2 Legitimate Interest (Article 6(1)(f))
- Responding to contact form enquiries.
- Analysing platform usage via Google Analytics (with IP anonymisation) to improve our Services.
- Indexing publicly available academic metadata and patent data to power research tools.
- Preventing fraud, credential sharing, sequential multi-user use, unauthorised access, automation, circumvention and other abuse, and ensuring platform security.
- Using account, session, device, network and tool-operation patterns to create internal warning signals, investigate suspected misuse, enforce our Fair Usage Policy and maintain service quality. Usage volume or running multiple tools at the same time is not treated as proof of misuse by itself.
3.2.1 Fair-Usage Alerts and Human Review
Automated rules may flag unusual activity and may apply temporary security measures such as reauthentication, email verification, password reset, session revocation or a short restriction while a concern is reviewed. Numerical usage thresholds are internal warning signals only. We do not use usage volume alone to make a permanent suspension or termination decision. Permanent fair-usage decisions will normally involve meaningful human review, and affected users may provide an explanation and appeal.
3.3 Consent (Article 6(1)(a))
- Sending newsletter and marketing communications (you can unsubscribe at any time).
3.4 Legal Obligation (Article 6(1)(c))
- Retaining financial records as required by HMRC (6 years).
- Responding to lawful requests from regulatory authorities.
4. Our Third-Party Service Providers (Sub-Processors)
To deliver our Services, we share personal data with the following trusted third-party service providers. Each operates under a Data Processing Agreement (DPA) with appropriate safeguards for international transfers:
4.1 AI Processing
- OpenAI (US) — Processes user-submitted content, research queries and generates AI outputs using large language models. Data is transmitted via API with zero-retention for training. Transfer safeguard: International Data Transfer Agreement (IDTA) / Standard Contractual Clauses (SCCs). Privacy: https://openai.com/policies/privacy-policy
- Google Gemini (US) — Processes research queries and generates AI outputs using large language models. Data is processed via the Vertex AI API under Google Cloud’s Data Processing Addendum. Transfer safeguard: IDTA/SCCs. Privacy: https://policies.google.com/privacy
4.2 Data Storage and Authentication
- Supabase (EU/UK hosting on AWS) — Database, user authentication, data storage, and storage of user-uploaded documents for 2 years to enable search history and re-use. User data is hosted in EU/UK regions (Frankfurt/London). DPA with SCCs in place. Privacy: https://supabase.com/privacy
4.3 Hosting and Deployment
- Vercel (US) — Web application hosting and content delivery. Transfer safeguard: IDTA/SCCs + EU-US Data Privacy Framework. Privacy: https://vercel.com/legal/privacy-policy
- Cloudflare, Inc. (US) — DNS management, DDoS protection, and web security for assistemia.com. Cloudflare processes visitor IP addresses, HTTP request metadata (user agent, headers), and request logs to provide DNS resolution, traffic filtering, and protection against malicious activity. Cloudflare is ISO 27001 and SOC 2 Type II certified. DPA available at cloudflare.com/trust-hub/gdpr/. Transfer safeguard: UK IDTA / SCCs.
4.4 Academic Data Storage
- Hetzner (Germany) — Dedicated servers storing academic article and patent data. EU-based; no international transfer safeguards required. Privacy: https://www.hetzner.com/legal/privacy-policy
4.5 GPU Compute
- RunPod (US) — GPU compute for document preprocessing and OCR. Stateless architecture — no user data is retained after processing. Transfer safeguard: IDTA/SCCs. Privacy: https://www.runpod.io/privacy-policy
- Dataset Sources (Zenodo, DataCite, GitHub, Figshare, OpenAlex, and others) — Public data repositories queried by our Dataset Finder tool to retrieve dataset metadata. User search queries are transmitted to these services via their public APIs. No personal account data is shared. These are public APIs and no DPA is required as only search queries (not personal data) are transmitted.
4.6 Payment Processing
- Stripe (US) — Processes subscription payments. Assistemia does not store card data; all payment information is handled directly by Stripe (PCI DSS Level 1 certified). Transfer safeguard: IDTA/SCCs. Privacy: https://stripe.com/privacy
4.7 Authentication and Analytics
- Google OAuth (US) — Provides “Sign in with Google” functionality. Only authentication tokens are exchanged. Privacy: https://policies.google.com/privacy
- Google Analytics (US) — Collects anonymised usage analytics (IP anonymisation enabled). Privacy: https://policies.google.com/privacy
4.8 Academic Data APIs
- OpenAlex (US) — Public API for retrieving academic article metadata. No user personal data is sent to OpenAlex.
We do not sell your personal data to any third party. We do not use third-party advertising services or share data with advertisers.
