1. Parties and roles
This agreement applies where AudiDesk processes personal data on behalf of a customer. The customer is the controller; AudiDesk is the processor. It supplements the terms of service and, on the subject of processing personal data, prevails over them.
Where the customer is itself a processor for its own client — a service provider or consultant running an assessment for a third organization — AudiDesk is a subprocessor, and this agreement is to be read accordingly.
Accepting the terms of service incorporates this agreement by reference, and no separate signature is needed for it to apply. Where a customer's own procurement requires a signed counterpart, we will sign this agreement on request; the terms are the same either way, and signing changes the paperwork rather than the obligations.
2. Subject matter, duration, nature and purpose
- Subject matter. Processing of software inventory data, evidence documents and workspace records supplied by the controller.
- Duration. The term of the controller’s agreement for the service, plus the deletion period in section 9.
- Nature. Ingestion, normalisation, enrichment against public catalogues, deterministic scoring, storage, generation of findings and reports, and making all of it available to authorised members of the controller’s workspace.
- Purpose. Providing the security and compliance assessment service, and nothing else. We do not process controller data for our own purposes, for analytics across customers, or to train models.
3. Categories of data subjects and personal data
3.1 Categories of data subjects
- Employees, contractors and other staff of the controller, and of the controller’s own clients where the controller assesses them.
- Individuals named in evidence documents — policy owners, approvers, reviewers and assigned remediation owners.
- Users of the service holding a workspace membership.
3.2 Categories of personal data
- Device and account identifiers from inventory exports: computer and host names, IP addresses, and usernames. These identify or can identify individuals and are treated as personal data throughout the platform.
- Software installed on a named machine, its version, and its install date, which is capable of revealing information about the individual using that machine.
- Names, business email addresses, job roles and organizational assignments appearing in evidence documents, risk registers, policy registers and remediation records.
- Account data: email address, display name, workspace memberships and role.
- Audit records of actions taken in the workspace, attributed to the account that took them, with a timestamp.
3.3 Special categories
The service is not designed for special category data within the meaning of Article 9, and the controller must not upload it. If it is uploaded regardless, it is processed under the same terms; the controller remains responsible for its lawfulness.
4. Processing on documented instructions
We process personal data only on the controller’s documented instructions, which comprise this agreement, the terms of service, and the use the controller makes of the service’s own features. We will tell the controller if, in our opinion, an instruction infringes data protection law.
If we are required by law to process beyond those instructions, we will inform the controller before doing so unless the law forbids it.
5. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations, and access is limited to those who need it to operate or support the service. Access to production data is logged.
6. Security measures
Taking account of the state of the art and the risks presented, we implement the following technical and organisational measures under Article 32:
- Encryption of personal data in transit over public networks and at rest in the underlying storage services.
- Tenant isolation enforced at the database and object-storage layer by deny-by-default rules scoped to a single workspace, with an automated cross-tenant isolation test suite that gates every release.
- Role-based access within a workspace, with an append-only audit record of mutations.
- Secrets held in a managed secret store, never in source control, and connector credentials never written to the database.
- Malware scanning of uploaded files in quarantine before they are made available, and sensitivity classification gating visibility of evidence by role.
- Exclusion of identifying inventory data and of confidential evidence from any language-model context, enforced in code and covered by an automated test.
- Rate limiting on mutating endpoints, and infrastructure-level resilience and backup provided by the underlying platform.
Measures may be updated as the service evolves, provided the level of protection is not reduced.
7. Subprocessors
The controller gives general authorisation for the engagement of subprocessors. Those currently engaged are listed, with purpose and location, on our subprocessors page. Each is bound by data protection obligations no less protective than those in this agreement, and we remain fully liable to the controller for their performance.
We will give the controller advance notice of the addition or replacement of a subprocessor. The controller may object on reasonable data protection grounds; if the objection cannot be resolved, the controller may terminate the affected part of the service.
Notice is given at least 30 days before the change takes effect, by email to each workspace owner and by an update to the subprocessors page. A controller who wants notices at a different address can subscribe one by writing to privacy@audidesk.com.
One exception, stated because it is the case where a notice period would work against the controller: where a subprocessor must be replaced immediately to contain a security incident or because the existing one has ceased to operate, we will make the change and give notice as soon as we can rather than waiting out the period.
8. Assisting the controller
Taking into account the nature of the processing, we will assist the controller by appropriate technical and organisational measures in responding to requests to exercise data subject rights. Because the controller has direct access to workspace data, most requests can be answered without our involvement; where they cannot, we will help.
We will also assist the controller in meeting its obligations under Articles 32 to 36, including security of processing, breach notification, and data protection impact assessments, taking into account the information available to us.
We will notify the controller without undue delay after becoming aware of a personal data breach affecting their data, with the information reasonably available to us at the time and further information as it becomes available.
9. Deletion or return on termination
At the controller’s choice, we will delete or return all personal data after the end of the provision of services, and delete existing copies unless retention is required by law. The controller may export workspace data through the service before the term ends.
Absent a contrary instruction, workspace data is deleted after the retention window following termination. Backups age out on their own cycle and are not selectively edited; data in backups remains subject to this agreement until it expires.
The retention window is 30 days from termination, after which workspace data is deleted. Backups expire within 90 days of the data being deleted from the live system.
The live window exists for the controller's benefit rather than ours: the commonest reason a customer asks for data after termination is that somebody cancelled by mistake, and an immediate purge turns a billing error into permanent loss. A controller who wants immediate deletion instead can instruct it, and we will carry it out.
10. Audit and information
We will make available to the controller the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the controller or an auditor it mandates.
Audits are to be requested with reasonable notice, conducted during business hours, no more than once in any twelve-month period except following a personal data breach or where a supervisory authority requires it, and carried out so as not to disrupt the service or compromise the confidentiality of other customers. We may satisfy an audit request by providing current third-party assurance reports where they answer the question asked.
11. International transfers
Unless the customer’s order form names another location, hosting, the application database and file storage are provided by Google Cloud in the us-central1 region, in the United States. That is a transfer outside the European Economic Area, made under Google’s Cloud Data Processing Addendum incorporating the European Commission Standard Contractual Clauses, with Google LLC certified under the EU–US Data Privacy Framework.
Where the order form names a European Union or other regional location, the customer’s workspace is provisioned in a separate deployment in that location, and its data is stored there and nowhere else. The location a workspace is stored in is shown on its settings page.
Transactional email is delivered through Amazon Simple Email Service in the us-east-1 region. That is a transfer outside the European Economic Area, made under the European Commission Standard Contractual Clauses together with supplementary measures. Details are on the privacy and subprocessors pages.
12. Contact
Matters arising under this agreement go to privacy@audidesk.com.