Back

Privacy Policy

AuditOwl · Last updated 29 July 2026

This Privacy Policy explains how AdaptifyAI Spółka z ograniczoną odpowiedzialnością (AdaptifyAI sp. z o.o.) ("AdaptifyAI", "we", "us") collects and uses personal data when you use AuditOwl. We act in accordance with the European Union (GDPR & ePrivacy).

1. Who we are (data controller)

AdaptifyAI Spółka z ograniczoną odpowiedzialnością (AdaptifyAI sp. z o.o.), with its registered office at ul. Franciszka Żwirki i Stanisława Wigury 6C, 38-400 Krosno, Poland (Tax ID (NIP): 6842685622 · REGON: 543319899), is the data controller for the account data of AuditOwl users. You can contact us about privacy at supportauditai@gmail.com.

2. Our two roles

As a controller: for the personal data of the people who hold AuditOwl accounts (you and your colleagues).

As a processor: AuditOwl lets agencies store information about their own clients. For that client data the agency is the controller and we process it only on the agency's instructions. Agencies are responsible for having a lawful basis and, where required, a data processing agreement with us.

3. What data we collect

  • Account & identity: email address, first and last name, agency name.
  • Authentication: password (stored only as a salted BCrypt hash), Google sign-in identifier (if you use Google), two-factor secret (stored encrypted) and backup codes (hashed).
  • Security & sessions: IP address and browser user-agent recorded with each sign-in session, API key metadata. Visits and submissions on public share links also record the visitor's IP address and user-agent (abuse prevention and view counting).
  • Billing (when enabled): subscription status and identifiers held by our payment provider (Stripe). We never store card numbers.
  • Client/business data you enter: the audit and client records you create (processed on your behalf, see section 2).
  • One-time audit (no account): if you order a one-time report, we collect your email address, company name, questionnaire answers, financial figures and the generated report, all tied to a private access link.
  • Feedback: if you send feedback, we store the message, the page it was sent from, your browser user-agent and — only if you choose to give it — your email.

4. Legal bases

  • Performance of a contract — to provide your account and the service.
  • Legitimate interests — security, fraud prevention and service improvement.
  • Consent — for any optional cookies/storage (see the Cookie Policy).
  • Legal obligation — to meet accounting and tax requirements for payments.

5. How we use your data — and what we never do

We use personal data only for the purposes described above. In particular:

  • We never sell your personal data.
  • Client data you enter is processed only to provide the service, on your instructions (we act as your processor) — never for our own purposes.
  • We never train AI models on your or your clients' data; our AI provider processes submitted content only to generate the requested response.
  • We do not repurpose your data for unrelated marketing or profiling.
  • AI features and automated decisions: the service uses AI to help draft audit content and to suggest a lead score. These are suggestions to a human — no decision producing legal or similarly significant effects about any person is made automatically by the service.
  • Any new purpose would require a compatible legal basis and, where needed, your consent.

6. Who we share data with (processors)

  • Hostinger (VPS hosting) — runs the server and the self-hosted database that store your data.
  • Google AI (Gemini) — when you use the AI features (opportunity scoring, business-case refinement, solution generation, report-narrative generation), the audit/client content you submit is sent to Google's Gemini API to be processed. AI prompts never include contact e-mail addresses or contact-person names. If no AI key is configured, a deterministic on-server fallback runs instead and nothing is sent to Google.
  • Google (Sign-In) — only if you choose Google sign-in, to verify your identity.
  • Stripe — payment processing and invoicing (only when billing is enabled).
  • Resend (email) — to send verification and notification emails.

We do not sell your personal data. The full, current list is on our sub-processors page.

7. International transfers

Where data is transferred outside the EEA (our US providers: Google, Resend, Stripe), we rely on appropriate safeguards — the EU-US Data Privacy Framework and/or Standard Contractual Clauses.

8. How long we keep data

We keep account data for as long as your account is active. When you delete your account it is deactivated immediately and you lose access at once; we then permanently erase your personal data within up to 90 days (residual copies in rotating backups disappear within a further 14 days), except where we must retain certain records to meet legal obligations (e.g. tax records). One-time audits (ordered without an account) are erased automatically 90 days after creation on the same terms.

9. Your rights

You have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. You can:

  • download your data from Settings → Your data (right of access);
  • delete your account from Settings → Delete account (right to erasure);
  • contact us at supportauditai@gmail.com for any other request — including all requests about a one-time audit, which has no account or settings screen (write from the e-mail address you ordered with).

You also have the right to lodge a complaint with a data protection authority — our lead authority is the President of the Personal Data Protection Office (UODO) in Poland, and you may equally complain to your own local supervisory authority.

10. Changes

We may update this policy. Material changes will be reflected by the "last updated" date and, where appropriate, by asking for your consent again.