Ascent← Ascent
Legal

Privacy Policy

How Ascent collects, uses, shares and protects personal data across the website, app and developer services.

Operated by Innovanet Software Ltd · Contact hello@ascent.dev · Last updated 23 July 2026
Ascent is in beta. These terms are current as of 23 July 2026 and may be updated as the product and its legal entity details are finalised. Some formal particulars (registered address and governing law) are marked below and will be confirmed. Questions or requests: hello@ascent.dev.

01Who we are & scope

Innovanet Software Ltd, [registered address — to be confirmed] (trading as "Ascent"), is the controller for account, website, sales and product-usage data described here. For customer-site data processed only on a business customer’s instructions, we generally act as processor/service provider under a Data Processing Addendum. Contact hello@ascent.dev. This notice covers the Ascent website, hosted application, developer portal, API and support interactions.

02Personal data we collect

CategoryExamplesSource
Account & identityName, email, organisation, role, authentication identifiersYou, identity provider
CommercialPlan, orders, invoices, tax location, payment token/statusYou, payment processor
Connected propertyDomains, CMS identifiers, Search Console & analytics data, permissionsYou & connected providers
Content & instructionsPrompts, brand inputs, approvals, generated drafts, publish actionsYou & authorised users
Technical & usageIP address, device/browser, logs, events, diagnostics, API callsAutomatically
Support & feedbackMessages, attachments, surveys and notesYou
Public web dataPublic pages, sitemap content, search results, competitor signalsPublic sources & search providers

03Purposes & lawful bases

PurposeTypical lawful basis
Provide accounts, audits, generation, publishing, monitoring, support & billingContract; legitimate interests; legal obligation
Secure the Service, prevent abuse, maintain audit logsLegitimate interests; legal obligation
Improve reliability & features using minimised usage dataLegitimate interests; consent where required
Send requested product communications & service noticesContract; legitimate interests
Send marketing & set non-essential trackingConsent where required; otherwise opt-out
Comply with law, disputes & enforcementLegal obligation; legitimate interests

04AI & automated processing

Ascent may use automated systems to prioritise SEO opportunities, generate content, estimate potential, recommend actions and — only when you configure it — publish or reverse changes. These decisions ordinarily concern website operations rather than legal or similarly significant effects on individuals. You select off, human-approved or automatic modes per task. We provide explanations, logs, reversal controls and a contact route for concerns.

05Sharing & subprocessors

We maintain a subprocessor list naming provider, purpose, processing location and transfer mechanism. We do not train Ascent or third-party foundation models on identifiable Customer Content without your separate opt-in.

06International transfers

Where personal data moves outside its origin country, we use applicable safeguards — adequacy decisions, standard contractual clauses, the UK addendum/IDTA or another lawful mechanism — plus supplementary measures where required. Actual corporate and hosting locations are being finalised.

07Retention

DataRetention rule
Account & contractTerm plus up to 7 years where needed for tax, claims and audit
Operational content & project dataActive term; 30-day export window; deletion within 60 days thereafter
Security & API logs12 months unless an incident requires longer
Consent recordsDuration of processing plus the limitation period
BackupsRolling encrypted backups deleted within [90 days — to be confirmed]

08Your rights & choices

Depending on your location, you may request access, correction, deletion, portability, restriction or objection; withdraw consent; opt out of marketing, sale/sharing or targeted advertising; limit certain sensitive-data use; and appeal a denied request. Requests: hello@ascent.dev. We verify only as reasonably necessary and never require verification for an opt-out where prohibited. You may complain to your data-protection authority.

09Cookies & tracking

Strictly necessary technologies operate the service and security. Analytics, personalisation and advertising technologies remain disabled until valid consent where required. "Reject all" is as easy as "Accept all", and you can reopen settings and withdraw consent at any time. See the Cookie & Consent Notice for categories and vendors.

10Security, children & changes

We use administrative, technical and organisational safeguards, but no system is completely secure. The Service is for business users and not directed to children. We post material changes and obtain consent where required.

11Regional supplements

Where applicable thresholds are met (for example under US state privacy laws), we disclose categories collected, purposes, sources, recipients and retention; state whether personal information is sold or shared; provide "Do Not Sell or Share My Personal Information" and sensitive-data limitation mechanisms; honour opt-out preference signals; and avoid discriminatory treatment. Applicability and roles are being confirmed for each launch market.