1. Parties and roles
1.1. This Agreement is concluded between:
- the Customer within the meaning of the Terms of Service, on whose behalf the Organization was created, acting as controller; and
- Effiware Andrzej Ratajski, a sole proprietorship entered in CEIDG, ul. Wrocławska 69, 63-200 Jarocin, Poland, REGON 520168139, NIP PL6172221670, acting as processor ("Effiware").
1.2. The Customer determines the purposes and means of processing personal data in its Organization: which audits run, what questions are asked, who is assigned, what evidence is required and how long the record is kept. Effiware processes that data only on the Customer's documented instructions.
1.3. This Agreement forms part of the Terms of Service and applies for as long as Effiware processes personal data on the Customer's behalf.
1.4. Uranium deployments are outside this Agreement. They run on the Customer's own infrastructure, which the Customer operates; Effiware neither hosts nor processes the data. Where Effiware is granted access to a running uranium installation for support, §12 applies.
1.5. Payments are outside this Agreement. Subscriptions are paid through Stripe, which acts as an independent controller for the payment data it collects, under its own privacy policy. Stripe is not a sub-processor of Effiware, and Effiware never receives payment card numbers.
2. Subject matter, nature, purpose and duration
| Subject matter | Provision of the Auditee audit management service in a SaaS model. |
| Nature of processing | Collection, recording, organization, storage, retrieval, display, transmission by e-mail notification, export where the Plan allows it, erasure or restriction as set out in §9, and, on the silver and gold plans, anonymisation to produce Derived Data (Terms clause 8.6a). |
| Purpose | Enabling the Customer to run audits and remediation tasks in its Organization. Processing for no other purpose, save the anonymisation described in clause 2.1. |
| Duration | The term of the Terms of Service, plus the periods in §9. |
2.1. Derived Data. On the silver and gold plans the Customer authorises Effiware to anonymise Customer Data in order to produce Derived Data under clause 8.6a of the Terms of Service. Derived Data is not personal data; §9 and the return-and-deletion obligation do not apply to it. The Customer may object to that operation as described in clause 8.6a of the Terms.
3. Categories of data subjects and personal data
3.1. Data subjects: the Customer's employees, contractors and other people it invites into its Organization in the roles of org admin, auditor, reviewer and auditee; and external participants who open a poll with a one-time access code.
3.2. Categories of personal data, as far as the Application's design determines them:
- Account and identity: first and last name, e-mail address, interface language, role and team membership, organization affiliation. Passwords are held by the identity provider only as salted hashes, never by the Application; authentication is OAuth2 / OpenID Connect.
- Activity: audit assignments, submitted answers, scores and pass/fail results, task ownership, deadlines, approvals and status changes, and the versioned history of all of these.
- Content supplied by the Customer's people: free-text answers, photographs captured in the application, handwritten signatures, uploaded documents and other evidence.
- Notification data: the e-mail addresses to which alerts, reminders and invitations are sent.
3.3. Poll answers contain no identifier of any kind — no user ID, name, e-mail address or IP address. See §7.4.
3.4. Users in the auditee role need no e-mail address. This affects how a data subject request is authenticated; see §7.3.
4. The Customer's obligations
4.1. The Customer warrants that it has a lawful basis for the processing it instructs, that it has satisfied its own information obligations towards the data subjects, and that its instructions do not infringe the GDPR or other applicable data protection law.
4.2. The Customer is responsible for the content of its audits, including whether they elicit special categories of data, and for having a condition under Art. 9(2) GDPR where they do. Clause 10.2a of the Terms of Service lists the data the Customer undertakes not to enter, and clause 10.2b records what the Customer must tell its people about the limits of erasure on the silver and gold plans.
4.3. The Customer configures roles and team membership, and is responsible for granting access only to appropriately authorised people and for withdrawing it promptly.
4.4. The Customer must inform its people, before they use an anonymous audit, of what anonymity in Auditee does and does not mean — see §8. Effiware publishes that account at https://auditee.com/anonymity in seven languages, which the Customer may reference.
