AuditHQ

Data Processing Agreement

Last updated: September 24, 2026

This agreement applies whenever you use AuditHQ to audit a site, plugin or listing. For that data you are the controller and we are the processor. It forms part of our Terms and sits alongside our Privacy Policy, which covers the separate case where we are the controller of your own account data.

1. What we process, and why

We process only what is needed to run an audit and show you the result: the URLs and repositories you ask us to scan, the HTML, headers and public files fetched from them, the findings we derive, and the tickets and comments you create from those findings.

Audited pages can themselves contain personal data — author bylines, contact addresses, staff names. Where that appears in a stored finding it is processed under this agreement as your data, not ours.

2. Our instructions

We process this data only on your documented instructions, which are the actions you take in the product and the terms of this agreement. If we believe an instruction breaches applicable data protection law we will tell you rather than act on it.

3. Confidentiality

Access is limited to personnel who need it to operate or support the service, and they are bound by confidentiality obligations.

4. What we will not do

We certify that we understand and will comply with these restrictions. You may take reasonable steps to confirm we are doing so.

5. Security

Data is encrypted in transit and at rest. Access is authenticated and scoped per project and per company role. Audits run through a guarded fetch layer that refuses private and internal network addresses. Secrets found during a scan are redacted at the point of detection, so a raw credential is never written to a stored finding.

6. Sub-processors

We use the providers below. We remain responsible for their processing. We will give notice before adding or replacing one, and you may object on reasonable data protection grounds.

ProviderPurposeLocation
VercelApplication hosting and deliveryUS / global edge
Google Cloud (Firebase)Authentication, Firestore database, report storageUS / EU
Google PageSpeed InsightsPerformance measurement of the URL you submitUS
PaddlePayments, invoicing and tax. Merchant of recordUK / EU
SentryError monitoringUS / EU
SMTP email providerAccount, digest and ticket emailPer configuration

7. International transfers

Where data leaves the UK or EEA we rely on the European Commission’s Standard Contractual Clauses, together with the UK Addendum for UK transfers. Where Brazilian law applies we rely on the ANPD’s standard clauses.

8. Personal data breach

We will notify you without undue delay, and in any case within 48 hours of becoming aware of a breach affecting your data, with the information you need to meet your own reporting deadlines. We target 48 hours because Kenya’s Data Protection Act sets the tightest processor deadline we are subject to; meeting it also clears the 72-hour regimes.

9. Assistance

Taking into account the nature of the processing, we will help you respond to data subject requests and meet your obligations on security, breach notification and impact assessments.

10. Deletion and return

You can delete a project at any time, which removes its audits, findings, tickets and stored report bodies. On termination we delete your data within 30 days unless we are required to keep it longer, and retention limits set by your plan apply in the meantime. Report bodies held in object storage are covered by the same terms as database records.

11. Audit

On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information needed to demonstrate compliance with this agreement.

12. Contact

Data protection questions, sub-processor objections and audit requests: support@audithq.app.

Need this executed as a signed document, or with your own paper? Email us and we will sign yours.