Privacy Policy

Last Updated September 2026

AssessrLog is the self-serve system of record where an FCI-only defense supplier prepares and maintains its CMMC Level 1 self-assessment. The service is provided by ProfytAI Pte. Ltd., a Singapore company. AssessrLog is a product and trading name of ProfytAI Pte. Ltd., not a separate legal entity. This policy explains what information the service collects, who controls it, how it is used and shared, how long it is kept, and the choices you have. It covers both the AssessrLog website and the AssessrLog application. AssessrLog is a self-assessment tool. It is not a certification, and it is not an accredited or third-party assessor.

01Information We Collect

We collect three kinds of information.

  • Account information. The name, work email, and organization details you provide when you create an account, together with the sign-in and billing records needed to run your subscription. Payment is handled by a third-party payment processor, and we do not store full card numbers.
  • Assessment content. The content you enter to build and maintain your Level 1 self-assessment. This includes your scoping decisions, your Met, Not Met, and N/A determinations, the plain-English basis you record for each determination, the narratives you write, the evidence files you upload, and the dates and record of who confirmed each item.
  • Usage and device data. Standard technical data such as IP address, browser type, device and operating system, referring pages, and the pages and features you use. This helps us keep the service secure and reliable, and on the website it also tells us which pages people find useful. How that works on each surface, and how to turn it off on the website, is set out in Cookies and Similar Technologies below.
  • Progress through the Readiness Check. If you take the free Readiness Check on our website, we record your progress through it, such as whether you started, which step you reached, and whether you completed it. Your answers themselves stay in your browser. You can turn this off before you start. It is covered in Cookies and Similar Technologies below.

Evidence you upload. The service is the system of record for your self-assessment, and the evidence files you upload are stored in it, versioned and content-hashed. Evidence for a Level 1 assessment can contain Federal Contract Information, and the service is built to hold it in one protected place. Do not upload Controlled Unclassified Information, classified material, or other information beyond the Level 1 FCI scope. The safeguards for that stored evidence are summarized in the Data Security section below.

02Controller and Processor Roles

Our role depends on the type of information, because it changes who decides how that information is used.

  • Where we are the controller. For account, billing, website, and marketing information, ProfytAI Pte. Ltd. decides why and how the information is handled. This policy governs that information.
  • Where we are the processor. For the assessment content you enter, we act on behalf of your organization, which is the controller of that content. We process it to provide the service and only on your organization's documented instructions, except where the law requires otherwise or where our agreement with your organization permits it, such as the quarantine or removal of out-of-scope material.

We offer a data processing agreement to organizations that require one, available through our Contact page. Where a data processing agreement is in place between us and your organization, it governs our processing of your assessment content, and if a term of that agreement conflicts with this policy for that content, the agreement controls.

03How We Use Your Information

We use the information we collect to run the service and to support you.

  • To provide and maintain the service, and to save, display, and let you return to your assessment as you build it a little at a time.
  • To authenticate you, process your subscription, and provide customer support.
  • To secure the service, prevent abuse, and keep records for troubleshooting.
  • To send service messages about your account, its security, and material changes to the product or this policy.
  • To understand how the product is used and to improve it, working from aggregated and de-identified data where we can.

AI features. Where you use an AI feature of the service, the content you submit to it is processed to return advisory output to you. That output never makes a determination for you, as the Terms of Service explain.

We do not sell your personal information for money, and we do not sell or rent your assessment content. We do not use the assessment content you enter to train machine-learning models. We do use advertising and measurement cookies on the website, which counts as sharing under California and other state privacy laws. How that works, and how to stop it, is in Cookies and Similar Technologies and in Your Rights and Choices below.

04Categories of Personal Information

For transparency, and to meet state privacy laws such as the California Consumer Privacy Act as amended, the categories of personal information we handle and the sources they come from are as follows.

  • Identifiers. Name, work email, organization, and account identifiers. Collected from you when you create and use an account.
  • Commercial information. Subscription and billing records. Collected from you and from our payment processor.
  • Internet and network activity. IP address, device and browser data, and usage logs. Collected automatically as you use the website and application.
  • Professional information. Your role and the assessment content you enter in the course of your work. Collected from you and other authorized users at your organization.

