Privacy
Privacy and your data
What we capture, how we handle it, and how to delete it, in plain English first, with the full policy alongside.
Last updated
This is a summary to help you understand quickly. The Full policy tab is the binding document.
What we capture
We only keep what’s needed to run your account and the service:
- Your account: Your email address and sign-in records, held in our own UK database, and your first name if you choose to give it. We use the name to greet you and to show who is signed in. Sign-in is passwordless (an emailed link, or an emailed one-time code); no third-party identity provider is involved.
- Your children: The name you give us (we ask for a first name), an approximate age, and gender or pronouns for the children you add. A child added by a school may also carry a surname initial. We never record a full date of birth.
- Answers and observations: Profiler answers and any free-text observations you share, per child.
- Chats and messages: Conversation history with Assembly, per child.
- Reports: The written report for each child, held in our UK database. A PDF is built when you ask for one and is not kept afterwards; every download is authenticated and logged.
- Programme progress: Which programmes and episodes you've started or completed, per child.
- Waitlist and enquiries: If you join the waitlist or register interest from the public site, we hold the email address you give us, and for an organisation enquiry your name, organisation, role and message. It is saved in UK cloud storage, kept apart from the product database, as soon as you submit the form, and marked unconfirmed until you follow the link in the email we send you. Once you confirm an organisation enquiry, a copy is also emailed to our inbox. Ask us to delete it at any time and we will.
- Usage analytics: Which features are used (PostHog, EU), so we can improve the product. Tied to a session, but never your child's profile or answers. We don't sell your data.
How we handle it
Your data lives in a single, secure area tied to your account. Your child's profile, answers and reports are stored in the UK, in Microsoft Azure. To write a report or a reply in chat, Microsoft's AI service may process the request in another Azure region; what is kept is kept in the UK, and nothing you give us is used to train AI models. Usage analytics (PostHog) is processed in the EU: it's linked to a session, not your name, and it never receives your child's profile, answers or reports. Access is limited to you, the systems that run the service, and the few of us who need it to operate or support it, which is logged. We don’t sell or share your data with third parties for marketing.
Sign-in is passwordless: we email you a secure link, or a short one-time code if you would rather type one in. Authentication runs inside our own application, and your sign-in data lives in our own UK database. The email itself is sent by Microsoft’s email service on our own Azure account, which we have set to hold what it stores in the United Kingdom; Microsoft says that data may be processed outside that location when it is sent.
The chat and reports are powered by Azure OpenAI, operated by Microsoft. Your data is stored in the UK, and to write a response Microsoft may process the request in another Azure region. OpenAI the company never receives your data. We do not use your data to train AI models, and neither does Microsoft. One honest detail: Microsoft can retain prompts for up to 30 days, inside the UK, for abuse monitoring, and we are pursuing Microsoft’s option that disables even that.
We run the product on a deliberately small set of providers, and only share what’s needed for each service:
- Microsoft Azure (UK (Azure UK South)): Runs the UK-hosted core of the service, in Azure's UK South region: hosting, database, file storage, background jobs and monitoring. Requests reach it through Microsoft's global edge network, Azure Front Door, which filters them and serves our pages from the location nearest to you. It also stores what you send through the forms on our public website, in UK cloud storage, and asks the email service below to send your confirmation link. Three parts of the service are listed separately, because what we can promise about where they process your data is different. The AI that writes reports and chat replies runs on an Azure resource in the UK, but an individual request may be processed in another Azure region (see Microsoft Azure AI). The email service that sends your sign-in link is the same Azure account and the same agreement, but it has no single region, so we have set it to hold what it stores in the UK (see Microsoft email delivery). The public website is hosted in Azure's West Europe region, in the Netherlands, because that hosting service has no UK region (see Microsoft website hosting).
