Privacy Policy
Last Updated September 2026
AssessrLog is the self-serve system of record where an FCI-only defense supplier prepares and maintains its CMMC Level 1 self-assessment. The service is provided by ProfytAI Pte. Ltd., a Singapore company. AssessrLog is a product and trading name of ProfytAI Pte. Ltd., not a separate legal entity. This policy explains what information the service collects, who controls it, how it is used and shared, how long it is kept, and the choices you have. It covers both the AssessrLog website and the AssessrLog application. AssessrLog is a self-assessment tool. It is not a certification, and it is not an accredited or third-party assessor.
01Information We Collect
We collect three kinds of information.
- Account information. The name, work email, and organization details you provide when you create an account, together with the sign-in and billing records needed to run your subscription. Payment is handled by a third-party payment processor, and we do not store full card numbers.
- Assessment content. The content you enter to build and maintain your Level 1 self-assessment. This includes your scoping decisions, your Met, Not Met, and N/A determinations, the plain-English basis you record for each determination, the narratives you write, the evidence files you upload, and the dates and record of who confirmed each item.
- Usage and device data. Standard technical data such as IP address, browser type, device and operating system, referring pages, and the pages and features you use. This helps us keep the service secure and reliable, and on the website it also tells us which pages people find useful. How that works on each surface, and how to turn it off on the website, is set out in Cookies and Similar Technologies below.
- Progress through the Readiness Check. If you take the free Readiness Check on our website, we record your progress through it, such as whether you started, which step you reached, and whether you completed it. Your answers themselves stay in your browser. You can turn this off before you start. It is covered in Cookies and Similar Technologies below.
Evidence you upload. The service is the system of record for your self-assessment, and the evidence files you upload are stored in it, versioned and content-hashed. Evidence for a Level 1 assessment can contain Federal Contract Information, and the service is built to hold it in one protected place. Do not upload Controlled Unclassified Information, classified material, or other information beyond the Level 1 FCI scope. The safeguards for that stored evidence are summarized in the Data Security section below.
02Controller and Processor Roles
Our role depends on the type of information, because it changes who decides how that information is used.
- Where we are the controller. For account, billing, website, and marketing information, ProfytAI Pte. Ltd. decides why and how the information is handled. This policy governs that information.
- Where we are the processor. For the assessment content you enter, we act on behalf of your organization, which is the controller of that content. We process it to provide the service and only on your organization's documented instructions, except where the law requires otherwise or where our agreement with your organization permits it, such as the quarantine or removal of out-of-scope material.
We offer a data processing agreement to organizations that require one, available through our Contact page. Where a data processing agreement is in place between us and your organization, it governs our processing of your assessment content, and if a term of that agreement conflicts with this policy for that content, the agreement controls.
03How We Use Your Information
We use the information we collect to run the service and to support you.
- To provide and maintain the service, and to save, display, and let you return to your assessment as you build it a little at a time.
- To authenticate you, process your subscription, and provide customer support.
- To secure the service, prevent abuse, and keep records for troubleshooting.
- To send service messages about your account, its security, and material changes to the product or this policy.
- To understand how the product is used and to improve it, working from aggregated and de-identified data where we can.
AI features. Where you use an AI feature of the service, the content you submit to it is processed to return advisory output to you. That output never makes a determination for you, as the Terms of Service explain.
We do not sell your personal information for money, and we do not sell or rent your assessment content. We do not use the assessment content you enter to train machine-learning models. We do use advertising and measurement cookies on the website, which counts as sharing under California and other state privacy laws. How that works, and how to stop it, is in Cookies and Similar Technologies and in Your Rights and Choices below.
04Categories of Personal Information
For transparency, and to meet state privacy laws such as the California Consumer Privacy Act as amended, the categories of personal information we handle and the sources they come from are as follows.
- Identifiers. Name, work email, organization, and account identifiers. Collected from you when you create and use an account.
