Legal

Data Processing Agreement

Effective date: 1 July 2026  ·  Version 1.0

This DPA is incorporated by reference into the AUDT Terms of Service. It applies to all processing of personal data by AUDT on behalf of customers.

1. Definitions

  • “Controller” means the Customer, who determines the purposes and means of processing personal data.
  • “Processor” means AUDT, who processes personal data on behalf of the Controller.
  • “Personal Data” means any information relating to an identified or identifiable natural person, as defined under applicable privacy laws including the DPDP Act 2023.
  • “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
  • “Sub-processor” means any third party engaged by AUDT to process Personal Data.

2. Scope and Purpose

AUDT processes Personal Data provided by the Customer solely to deliver the Service described in the Terms of Service. AUDT acts as a Data Processor under applicable privacy laws, including the Digital Personal Data Protection Act 2023 (India) and the General Data Protection Regulation (EU) where applicable.

AUDT processes Personal Data only on documented instructions from the Customer, unless required by applicable law. AUDT will notify the Customer of any legal requirement to process data without instructions where permitted by law.

3. Categories of Data Processed

AUDT may process the following categories of Personal Data on behalf of the Customer:

  • Identity data: name, job title, department, employee identifier;
  • Contact data: work email address, work phone number;
  • Account data: authentication credentials (password hashes, MFA secrets encrypted at rest), login history, session tokens;
  • Governance data: vendor names, vendor contact information, assessment responses, audit findings;
  • Usage data: platform activity logs, feature usage telemetry, audit trail events.

AUDT does not intentionally collect or require sensitive personal data (e.g., health information, financial account numbers, government identification numbers) as part of normal Service operation. Customers must not upload such data without prior written agreement.

4. Data Localisation and Transfers

All Customer Data, including Personal Data, is stored in India (Mumbai, ap-south-1 region) by default. AUDT does not transfer Personal Data outside India except as required to operate the Service and with appropriate safeguards in place.

Where Personal Data of EU data subjects is processed, AUDT provides appropriate transfer mechanisms (such as Standard Contractual Clauses) upon request. Contact privacy@audt.tech to request applicable transfer documentation.

5. Security Measures

AUDT implements appropriate technical and organisational measures to protect Personal Data against unauthorised access, disclosure, alteration, or destruction. Current measures include:

  • AES-256-GCM encryption for data at rest;
  • TLS 1.3 with HSTS for data in transit;
  • Row-Level Security (RLS) on all 259+ database tables, enforcing tenant isolation;
  • bcrypt password hashing with 12 rounds;
  • TOTP-based multi-factor authentication for all user accounts;
  • Comprehensive audit logging of all platform actions with actor attribution;
  • Enterprise: Customer Managed Encryption (AWS KMS, Azure Key Vault, Google KMS).

A full description of security measures is available in our Security Architecture and Encryption documentation.

6. Sub-processors

AUDT engages the following sub-processors to deliver the Service. AUDT remains responsible for sub-processor compliance with this DPA.

Sub-processorPurposeLocation
SupabaseDatabase hosting, authentication, and file storageIndia (Mumbai)
VercelApplication hosting and edge deliveryIndia (Mumbai)
Google (Gemini)AI processing for governance insights — no training on customer dataIndia (processed in-region where available)
ResendTransactional email delivery (expiry alerts, digest emails)US (processed in-region)

AUDT will provide thirty (30) days’ notice before adding new sub-processors that process Personal Data. Customers who object to a new sub-processor may terminate the Service in accordance with the Terms.

7. Data Subject Rights

AUDT will assist the Customer in fulfilling data subject rights requests under applicable law, including rights of access, rectification, erasure, portability, and objection. AUDT provides the following mechanisms:

  • Data Export: Customers can export all their data at any time from Settings → Data Governance → Export Tenant Data.
  • Data Deletion: Customers can request permanent data deletion from Settings → Data Governance → Request Data Deletion.
  • Account Deletion: Customers may request account deletion by emailing privacy@audt.tech.

AUDT will notify the Customer promptly if it receives a data subject rights request directly from a data subject and will not respond to such requests without Customer instruction.

8. Data Breach Notification

AUDT will notify the Customer without undue delay, and in any case within 72 hours of becoming aware of a personal data breach that affects Customer Data. Notification will be sent to the primary contact email on the Customer’s account and will include:

  • A description of the nature of the breach;
  • Categories and approximate number of data subjects affected;
  • Likely consequences of the breach;
  • Measures taken or proposed to address the breach.

9. Audit Rights

Enterprise customers may request an audit or inspection of AUDT’s data processing activities once per year with thirty (30) days’ advance notice. Audits are conducted at the Customer’s expense. AUDT may satisfy this obligation by providing a SOC 2 Type II report or equivalent third-party audit report where available.

All audit findings are treated as confidential information of both parties.

10. Retention and Deletion

AUDT retains Customer Data for the duration of the subscription. Upon termination, AUDT will make Customer Data available for export for thirty (30) days, after which it will be securely deleted from production systems within 90 days. Backup copies may persist for up to 180 days before permanent deletion.

Audit logs and billing records may be retained for longer periods as required by applicable law (typically 7 years for financial records under Indian law).

11. Contact

For DPA-related inquiries, data subject rights requests, or to request an executed DPA for your organisation, contact: privacy@audt.tech

AUDT · Governance Built on Proof. · audt.tech