Legal
Data Processing Agreement
Version 1.7 · Effective:
Summary
- Audulate acts as a data processor when processing personal data on behalf of your organisation.
- We only process data on your documented instructions.
- All EU/UK data stays within EU infrastructure unless SCCs are in place.
- Paid-plan customers can request a signed DPA — email [email protected].
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Audulate Terms of Service and applies where Audulate (“Processor”) processes personal data on behalf of a customer (“Controller”) in the course of providing the Audulate platform.
The DPA is incorporated by reference into the Terms of Service. By using the Audulate platform, paid-plan customers agree to the terms of this DPA. Free plan customers are covered by the Terms of Service only.
2. Processor obligations (Article 28 GDPR)
Audulate, as data processor, commits to:
- Process personal data only on documented instructions from the Controller.
- Ensure authorised personnel are subject to confidentiality obligations.
- Implement appropriate technical and organisational security measures (Article 32).
- Assist the Controller with data subject rights requests (Articles 15–22).
- Assist the Controller with breach notification obligations (Articles 33–34).
- Delete or return all personal data at termination, at the Controller's choice.
- Make available all information necessary to demonstrate compliance and support audits.
- Not engage sub-processors without prior written authorisation from the Controller (met by acceptance of this DPA).
3. Sub-processors
Audulate uses the following sub-processors to deliver the platform. Each is bound by data processing agreements with equivalent obligations. This list is versioned — see the change log at the bottom of this page.
| Vendor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Supabase | PostgreSQL database & authentication | EU — Frankfurt (eu-central-1) | SCCs in place |
| Upstash | Redis queue (BullMQ) | EU — Frankfurt | SCCs in place |
| Railway | Worker service hosting | EU — Frankfurt | SCCs in place |
| Vercel | Frontend & API hosting | USA | SCCs in place |
| Cloudinary | Encrypted file storage (CAPA attachments, audit-package ZIPs, evidence) | EU + USA | SCCs in place |
| Stripe | Payment processing | USA | SCCs in place |
| OpenAI | AI risk summaries & remediation (gpt-4o-mini) and the read-only Compliance Copilot assistant | USA | SCCs in place |
| Anthropic | AI compliance summaries and remediation guidance (Claude) | USA | SCCs in place |
| Resend | Transactional email | USA | SCCs in place |
| GitHub | PR scanning webhooks & source control | USA | SCCs in place |
| Cloudflare | CDN + DDoS protection for marketing site (no customer data) | Global edge | SCCs in place |
4. Sub-processor change notification
Audulate will notify customers at least 30 days before adding or replacing a sub-processor via an in-app notification delivered to all account members in your Audulate dashboard. The notification will state the vendor name, the nature of the change, and the effective date.
Enterprise customers may object to a change within 14 days of notification; if we cannot reasonably accommodate the objection, either party may terminate the affected services without penalty. Free and Starter plan customers are deemed to accept changes unless they cancel their account before the effective date.
5. International data transfers
The majority of personal data processed by Audulate is stored within EU infrastructure (Supabase Frankfurt, Upstash Frankfurt, Railway Frankfurt). Where data is transferred outside the EU/UK — specifically to Vercel, Stripe, OpenAI, Resend, and GitHub in the USA — we rely on the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor) as the transfer mechanism.
For UK customers, we rely on the International Data Transfer Agreement (IDTA) addendum for UK-to-USA transfers. Transfer Impact Assessments (TIAs) for each non-EU processor are available to Enterprise customers on request.
6. Security measures (Article 32)
- Encryption at rest (AES-256) and in transit (TLS 1.2+) for all personal data.
- Passwords hashed with bcrypt (cost factor 12).
- Multi-factor authentication enforced for all internal staff accounts.
- Annual third-party penetration testing. Summary reports available to Enterprise customers on request.
- Role-based access control — only authorised personnel access production data.
- Documented incident response policy with 72-hour internal escalation SLA.
7. Data subject rights assistance
Audulate will assist the Controller in fulfilling data subject rights requests (Articles 15–22 GDPR) within the platform via the DSR Management module. Customers can also request manual assistance by emailing [email protected].
8. Audit rights
Enterprise customers may request an audit of Audulate's data processing practices once per calendar year, with 30 days' notice. Audits will be conducted during business hours and must not unreasonably disrupt operations. Alternatively, Audulate may provide a summary audit report prepared by a qualified third party in lieu of an on-site audit.
9. Data return and deletion
On termination or expiry of the Agreement, Audulate will, at the Controller's election: (a) return all personal data in a machine-readable format within 30 days, or (b) securely delete all personal data within 30 days and confirm deletion in writing. Backups are purged within 90 days of the deletion request.
