انتقل إلى المحتوى
AudiDesk

الشؤون القانونية

سياسة الخصوصية

مسودة بانتظار المراجعة القانونية — غير ملزمة بعد.

تُنشر وثائقنا القانونية بالإنجليزية. اعتماد لغة واحدة ذات حجية يزيل أي تساؤل عن الترجمة التي تسود. قراءة النسخة الإنجليزية

آخر تحديث
2026-09-27
الإصدار
0.2-draft

1. Who we are

AudiDesk provides a security and compliance assessment platform that ingests software inventories and produces findings, registers and reports. This policy explains what personal data we process, why, and what you can ask us to do about it.

The controller for the data described in section 3 is the operating company, to be named here, company number pending, registered at an address to be stated here. Data protection correspondence goes to privacy@audidesk.com.

2. Two different roles

We act in two capacities, and the distinction decides who answers a data subject request.

  • As controller for this marketing website and for our own business contacts: people who write to us, request access, or hold an account with us. We decide why and how that data is processed.
  • As processor for everything a customer uploads into their workspace. The customer decides what to upload and why; we process it on their documented instructions. Those terms are set out in our data processing agreement.

If you are an employee of one of our customers and you want to know what is held about you, your employer is the controller and the request goes to them. We will support them in answering it.

3. What we process, and why

3.1 Visitors to this website

Pages on this site are static and are served without advertising, tracking pixels or profiling of any kind. Our hosting provider records standard server request logs, which include IP addresses, for the purpose of operating and securing the service.

If — and only if — you consent to analytics, we measure how the site is used with Google Analytics 4. What that involves, what it sets, and how to change or withdraw the decision are set out in section 6. Nothing analytics-related loads before you have agreed to it.

3.2 People who use the contact form

When you submit the contact form we process the name, email address, organization (if you give one), subject and message you write, plus the locale you were reading in. It is delivered to our support inbox by email so that we can answer you. It is not added to a marketing list, and we do not send unsolicited mail.

To stop the form being used to flood our inbox, we rate-limit submissions. Your IP address, as our host reports it, is passed through a keyed hash and the result is counted in memory on the server handling the request. We do not store the address itself, the hash is not written to disk, and the counters are discarded within an hour and on every restart or deployment. No third-party anti-automation service is used, so nothing about your browser is sent anywhere.

3.3 Account holders

For people who hold a workspace account we process the email address and display name held by the authentication provider, the workspaces and role each account is a member of, and an append-only audit record of actions taken in a workspace. The audit record exists because a compliance product that cannot say who changed a control assessment is not usable by a compliance buyer.

3.4 Data inside a customer workspace

This is the category most often misdescribed, so we will be direct about it. A software inventory export contains computer names, IP addresses and usernames. Those are personal data under the GDPR: they identify or can be used to identify individual members of staff and the machines they use. We treat them as personal data throughout, and so should you when deciding what to upload.

Where a customer uses the evidence library, the documents they upload may contain further personal data — names of policy owners, approvers and reviewers, and whatever appears in a screenshot. We do not inspect or repurpose that content.

Inventory data identifying individuals is never placed into a language-model context. Our language-model use is limited to drafting document prose from structured fields, and the boundary is enforced in code and covered by an automated test.

4. Lawful basis

  • Legitimate interests (Article 6(1)(f)) for answering enquiries sent to us, for operating and securing this website, and for protecting the contact form against abuse. Our interest is in running a service that works and is not used as a spam relay; the processing is minimal and expected.
  • Performance of a contract (Article 6(1)(b)) for providing the platform to an account holder and for billing.
  • Legal obligation (Article 6(1)(c)) where we must retain records, for example for accounting purposes.
  • For data inside a customer workspace, the lawful basis is established by the customer as controller, not by us.

5. Where the data came from

Data about account holders and enquirers comes from those people directly. Data inside a workspace reaches us from our customer, who exports it from their own systems and uploads it, or later connects those systems directly. We do not buy personal data, and we do not enrich it from external sources about individuals.

6. Cookies and analytics

This website sets no cookies and loads no third-party content until you decide. Arriving here places nothing on your device. A cookie banner asks about analytics, and until you answer it, nothing analytics-related is loaded, requested or stored.

6.1 The one cookie we set ourselves

Answering the banner stores your answer in a first-party cookie named audidesk_consent, so you are not asked again on every visit. It records the version of this policy, which categories you allowed, and the date you chose — and nothing else. It contains no identifier and cannot be used to recognise you. It is strictly necessary for honouring your own choice, so it is set on that basis rather than on consent, and it expires after 180 days.

We do not store your language preference in a cookie — the language is part of the URL instead.

6.2 Analytics, if you allow it

With your consent we use Google Analytics 4, provided by Google Ireland Limited, to measure how this site is used: which pages are read, how visitors arrive, and approximate location derived from the IP address. Google Analytics sets its own cookies (names beginning _ga) to distinguish one browser from another across a visit. We do not send it your name, your email address, or anything you typed into the contact form, and the page addresses we report carry no query string or fragment.

The lawful basis is your consent, under Article 6(1)(a) and under the national rules implementing the ePrivacy Directive. We use Google’s consent signalling, so before consent every analytics and advertising signal is set to denied; advertising signals stay denied in all cases, because this site runs no advertising or marketing cookies at all.

You can change or withdraw your decision at any time through Cookie preferences in the footer of every page. Withdrawing analytics consent stops further measurement and deletes the Google Analytics cookies already on your device. Measurement already collected remains in Google’s reporting, aggregated, for the retention period configured on the property.