5. International Data Transfers
Assistemia Ltd is based in the United Kingdom. Some of our sub-processors are based in the United States and Germany. When we transfer your personal data outside the UK, we ensure adequate protection through one or more of the following mechanisms:
- International Data Transfer Agreement (IDTA) — The UK equivalent of Standard Contractual Clauses, as approved by the ICO.
- Standard Contractual Clauses (SCCs) — EU-approved contractual safeguards incorporated into our DPAs.
- EU-US Data Privacy Framework — Where applicable (e.g., Vercel, Google).
- EU Adequacy — For transfers to EEA countries (e.g., Hetzner in Germany), no additional safeguards are required.
All sub-processor DPAs include commitments on data security, breach notification, and data subject rights assistance.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:
- Account data: Retained for the duration of your account and normally deleted within 30 days of account closure, except for limited records that must be retained for security, dispute-resolution, legal or regulatory purposes.
- AI research inputs: stored in Supabase for 2 years to enable search history and re-use, then automatically deleted by AI providers after processing (zero-retention API). Outputs stored for up to 2 years of inactivity, then deleted.
- Payment records: Retained for 6 years as required by HMRC.
- Contact form enquiries: Retained for 2 years, then deleted.
- Analytics data: Anonymised; retained for 14 months (Google Analytics default).
- Routine security and fair-usage logs: Retained for up to 12 months.
- Investigation, warning, suspension, termination and appeal records: Retained for up to 24 months after the matter is resolved or the account is closed. Where reasonably necessary to establish, exercise or defend legal claims, relevant records may be retained for a longer period up to the applicable legal limitation period.
- Marketing consent records: Retained for 3 years after last activity, then deleted.
You can request deletion of your personal data at any time by contacting info@assistemia.com. We will respond within one calendar month.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256) across all services.
- Access Controls: Role-based access with multi-factor authentication for administrative access and a one-active-device-session rule for Individual accounts.
- Session Security: A new login may end the previous active device session. Repeated forced logouts, session changes or other risk signals may result in additional verification or review.
- Infrastructure Security: Supabase Row-Level Security (RLS), Vercel edge network protection, and Hetzner data centre physical security.
- Regular Audits: Security assessments and monitoring of all sub-processor compliance.
- Password Security: User passwords are hashed using industry-standard algorithms and are never stored in plain text.
While we strive to protect your personal information, no method of transmission over the internet is 100% secure. We encourage you to safeguard your account credentials and notify us immediately of any unauthorised access.
8. Your Rights Under UK GDPR
Under the UK GDPR and Data Protection Act 2018, you have the following rights in relation to your personal data:
- Right of Access (Article 15) — Request a copy of the personal data we hold about you.
- Right to Rectification (Article 16) — Request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17) — Request deletion of your personal data (“right to be forgotten”).
- Right to Restrict Processing (Article 18) — Request limitation of how we process your data.
- Right to Data Portability (Article 20) — Request transfer of your data in a structured, machine-readable format.
- Right to Object (Article 21) — Object to processing based on legitimate interest or direct marketing.
- Fair-Usage Decision Review — Ask us to explain and reconsider a suspension or termination decision that used your personal data, provide your point of view, and obtain human review where applicable.
- Right to Withdraw Consent — Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at info@assistemia.com. We will respond to your request within one calendar month. If we need to extend this period (by up to two further months), we will inform you within the first month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk
- Telephone: 0303 123 1113
9. Cookies
We use the following categories of cookies on our Site:
9.1 Essential Cookies
Required for the operation of the Site, including authentication and session management. These cannot be disabled.
9.2 Analytics Cookies
We use Google Analytics with IP anonymisation enabled to understand how users interact with our platform. These cookies collect anonymised data about page visits, session duration, and feature usage.
9.3 Managing Cookies
You can control or disable non-essential cookies through your browser settings or via our cookie consent banner. Disabling cookies may affect some functionality.
We do not use advertising cookies, retargeting pixels, or third-party advertising trackers.
10. Third-Party Links
Our Site may contain links to third-party websites (e.g., academic publishers, patent databases). We are not responsible for the privacy practices of these third-party sites. We encourage you to review their privacy policies before providing any personal information.
11. Children’s Privacy
Our Services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly.
12. Changes to This Privacy Policy
We may update this privacy policy from time to time. We will notify you of any material changes by:
- Updating the “Last Updated” date at the top of this policy.
- Providing a prominent notice on our Site.
- Sending you an email notification for material changes (at least 14 days’ notice).
Continued use of the Services after changes become effective constitutes your acceptance of the updated policy. If you disagree with any changes, you should stop using the Services and contact us to close your account.
13. Data Protection Contact
For all privacy-related enquiries, data subject rights requests, or complaints:
Data Protection Lead: Cemal Okan Sakar
Email: info@assistemia.com
Address: Assistemia Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Website: https://assistemia.com
You also have the right to contact the ICO directly:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk | Telephone: 0303 123 1113