Data Processing Agreement
The terms on which we handle personal data for you, written for the person doing your security review. Short, because we hold very little.
01Who is who
When you use Auddomate, you are the controller of the personal data in your account and we are the processor. We process it only to provide the service, on your instructions, as set out here and in the Software Licence Agreement.
This agreement takes effect when you start using the service and lasts as long as we process personal data for you. It is written to satisfy Article 28 of the UK and EU GDPR. If you need it signed, ask.
On a self-hosted installation there is nothing for us to process. The software runs on your servers, the data never reaches us, and you are both controller and processor. This agreement then covers only the small amount of information your installation sends when it checks for updates: the licence key, the domain and the version number. No personal data, no study content.
02What we process, and why
| Category | What it is | Why |
|---|---|---|
| Account data | Name, work email, password hash, role, language and unit preferences, profile picture if uploaded | To let people sign in and to keep organisations separate |
| Sign-in records | Email attempted, whether it succeeded, IP address, timestamp | To rate-limit and to protect accounts from being broken into |
| Content | Site plans, markup, machine profiles, studies, telemetry, reports and the names of clients you enter | To run the calculations you asked for and to store your work |
| Correspondence | Anything you write to support, and the record that an email was sent | To answer you, and to show whether a message left the building |
The people affected are those you invite into your organisation, plus anyone whose name you choose to type into a study. We do not ask for special category data and the service has no use for it; please do not put it in.
There is no advertising, no profiling, no automated decision-making about individuals, and no analytics vendor watching your people work.
03Our instructions
We process personal data only on your documented instructions — which, in practice, means the actions your people take in the software — unless the law requires otherwise, in which case we will tell you unless prohibited from doing so.
We will tell you if we think an instruction breaches data protection law. We do not use your content for our own purposes, do not sell it, and do not use it to train models.
04How it is protected
- Everything travels over HTTPS. Sessions are cookies marked secure, HTTP-only and same-site.
- Passwords are stored as bcrypt hashes, never in a readable form. Sign-in attempts are rate-limited.
- Optional two-step verification with recovery codes, and single sign-on through your own identity provider for Enterprise, so your directory decides who gets in.
- Every database query is scoped to one organisation, so another customer's study is not merely hidden — it is not returned.
- Secrets we must keep, such as an identity provider's client secret or a handover, are encrypted before storage.
- Uploaded plans are stored outside the web root and served only through the application, to people who are entitled to them.
- Shared report links carry a random token, can be given an expiry, and can be withdrawn at any moment.
- Access to production is limited to the people who run the service, which today is a very short list.
We hold no security certification today. We would rather say so than imply one. A self-hosted installation is the answer for organisations whose rules require the data to stay on their own infrastructure.
05Our people
Everyone with access to personal data is bound by confidentiality, has access only where it is needed to run or support the service, and is briefed on handling it.
06Sub-processors
You give us general authorisation to use the sub-processors below. We will publish any addition on this page, and tell Enterprise customers by email, at least thirty days before it starts, so you have time to object. If you object on reasonable data protection grounds and we cannot resolve it, you may end the agreement for the affected service.
| Sub-processor | What it does | Where |
|---|---|---|
| Namecheap, Inc. | Runs the servers, the database and the file storage for the hosted service, and delivers its email | United States |
| Stripe | Takes card payments and holds the billing details for paid plans on the hosted service. Card numbers go straight to Stripe and never reach us. | United States, Ireland |
That is the whole list. There is no analytics provider, no customer-messaging tool, no data warehouse, and no third-party AI service in the path of your data. Ask and we will name the hosting company, its data centre location and the contract we hold with it.
07International transfers
The hosted service runs in the United States. Where personal data from the UK or the European Economic Area is transferred there, it is covered by the Standard Contractual Clauses (and the UK Addendum) in our agreements with those sub-processors, together with the measures in section 04.
If you need the data to stay in a particular country, use a self-hosted installation and choose the country yourself.
08Helping with people's rights
Most requests you can satisfy yourself: a person's details are editable under Settings, a study exports as JSON and can be deleted from its page, a machine library and telemetry export as CSV, a person can remove their own account, and an owner can export the whole organisation as one archive from Settings.
Where you need us, we will help. If someone contacts us directly about data in your account, we will not answer them on your behalf — we will point them to you and tell you it happened. We do not charge for reasonable assistance.
09If something goes wrong
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 72 hours, with what we know: what happened, whose data, the likely consequences, and what we are doing. We will keep telling you as we learn more, and we will help you meet your own notification duties.
We will not quietly fix it and hope you do not notice.
10Audit
You may ask us for the information you need to show that we are meeting this agreement, once a year or after a breach, and we will answer in writing. The source of a self-hosted installation is yours to read, which is usually a faster answer than any questionnaire.
For an on-site or third-party audit, ask; we will agree reasonable scope, notice and cost.
11Return and deletion
You do not need to ask us. An owner can download the whole organisation — every study, plan file, markup, scenario, machine profile, person and the audit log — as one archive from Settings, and can delete the organisation from the same place. Deletion is immediate: every record and file goes, any subscription is cancelled, and what remains with us is a note that an organisation of that name was deleted, and the copies in routine backups until they are overwritten in the normal cycle of fourteen days. A confirmation is emailed to the owner who did it.
When our agreement ends without you doing this yourself, we delete your data within thirty days, except where the law requires us to keep something. Demo sandboxes are deleted automatically a few hours after they are created, sign-in records after ninety days, and the audit log after two years. We will confirm deletion in writing if you ask.
12Changes
We may update this agreement to reflect how the service actually works. Material changes are announced here, with the date at the top, and by email to Enterprise customers before they take effect.
13Contact
Write to legal@auddomate.com. We are a small company, so the person who answers is the person who built it.