5. Effiware's obligations
5.1. Instructions. Effiware processes personal data only on the Customer's documented instructions, including as to transfers, unless required otherwise by EU or Member State law; in that case Effiware informs the Customer before processing, unless the law prohibits it. The Terms of Service, this Agreement and the Customer's use of the Application's own functions constitute the Customer's documented instructions. Effiware informs the Customer if, in its opinion, an instruction infringes the GDPR.
5.1a. Requests from authorities. If Effiware receives a legally binding request from a court or public authority for disclosure of the Customer's personal data, it informs the Customer without undue delay, unless the law prohibits it, and discloses only the minimum the request lawfully requires. Effiware does not disclose the Customer's personal data voluntarily.
5.2. Confidentiality. Effiware ensures that persons authorised to process the personal data are bound by confidentiality and are informed of their obligations. Access is granted on a need-to-know basis and is limited to what support and operation require.
5.3. Security. Effiware implements the technical and organizational measures described in Annex B, taking account of the state of the art, the costs of implementation and the risks to data subjects.
5.4. Sub-processors. §6.
5.5. Assistance with data subject rights. §7.
5.6. Assistance with Arts. 32–36. Taking into account the nature of processing and the information available to it, Effiware assists the Customer in ensuring compliance with the obligations on security, breach notification and communication, data protection impact assessment and prior consultation.
5.7. Personal data breach. Effiware notifies the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer's data (on platinum and uranium, within the period set in the individual contract), providing the information available to it under Art. 33(3) GDPR and supplementing it as the investigation proceeds. Effiware does not notify a supervisory authority or data subjects on the Customer's behalf unless separately instructed.
5.8. Information and audits. §11.
5.9. Deletion and return. §9.
6. Sub-processors
6.1. The Customer grants general written authorisation for Effiware to engage sub-processors. Those engaged at the date of this Agreement are listed in Annex A.
6.2. Effiware imposes on each sub-processor, by contract, data protection obligations no less protective than those in this Agreement, and remains fully liable to the Customer for their performance.
6.3. Effiware informs the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by e-mail to the address held for the Organization. The Customer may object on reasonable data-protection grounds within 14 days. If the parties cannot resolve the objection, the Customer may terminate the Terms of Service in respect of the affected services, with a pro-rata refund of Fees paid for the unused period, as its sole remedy.
6.4. All sub-processors process the personal data within the European Union. One of them, the hosting provider, is incorporated outside the EU; §10 addresses what follows from that.
7. Data subject requests
7.1. Effiware provides the Customer with the functions of the Application needed to respond to requests under Arts. 15–22 GDPR, and assists by appropriate technical and organizational measures where the Customer cannot do so through those functions.
7.2. Where a data subject addresses Effiware directly, Effiware does not respond on the substance. It forwards the request to the Customer without undue delay and informs the data subject that it has done so.
7.3. Authenticating a request from a user with no e-mail address. People in the auditee role may have no e-mail address, so a request cannot be verified against one. Identification of such a data subject is the Customer's responsibility, as the party that knows who its people are.
7.4. Polls: Art. 11 GDPR applies. A poll answer carries no identifier of any kind, and access codes exist only as a one-way hash, so neither the Customer nor Effiware can identify the person who gave a poll answer, and, once a response is submitted or the poll closes, neither can re-associate an answer with a person at the request of a data subject, the Customer or a public authority. Where the controller can demonstrate it is not in a position to identify the data subject, Arts. 15 to 20 GDPR do not apply to that data. Effiware will not acquire additional information solely to enable identification. While a participant is still filling in a poll, their code is linked to their draft answers so the session can save and resume. That link is removed, in the same database transaction, when the participant submits or when the poll closes, whichever comes first; from then on the code record says only that it was redeemed, and no column, key or identifier connects it to any answer, file or history entry. A data subject who supplies their own code can therefore be matched to their answers only while their response is in progress, and Arts. 15 to 20 apply to that extent and for that period only. Any such request is handled as an additional instruction under Annex C.
7.5. Anonymous audits. The submitter's identity is stored but is not accessible through any read surface in the Application, to anyone, including the Customer's org admins and Effiware. A request concerning an individual anonymous submission therefore cannot be satisfied through the product. §8 describes what is and is not possible.