- Microsoft email delivery (stored in the UK, may be processed outside the UK): Sends the emails the service has to send: your sign-in link or the short one-time code you can ask for instead, an invitation to join a child's profile, one welcome email the first time you start a child's profile, notifications such as telling you that a profile is ready to read, and, if you stop part way through a profile, one reminder the next day and at most one more a week later, which you can turn off. It also sends the two emails our public website needs: the link that confirms the address you gave on a form, which carries the kind of form it was in the link itself, and, when an organisation enquiry is confirmed, a message to our own inbox repeating what you wrote. This is our own Azure resource in our own Azure subscription, Azure Communication Services, covered by the same Microsoft agreement as the rest of Azure above, so it is the same provider rather than a new one. It is listed on its own line only because where its data is held is a setting of its own: it is a global Azure resource rather than one in a single region, and we have set its data location to the United Kingdom, so what it holds is held here. Microsoft's own documentation for that service says data at rest stays in the location we chose, and that data may travel through or be processed in other parts of the world, so we do not claim the sending happens in the United Kingdom. Some of these emails are about a child: an invitation, the welcome email, a ‘profile is ready’ notice and a reminder to finish a profile carry the child’s first name, and an invitation sent by a school also names that school. An invitation from one parent to another carries no school name. None of them carry a child's answers, observations, chat messages or the report as the product holds them. The one free-text field any of these emails carries is the message you type into an organisation enquiry on the public website. That box is an open question and we do not restrict what goes in it, so a professional writing to us could put details of a family in there, including the kind of thing the product keeps as answers or observations; we do not claim otherwise.
- Microsoft Azure AI (stored in the UK, processed in any Azure region): Runs the AI models that write each child's report, the plain-language explanations in it, and the replies in chat. Your data is stored in the UK. To write a response, Microsoft may process the request in another Azure region. Anything kept at rest stays in the UK, including the copy Microsoft holds for up to 30 days to check for misuse of the service. OpenAI the company never receives your data, and nothing you give us is used to train AI models.
- Microsoft website hosting (EU (Azure West Europe, Netherlands)): Hosts our public website, www.helloassembly.com, on Azure Static Web Apps. That service is not offered in a UK region, so it runs in Azure's West Europe region, in the Netherlands. When you fill in a form on the website, what you type is received there and passed on to our UK storage and to the email service that sends your confirmation link, which holds what it stores in the UK but has no single region (see Microsoft email delivery).
- Microsoft 365 (UK or EEA (Microsoft 365, Europe)): Our email inbox. info@helloassembly.com, the address this website gives for questions, privacy requests and deletion requests, is a Microsoft 365 mailbox, so anything you email us is held there. When you confirm an organisation enquiry made on the website, we are told by an email to the same inbox that repeats the enquiry.
- PostHog (EU): Product analytics: which features are used, so we can improve the product. Events are tied to a session so we can make sense of them, but PostHog never sees your child's profile, answers or reports. We don't sell your data, and we minimise what PostHog receives.
- Google Calendar (US and worldwide (Google)): Runs the booking calendar that families in a pilot use to book a call with a clinician. The calendar is Google's own page, shown inside ours: opening it connects your browser to Google, and if you book, what you type into Google's form and the time you choose go to Google, which holds the booking for us. The address of our page is not sent to Google, and nothing about your child is passed to it.
The same register, with what each provider handles, lives in the trust centre .
How to delete your data
Everything we hold about one child, their profile, answers, chats and reports, is yours to download or delete from that child’s page in the app. Deletion there removes it from the live service straight away, and you don’t need to ask us or give a reason. Copies can stay in our backups for a while: the database’s continuous backups expire after 35 days, and our nightly backup copies are kept for at least 35 days. The deletion page walks through the steps.
To close your whole account, or to remove your own data rather than a child’s, email us and we’ll handle it:
Request data or account deletion
We’ll confirm receipt and process your request. You can also ask us to delete your analytics data at the same time.
For any other privacy question or request (correction, restriction, or anything about your own data), email us at info@helloassembly.com .
Privacy policy
Last updated . This is the binding document. The list of providers in it, and the categories of data it describes, are generated from the same register the trust centre publishes, so the two cannot describe different things.
Last updated: 18 September 2026.
