Privacy policy
Effective [OWNER: date at deploy]. Applies to fsassertions.com and the fsassertions application at app.fsassertions.com.
fsassertions is operated by [OWNER: legal entity name, registered address] (“we”), the controller of the personal data described in this policy. You can reach us about anything in it at hello@fsassertions.com.
In short
- Your work is yours. The figures, instruments and scenarios your company enters belong to your company, and we use them only to run the service for you.
- No trackers. Neither this website nor the application runs analytics, telemetry or advertising trackers.
- Stored in the EU. Application data lives in Google’s Belgium (europe-west1) region.
This website
fsassertions.com is a static site. It sets no cookies and collects nothing about you directly. Our hosting provider (Google Firebase Hosting) keeps standard server access logs to deliver the pages and protect the service. Tutorial videos are embedded through YouTube’s youtube-nocookie.com player and load only if you press play; from that point YouTube’s own terms and privacy policy apply to the playback.
The application
When your company subscribes and you sign in, we process:
- Account details. Your email address and password. Passwords are handled by Google Firebase Authentication; we never see or store them in readable form.
- The content you enter. Scenario data — share movements, instrument terms, earnings figures, the names and notes you type — together with the working state around it: to-dos, review points, and the workflow history of who prepared, reviewed or assigned a file and when.
- Team details. Your team’s name, its members, and the email addresses of colleagues you invite.
- Billing details. Payment is handled by Creem, our merchant of record. Creem collects your payment information under its own terms; we receive your subscription tier, status and billing contact — never card numbers.
- Service email. We send transactional email only: workflow notifications (for example, a file assigned to you for preparation) and account emails such as password resets. There is no marketing list unless you separately ask to join one.
How we use it
We use this data to provide the service your company subscribed to, to support you when you write to us, to bill correctly, and to keep the service secure — in legal terms: performance of a contract, our legitimate interest in running the service safely, and the legal obligations that come with billing. We do not sell personal data, and we do not use your content for anything other than operating the service. We access the content of your scenarios only if you ask us to help with something in them, or where the law requires it.
Who processes it for us
- Google (Firebase). Authentication, database and hosting. Application data is stored in the Belgium (europe-west1) region.
- Creem. Merchant of record for subscriptions — checkout, payment processing, tax receipts.
- [OWNER: email delivery provider]. Delivery of the transactional emails described above.
Where a provider processes limited data outside the EU (for example, billing or support records), it does so under recognised safeguards such as the EU standard contractual clauses.
How long we keep it
Your account and scenario data are kept for as long as your account exists. If your subscription lapses, your data is never locked: you keep access to your files and can export them at any time. If you ask us to delete your account, we delete the account and its data, except billing records that Creem or we must keep for tax and accounting law.
Your rights
You can ask for a copy of the personal data we hold about you, have it corrected, have it deleted, or take your data with you (scenario content is exportable from the application itself, including to Excel). Write to support@fsassertions.com and we will respond within a month. If you believe we have handled your data badly, you can complain to your local data protection authority.
Security
All traffic is encrypted in transit. Access to team data is enforced server-side — database rules restrict every read and write to the members of your team, and review-workflow segregation is enforced at the same level. Passwords must be at least 12 characters with mixed character classes. The application loads no third-party scripts.
Children
The service is for professional use and is not directed at children.
Changes
If this policy changes, the new version is posted here with a new effective date; for significant changes we will tell subscribers by email.