8. Anonymity, stated precisely
The two mechanisms are not equally strong, and the difference changes what the Customer must tell its people and what either party can do in response to a request.
8.1. Anonymous audits are anonymous at display level. The identity of the submitter is recorded and retained; it is hidden on every read surface. There is no per-submission drill-in for anyone. Alert e-mails, reminders, identity-carrying exports and per-person analytics are structurally unavailable on an anonymous audit. Results are withheld until distinct submitters reach the greater of 5 and 20% of the people assigned. Anyone with direct database access could re-identify a submitter: on silver and gold that is Effiware's authorised personnel, on platinum and uranium also the Customer's own administrators, which is why Annex B restricts who has such access. Polls are different: nothing identifying is stored, so no level of database access reveals a respondent. Effiware does not claim that it fails to record who answered.
8.2. Anonymity is chosen before publication and frozen at publication; it cannot be switched on or off afterwards.
8.3. Polls are anonymous at storage level. No user identifier is ever stored with a poll answer. Access codes are 32 cryptographically random characters, stored only as a one-way hash. The join link carries the code after the #, which browsers never transmit, so it cannot appear in access logs, traces or proxy records. On submission, and at the latest when the poll closes, the link between a code and the answers given with it is removed in the same transaction. Exports carry no respondent axis and rows are shuffled. This addresses linkability through the code; it is not a claim that anonymity is guaranteed against every form of statistical inference.
8.4. Where poll invitations are sent by e-mail, the outbound mail queue briefly holds a recipient address next to a link. Those rows are pruned within 3 days and the code table never stores a recipient. Until they are pruned, they can show that a code was sent to an address, never what was answered with it.
9. Deletion, return and retention
Auditee is built to keep an audit trail that stays defensible; deleting a record does not remove it from that trail. This section sets out what deletion, return and erasure do on each plan.
9.1. Export. For 30 days after the Terms of Service end, Effiware makes the Customer's data available for export on written request — including for Customers on the silver plan, whose plan otherwise has no export capability.
9.2. Deletion at the end of the relationship. Where the Customer terminates or the Agreement otherwise ends, Effiware deletes the Organization and the personal data in it 30 days after the Agreement ends, once the export period has closed. Where the relationship ends through suspension for non-payment, deletion instead occurs 12 months after suspension, and Effiware gives the Customer at least 14 days' notice by e-mail beforehand. Payment of the outstanding Fees before the date stated in that notice restores access, and the Organization is not deleted. A trial Organization that never purchases a Subscription is deleted 30 days after the trial ends, after a reminder by e-mail. Deletion covers database rows and stored files alike. Derived Data remains, in accordance with clause 2.1.
9.3. Backups. Deletion from production systems does not immediately remove data from backups. Backups are point-in-time and cover the preceding 14 days — shared across the service on silver and gold, and per-customer on platinum — so deleted data may persist in them for up to 14 days after it leaves production. Backups are not restored selectively to recover deleted data.
9.4. Erasure on silver and gold. The Application maintains versioned history tables for organizations, teams, audits, answers, tasks, assignments and evidence sets, written in the same database transaction as the change itself, and designed to remain interpretable after a person has been erased. On the Customer's instruction to erase a data subject, Effiware removes or pseudonymises that person's identifying attributes in structured fields — name, e-mail address, account and assignment references — and the underlying audit records, answers, scores and approvals are retained.
9.4a. The Customer must understand the limit of that operation. Erasure on these plans does not alter free-text answers, photographs, handwritten signatures or uploaded documents, which are retained as entered. Such content may continue to identify a person — a photograph showing them, a signature, a name typed into someone else's answer — and Effiware does not redact, blur or rewrite it. On silver and gold, hard deletion of individual records is not offered.
9.4b. The Customer accordingly instructs its people not to enter personal data, and in particular special categories of data, into free-text answers and evidence beyond what the audit requires, and accepts responsibility for that instruction. Where the Customer needs erasure to reach free-text and image content, the platinum or uranium plan is the supported route.
9.5. Erasure on platinum. A platinum Organization has its own database and identity realm, so targeted hard deletion of specified records, including free-text answers and evidence files, is technically available. Effiware performs it on the Customer's written request, on terms — scope, lead time, effect on the audit trail and any charge — set in the individual contract.