Assembly (a trading name of Family Emotional Health Limited) respects your privacy and is committed to protecting your personal data. This privacy notice explains how we look after the personal data of the parents, carers and professionals who use Assembly, and of the children they add, and it sets out your rights and how the law protects you.
Key points:
What Assembly is: a tool that helps parents, carers and professionals understand a child’s behaviour, strengths and needs. It is not a medical or clinical service, we do not provide healthcare, and nothing we produce is a diagnosis or medical advice.
Why we use your data: to provide the service you have asked for, to keep it safe and working, and to improve it.
Sensitive data: information about a child’s behaviour and development can be health data, which the law gives extra protection. Where we rely on your consent for that, you can withdraw it at any time.
Sharing data: we do not sell your data, and we do not share it for marketing. We share it with the small number of service providers named in section 7, with a school or clinic where you have chosen to share a child’s profile with them, and with authorities where the law requires it.
Where your data lives: in the United Kingdom, apart from the limited exceptions named in section 8.
Questions: email us at info@helloassembly.com.
IMPORTANT INFORMATION AND WHO WE ARE
1.1. Under the UK GDPR and the Data Protection Act 2018, we are required to explain why we collect information about you, how we intend to use it, and whether we will share it with anyone else.
1.2. This notice applies to everyone who uses Assembly, to people who are considering using it, and to the children whose information a user gives us.
1.3. We may update this notice at any time. Where a change is substantial we will tell you, and the date at the top of this notice always shows when it was last updated.
1.4. It is important that you read this notice so that you know how and why we use information about you. It is also important that you tell us about any changes to your personal information, so that what we hold stays accurate and up to date.
1.5. Family Emotional Health Limited, which trades as Assembly, is the data controller for the personal data described in this notice. This means the company is responsible for deciding how that data is held and used.
1.6. We have not appointed a statutory Data Protection Officer. Responsibility for data protection sits with the company’s directors, and we have a named privacy contact who handles privacy questions, rights requests and complaints. You can reach that contact at info@helloassembly.com, and any request you send there is logged and answered whoever is on duty.
CONTACT DETAILS
1.7. Our full details are:
Full name of legal entity: Family Emotional Health Limited, a company registered in England and Wales under company number 14078663, whose registered address is:
Euston House
24 Eversholt Street
London NW1 1DB
ICO Registration number: ZB525887
Privacy contact email address: info@helloassembly.com
Postal address: Family Emotional Health Limited, Euston House, 24 Eversholt Street, London NW1 1DB
You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.
WHY ARE WE COLLECTING YOUR INFORMATION?
2.1. We ask for information about you and your child so that we can provide the service, make what it produces genuinely useful for your family, and keep your account secure.
2.2. Where we need to collect personal data by law, or under the terms of our agreement with you, and you do not provide it when asked, we may not be able to provide the service. We will tell you if that is the case at the time.
TYPES OF PERSONAL INFORMATION WE USE
3.1. The personal data we hold falls into the following categories. This is the same list as the plain-English summary on this page and the trust centre, because all three are generated from one record:
3.1.1. Your account: Your email address and sign-in records, held in our own UK database, and your first name if you choose to give it. We use the name to greet you and to show who is signed in. Sign-in is passwordless (an emailed link, or an emailed one-time code); no third-party identity provider is involved.
3.1.2. Your children: The name you give us (we ask for a first name), an approximate age, and gender or pronouns for the children you add. A child added by a school may also carry a surname initial. We never record a full date of birth.
3.1.3. Answers and observations: Profiler answers and any free-text observations you share, per child.
3.1.4. Chats and messages: Conversation history with Assembly, per child.
3.1.5. Reports: The written report for each child, held in our UK database. A PDF is built when you ask for one and is not kept afterwards; every download is authenticated and logged.
