Privacy Policy

AssetMon

Last Updated: May 2026

AssetMon is a multi-tenant IT asset management platform. This Privacy Policy explains what the platform collects, how it is used and stored, who it is shared with, and the choices available to you. It applies to everyone using the service, on the free Starter plan, on a trial, and on a paid subscription.

By using AssetMon, you agree to the collection and processing described in this policy. If you do not agree, please do not use the service.

1. Information We Collect

Account Information

When a workspace is created we collect the name and email address of the person creating it, the workspace name and its slug, and the details of any users subsequently invited. Passwords are stored hashed, never in readable form.

Workspace Content

The asset records, categories, locations, departments, service tickets, maintenance schedules, software licence records, purchase requests and orders, reservations, audit records and any photographs or files attached to them. This is your data; the platform holds it on your behalf.

Technical Data

Session and authentication tokens, server access logs including IP address, timestamp and user agent, and error logs used for diagnosis and service improvement.

Billing Information

Subscription plan, seat count, billing period and payment status. Card, UPI and bank details are handled by the payment processor and are not stored by AssetMon.

2. How We Use Your Information

To provide and operate the service; to authenticate users and enforce role-based access; to send transactional email such as invitations, alerts and billing notices; to diagnose faults and improve reliability; to process subscriptions; and to meet legal obligations. We do not use customer workspace data to train models.

3. Tenant Isolation and Security

Database-per-tenant isolation

Each workspace runs in its own isolated PostgreSQL database rather than sharing tables behind a tenant identifier column, so one workspace's records are not reachable from another's queries.

Encryption

Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. Backups are encrypted with separate keys.

Access controls

Role-based access control within each workspace, security headers, rate limiting, magic-byte verification of uploaded files, and parameterised database access. API keys are tenant-scoped, hashed at rest, can be read-only or read-write, and support revocation and expiry. Two-factor authentication is available using TOTP.

Audit logging

Every asset event — creation, update, check-out, check-in, licence assignment and ticket activity — is written to an immutable log that can be exported.

4. Cookies and Local Storage

AssetMon sets first-party cookies only, and stores an access token in the browser's local storage to keep you signed in. It uses no advertising trackers, no social media pixels and no third-party analytics.

5. Third-Party Services

AssetMon relies on a small number of sub-processors to operate: a cloud hosting provider, a managed database provider, a transactional email provider, an error-tracking provider, and a payment processor for subscription billing. Each handles data only as needed to deliver its part of the service.

6. Data Storage and Location

Workspace data is stored in the European Union by default. Enterprise customers can request region pinning to the EU, India or the United States.

7. Data Retention

Active workspaces

Workspace data is retained for as long as the workspace is active.

After a trial

A workspace pauses for 14 days at the end of a trial. Data remains exportable during that window.

After cancellation

Workspace data is deleted within 30 days of cancellation. Encrypted backups are retained for 30 days after that point and then removed.

Audit logs

Retained for 365 days.

8. Your Rights

Access and export

Your data is exportable at any time while the workspace is live or paused, as CSV from the interface or through the REST API.

Correction and deletion

Records can be corrected in the interface, and a workspace can be closed from the dashboard. To request deletion of personal data held outside a workspace, contact us using the details below.

No sale of data

We do not sell personal data, and we do not share workspace content with third parties except the sub-processors described above.

9. Data Processing Agreement

A data processing agreement is signed with every paying customer. Contact us for the current version, or for an information-security review.

10. Changes to This Policy

This policy may be updated to reflect changes in the service, our sub-processors or the law. The "Last updated" date above changes when it does, and significant changes are notified by email or in-app notice.

Get In Touch

Cinute InfoMedia

Office #3, 2nd Floor, Ashley Tower, Kanakia Road, Vagad Nagar, Beverly Park

Mira Road, Mira Bhayandar, Mumbai, Maharashtra 401107

India

Thank you for trusting AssetMon with your information.

Cinute InfoMedia is committed to maintaining the highest standards of privacy and security.