9.6. Uranium. The installation runs on the Customer's infrastructure and the Customer performs deletion itself. Effiware may assist under the individual contract and §12.
9.7. Submitted answers are not deleted as a matter of ordinary operation, on any plan. Neither the Customer nor Effiware can make an individual submission disappear from the audit trail through the Application's own functions, and evidence that a reviewer may have judged keeps its stored file even where the live record is removed, so that a delete-and-re-upload cycle cannot erase what was reviewed. On platinum and uranium this is a design default that §§9.5–9.6 can override; on silver and gold it is absolute.
9.8. The Customer acknowledges §§9.4–9.7 as consistent with its own retention determination, and accepts that the design serves the integrity of the audit record.
10. International transfers
10.1. Effiware stores and processes the Customer's personal data within the European Union. The infrastructure runs in an EU region of DigitalOcean and the outbound e-mail service is operated by a Polish company; neither routinely moves the data outside the EU.
10.1a. DigitalOcean is incorporated in the United States. Where its personnel outside the EEA access data for support or maintenance of the underlying infrastructure, that access is a transfer to a third country. It is covered by the standard contractual clauses incorporated into DigitalOcean's data processing agreement, which DigitalOcean states it relies on for transfers from the EEA to the United States (https://www.digitalocean.com/trust/gdpr-at-do). The Customer acknowledges that a provider with a US parent may in principle be subject to disclosure orders under US law, notwithstanding where the data is stored.
10.2. Where a transfer becomes necessary, Effiware will not carry it out without the Customer's prior instruction and without a transfer mechanism under Chapter V GDPR.
10.3. Stripe's transfer of payment data to its US parent is made in Stripe's own capacity as controller and is outside this Agreement — see §1.5.
11. Information, audits and inspections
11.1. Effiware makes available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.
11.2. In the first instance Effiware satisfies a request under §11.1 by providing its security documentation and a completed security questionnaire. Effiware currently holds no certificate and publishes no penetration test report, so neither can be supplied in place of an audit.
11.3. An on-site or remote inspection takes place at most once in any 12 months unless a supervisory authority requires otherwise or a personal data breach has occurred, is announced at least 30 days in advance, takes place during business hours, does not unreasonably disrupt operations, is subject to confidentiality, and does not extend to data of other customers or to the infrastructure of a sub-processor beyond what that sub-processor permits.
11.4. The Customer bears the costs of an inspection, including Effiware's reasonable time spent on it, save where the inspection reveals a material breach of this Agreement by Effiware, in which case Effiware bears them.
12. Support access to uranium installations
12.1. Where Effiware is granted access to a running uranium installation in order to provide support, it processes personal data as a processor on the Customer's behalf, and §§5, 7 and 10 of this Agreement apply to that access.
12.2. Such access is granted ad hoc by the Customer, for a defined purpose, is limited in time and is logged. Effiware does not hold standing access to a uranium installation.
13. Liability, term and law
13.1. Liability under this Agreement is subject to the limitations in §14 of the Terms of Service, save where those limitations cannot be applied as a matter of law — in particular, they do not limit a data subject's rights under Art. 82 GDPR.
13.2. This Agreement takes effect with the Terms of Service and ends when Effiware has completed its obligations under §9.
13.3. Polish law governs. Disputes are subject to §18 of the Terms of Service.
13.4. In case of conflict between this Agreement and the Terms of Service on a matter of personal data protection, this Agreement prevails.
13.5. This Agreement is drawn up in Polish and published together with an English translation. In case of discrepancy, the Polish version prevails, as under clause 18.3 of the Terms of Service.
Annex A — Sub-processors
The sub-processors that process the Customer's personal data on Effiware's behalf, listed as required by Art. 28(2) and (4) GDPR.
| Purpose | Sub-processor (legal entity) | Country of incorporation | Place of processing |
|---|---|---|---|
| Hosting and infrastructure (Kubernetes) | DigitalOcean LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, USA | United States | Frankfurt (FRA1) |
| Object storage for evidence files | DigitalOcean LLC (Spaces), address as above | United States | Frankfurt (FRA1) |
| Transactional e-mail delivery | Vercom S.A., ul. Wierzbięcice 1B, 61-569 Poznań, Poland (operating the EmailLabs service) | Poland | Poland |
| Support and technical communication | None — e-mail only | — | — |
| Error monitoring and telemetry | None — self-hosted | — | — |
These are the only external vendors. The container registry (ghcr.io) holds application images, not personal data, and is therefore not a sub-processor.