3.1.6. Programme progress: Which programmes and episodes you've started or completed, per child.
3.1.7. Waitlist and enquiries: If you join the waitlist or register interest from the public site, we hold the email address you give us, and for an organisation enquiry your name, organisation, role and message. It is saved in UK cloud storage, kept apart from the product database, as soon as you submit the form, and marked unconfirmed until you follow the link in the email we send you. Once you confirm an organisation enquiry, a copy is also emailed to our inbox. Ask us to delete it at any time and we will.
3.1.8. Usage analytics: Which features are used (PostHog, EU), so we can improve the product. Tied to a session, but never your child's profile or answers. We don't sell your data.
3.1.9. Technical data: your IP address, browser and device type, and the pages you visit, collected when you use the site or the app.
3.2. SPECIAL CATEGORIES OF PERSONAL DATA
Some of what we hold may be “special category” personal data, which the law protects more strictly. In our case that is information about a child’s health and development: the behaviours, strengths, needs and any diagnoses or additional needs you choose to tell us about, including anything you write in an observation or a chat.
3.2.1. We do not ask for information about racial or ethnic origin, religious beliefs, sex life or sexual orientation, trade union membership, or genetic or biometric data, and we have no field for any of them. If you type something of that kind into an observation or a chat, we will hold it as part of that record, but we do not seek it and we do not use it to categorise anyone.
3.2.2. We hold no medical records, and we receive nothing from a GP, a hospital, or any other health or care provider.
3.3. AGGREGATED DATA
We also collect, use and share anonymised and aggregated data (“Aggregated Data”), such as statistical or usage data, for our own internal purposes and to describe the service publicly. Aggregated Data can be derived from your personal data but is not personal data in law, because it does not directly or indirectly reveal your identity. If we ever combine Aggregated Data with your personal data so that it can identify you, we treat the combined data as personal data and use it in accordance with this notice.
SOURCE OF YOUR PERSONAL INFORMATION
4.1. We obtain the information above from the following sources:
4.1.1. from you directly, when you create an account, add a child, answer profiler questions, write an observation, or chat with Assembly;
4.1.2. automatically from your device, when you use the website or the app, in the form of the technical and usage data described at 3.1.9;
4.1.3. from a school, clinic or other organisation, only where you have asked us to connect your child’s record to them and have given consent for that.
HOW AND WHY WE USE YOUR PERSONAL DATA
5.1. Under data protection law we need a “lawful basis” for collecting and using information about you for any particular purpose.
5.2. The purposes we use your personal data for, and the lawful basis for each, are:
5.2.1. Providing the service: creating and running your account, building a profile of your child from the answers you give, generating reports and recommendations, and answering you in chat. Our lawful basis: it is necessary to perform our contract with you.
5.2.2. Keeping the service safe and secure: authenticating you, preventing and investigating misuse, and protecting the service and the people who use it. Our lawful basis: it is necessary for our legitimate interests in running a secure service, where those interests are not overridden by your rights, and in some cases it is necessary to meet a legal obligation.
5.2.3. Supporting you: answering your questions, and handling complaints and rights requests. Our lawful basis: it is necessary to perform our contract with you, to meet our legal obligations, and for our legitimate interests in running the service well.
5.2.4. Improving the service: understanding which features are used, and reviewing the quality of what Assembly produces. Our lawful basis: it is necessary for our legitimate interests in improving the service, where those interests are not overridden by your rights. We use the least identifying data that will answer the question, and our usage analytics never receive a child’s profile, answers or reports.
5.2.5. Administration: the day-to-day running of the company, including our own accounts, and the prevention and investigation of fraud. Our lawful basis: it is necessary to perform our contract with you, and to meet our legal obligations.
5.2.6. Safeguarding: acting where something suggests a child or another person may be at risk of serious harm. Our lawful basis: it is necessary to protect someone’s vital interests, and it is necessary for our legitimate interests in keeping people safe. Assembly signposts urgent help rather than intervening, and section 7 sets out the limited circumstances in which we would share information.
5.2.7. Marketing: telling you about our products and services where you have asked to hear from us. Our lawful basis: your consent, which you can withdraw at any time, or our legitimate interests where the law allows us to contact an existing user about a similar service.
