Privacy policy for Assure

Last updated 25 September 2026

Assure is the document control and compliance system of Upward Technologies B.V. It is used by Upward Technologies and the organisations it works with to register, approve and retain their documents. Upward Technologies B.V. is responsible for the personal data processed in it. Questions and requests go to info@upwardtech.nl.

What Assure keeps about the people who use it

Your name, e-mail address, job title, role and security clearance; a hash of your password, never the password itself; your second factor, if you set one up; and an audit log of what you do in Assure, including the date, time and IP address of each action. The audit log exists because a document control system has to be able to show who did what, and it cannot be edited.

Google Drive: what Assure reads, and what it does not

An administrator can connect a Google account so that Assure can keep track of documents stored in Google Drive. Assure asks Google for two permissions only:

  • See information about your Google Drive files (drive.metadata.readonly). Assure reads the name, type, size, created and modified dates, version, checksum, owner and last editor (name and e-mail address), parent folders, whether a file is in the bin, and its link. It cannot read the contents of your files, and it cannot change, move, share or delete anything in your Drive.
  • See your e-mail address (userinfo.email), to show which Google account is connected.

Assure uses this information to:

  • show whether a registered document still exists in Drive, and whether it changed after it was approved;
  • list files in the one folder an administrator chose to watch that are not yet in the register, so somebody can decide whether to register them.

The access and refresh tokens Google issues are stored encrypted. The metadata of registered documents is kept with the document record, for as long as that record is retained.

Assure does not sell Google user data, does not use it for advertising, and does not use it to train any artificial intelligence model. It is not shared with anybody outside the organisation using Assure, except as described under the advisor below.

Assure's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Stopping access

An administrator can disconnect Google Drive under Settings, Storage providers. Assure then deletes the stored tokens at once, and documents that were linked to Drive stay in the register as plain links. You can also remove Assure's access yourself at myaccount.google.com/permissions.

The advisor

Assure has an optional advisor that answers questions about the screen you are on. When you ask a question, Assure sends it to a language model provider (Anthropic's Claude, through Amazon Web Services), together with counts about your organisation and, if you leave "Read this page" on, the text of the page in front of you. That text can include document titles and file names. Bank account numbers, e-mail addresses, citizen service numbers and identity document numbers are removed before it is sent. Nothing is sent unless you ask a question. The question and the page text are not stored in Assure.

Your rights

You can ask to see, correct or delete the personal data Assure holds about you, and you can object to its use. Some records, such as the audit log and approved documents, have to be kept for a period set by law or by the organisation's retention rules; where that applies we will tell you. Write to info@upwardtech.nl. You can also complain to the Autoriteit Persoonsgegevens.

Who we are

Upward Technologies B.V., Minister Kanstraat 16 F, 4815 HG Breda, Nederland. KvK 42169743, RSIN 870020870, BTW NL870020870B01. info@upwardtech.nl