We do not intend to collect special or sensitive categories of personal information through the service, and you should not enter them.

05How We Share Information

We share information only as needed to run the service, and never to sell it.

  • Service providers. We rely on a small set of providers for hosting, storage, AI model infrastructure, error monitoring, email delivery, and payment. Each is bound by contract to protect your data and to use it only to provide services to us.
  • Analytics provider. On the website we use PostHog to measure how the site is used. It receives the pages you viewed, the links and buttons you pressed, general device information, an approximate location derived from your IP address, and your progress through the free Readiness Check. It processes that data in the United States, on our behalf and under contract, and it is not present in the application.
  • Email and marketing provider. We use Customer.io to send the email we send you, including replies to your enquiries and any marketing or product updates you asked to receive. When you send the contact form or request the Readiness Check PDF, the name, email, and message you submit reach us through our own application, and we may use Customer.io to respond and follow up. It processes that data in the United States, on our behalf and under contract. It does not run on the website, sets no cookies here, and is not present in the application. Your Readiness Check answers are not included.
  • Legal and regulatory. We may disclose information if the law requires it, in response to a valid legal request, or to protect the rights, property, or safety of AssessrLog, our users, or the public.
  • Business transfers. If AssessrLog is involved in a merger, acquisition, or sale of assets, your information may move as part of that transaction. We will tell you before your information becomes subject to a different policy.
  • Advertising and measurement partners. On the website we run advertising and measurement tags from Google, LinkedIn, and Meta so we can see which advertisements bring people here. These set their own cookies and receive the pages you viewed on our website, along with the identifiers those platforms use to recognize a browser. They never receive your assessment content, and they are not present in the application.

We do not sell your personal information for money. We do share it for cross-context behavioral advertising, as that term is used under California and other state privacy laws, because the advertising tags described above work that way. You can stop that at any time. Use the Do Not Sell or Share My Personal Information control in the footer of any page, or send a Global Privacy Control signal from your browser, which we honor automatically.

We never share your assessment content, your evidence files, or anything you enter in the application with an advertising platform. Those tags exist only on the marketing website.

06Cookies and Similar Technologies

The website and the application behave differently here, so we describe them separately.

6.1The Website

Website analytics. We use PostHog to understand which pages people find useful and where they lose their way. PostHog sets no cookies. It records the pages viewed, the referring page, the links and buttons pressed, general device information, and an approximate location derived from your IP address, and it processes that data in the United States. It does not record the values you type into a form.

The Readiness Check. The free Readiness Check runs in your browser. Your answers are processed there and are not sent to our analytics provider. We record your progress through the check, such as whether you started, which step you reached, and whether you completed it, so we can understand where people stop and improve the experience. If you request the PDF, the name and email you provide are sent to us along with a short summary of your result, such as how many requirements you reported in place and how many to review.

Nothing you enter in the AssessrLog application is included. Your scoping decisions, your Met, Not Met, and N/A determinations, your narratives, and your uploaded evidence stay in the application, which is a separate site that runs no analytics and carries no advertising code at all.

Advertising and measurement. We advertise, so the website also carries advertising tags from Google, LinkedIn, and Meta. They set their own cookies, record which pages you viewed on our website, and let those platforms recognize your browser so we can measure which advertisements work and show our advertisements to people who have visited. They never receive your assessment content.

Your choice. These start when you arrive, and a notice tells you so on your first visit. You can turn all of it off at any time, either from that notice or from the Do Not Sell or Share My Personal Information control in the footer of every page. We honor the Global Privacy Control signal and the Do Not Track setting, so if your browser sends either one, nothing runs at all and you will not see the notice. Visitors in the United Kingdom, Switzerland, and the European Economic Area are treated as not having consented unless they say otherwise.

Checkout is the one exception. Our payment processor loads its own code on the checkout page and sets its own cookies to prevent fraud and secure the payment. Those cookies are set by the payment processor, not by us, and they are required for the payment to work. That page is reached only when you choose to subscribe.

6.2The Application

The AssessrLog application sets a small number of first-party cookies and uses no analytics service at all.