5.2.8. Research: we may use personal data for academic research, but only where we have a lawful basis to do so, which will normally be your explicit consent. We collect no more than the research needs, anonymise wherever we can, apply the same technical and organisational protections as we do everywhere else, and require any research to have the ethical approvals it needs.
5.3. Where the personal data we use for one of the purposes above is special category data (see 3.2), we need a second lawful basis under Article 9 of the UK GDPR as well as the one named above. We rely on your explicit consent, which you can withdraw at any time (see section 12). Where we act to protect someone from serious harm, we may instead rely on the vital interests ground, and where the law requires disclosure we may rely on the substantial public interest ground.
COMPLYING WITH DATA PROTECTION LAW
6.1. We will comply with data protection law when using your personal information. At the heart of that law are the “data protection principles”, which say that the personal information we hold about you must be:
6.1.1. used lawfully, fairly and in a transparent way;
6.1.2. collected only for valid purposes that we have clearly explained to you, and not used in any way that is incompatible with those purposes;
6.1.3. relevant to the purposes we have told you about, and limited to those purposes;
6.1.4. accurate and kept up to date;
6.1.5. kept only as long as necessary for the purposes we have told you about; and
6.1.6. kept securely.
SHARING YOUR PERSONAL INFORMATION
7.1. We do not sell your personal data, and we do not share it with third parties for their own marketing. We share it only where we have a lawful basis, and only as described below.
7.2. The types of organisation we share personal data with are:
7.2.1. A school, clinic or other organisation you have chosen to share with: sharing a child’s profile with an organisation is a consent you give, and you can withdraw it at any time from that child’s page in the app. Withdrawing stops their access from that point on; it cannot recall something they have already downloaded.
7.2.2. The police, other law enforcement agencies, and safeguarding authorities: in limited circumstances we may be required to share personal data with them, or may need to in order to protect someone from serious harm.
7.2.3. Regulators and other public bodies: where the law requires us to.
7.2.4. Professional advisers and, if the business is ever sold or reorganised, the other party to that transaction: in each case under a duty of confidentiality, and we would tell you before your data moved to a new controller.
7.2.5. Someone with legal authority to act on your behalf, such as a person holding a power of attorney, where it is lawful for us to do so.
7.3. We also use a small number of service providers to run Assembly. They act on our instructions as processors, under a contract that holds them to the same protections, and they may only use the data to provide their service to us. The full register, with what each one does and why, is published in our trust centre. They are:
7.3.1. Microsoft Azure, UK (Azure UK South): All service data for the UK-hosted core, at rest and in transit: accounts, profiles, answers, chats, reports, files, the job queue and the logs. Not the three services listed separately below, which carry their own locations: the AI, the email service and the public website hosting.
7.3.2. Microsoft email delivery, stored in the UK, may be processed outside the UK: Your email address, and what the sign-in, invitation or notification email says, which for an invitation, the welcome email, a ‘profile is ready’ notice or a reminder to finish a profile includes a child’s first name and, for a school-issued invitation, the school’s name. For the public website: the address a confirmation link is sent to and the kind of form it came from (parent waitlist, school, NHS, clinician or press, carried in the link), and for a confirmed organisation enquiry the kind of enquiry it is (school, NHS, clinician or press), plus the name, organisation, role, email address and free-text message, repeated to our own inbox. All of it in transit while it is sent, and at rest in what the email service keeps about the send, which its data location setting holds in the United Kingdom.
7.3.3. Microsoft Azure AI, stored in the UK, processed in any Azure region: Profiler answers, observations, chat messages and the reports written from them: in transit while a response is written, and at rest in the UK in the copy Microsoft keeps for up to 30 days to check for misuse.
7.3.4. Microsoft website hosting, EU (Azure West Europe, Netherlands): What you type into a website form, in transit: your email address, and for an organisation enquiry your name, organisation, role and message.
7.3.5. Microsoft 365, UK or EEA (Microsoft 365, Europe): Emails you send us, and confirmed organisation enquiries from the website (name, organisation, role, email address and message).