Stripe is not listed: it is an independent controller for payment data, not a sub-processor (§1.5).
Effiware has a written data processing agreement in place with each sub-processor listed above, imposing data protection obligations equivalent to those in this Agreement, as required by Art. 28(4) GDPR. DigitalOcean maintains its own sub-processor list for the infrastructure beneath ours; that chain sits below this annex and is governed by DigitalOcean's agreement rather than this one.
Annex B — Technical and organizational measures (Art. 32)
Identity and access
- Authentication by OAuth2 / OpenID Connect against an identity provider operated by Effiware. No password is ever stored by the Application. Any identity provider speaking OpenID Connect or SAML works; platinum customers can configure their own.
- Five distinct permission shapes, derived per request from the token, plus a per-resource check on every detail page and every mutation.
- Sessions held in an in-memory session store: persistence is disabled, nothing is written to disk, and a restart of the session store ends every session. The session identifier is rotated at login and tokens are refreshed server-side. No session cookie outlives 24 hours.
- No public sign-up on the realm: people join by invitation. Invitations are reusable for at most 72 hours; admin-issued sign-in links are single-use and valid for 30 minutes.
Data separation
- Every database row is scoped to its organization and every stored file key is prefixed with it.
- On silver and gold, separation between organizations is logical, not physical: one database and one identity realm. Platinum and uranium have their own database and identity realm.
Storage and content handling
- Files are served as presigned links valid for 24 hours, minted only after the permission check passes.
- Uploads are validated by inspecting the file itself, never by trusting the browser; SVG is refused everywhere.
- User-authored Markdown is rendered through CommonMark in safe mode with raw HTML dropped and an explicit allowlist applied; only
httpslinks with a real host andmailto:survive.
Logging and monitoring
- Request logs record method, path, status, size and duration. No IP address and no user identifier is written to them.
- OpenTelemetry tracing and Prometheus metrics throughout.
Resilience and integrity
- Versioned history tables written in the same transaction as the change (see §9.4).
- Background work serialised with database advisory locks, so running several application instances never doubles an e-mail or a scheduled round.
- All outbound e-mail passes through a transactional outbox with retry and deduplication.
Encryption
- Data is encrypted in transit and at rest by the hosting platform.
Backup and recovery
- Point-in-time backups covering the preceding 14 days: the state of the Application can be restored to any chosen moment within that window. On silver and gold the backups are shared across the service; on platinum they are per customer.
- Restores are tested quarterly. The recovery time for a full restore is up to 48 hours; the recovery point is any moment within the 14-day window, so a restore is not limited to a fixed snapshot interval.
Access control
- On silver and gold, administrative and database access is held by Effiware personnel only. On platinum and uranium it is shared with the Customer under the individual contract.
- Access is granted on a need-to-know basis and limited to what operation and support require. §8.1 of this Agreement depends on this restriction.
Maintenance
- The Application is actively maintained. Fixes for critical vulnerabilities are applied within 7 days of a patch being available; other updates follow the ordinary release cycle and are delivered as patch releases.
Confidentiality of personnel
- Production access is held by authorised Effiware personnel only; no third party holds it. Any contractor engaged is bound by a written confidentiality undertaking before being granted access.
Incident response
- Personal data breaches are notified to the Customer within 48 hours of Effiware becoming aware (§5.7); on platinum and uranium, within the period set in the individual contract.
What is not claimed
- No security or compliance certificate as yet; certification is in progress. No published penetration test.
Annex C — Instructions
The Customer's documented instructions comprise: the Terms of Service; this Agreement; the configuration the Customer makes in the Application; and any further written instruction given to privacy@auditee.com. Additional instructions outside the Application's functions may be subject to a charge and to technical feasibility.