  • Strictly necessary. Cookies that sign you in, keep your session secure, refresh your session, and remember which organization and assessment you are working in. These cannot be switched off, because the application cannot run without them.
  • Preference. One cookie that remembers your chosen display mode, and a browser storage entry that remembers your light or dark theme.

We run no analytics, tracking, or advertising code inside the application. It holds your assessment content and the evidence you upload, so nothing loads there that we did not build.

You can also control or clear cookies through your browser settings. Blocking the strictly necessary cookies will stop the application from working.

07Data Retention

We keep information for as long as it is needed for the purpose it was collected.

  • Assessment records. The CMMC rule requires the artifacts behind each annual Level 1 self-assessment to be kept for six years from the CMMC Status Date (32 CFR § 170.15), and that retention obligation belongs to your organization. While your paid subscription is active, the service is designed to support retention of completed assessment records for six years from the applicable CMMC Status Date, so you can show a defensible history if your determinations are ever reviewed.
  • After your subscription ends. You have at least 30 days to export your then-available records. After the export period, we may keep a dormant copy for up to 18 months for recovery, reactivation, dispute resolution, security, and legal purposes. Dormant retention is not continued application access. After that, we may delete or de-identify the data unless a longer period is required by law, a legal hold, a backup lifecycle, or a separate signed agreement.
  • Account and billing data. We keep this for as long as your account is active, and for as long afterward as we need it to meet our legal, tax, and record-keeping obligations.
  • Usage and log data. We keep this for as long as we need it for security and reliability, and no longer than our record-keeping obligations require.

You can ask us to delete your data on request or when your account is terminated, subject to records we are required to keep by law, records needed to preserve the integrity of a self-assessment you have already relied on, and the dormant-retention period described above. Your organization remains responsible for its own retention obligation, so export your records before the export period closes.

08Data Security

We use administrative, technical, and physical safeguards designed to protect your information, and we keep working to improve them. No method of storage or transmission is perfectly secure, so we cannot promise absolute security.

The service stores your assessment record and the evidence you upload in one protected place, scoped to Level 1 and FCI only. Contact us if you need a fuller description of how the platform is built or how stored evidence is protected.

09Your Rights and Choices

Depending on where you live, you may have rights over your personal information. We honor the rights that apply to you and will not discriminate against you for exercising them.

  • Under US state privacy laws. You may have the right to know what we collect, to access it, to correct it, to delete it, and to opt out of any sale or sharing or of targeted advertising, along with the right not to be discriminated against for exercising these rights. To opt out of sharing for targeted advertising, use the Do Not Sell or Share My Personal Information control in the footer of any page. You do not need an account and we do not ask you to identify yourself to use it. We also honor the Global Privacy Control signal automatically, so a browser that sends it is opted out without doing anything further.
  • Under Singapore’s PDPA. Because ProfytAI Pte. Ltd. is a Singapore company, the Personal Data Protection Act also applies to our handling of your personal data. You may request access to and correction of personal data we hold about you, and withdraw consent where processing relies on it.

To exercise any of these rights, reach us through our Contact page. We will verify your request and respond within the timeframes required by applicable law. You can also review and update your account information at any time inside the application. If we process your assessment content on behalf of your organization, we will direct your request to that organization or act on its instructions.

10Where We Operate and Store Data

The service is provided by ProfytAI Pte. Ltd., a Singapore company, and is built for United States defense suppliers.

Your information is stored in the United States. The service and your assessment content are hosted on United States infrastructure, and we do not store assessment content anywhere else. Our personnel may access information from outside the United States, including from Singapore, to operate, support, and secure the service. That access is the only cross-border element in how the service is run, and where the law requires a safeguard for it, we put one in place.

11Children's Data

AssessrLog is a business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, reach us through our Contact page and we will delete it.

12Changes to This Policy

We may update this policy as the product and our practices change. When a change is material we will update the date shown above and, where appropriate, tell you through the service or by email. If you keep using the service after an update takes effect, that means you accept the updated policy.

13Contact Us

Questions about this policy, or requests about your data, can be sent through our Contact page.