Google acts as our processor for this measurement, under the Google Ads Data Processing Terms, and transfers outside the European Economic Area rely on Google’s own European Commission Standard Contractual Clauses together with the supplementary measures Google documents for them. The property is configured to retain event-level data for 14 months, which is the shortest setting that still allows a year-on-year comparison.

IP addresses are not stored: Google Analytics 4 discards them after deriving an approximate location, and we neither enable Google signals nor link this property to an advertising account, so nothing measured here is used to build a profile or to target advertising.

6.3 Everything else

There is no other third party. We embed no social media widgets, and the contact form has no CAPTCHA widget; it is protected as described in section 3.2. Beyond the Google tag described above, every script, style, font and image comes from this origin, and the site’s content security policy permits nothing else.

The application at the app subdomain does set a session cookie, which is strictly necessary to keep you signed in.

7. Who we share it with

We do not sell personal data and we do not share it for advertising. We use a small number of service providers to run the platform — hosting, database and file storage, transactional email, payments, and, where you have consented to it, website analytics. Each is listed by name, purpose and location on our subprocessors page, which is part of this policy.

We may disclose data where we are legally required to. If we receive such a request we will tell the affected customer unless we are prohibited from doing so.

8. International transfers

Our hosting, application database and file storage are provided by Google Cloud in the us-central1 region, in the United States. Customer workspace data is stored there.

That region is outside the European Union, so storing workspace data there is a transfer of personal data to a third country. It is made under Google’s Cloud Data Processing Addendum, which incorporates the European Commission Standard Contractual Clauses, and Google LLC is certified under the EU–US Data Privacy Framework. Data is encrypted in transit and at rest. We hold a transfer impact assessment covering it, available to customers on request. Storage in a European Union region is available where a customer’s contract requires it.

Transactional email leaves the European Union. Outbound mail — invitations, notifications, and messages sent through the contact form — is delivered through Amazon Simple Email Service in the AWS us-east-1 region. The recipient address, the sender address, the subject and the message body pass through and are processed there.

That region is outside the European Union. The transfer is made under the European Commission Standard Contractual Clauses, module two, together with the provider’s supplementary technical measures — transport encryption in transit and encryption at rest — and is limited to what an email must carry to be delivered. We hold a transfer impact assessment covering it, available to customers on request.

9. How long we keep it

  • Contact form messages: kept in the support inbox for as long as needed to deal with the enquiry and to keep a record of what was agreed, then deleted.
  • Account records: for the life of the account, then deleted or anonymised.
  • Customer workspace data, including inventories, snapshots, evidence and reports: retained for the term of the customer’s agreement and deleted or returned on termination, as set out in the data processing agreement.
  • Audit records: retained for the life of the workspace, because their value to a compliance buyer is precisely that they cannot be selectively erased.
  • Server request logs: retained by our hosting provider for their standard operational period.

10. Automated processing

Risk scores, lifecycle statuses and findings are produced by a deterministic, versioned rule engine rather than by a person. This is automated processing, and we want to be precise about what it is not: it evaluates software products and machines, not individuals, and it produces no decision that has a legal or similarly significant effect on a person within the meaning of Article 22.

Every finding records the ruleset version that produced it, so any result can be explained and reproduced.

11. Your rights

Where we are the controller, you have the right to ask us for a copy of your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive data in a portable form. Where processing rests on legitimate interests you may object at any time on grounds relating to your particular situation.

We will answer within one month. We do not charge for this. If you are not satisfied with our answer you may complain to the data protection supervisory authority in the country where you live or work.

12. Security

Workspace isolation is enforced at the database layer by deny-by-default security rules, with an automated cross-tenant isolation test suite that runs on every change and blocks release if it fails. Data is encrypted in transit and at rest by our infrastructure providers. Secrets are held in a managed secret store and never in source control. Uploaded files are scanned before they are made available.

No system is perfect. If you believe you have found a vulnerability, please write to us before disclosing it publicly.

13. Changes, and how to reach us

If we change this policy we will update the date at the top of the page and, where the change is material, tell affected customers directly.

Privacy and data protection questions, including data subject requests, go to privacy@audidesk.com.

We have not appointed a data protection officer. Article 37 requires one of a public authority, or where large-scale monitoring or large-scale processing of special-category data is a core activity; none of those describes this service, whose core activity is processing software inventories and organisational records. The address above reaches the person accountable for this policy.

No Article 27 representative is appointed either, because the controller is established in the Union rather than outside it. A controller established outside the Union would need one, which is why this paragraph and the identity in section 1 are settled together.

تفضيلات ملفات تعريف الارتباط

الملفات الضرورية هي ما يجعل AudiDesk يعمل. وكل ما عداها معطّل حتى تفعّله، ويمكنك تغيير تفضيلاتك في أي وقت من تذييل الصفحة.

ضرورية

audidesk_consent

لازمة لعمل AudiDesk. والملف الوحيد الذي نضعه يسجّل هذا الاختيار حتى لا نسألك في كل زيارة. لا يحمل أي معرّف ولا يمكن تعطيله.

قياس الاستخدام

Google Analytics 4

قياس مجمَّع لطريقة استخدام AudiDesk — أي الصفحات تُقرأ، ومن أي بلد. لا يُحمَّل شيء ولا يُوضع أي ملف قياس دون تفعيلك؛ وإذا أعدت تعطيله تُحذف الملفات الموجودة بالفعل.

ما تقوله سياسة الخصوصية عن ذلك