- Commercial information. Subscription and billing records. Collected from you and from our payment processor.
- Internet and network activity. IP address, device and browser data, and usage logs. Collected automatically as you use the website and application.
- Professional information. Your role and the assessment content you enter in the course of your work. Collected from you and other authorized users at your organization.
We do not intend to collect special or sensitive categories of personal information through the service, and you should not enter them.
07Data Retention
We keep information for as long as it is needed for the purpose it was collected.
- Assessment records. The CMMC rule requires the artifacts behind each annual Level 1 self-assessment to be kept for six years from the CMMC Status Date (32 CFR § 170.15), and that retention obligation belongs to your organization. While your paid subscription is active, the service is designed to support retention of completed assessment records for six years from the applicable CMMC Status Date, so you can show a defensible history if your determinations are ever reviewed.
- After your subscription ends. You have at least 30 days to export your then-available records. After the export period, we may keep a dormant copy for up to 18 months for recovery, reactivation, dispute resolution, security, and legal purposes. Dormant retention is not continued application access. After that, we may delete or de-identify the data unless a longer period is required by law, a legal hold, a backup lifecycle, or a separate signed agreement.
- Account and billing data. We keep this for as long as your account is active, and for as long afterward as we need it to meet our legal, tax, and record-keeping obligations.
- Usage and log data. We keep this for as long as we need it for security and reliability, and no longer than our record-keeping obligations require.
You can ask us to delete your data on request or when your account is terminated, subject to records we are required to keep by law, records needed to preserve the integrity of a self-assessment you have already relied on, and the dormant-retention period described above. Your organization remains responsible for its own retention obligation, so export your records before the export period closes.
08Data Security
We use administrative, technical, and physical safeguards designed to protect your information, and we keep working to improve them. No method of storage or transmission is perfectly secure, so we cannot promise absolute security.
The service stores your assessment record and the evidence you upload in one protected place, scoped to Level 1 and FCI only. Contact us if you need a fuller description of how the platform is built or how stored evidence is protected.
09Your Rights and Choices
Depending on where you live, you may have rights over your personal information. We honor the rights that apply to you and will not discriminate against you for exercising them.
- Under US state privacy laws. You may have the right to know what we collect, to access it, to correct it, to delete it, and to opt out of any sale or sharing or of targeted advertising, along with the right not to be discriminated against for exercising these rights. To opt out of sharing for targeted advertising, use the Do Not Sell or Share My Personal Information control in the footer of any page. You do not need an account and we do not ask you to identify yourself to use it. We also honor the Global Privacy Control signal automatically, so a browser that sends it is opted out without doing anything further.
- Under Singapore’s PDPA. Because ProfytAI Pte. Ltd. is a Singapore company, the Personal Data Protection Act also applies to our handling of your personal data. You may request access to and correction of personal data we hold about you, and withdraw consent where processing relies on it.
To exercise any of these rights, reach us through our Contact page. We will verify your request and respond within the timeframes required by applicable law. You can also review and update your account information at any time inside the application. If we process your assessment content on behalf of your organization, we will direct your request to that organization or act on its instructions.
10Where We Operate and Store Data
The service is provided by ProfytAI Pte. Ltd., a Singapore company, and is built for United States defense suppliers.
Your information is stored in the United States. The service and your assessment content are hosted on United States infrastructure, and we do not store assessment content anywhere else. Our personnel may access information from outside the United States, including from Singapore, to operate, support, and secure the service. That access is the only cross-border element in how the service is run, and where the law requires a safeguard for it, we put one in place.
11Children's Data
AssessrLog is a business tool. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, reach us through our Contact page and we will delete it.
12Changes to This Policy
We may update this policy as the product and our practices change. When a change is material we will update the date shown above and, where appropriate, tell you through the service or by email. If you keep using the service after an update takes effect, that means you accept the updated policy.
13Contact Us
Questions about this policy, or requests about your data, can be sent through our Contact page.