10. Request a signed DPA
Paid-plan customers requiring a countersigned DPA for their own compliance records should contact our legal team. We will respond within 5 business days.
Request your signed DPA
Email us with your company name, registered address, and the email address of the signatory. We'll send a countersigned copy within 5 business days.
Email [email protected]Annex 1 — Details of the processing (Article 28(3))
Subject matter and duration. Audulate processes personal data on behalf of the Controller solely to provide the Audulate compliance platform, for the duration of the Controller's subscription and until data is returned or deleted in accordance with §9.
Nature and purpose. Automated compliance monitoring, evidence collection, website / cloud / code scanning, and reporting — performed on the Controller's documented instructions.
Categories of data subjects.
- The Controller's account users — individuals who access the Audulate platform.
- The Controller's personnel / employees — where the Controller connects an identity provider (e.g. Okta, Microsoft Entra ID, Google Workspace), an HR system (e.g. Rippling, BambooHR, Gusto), a device-management (MDM) system (e.g. Jamf, Microsoft Intune), or a ticketing system (e.g. Jira, Linear), so Audulate can evidence access-control, device-security, people-security, and change-control controls.
- The Controller's website visitors and other end-users — as they appear in scan findings, consent records, or data-subject-request workflows.
Categories of personal data.
- Account & contact data — names, work email addresses, roles.
- Identity & access data (from a connected identity provider) — email, name, administrator status, account status, last sign-in, multi-factor-authentication enrolment / enforcement status, and organisational unit.
- Personnel data (from a connected HR system) — email, name, employment status, start / end dates, role, department, and the completion dates of NDA signature and background checks (the underlying documents are not processed).
- Device data (from a connected MDM) — device name, platform, OS version, disk-encryption and compliance status, the assigned owner's email, and last check-in time.
- Change-management data (from a connected ticketing system) — ticket summary, type, status, priority, the assignee's name, and key dates. Audulate does not modify tickets.
- Compliance records — scan findings, consent records, and evidence artefacts the Controller generates or imports.
- Technical data — IP addresses and application logs.
Audulate does not intentionally process special categories of personal data (Article 9). Personnel, identity, device and change-management data is minimised to the fields necessary to evidence the relevant security, people and change controls (e.g. access and MFA status, training and screening dates, device-encryption status) and is retained in line with Audulate's data-retention policy.
11. Version history
| Version | Effective date | Changes |
|---|---|---|
| v1.7 | 11 Jul 2026 | Documented the Compliance Copilot — a read-only, tenant-scoped in-app AI assistant that answers questions from the customer’s own workspace data — as an additional AI use of the existing OpenAI sub-processor. No new sub-processor added; the assistant sends only data the user can already see, never credentials or secrets, and the provider does not train on inputs. Pre-existing SCCs apply. |
| v1.6 | 27 Jun 2026 | Expanded Annex 1 to reflect additional connected integrations now available — device-management / MDM (Jamf, Microsoft Intune), security telemetry (CrowdStrike, Snyk), ticketing (Jira, Linear), and the GitLab / Bitbucket code hosts — and added device and change-management data to the categories of personal data. These are data sources the Controller connects, not Audulate sub-processors; the sub-processor list is unchanged. No change to processing activities; existing processing formalised. |
| v1.5 | 25 Jun 2026 | Added Annex 1 (Details of the processing, Article 28(3)) — the categories of data subjects and personal data Audulate processes as processor, including personnel / identity data processed via connected identity (Google Workspace) and HR (Rippling) integrations. No change to processing activities; existing processing formalised. |
| v1.4 | 5 Jun 2026 | Added Cloudinary (encrypted file storage), Anthropic (Claude AI summaries), and Cloudflare (marketing-site CDN) to sub-processor list to bring the contract document into parity with the Trust page disclosure. No change to processing activities; pre-existing use of these services formalised. Enterprise customers may object within 14 days per §4. |
| v1.3 | 25 May 2026 | Privacy review pass; no sub-processor change. AI feature copy added to Annex. |
| v1.2 | 1 May 2026 | Added OpenAI as sub-processor (AI risk summaries, gpt-4o-mini). Updated SCC references to 2021 Commission SCCs. Changed sub-processor change notifications from email to in-app dashboard notifications. |
| v1.1 | 1 Jan 2026 | Added UK IDTA addendum for UK-to-USA transfers. Added audit rights clause. |
| v1.0 | 1 Jul 2023 | Initial DPA published. |
Questions about this DPA? Contact us or email [email protected]. For the full Privacy Policy, see /privacy.