Data Processing Agreement

Effective date: 4 August 2026 · Version 2026-08-ai-v3

Overview

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer" or "Data Controller") and Auditara Ltd (the "Processor"), for the use of the Auditara programme management platform. This DPA complies with UK GDPR Article 28 and governs the processing of personal data on behalf of the Customer.

Your use of the platform constitutes acceptance of this DPA. No separate signature is required.

1. Definitions

  • Customer: The individual or organisation using Auditara and determining the purposes of processing.
  • Processor: Auditara Ltd, processing data on the Customer's behalf.
  • Customer Personal Data: Any personal data processed by Auditara on the Customer's behalf, including organisation and people names, programme notes, and uploaded files.
  • Sub-processor: Any third party engaged by Auditara Ltd to process Customer Personal Data.
  • Personal Data Breach: A breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised access to Customer Personal Data.

2. Scope of Processing

  • Subject matter: Providing programme management tools for implementation and conformity programmes across the frameworks the platform supports, currently ISO/IEC 27001, ISO/IEC 42001, ISO 9001, ISO 14001, ISO 45001, ISO 22301, IEC 62443, SOC 2, GDPR, NIS2, DORA and the Bank of Ghana Cyber and Information Security Directive.
  • Nature: Storage and retrieval of programme data and evidence files. Auditara processes Customer Personal Data through an AI sub-processor only where the Customer has enabled AI assistance, as described in 3.4.
  • Purpose: As instructed by the Customer through the platform interface.
  • Duration: For the term of the Customer's active subscription plus any applicable retention period.
  • Categories of data: Organisation and people names, programme notes, evidence file contents, activity commentary, and completion records.
  • Categories of data subjects: The Customer's clients and any individuals referenced in uploaded evidence files.

3. Processor Obligations

3.1 Instructions

Auditara Ltd will process Customer Personal Data only on the Customer's documented instructions as provided through the platform interface.

3.2 Confidentiality

All personnel with access to Customer Personal Data are subject to confidentiality obligations and receive appropriate data protection training.

3.3 Security

Auditara Ltd implements the following technical and organisational measures:

  • Encryption in transit (TLS) and at rest for all stored data and files.
  • Row-level security in the database preventing cross-account data access.
  • Private storage bucket for evidence files, accessible only by the account owner.
  • Google sign in, or email and password with credentials stored only as salted hashes by our authentication provider.
  • EU West data residency for all Customer Personal Data.
  • Automated database backups managed by our hosting and database provider.
  • Uptime monitoring of the application.

3.4 Sub-processors

Auditara Ltd engages the following sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEU West
StripePayment processingGlobal, PCI DSS Level 1
GoogleOAuth authenticationGlobal
LovableWeb application hostingEU
Mistral AI SASOptional AI text drafting (remediation notes, summaries, document sections)France (EU)

Safeguards for Mistral AI SAS: EU hosted inference, zero data retention, no model training on customer data, engaged only when the customer enables AI assistance.

Where the Customer enables AI assistance, Auditara transmits control reference text, Customer typed notes and statuses, and Customer provided intake answers to the sub-processor listed above for the sole purpose of generating draft text. Uploaded evidence files are never transmitted. Processing occurs within the EU with zero retention.

Auditara Ltd will provide at least 30 days notice before adding or replacing any sub-processor that processes Customer Personal Data. You may object within that period by emailing hello@auditara.io.

3.5 Data Subject Rights

Auditara Ltd will assist you in responding to data subject rights requests including access, rectification, erasure, and portability. Requests should be sent to hello@auditara.io and will be fulfilled within 30 days.

3.6 Data Breach Notification

In the event of a confirmed Personal Data Breach affecting Customer Personal Data, Auditara Ltd will notify you within 48 hours of confirmation, providing details of the breach, the data affected, and the steps being taken to address it. You remain responsible for notifying the ICO within 72 hours where required under UK GDPR Article 33.

3.7 Deletion of Data

On termination of your subscription or on request, all Customer Personal Data will be permanently deleted within 30 days. Anonymised billing records are retained for 7 years as required by HMRC. Written confirmation of deletion is available on request.

3.8 Audit Rights

You may request evidence of Auditara Ltd's compliance with this DPA by emailing hello@auditara.io. Formal on-site audits may be conducted with 60 days advance written notice, no more than once per year, at the Customer's cost unless non-compliance is confirmed.

4. International Data Transfers

All programme data and evidence files are stored in the EU West region. A small number of named sub processors, including Stripe and Google, operate outside the EEA under standard contractual clauses. AI processing, where enabled by the Customer, occurs within the EU with zero retention.

5. Customer Obligations

You warrant that you have a lawful basis for processing any personal data you upload to the platform, that you have informed data subjects as required, and that you maintain your own records of processing activities under UK GDPR Article 30.

6. Governing Law

This DPA is governed by the laws of England and Wales. The supervisory authority is the UK Information Commissioner's Office (ICO).

7. Contact

For DPA-related questions, email hello@auditara.io with the subject line "DPA Request".

Auditara Ltd

hello@auditara.io

auditara.io

← Back to home