Privacy Policy
1. Roles
For Customer's own users (auditor firm employees and the client members it invites), AuditAI acts as a processor under GDPR / UK GDPR and as a service provider under CCPA/CPRA, processing personal data on Customer's instructions. For visitors to our marketing surfaces and people who contact us directly, AuditAI is the controller.
2. Data we collect (as controller)
- Account data: name, work email, organisation, role. Provided by you when you sign up.
- Marketing data: pages visited, referrer, broad geolocation derived from IP. Captured via PostHog and Sentry; subject to consent in jurisdictions that require it.
- Support data: messages and metadata when you contact us.
- Billing data: handled by Stripe; we receive only customer id, last four digits of card, status. Card numbers never reach our servers.
3. Data we process on Customer's behalf (as processor)
- Engagement data: organisation names, departments, AI tool inventory, control assessments, findings, recommendations, reports.
- Evidence files: documents the auditor or the client uploads.
- Survey responses: name, role, free-text responses from department surveys.
- Interview content: scheduled times, optional transcripts and notes.
- AI logs: prompt + completion metadata (token counts, cost, model). Prompt and completion bodies are not persisted by AuditAI; if Anthropic Zero Data Retention is enabled for our deployment, Anthropic does not retain them either.
4. Lawful bases (GDPR / UK GDPR)
We rely on (a) contract for account, billing, and Service delivery; (b)legitimate interest for product analytics, security, fraud prevention, and improving the Service; (c) consent for non-essential cookies and certain marketing communications; and (d) legal obligation for tax, audit-log, and responding to regulatory requests.
5. Retention
Default retention windows (Customer can negotiate enterprise-tier overrides):
- AuditLog records: 7 years (with PII scrubbed at the per-tenant retention boundary).
- AI call logs: 24 months.
- Finding edit history: 24 months.
- Raw interview transcripts: 90 days, then text fields nulled.
- Evidence files: kept while the engagement is open + 365 days.
- Engagement, finding, and report rows: 7 years (typical audit retention).
- Account data: until deletion request + 30-day grace, plus 90 days of backups.
6. Subprocessors
Current subprocessors are listed and kept up-to-date at /legal/subprocessors. We notify customers at least 30 days before adding a new subprocessor that processes personal data.
7. International transfers
Personal data may be transferred to the United States and other jurisdictions where our subprocessors operate. AuditAI relies on the EU Standard Contractual Clauses (Module 2 / Module 3 as applicable) and the UK International Data Transfer Addendum. For EU customers we route PostHog telemetry to PostHog EU; Sentry session replay is disabled by default in the EU and requires opt-in consent.
8. Your rights
Subject to applicable law, you have the right to access, correct, delete, restrict, port, or object to processing of your personal data. EU/UK data subjects can lodge a complaint with their supervisory authority. CCPA/CPRA covered consumers can opt out of sale or sharing of personal information; AuditAI does not sell or share personal information for cross-context behavioural advertising.
To exercise rights:
- Account holders: download your organisation's data via the in-app export at
/api/portal/data-export. Personal export is available from your user-settings panel. - Anyone: email privacy@auditai.example. We respond within 30 days, extendable by another 60 days where complexity requires.
9. Cookies
See the dedicated Cookie Policy. Non-essential cookies require opt-in for users in the EU, UK, and California (where applicable).
10. Security
Encryption in transit and at rest, multi-tenant Postgres Row-Level Security, immutable audit logging, AES-256-GCM token cipher for stored integration credentials, signed webhooks. Full description on the Security page.
11. Children
AuditAI is a B2B service not directed to individuals under 16. We do not knowingly collect personal data from children.
12. AI-specific disclosures
AuditAI uses Claude (Anthropic) to draft findings, recommendations, and executive summaries. AI-drafted content is labelled (AI-drafted; reviewed by [auditor])in every report. AuditAI does not use Customer Data to train Anthropic or any other third-party AI model.
13. Changes
Material changes will be announced by email and in-app notice at least 30 days before they take effect for existing customers.
14. Contact
Privacy: privacy@auditai.example.
Data Protection Officer: dpo@auditai.example.
EU representative (Art. 27 GDPR): to be appointed before launching to EU customers.
UK representative (UK GDPR): to be appointed before launching to UK customers.