EQASSURE← Home

Privacy Policy

Last updated: June 2026

This policy explains how we collect, use and protect personal data when you use the EQAssure™ tool at chiselforge.com and when you contact us. The tool is provided by ChiselForge, based in the United Kingdom.

For the account, billing and enquiry data described below, ChiselForge is the data controller. For the assessment content and evidence files your organisation enters and uploads, we act as a data processor on your organisation’s behalf (your organisation is the controller of that content).

1. Who we are & how to contact us

Controller: ChiselForge, a UK-based business currently completing incorporation as a UK limited company. Our full registered details (company name, number and registered office) will be published here on incorporation, and are available on request in the meantime. For any privacy question or to exercise your rights, contact privacy@chiselforge.com. [ICO registration number — to add once registered.]

2. The personal data we collect, and why

3. Cookies & local storage

We use only essential cookies needed to keep you securely signed in. We do not use advertising or analytics/tracking cookies. The app stores a few functional preferences in your browser’s local storage (for example, whether you’ve dismissed a guide). Because we use only essential cookies, no cookie-consent banner is required.

4. Who we share data with

We use trusted providers to run the service; they process personal data only on our instructions and under their own data-processing terms:

We do not sell your personal data, and we don’t share it for anyone else’s marketing.

5. International transfers

Some of these providers process data outside the UK (for example, in the United States). Where they do, the transfer is protected by appropriate safeguards — such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses — under each provider’s terms. Our database is hosted in the European Union (Ireland).

6. How long we keep it

We keep account and assessment data while your organisation has an account, and for 12 months afterwards unless you ask us to delete it sooner. The IP address and browser details recorded with your terms-acceptance records are automatically removed after 24 months (the acceptance record itself is retained as evidence). Enquiry/lead data, and trial requests that don’t lead to an account, are deleted after 12 months. These retention purges run automatically.

7. Your rights

Under UK GDPR you can ask to access, correct, delete, restrict or object to our use of your personal data, and to receive a copy in a portable format. To exercise any of these, emailprivacy@chiselforge.com. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

8. Business customers — data processing

For the content your organisation enters and uploads, we act as your processor and handle it only to provide the service. Business customers can request a Data Processing Addendum (DPA) setting out these terms.

9. Security

We protect personal data with measures including encryption in transit, per-organisation data isolation, restricted access, and review of our application’s security. Card payments are handled entirely by Stripe and never stored on our systems.

10. Children

The service is intended for internal audit professionals and is not directed at children.

11. Changes to this policy

We may update this policy from time to time; we’ll update the date above and, for significant changes, notify account holders.

12. Contact

privacy@chiselforge.com · ChiselForge, United Kingdom.