Legal

Privacy Policy

How A-SAFE collects, uses, shares and protects personal data in Conek and the Conek mobile apps.

Last updated 24 September, 2026

This Privacy Policy explains how personal data is handled in Conek, A-SAFE’s business platform, and in the Conek mobile apps for iOS and Android. It covers the web application at conek.com, the mobile apps published as Conek by A-SAFE, and the APIs and integrations that support them.

It sits alongside, and does not replace, the A-SAFE privacy policy at asafe.com, which covers the A-SAFE website.

1. Who we are

Conek is provided by A-SAFE (UK) Ltd, registered in England and Wales under company number 5407505, registered office Habergham Works, Ainleys Industrial Estate, Elland, West Yorkshire, England, HX5 9JP. VAT number GB 893 1518 05.

A-SAFE HQ Limited, at the same address, is the data controller for personal data processed in Conek. In this policy, “A-SAFE”, “we” and “us” refer to the A-SAFE group companies together.

2. Who Conek is for

Conek is A-SAFE’s business platform for everyone who works with A-SAFE, its products and its customers. Its users include:

  • A-SAFE teams — sales, engineering, installation, inspection, support and operations staff across the A-SAFE group;
  • Third parties working with A-SAFE — distributors, installation partners, contractors and other business partners; and
  • A-SAFE customers — the organisations that buy and operate A-SAFE products, for example to raise and follow support tickets, review inspections of their sites, and see data from connected products.

Every user signs in with a Conek account. A-SAFE issues each account and sets what it can see according to the user’s organisation and role, so there is no open public sign-up, and the app is not usable without an account.

A-SAFE is the controller for your account data and for the business records held in the platform — the contacts, companies, opportunities, quotes, orders, drawings, inspections and tickets that make up A-SAFE’s customer relationships. Where you use Conek on behalf of a customer or partner organisation, the agreement between that organisation and A-SAFE may also set out how its own data is handled.

3. What we process

Account and identity

Name, work email address, profile photo (optional), job role, language and locale preference, branch and team membership, permissions and roles, and the identifiers issued by the A-SAFE identity provider when A-SAFE staff sign in through single sign-on (Microsoft Entra ID) or when your account is provisioned automatically through SCIM. If you sign in with a password, we store only a salted hash, never the password itself.

Business records you create

Everything you or your colleagues enter into Conek: contacts and companies, opportunities, tasks and calendar bookings, quotes, orders and drawings, products and bills of materials, inspections and their photos, facilities, support tickets, notes, attachments and comments. Much of this is personal data about A-SAFE’s customers and prospects; where you enter it as part of your work with or for A-SAFE, you are handling it on A-SAFE’s behalf.

Usage, device and diagnostic data

Sign-in times, IP address, browser or app version, operating system, device model, pages and actions performed, feature-adoption events, and error reports. Crash and error diagnostics from the mobile apps are sent to Sentry with personally identifying payloads disabled.

Location

If a feature needs it — route planning and field-sales day planning are the main ones — the app asks for location permission and uses your position while the app is in use to order and map visits. Conek does not track your location in the background and does not build a movement history beyond the visits recorded against your planned route.

Camera, photos and barcode scanning

When you attach a photo to an inspection, a ticket or a drawing, or scan a barcode, the app asks for camera or photo-library access. Images are uploaded to Conek; barcode scans are read on the device and only the decoded value is used.

Phone calls

How calls are handled differs by platform, and the difference is important:

  • On iOS, the app uses Apple’s CallKit only to notice that a call started and ended, so it can offer to log it. It cannot read the phone number, the contact or any audio, and it makes no attempt to record. Apple does not permit third-party apps to record cellular calls. The call metadata is held in a single local file on the device until you use it.
  • On Android, on company-managed devices and only where local law allows it, Conek can capture call audio, transcribe it, redact personal data from the transcript and derive a summary and suggested follow-up. This is controlled per jurisdiction, is announced to the other party where required, and is switched off unless it has been explicitly enabled.

In both cases, whatever is logged — number, duration, notes, transcript — becomes part of the CRM record and is kept under the retention rules below.

Notifications

The Android app registers a push token with Google Firebase Cloud Messaging so notifications can be delivered. The iOS app uses only local notifications scheduled on the device; it does not register for remote push.

Cookies

Conek uses strictly necessary cookies for your session, authentication and security. See the Cookie Policy.

