Privacy & Data Handling

Your governance data is yours. AUDT acts as a data processor on your behalf — we never use your data for any purpose other than providing you the AUDT platform.

What We Collect

  • Account information — name, email address, job title, organization name
  • Usage events — which features are used, page views, action counts (no content)
  • Audit logs — user actions within your org (who did what, when, from which IP)
  • Vendor and governance data — data entered by your team into AUDT modules
  • Device signals — browser type, OS, IP address for session management and security
  • Billing information — invoice details, payment reference numbers (no card data)

What We Never Do

  • We never use your data to train AI models — zero-day guarantee
  • We never sell or share your data with third parties without your explicit consent
  • We never store payment card numbers — all billing is handled via bank transfer or invoice
  • We never retain data after account deletion beyond legally required minimums
  • We never access your data except for support tickets you raise or contractual obligations
  • We never serve advertising based on your governance or compliance data

Customer Data Ownership

You retain full ownership of all data you store in AUDT. AUDT has a limited licence to process your data solely to provide the platform services you’ve subscribed to.

You can export all your data at any time via Settings — Data Governance — Export Tenant Data. Exported data is provided as a ZIP archive of CSV files covering all modules.

Third-Party Sub-Processors

AUDT uses a minimal set of sub-processors. Each is engaged under a Data Processing Agreement.

SupabaseDatabase and file storage — ap-south-1 MumbaiIndia
VercelApplication hosting — bom1 Mumbai regionIndia
Google (Gemini)AI feature processing — data not retained for trainingNot retained
ResendTransactional email deliveryEU / India

Cookies

AUDT uses only essential, functional cookies. No advertising or tracking cookies are used.

sb-...-auth-tokenSupabase session token — required for authentication
audt-sidAUDT session record — enables session management and timeout
audt-mfaTOTP verification state — set after successful MFA verification

Your Rights

Under DPDP Act 2023, GDPR, and other applicable laws, you have the following rights:

Access
Request a copy of your personal data
Rectification
Correct inaccurate personal data
Erasure
Request deletion of your personal data
Portability
Export your data in machine-readable format
Restriction
Request limited processing of your data
Objection
Object to certain types of processing

To exercise any of these rights, email security@audt.tech. We will acknowledge within 72 hours and respond within 30 days.