Audrey
HomeFeaturesAbout
Explore the Platform
HomeFeaturesAbout

Legal

Privacy policy

Last updated: May 2026. This policy describes how Audrey ("we", "us") handles personal information in connection with auditaudrey.com and the Audrey platform. Audrey is operated from the Republic of South Africa and complies with the Protection of Personal Information Act 4 of 2013 (POPIA). Where we serve customers in other jurisdictions, we also observe applicable local privacy law, including the EU/UK General Data Protection Regulation (GDPR) where it applies. If you are covered by a customer data processing agreement, that agreement governs processing of personal information on behalf of your organisation as a responsible party or controller.

1. Responsible party

The responsible party (as defined in POPIA) for personal information collected through this website is the Audrey operating entity registered in South Africa. For privacy enquiries or requests, contact our Information Officer at info@auditaudrey.com.

For EU/UK customers, we act as the data controller for our own business contact data and as a processor when handling personal data in your workspace on your instructions.

2. What we collect

  • Account and contract data: name, work email, organisation, role, billing contacts where applicable, and records of licences or pilots.
  • Service and assurance content: data you or your users upload or create in Audrey (for example workpapers, findings, attachments, and chat prompts tied to the workspace).
  • Technical and security logs: IP address, device and browser type, timestamps, authentication events, and diagnostic data needed to secure and operate the service.
  • Marketing and communications: preferences, demo requests, webinar sign-ups, and email engagement where you have not opted out or have given consent, as applicable.

3. Purpose of processing

We process personal information to provide and improve Audrey, authenticate users, support customers, invoice and administer contracts, detect fraud and abuse, comply with law, and—where permitted—communicate product updates or events. AI features process prompts and context you submit to return outputs to your workspace; they are not used to train unrelated public consumer models from your audit content.

4. Legal grounds

Under POPIA: we process personal information where it is necessary to perform a contract, to comply with a legal obligation, to protect a legitimate interest of the data subject, or where you have given consent. We do not process special personal information unless a specific condition of section 27 applies.

Under GDPR (where applicable): we rely on performance of a contract, legitimate interests (for example securing our infrastructure or improving the service in an aggregated way), legal obligation, or explicit consent where required.

5. Operators, processors and international transfers

We use vetted operators/subprocessors (such as cloud hosting, email, and AI model providers where enabled) under written agreements that meet POPIA section 21 requirements. Where personal information is transferred outside South Africa, we ensure the recipient country has adequate protection or that appropriate contractual safeguards are in place (section 72 of POPIA; for EU/UK data subjects, Standard Contractual Clauses or equivalent mechanisms). A current subprocessor list is available on request and referenced in customer security documentation.

6. Retention

We retain personal information only as long as necessary to fulfil the purpose for which it was collected, or as required by law. Customer workspace data is retained in line with your settings, contract, and applicable record-keeping obligations. Marketing contact data is kept until you object or unsubscribe. When retention periods expire, records are destroyed, deleted, or de-identified in accordance with POPIA section 14.

7. Security safeguards

We implement appropriate technical and organisational measures to protect personal information against loss, unauthorised access, and unlawful processing (POPIA section 19). These include access controls, encryption in transit and at rest, activity logging, and regular vendor review. In the event of a security compromise that may affect data subjects, we will notify the Information Regulator and affected parties as required by POPIA section 22.

8. Your rights

South Africa (POPIA): you have the right to request access to, correction, or deletion of your personal information; to object to processing; and to lodge a complaint with the Information Regulator (inforegulator.org.za).

EU/UK (GDPR): you may also have rights to data portability and restriction of processing, and may lodge a complaint with your local supervisory authority (e.g. the ICO in the UK).

Workspace users should contact their organisation's administrator for data held within a customer tenant. For all other requests, email info@auditaudrey.com.

9. Direct marketing

We may contact you by email about Audrey product updates or events if you are an existing customer or have given consent. You can opt out of marketing communications at any time by clicking "unsubscribe" or by emailing us. We honour opt-outs without delay, in accordance with POPIA section 69 and the Electronic Communications and Transactions Act (ECTA) where applicable.

10. Cookies and similar technologies

We use cookies and local storage for session management, preferences (such as theme), security, and analytics. You can control cookies through your browser settings; disabling strictly necessary cookies may affect sign-in functionality.

11. Children

Audrey is a business service and is not directed at children. We do not knowingly process personal information of anyone under 18 (the age of majority in South Africa) without appropriate consent. If you believe a child's data has been submitted, contact us for removal.

12. Changes to this policy

We will post updates on this page and revise the "Last updated" date. Material changes for customers may also be communicated by email or in-product notice as required by law or contract.

13. Information Regulator (South Africa)

If you are unsatisfied with our handling of your personal information, you may lodge a complaint with the Information Regulator:

  • Website: inforegulator.org.za
  • Email: complaints.IR@justice.gov.za

14. Related

See also our Terms of use.

Audrey

Product

  • About
  • Features

Resources

  • FAQ
  • Security & data
  • Platform
  • Modules
  • Workflow

Help

  • Contact
  • Request a demo
  • Log in

Apps

Mobile app launching soon

MacOS
App Store
Google Play
  • Terms & conditions
  • Privacy policy

© Audrey - Robotic Audit Platform 2024-2026 · Home · info@auditaudrey.com