AuditOwl · Last updated 29 July 2026
Version 1.0 · Effective 29 July 2026 · This DPA forms an integral part of the AuditOwl Terms of Service.
By creating a workspace and accepting the Terms of Service, the agency ("Controller") and AdaptifyAI Spółka z ograniczoną odpowiedzialnością (AdaptifyAI sp. z o.o.) ("Processor") conclude this DPA in electronic form. The date of account creation is the date of conclusion.
For personal data of the Controller's own clients, leads and their contacts entered into or collected through AuditOwl, the Controller determines the purposes and means of processing and the Processor processes that data solely to provide the service.
For the life of the Controller's account; obligations survive until the data is deleted or returned.
Hosting and storing client and audit records; organising and analysing them (scoring, business cases, roadmaps); generating documents and reports, including AI-assisted generation of audit content; collecting assessment, lead and file submissions through the Controller's public links; calendar synchronisation; sending notifications; related operations. AI-assisted generation sends business content (company name, questionnaire answers, pain-point descriptions, financial figures) to the AI sub-processor; the service does not include contact e-mail addresses or contact-person names in AI prompts.
The Processor processes the data only on the Controller's documented instructions — given through the product's features and this DPA — unless required by EU or member-state law (in which case the Processor informs the Controller before processing, where legally permitted). The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR.
Persons authorised by the Processor to process the data are bound by confidentiality obligations and process it only as needed to provide the service.
The Processor maintains measures appropriate to the risk, including: encryption in transit (HTTPS/TLS); passwords stored only as salted hashes; optional two-factor authentication; short-lived, signed access tokens; strict per-tenant (workspace) data isolation enforced on every query; authenticated service-to-service calls; least-privilege, key-based server access; nightly backups with rotation; log rotation; soft-delete with scheduled permanent purge. Details available on request (see section 12).
The Controller gives general authorisation for the sub-processors listed on our sub-processors page. The Processor: (a) imposes data-protection obligations no less protective than this DPA on each sub-processor and remains fully liable for their performance; (b) gives the Controller at least 14 days' notice of any intended addition or replacement (via the sub-processors page and/or e-mail); (c) if the Controller objects on reasonable data-protection grounds within 14 days of the notice and no solution is found, the Controller may terminate the affected service and the Processor will delete the data per section 13; absence of an objection within that period is deemed authorisation.
Taking into account the nature of processing, the Processor assists the Controller with data-subject requests (access, rectification, erasure, restriction, portability, objection) — primarily through the product's built-in export and deletion tools — and, insofar as possible, with the Controller's obligations under Articles 32–36 GDPR. If a data subject contacts the Processor directly about the Controller's data, the Processor forwards the request to the Controller within 3 business days and does not respond on the merits unless instructed.
The Controller warrants it has a lawful basis for the data it enters and is responsible for the transparency duties of Articles 13/14 GDPR towards its clients, leads and contacts (informing them that their data is processed in the Controller's tools, including AuditOwl). The Processor makes this DPA and the sub-processor list publicly available to support that duty.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably needed for the Controller's own notification duties, and cooperates on remediation.
The Processor makes available all information necessary to demonstrate compliance with Art. 28. Audits are satisfied first through written information, documentation and summaries of third-party attestations of the sub-processors; where an on-site inspection is legally required (e.g. by a supervisory authority), it takes place at most once per year, on at least 14 days' notice, during business hours, under confidentiality, at the Controller's cost.
On termination of the account, or earlier on the Controller's instruction (in-product deletion), the Processor deletes the personal data: soft-delete immediately, permanent purge within 90 days (residual copies in rotating backups disappear within a further 14 days), unless EU or member-state law requires longer retention (e.g. accounting records). Return of the data in a structured, commonly used format is available at any time before termination through the product's built-in export — the Controller should export before deleting the account.
Personal data is hosted in the EEA. Transfers to sub-processors outside the EEA (USA: Google, Resend, Stripe) rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses, as published by each sub-processor.
Liability under this DPA follows the limitations of the Terms of Service. This DPA is governed by Polish law; disputes follow the Terms' venue.
Data-protection queries: supportauditai@gmail.com.