7.3.6. PostHog, EU: Usage events tied to a session (not your child's data).
7.3.7. Google Calendar, US and worldwide (Google): When you open the booking page, your IP address and browser details; if you book, the name and email address you type in and the time you choose. Nothing about your child.
7.4. In addition, our own staff may access personal data where it is necessary to run the service, meet a legal obligation, or investigate a security or safety concern. Access is limited to the people who need it and is logged.
TRANSFERRING INFORMATION OUTSIDE THE UNITED KINGDOM
8.1. Whenever we transfer personal data out of the United Kingdom, we make sure a similar level of protection travels with it, by relying on at least one of the following safeguards:
8.1.1. the country or organisation is covered by UK adequacy regulations, which the Secretary of State makes to confirm that it provides an adequate level of protection. The EEA is covered by these regulations;
8.1.2. we use the ICO’s International Data Transfer Agreement (IDTA), or the UK Addendum to the European Commission’s standard contractual clauses, together with any additional measures a transfer risk assessment shows are needed;
8.1.3. another safeguard permitted by Chapter V of the UK GDPR applies.
8.2. At the date of this notice, your child’s profile, answers, chats and reports are stored only in the United Kingdom. To write a report or a reply in chat, we send the answers and observations it needs to Microsoft's AI service: Microsoft Azure AI, handling Profiler answers, observations, chat messages and the reports written from them: in transit while a response is written, and at rest in the UK in the copy Microsoft keeps for up to 30 days to check for misuse. Microsoft may process that request in another Azure region, outside the United Kingdom, while everything it keeps stays in the United Kingdom. That processing relies on Microsoft's Products and Services Data Protection Addendum, which incorporates the standard contractual clauses and the UK Addendum (see 8.1.2). For the following, what the provider holds is kept in the United Kingdom, and the provider's own documentation says a request may be processed outside the United Kingdom without saying where: Microsoft email delivery (stored in the UK, may be processed outside the UK): Your email address, and what the sign-in, invitation or notification email says, which for an invitation, the welcome email, a ‘profile is ready’ notice or a reminder to finish a profile includes a child’s first name and, for a school-issued invitation, the school’s name. For the public website: the address a confirmation link is sent to and the kind of form it came from (parent waitlist, school, NHS, clinician or press, carried in the link), and for a confirmed organisation enquiry the kind of enquiry it is (school, NHS, clinician or press), plus the name, organisation, role, email address and free-text message, repeated to our own inbox. All of it in transit while it is sent, and at rest in what the email service keeps about the send, which its data location setting holds in the United Kingdom. Any of that processing which happens outside the United Kingdom relies on Microsoft's Products and Services Data Protection Addendum, which incorporates the standard contractual clauses and the UK Addendum (see 8.1.2). Some other personal data is processed outside it: Microsoft website hosting (EU (Azure West Europe, Netherlands)): What you type into a website form, in transit: your email address, and for an organisation enquiry your name, organisation, role and message; PostHog (EU): Usage events tied to a session (not your child's data); Google Calendar (US and worldwide (Google)): When you open the booking page, your IP address and browser details; if you book, the name and email address you type in and the time you choose. Nothing about your child. For the following, the data is held in either the United Kingdom or the EEA and we cannot yet say which: Microsoft 365 (UK or EEA (Microsoft 365, Europe)): Emails you send us, and confirmed organisation enquiries from the website (name, organisation, role, email address and message). Processing in the EEA relies on UK adequacy regulations, which cover the EEA, rather than on contractual safeguards. Processing anywhere else relies on one of the safeguards in 8.1, and you can ask us which one applies.
8.3. We do not work with medical or clinical providers, in the United Kingdom or anywhere else, so no data is transferred to any such organisation. If you want further information about the specific mechanism we use for a transfer, email us at info@helloassembly.com.
CAN WE USE YOUR INFORMATION FOR ANY OTHER PURPOSE?
