Privacy Policy

Effective date: 4 August 2026 · Version 2026-08-ai-v3

Overview

This Privacy Policy describes how Auditara ("we", "us", "our"), operated by Auditara Ltd, collects, uses, and protects your personal information when you use the Auditara programme management platform at auditara.io.

We do not sell your data to any third party. Optional AI assistance features are described below.

AI assistance (optional)

Auditara includes optional AI assistance features. They are switched off by default and only operate if a workspace owner turns them on. When enabled, AI assistance can draft remediation notes, executive summaries, and document narrative sections for your review.

What is sent to the AI provider when you use these features: the reference text of the framework control or document section you are working on, the notes and statuses you have typed into Auditara, and, for document generation, the intake answers you have chosen to provide. What is never sent: files you upload as evidence, their contents, or any data from connected systems.

All AI processing runs server side on EU hosted infrastructure provided by Mistral AI (France). We use a zero retention configuration: your data is not stored by the provider after processing and is not used to train models. AI output is always presented as a draft. Nothing is saved until a person in your workspace reviews and confirms it.

You can turn AI assistance off at any time in Settings. Turning it off disables the features immediately. Your consent, including the policy version you accepted, is recorded for audit purposes.

Data Controller

Auditara Ltd

United Kingdom

Contact: hello@auditara.io

Supervisory Authority: UK Information Commissioner's Office (ICO), ico.org.uk

What We Collect

  • Account information: Your name and email address, obtained via Google OAuth when you sign in. We do not store passwords.
  • Programme data: Organisation and people names, programme notes, target certification dates, activity commentary, and completion status that you create within the platform.
  • Evidence files: Documents and files you upload to programme activities, stored in a private encrypted storage bucket.
  • Billing information: Subscription status and Stripe customer identifiers. We never store card numbers. Payment card data is handled exclusively by Stripe.
  • Usage data: Page views, feature interactions, and session data collected to improve the platform. Configured to exclude personally identifiable information.
  • Error logs: Anonymised error reports to support debugging. No programme data or file content is included.

How We Use Your Information

  • To provide the service: Authenticate your account, store your programme data, and deliver the features you have requested. Legal basis: Contract performance.
  • To improve the service: Analyse usage patterns and fix technical issues. Legal basis: Legitimate interest.
  • To process payments: Manage your subscription and billing via Stripe. Legal basis: Contract performance.
  • To comply with the law: Retain billing records as required by HMRC. Legal basis: Legal obligation.

Who We Share Your Information With

We share your data only with the following service providers, each bound by data processing agreements:

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageEU West
StripePayment processingGlobal, PCI DSS Level 1
GoogleOAuth authenticationGlobal
LovableWeb application hostingEU
Mistral AI SASOptional AI text drafting, engaged only when AI assistance is enabledFrance (EU)

We share data with the AI provider listed above only when a workspace owner has enabled AI assistance, and only the content described in the AI assistance section. We do not use third-party advertising or marketing analytics.

Data Storage and Residency

All programme data and uploaded evidence files are stored in the EU West region via Supabase. Billing data is processed by Stripe under their standard GDPR-compliant terms.

Data Retention

Account data is retained while your account is active. Programme data and evidence files are retained until you delete them or delete your account. Billing records are retained for 7 years as required by HMRC. On account deletion, all personal data is permanently deleted within 30 days.

Your Rights Under UK GDPR

You have the right to access, correct, export, and delete your personal data. You also have the right to object to processing and to lodge a complaint with the ICO at ico.org.uk.

To exercise any right, email hello@auditara.io with the subject line "Privacy Request". We will respond within 30 days.

Children

Auditara is not intended for individuals under 18. We do not knowingly collect data from minors.

Changes to This Policy

We will notify you by email at least 14 days before any material change to this policy. The effective date at the top of this page will be updated with each revision.

Contact

hello@auditara.io

← Back to home