ASL is committed to protecting the privacy and integrity of all data stored on our platform.
We follow strict European data protection standards to ensure that every record, document and user profile remains secure and compliant with the General Data Protection Regulation (GDPR).
Data Protection Principles
Our approach to data protection is built on transparency, accountability, and trust.
Every technical and organisational measure within ASL is designed to protect both personal and operational data from unauthorised access or misuse.
We follow these key principles:
- Data is collected and processed only for legitimate maintenance and service purposes.
- We do not sell, rent or share user data with third parties.
- All data access is role-based and requires authentication.
- Users may request data deletion or export in accordance with applicable GDPR rights.
Secure Data Storage
All service records and user information are hosted on servers located within the European Union, managed by ISO 27001-certified providers.
Data is encrypted both in transit and at rest, ensuring confidentiality and integrity throughout its lifecycle.
Technical safeguards include:
- HTTPS/TLS encryption for all communication.
- Encrypted storage for all maintenance records and file uploads.
- Daily backups and monitored uptime.
- Access logs are maintained for all modifications and system interactions.
User Verification & Access Control
Only verified professionals and registered companies may create or edit service logs.
Each action within the system is traceable to a verified account, ensuring accountability and compliance with professional standards.
Property owners and managers can access installation histories via secure, read-only links — maintaining transparency without exposing sensitive data.
Data Retention & Ownership
ASL retains digital maintenance records for up to 10 years per QR tag activation.
This ensures long-term traceability while keeping users in full control of their information.
- Service companies retain ownership of their records.
- Property owners maintain access to shared maintenance data.
- Data can be exported or permanently deleted upon verified request.
GDPR Compliance & User Rights
As a European platform, ASL fully complies with the EU General Data Protection Regulation (Regulation EU 2016/679).
We actively support the rights of our users, including:
- Right to Access – Obtain a copy of your personal data.
- Right to Rectification – Correct inaccurate or incomplete information.
- Right to Erasure – Request deletion of your data at any time.
- Right to Data Portability – Export your data in a structured format.
- Right to Restrict or Object – Limit processing where applicable.
Requests may be submitted through our contact form or to the designated data protection officer.
Reporting & Data Breach Policy
In the unlikely event of a data breach, ASL follows a strict internal incident protocol.
Affected users and relevant authorities are notified within 72 hours, in line with GDPR Article 33 requirements.
We continuously monitor for potential vulnerabilities and conduct regular security reviews to maintain full compliance and trust.