1. Who we are
AudiDesk provides a security and compliance assessment platform that ingests software inventories and produces findings, registers and reports. This policy explains what personal data we process, why, and what you can ask us to do about it.
The controller for the data described in section 3 is the operating company, to be named here, company number pending, registered at an address to be stated here. Data protection correspondence goes to privacy@audidesk.com.
2. Two different roles
We act in two capacities, and the distinction decides who answers a data subject request.
- As controller for this marketing website and for our own business contacts: people who write to us, request access, or hold an account with us. We decide why and how that data is processed.
- As processor for everything a customer uploads into their workspace. The customer decides what to upload and why; we process it on their documented instructions. Those terms are set out in our data processing agreement.
If you are an employee of one of our customers and you want to know what is held about you, your employer is the controller and the request goes to them. We will support them in answering it.
3. What we process, and why
3.1 Visitors to this website
Pages on this site are static and are served without advertising, tracking pixels or profiling of any kind. Our hosting provider records standard server request logs, which include IP addresses, for the purpose of operating and securing the service.
If — and only if — you consent to analytics, we measure how the site is used with Google Analytics 4. What that involves, what it sets, and how to change or withdraw the decision are set out in section 6. Nothing analytics-related loads before you have agreed to it.
3.2 People who use the contact form
When you submit the contact form we process the name, email address, organization (if you give one), subject and message you write, plus the locale you were reading in. It is delivered to our support inbox by email so that we can answer you. It is not added to a marketing list, and we do not send unsolicited mail.
To stop the form being used to flood our inbox, we rate-limit submissions. Your IP address, as our host reports it, is passed through a keyed hash and the result is counted in memory on the server handling the request. We do not store the address itself, the hash is not written to disk, and the counters are discarded within an hour and on every restart or deployment. No third-party anti-automation service is used, so nothing about your browser is sent anywhere.
3.3 Account holders
For people who hold a workspace account we process the email address and display name held by the authentication provider, the workspaces and role each account is a member of, and an append-only audit record of actions taken in a workspace. The audit record exists because a compliance product that cannot say who changed a control assessment is not usable by a compliance buyer.
3.4 Data inside a customer workspace
This is the category most often misdescribed, so we will be direct about it. A software inventory export contains computer names, IP addresses and usernames. Those are personal data under the GDPR: they identify or can be used to identify individual members of staff and the machines they use. We treat them as personal data throughout, and so should you when deciding what to upload.
Where a customer uses the evidence library, the documents they upload may contain further personal data — names of policy owners, approvers and reviewers, and whatever appears in a screenshot. We do not inspect or repurpose that content.
Inventory data identifying individuals is never placed into a language-model context. Our language-model use is limited to drafting document prose from structured fields, and the boundary is enforced in code and covered by an automated test.
4. Lawful basis
- Legitimate interests (Article 6(1)(f)) for answering enquiries sent to us, for operating and securing this website, and for protecting the contact form against abuse. Our interest is in running a service that works and is not used as a spam relay; the processing is minimal and expected.
- Performance of a contract (Article 6(1)(b)) for providing the platform to an account holder and for billing.
- Legal obligation (Article 6(1)(c)) where we must retain records, for example for accounting purposes.
- For data inside a customer workspace, the lawful basis is established by the customer as controller, not by us.
5. Where the data came from
Data about account holders and enquirers comes from those people directly. Data inside a workspace reaches us from our customer, who exports it from their own systems and uploads it, or later connects those systems directly. We do not buy personal data, and we do not enrich it from external sources about individuals.
8. International transfers
Our hosting, application database and file storage are provided by Google Cloud in the us-central1 region, in the United States. Customer workspace data is stored there.
That region is outside the European Union, so storing workspace data there is a transfer of personal data to a third country. It is made under Google’s Cloud Data Processing Addendum, which incorporates the European Commission Standard Contractual Clauses, and Google LLC is certified under the EU–US Data Privacy Framework. Data is encrypted in transit and at rest. We hold a transfer impact assessment covering it, available to customers on request. Storage in a European Union region is available where a customer’s contract requires it.
Transactional email leaves the European Union. Outbound mail — invitations, notifications, and messages sent through the contact form — is delivered through Amazon Simple Email Service in the AWS us-east-1 region. The recipient address, the sender address, the subject and the message body pass through and are processed there.
That region is outside the European Union. The transfer is made under the European Commission Standard Contractual Clauses, module two, together with the provider’s supplementary technical measures — transport encryption in transit and encryption at rest — and is limited to what an email must carry to be delivered. We hold a transfer impact assessment covering it, available to customers on request.
9. How long we keep it
- Contact form messages: kept in the support inbox for as long as needed to deal with the enquiry and to keep a record of what was agreed, then deleted.
- Account records: for the life of the account, then deleted or anonymised.
- Customer workspace data, including inventories, snapshots, evidence and reports: retained for the term of the customer’s agreement and deleted or returned on termination, as set out in the data processing agreement.
- Audit records: retained for the life of the workspace, because their value to a compliance buyer is precisely that they cannot be selectively erased.
- Server request logs: retained by our hosting provider for their standard operational period.
10. Automated processing
Risk scores, lifecycle statuses and findings are produced by a deterministic, versioned rule engine rather than by a person. This is automated processing, and we want to be precise about what it is not: it evaluates software products and machines, not individuals, and it produces no decision that has a legal or similarly significant effect on a person within the meaning of Article 22.
Every finding records the ruleset version that produced it, so any result can be explained and reproduced.
11. Your rights
Where we are the controller, you have the right to ask us for a copy of your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive data in a portable form. Where processing rests on legitimate interests you may object at any time on grounds relating to your particular situation.
We will answer within one month. We do not charge for this. If you are not satisfied with our answer you may complain to the data protection supervisory authority in the country where you live or work.
12. Security
Workspace isolation is enforced at the database layer by deny-by-default security rules, with an automated cross-tenant isolation test suite that runs on every change and blocks release if it fails. Data is encrypted in transit and at rest by our infrastructure providers. Secrets are held in a managed secret store and never in source control. Uploaded files are scanned before they are made available.
No system is perfect. If you believe you have found a vulnerability, please write to us before disclosing it publicly.
13. Changes, and how to reach us
If we change this policy we will update the date at the top of the page and, where the change is material, tell affected customers directly.
Privacy and data protection questions, including data subject requests, go to privacy@audidesk.com.
We have not appointed a data protection officer. Article 37 requires one of a public authority, or where large-scale monitoring or large-scale processing of special-category data is a core activity; none of those describes this service, whose core activity is processing software inventories and organisational records. The address above reaches the person accountable for this policy.
No Article 27 representative is appointed either, because the controller is established in the Union rather than outside it. A controller established outside the Union would need one, which is why this paragraph and the identity in section 1 are settled together.