9.1. We will normally only use your personal information for the purposes for which we collected it. We may use it for another purpose where that purpose is compatible with the ones set out in this notice. If we intend to do that, we will tell you about the new purpose before we start.
9.2. We may also use your personal information for other purposes where the law requires or permits it.
STORING YOUR INFORMATION AND DELETING IT
10.1. We keep your personal information only for as long as we need it for the purposes we collected it for, or for another lawful purpose described above. When we no longer have a lawful purpose for holding it, we securely destroy it in accordance with our retention policy. You can ask us for the retention periods that apply to each kind of data by emailing info@helloassembly.com.
10.2. In deciding how long to keep personal data, we consider the amount, nature and sensitivity of the data, the potential harm that unauthorised use or disclosure could cause, the purposes we process it for, whether we can achieve those purposes another way, and what the law requires.
10.3. You do not have to wait for us. Everything we hold about one child, including their profile, answers, chats and reports, can be deleted by you from that child’s page in the app. Deletion there removes it from the live service immediately. Copies can remain for a while in our database backups, which are held in the United Kingdom: the database’s continuous backups expire after 35 days, and our nightly backup copies are kept for at least 35 days.
10.4. One retention period is not ours to set. Microsoft may keep the prompts sent to the AI service for up to 30 days, inside the United Kingdom, so that it can monitor for abuse. We are pursuing the option that removes even that. This is stated in the plain-English summary on this page too, and the two say the same thing on purpose.
YOUR RIGHTS
11.1. Under certain circumstances, by law you have the right to:
11.1.1. Request access to your personal information (commonly known as a “data subject access request”). This lets you receive a copy of the personal information we hold about you and check that we are processing it lawfully. For a child, you can also download everything we hold about them yourself, from that child’s page in the app.
11.1.2. Request correction of the personal information we hold about you. This lets you have incomplete or inaccurate information corrected.
11.1.3. Request erasure of your personal information in certain circumstances. This lets you ask us to delete information where there is no good reason for us to keep processing it, or where you have objected to the processing. A child’s record you can delete yourself, immediately, from that child’s page in the app.
11.1.4. Object to processing of your personal information where we rely on a legitimate interest (ours or a third party’s) and something about your particular situation makes you object. You can always object to processing for direct marketing.
11.1.5. Request the restriction of processing of your personal information. This lets you ask us to suspend processing, for example while you contest its accuracy or our reason for holding it.
11.1.6. Request the transfer of your personal information to you or to another organisation, in a structured, commonly used and machine-readable format.
11.2. To exercise any of these rights, or if you have a question about them, email us at info@helloassembly.com or write to us at Family Emotional Health Limited, Euston House, 24 Eversholt Street, London NW1 1DB. We will respond within one calendar month, and there is no charge.
RIGHT TO WITHDRAW CONSENT
12.1. Where we rely on your consent as our lawful basis for processing your data for a particular purpose, you have the right to withdraw that consent at any time. You can withdraw consent for sharing a child’s profile with an organisation from that child’s page in the app, and for anything else you can email us at info@helloassembly.com. Once we have your withdrawal we will stop processing your information for that purpose, unless we have another lawful basis for continuing. Withdrawing consent does not make our earlier processing unlawful.
AUTOMATED DECISION MAKING
13.1. You will not be subject to a decision that has a legal effect on you, or a similarly significant effect, taken solely by automated means.
13.2. We do use AI to build profiles, generate reports and recommendations, and answer you in chat, all from the information you give us. What it produces is information for you to consider and act on as you see fit, not a decision about you or your child, and it is not a diagnosis. We do not use your data to train AI models, and neither do the providers we use. Our AI principles, and the detail of how the models are run, are published on our how we use AI page.
RIGHT TO COMPLAIN TO THE ICO
14.1. You have the right to complain to the Information Commissioner’s Office (the “ICO”) if you are not satisfied with the way we use your information. You can contact the ICO at ico.org.uk, or by writing to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Complaining to the ICO costs you nothing, and you do not have to come to us first, though we would like the chance to put things right.