Purpose Legal basis
Running A-SAFE’s business operations — sales, quoting, orders, inspections, support Legitimate interest in operating the business; performance of your employment contract where the processing is about you
Authenticating you and keeping accounts secure Legitimate interest in security; legal obligation where applicable
Managing customer and prospect relationships Legitimate interest in business-to-business commercial activity
Improving reliability and diagnosing faults Legitimate interest in a working, secure product
Call capture, transcription and analysis (Android, where enabled) Legitimate interest, or explicit consent in jurisdictions that require it
Complying with tax, accounting and legal obligations Legal obligation

Where a purpose relies on consent — location, camera, microphone, notifications, and call capture in two-party-consent jurisdictions — you can decline, and you can withdraw permission later in your device settings. Declining a permission disables the feature that needs it; it does not block the rest of the app.

5. Automated decision-making and AI

Conek uses AI features — an in-app assistant, summarisation, suggested next actions and, where enabled, call analysis. These produce suggestions for a person to act on. No decision with a legal or similarly significant effect on you is made automatically. Text sent for AI processing is handled by our AI sub-processor under a data processing agreement that prohibits using it to train their models.

6. Who we share it with

We do not sell personal data and we do not use it for advertising or cross-app tracking.

We share it with:

  • Colleagues inside A-SAFE with the relevant permissions, and with the administrators of the platform.
  • Infrastructure providers — Amazon Web Services, which hosts the platform and its data in the European Union.
  • Identity provider — Microsoft Entra ID, for single sign-on.
  • AI providers — for the AI features described above, under a no-training data processing agreement.
  • Diagnostics — Sentry, for crash and error reporting (EU ingestion, PII disabled).
  • Notification delivery — Google Firebase Cloud Messaging, for Android push notifications.
  • Connected business systems — NetSuite, Microsoft 365, Microsoft Teams, HubSpot and EDI partners, where data flows between Conek and those systems as part of normal operations.
  • Professional advisers and authorities — where we are legally required to disclose.

7. International transfers

Platform data is hosted in the European Union. A-SAFE operates internationally, so data is accessible to A-SAFE companies outside the EU and the UK, and some sub-processors — notably AI processing — operate in the United States. Those transfers are covered by the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses, together with supplementary technical measures (encryption in transit and at rest, and restricted access).

8. How long we keep it

  • Account and profile data — for as long as the account exists, then deleted or anonymised.
  • Authentication and audit logs — kept for security and accountability; audit history is retained as long as the underlying record, because it is what makes the record trustworthy.
  • Business records — kept for as long as they are needed for the customer relationship and for any legal or tax obligation that applies to them.
  • Call audio (Android, where enabled) — 60 days by default, configurable between 7 and 365 days, then deleted automatically.
  • Call transcripts — kept under the configured retention setting.
  • Analytics events — 90 days by default.
  • Crash diagnostics — 90 days.
  • Backups — deleted data can persist in encrypted backups for a limited period before those backups expire.

9. Your rights

Subject to local law, you can ask to access your data, correct it, delete it, restrict or object to its processing, receive a portable copy, or withdraw consent you previously gave. You also have the right to complain to a supervisory authority — in the UK the Information Commissioner’s Office (ico.org.uk), or the authority in the country where you live or work.

To exercise a right, contact our data protection team at conek.dev@asafe.com. Corrections to a record inside Conek go to the same address — see Support.

See Delete your account for how account deletion works specifically.

10. Security

Data is encrypted in transit (TLS) and at rest. Access inside Conek is enforced per branch and per permission on every request. Elevated access to sensitive material, such as unredacted call transcripts, requires a separate, individually logged authorisation with a stated reason. We keep an audit trail of changes to records, run automated security and dependency scanning, and separate production from development environments.

No system is perfectly secure. If a breach affects your personal data and the law requires it, we will notify the supervisory authority and, where applicable, you.

11. Children

Conek is workplace software. It is not directed at children and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

When we change this policy we update the date at the top of this page. If a change materially affects how your personal data is used, we will tell you in the app or by email before it takes effect.

13. Contact

Data protection: conek.dev@asafe.com.

By post: A-SAFE HQ Ltd, Habergham Works, Ainleys Industrial Estate, Elland, West Yorkshire, England, HX5 9JP. Tel: 01422 344402.