Data Processing Agreement
Last updated: September 24, 2026
This agreement applies whenever you use AuditHQ to audit a site, plugin or listing. For that data you are the controller and we are the processor. It forms part of our Terms and sits alongside our Privacy Policy, which covers the separate case where we are the controller of your own account data.
1. What we process, and why
We process only what is needed to run an audit and show you the result: the URLs and repositories you ask us to scan, the HTML, headers and public files fetched from them, the findings we derive, and the tickets and comments you create from those findings.
Audited pages can themselves contain personal data — author bylines, contact addresses, staff names. Where that appears in a stored finding it is processed under this agreement as your data, not ours.
2. Our instructions
We process this data only on your documented instructions, which are the actions you take in the product and the terms of this agreement. If we believe an instruction breaches applicable data protection law we will tell you rather than act on it.
3. Confidentiality
Access is limited to personnel who need it to operate or support the service, and they are bound by confidentiality obligations.
4. What we will not do
- We do not sell or share your data, in the sense those words carry under US state privacy law.
- We do not use your data to train machine-learning models. This covers stored audit findings and report bodies, not only source code.
- We do not combine your data with data from other customers, or use it outside the direct relationship between us — except to produce aggregate, non-identifying service statistics.
- We do not retain, use or disclose your data for any purpose other than performing the service.
We certify that we understand and will comply with these restrictions. You may take reasonable steps to confirm we are doing so.
5. Security
Data is encrypted in transit and at rest. Access is authenticated and scoped per project and per company role. Audits run through a guarded fetch layer that refuses private and internal network addresses. Secrets found during a scan are redacted at the point of detection, so a raw credential is never written to a stored finding.
6. Sub-processors
We use the providers below. We remain responsible for their processing. We will give notice before adding or replacing one, and you may object on reasonable data protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting and delivery | US / global edge |
| Google Cloud (Firebase) | Authentication, Firestore database, report storage | US / EU |
| Google PageSpeed Insights | Performance measurement of the URL you submit | US |
| Paddle | Payments, invoicing and tax. Merchant of record | UK / EU |
| Sentry | Error monitoring | US / EU |
| SMTP email provider | Account, digest and ticket email | Per configuration |
7. International transfers
Where data leaves the UK or EEA we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum for UK transfers. Where Brazilian law applies we rely on the ANPD’s standard clauses.
8. Personal data breach
We will notify you without undue delay, and in any case within 48 hours of becoming aware of a breach affecting your data, with the information you need to meet your own reporting deadlines. We target 48 hours because Kenya’s Data Protection Act sets the tightest processor deadline we are subject to; meeting it also clears the 72-hour regimes.
9. Assistance
Taking into account the nature of the processing, we will help you respond to data subject requests and meet your obligations on security, breach notification and impact assessments.
10. Deletion and return
You can delete a project at any time, which removes its audits, findings, tickets and stored report bodies. On termination we delete your data within 30 days unless we are required to keep it longer, and retention limits set by your plan apply in the meantime. Report bodies held in object storage are covered by the same terms as database records.
11. Audit
On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this agreement.
12. Contact
Data protection questions, sub-processor objections and audit requests: support@audithq.app.
Need this executed as a signed document, or with your own paper? Email us and we will sign yours.