0. The one thing to read first
Auditee wears two hats, and the rules are different under each.
| We are | Whose data | Governed by | |
|---|---|---|---|
| Website visitors, prospects, people who register an organization, billing and support contacts | Controller | Data we decide to collect | This Policy |
| Everything inside a customer's Organization: users, audit answers, scores, tasks, evidence files, poll answers, history | Processor | The customer's data, about the customer's own people | The customer's own privacy notice, plus our DPA |
If you fill in an audit at work, your employer is the controller, not Effiware. Ask them what they do with the results. This Policy tells you what we do on their behalf, and what we do in our own right.
PART I — PERSONAL DATA
1. Controller
1.1. The controller of personal data processed in the situations listed in the first row of the table above is Effiware Andrzej Ratajski, a sole proprietorship entered in the Central Registration and Information on Business (CEIDG), place of business ul. Wrocławska 69, 63-200 Jarocin, Poland, REGON 520168139, NIP PL6172221670, e-mail contact@auditee.com ("Effiware", "we").
1.2. Contact on any data protection matter: privacy@auditee.com
1.2a. Effiware has not appointed a Data Protection Officer. Data protection matters are handled by the controller directly at the address in clause 1.2. Each Customer additionally receives a named contact at Effiware once its organization is registered.
1.3. Terms capitalised but not defined here have the meaning given in the Terms of Service.
2. Where Effiware is a processor, not a controller
2.1. When a customer organization uses Auditee, that organization decides what audits to run, what questions to ask, who is assigned, what evidence to require and how long the record is kept. It is the controller. Effiware processes that data only on its documented instructions, under a data processing agreement concluded pursuant to Art. 28 GDPR.
2.2. This means that if you are a user inside a customer's Organization and you want to exercise your rights — access, rectification, erasure, objection — you should address your organization. If you contact us instead, we will forward your request to them and tell you we have done so; we are not permitted to act on our own initiative on their data.
2.3. Our sub-processors, the security measures we apply, our breach-notification duties and what happens to the data at the end of the contract are set out in the DPA, https://auditee.com/dpa.
3. What we process as controller, why, and on what basis
3.1. Website visitors
We run the public website with no cookies, no analytics, no advertising and no third-party requests. Fonts are served from our own servers. The only thing stored in your browser is your language choice, kept in localStorage under the key auditee.lang, which never leaves your device and is not a cookie.
Our web server writes one log line per request containing the time, method, path, query string, status, size, duration, referrer and user agent. The log line contains no IP address and no user identifier. The reverse proxy in front of the site does record the client IP address, for 14 days, for security purposes. Legal basis: our legitimate interest in operating and securing the site (Art. 6(1)(f) GDPR).
3.2. People who contact us
Data: name, e-mail address, organization, and whatever the message contains. Purpose: answering the enquiry, handling a complaint, security reports. Basis: Art. 6(1)(f) GDPR (our and your legitimate interest in dealing with the matter), or Art. 6(1)(b) where the contact is a step towards a contract.
3.3. Registration of an organization and administration of the contract
Data: the registering person's first and last name and e-mail address; the organization's name, address and registration/tax numbers; billing contact details. Purposes and bases: performance of the contract (Art. 6(1)(b)); our legal obligations, in particular tax and accounting (Art. 6(1)(c)); establishing or defending claims (Art. 6(1)(f)).
3.4. Service e-mails
Invitations, alerts, reminders, task notifications and similar transactional messages are sent on behalf of the customer organization, so they fall under Part I §2 above (we are the processor). Messages about the contract itself — invoices, service notices, security advisories — are ours, on the basis of Art. 6(1)(b) and (c) GDPR.
3.5. Marketing
We send commercial e-mail only to people who have consented to it. Consent is given separately from the contract, when an organization is registered, and is recorded in the registration service. It is never bundled with acceptance of the Terms and never required in order to use Auditee.
Data: e-mail address, first and last name, organization. Basis: your consent (Art. 6(1)(a) GDPR), together with Art. 10 of the Polish Act of 18 July 2002 on the provision of services by electronic means and Art. 398 of the Polish Electronic Communications Law. You may withdraw consent at any time — through the unsubscribe link in every message or by writing to us — without affecting the lawfulness of processing carried out before withdrawal.
3.6. What we do not do
- We do not sell personal data.
- We do not profile visitors or users, and we take no decisions about anyone by automated means within the meaning of Art. 22 GDPR. The conditional rules in the application are configured and run by the customer, on their own data, and produce corrective tasks — not decisions by us.
- We do not train artificial-intelligence models on personal data. On the silver and gold plans we may train them on data anonymised and pooled across many organizations so that it identifies neither a person nor an organization; this excludes free-text answers, evidence files and poll answers, and an organization can object. On the platinum and uranium plans we do not do this at all.
4. Recipients and sub-processors
4.1. We use service providers who process data on our behalf, under written contracts. All of them process that data within the European Union. One — our hosting provider, DigitalOcean — is incorporated in the United States and operates the EU region our infrastructure runs in; clause 4.3 explains what follows. The categories are:
| Purpose | Location |
|---|---|
| Hosting and object storage (DigitalOcean) | Frankfurt (FRA1); provider incorporated in the US |
| Transactional e-mail delivery (Vercom S.A., EmailLabs) | Poland |
DigitalOcean and Vercom (EmailLabs) are our only external vendors for the service itself; support runs on e-mail and telemetry is self-hosted. The full list, with legal entities and places of processing, is in Annex A of the DPA, https://auditee.com/dpa, and Customers are notified before a sub-processor is added or replaced.
4.1a. Uranium deployments are different. They run on the Customer's own infrastructure, in a location the Customer chooses, which may be outside the EU. In that case Effiware neither hosts nor processes the data, the Customer is the sole controller, and this Policy does not apply to that installation.
4.2. We may also disclose data to public authorities where a law or a decision of a competent authority requires it. We examine every such request before responding.
4.2a. Payments. Subscriptions are paid through Stripe. Payment details are entered directly with Stripe and Effiware never receives or stores payment card numbers. For the payment data it collects, Stripe acts as an independent controller — for its own fraud prevention and anti-money-laundering obligations — and its own privacy policy applies to that processing. We receive from Stripe only what we need to issue invoices and confirm that a subscription is paid. Stripe's own privacy notice describes where it processes payment data and on what transfer basis, and applies to that processing.
4.3. Where your data is. Audit content, evidence files, accounts and e-mail are stored and processed within the European Union. Four points in detail:
- Our hosting provider, DigitalOcean, is a US company running our servers in Frankfurt. Your data sits in Germany. Where DigitalOcean personnel outside the EEA access that infrastructure for support or maintenance, that is a transfer, made under the standard contractual clauses in DigitalOcean's data processing agreement. A provider with a US parent may in principle face disclosure orders under US law wherever the data is stored.
- Our outbound e-mail is sent by Vercom S.A., a Polish company based in Poznań, through its EmailLabs service, processing in Poland.
- Payments. Our payment operator is Stripe Payments Europe Limited, established in Ireland. Stripe decides where and how it processes the payment data it collects, as an independent controller, and its privacy notice governs that. The data concerned is billing data only: it does not touch audit answers, tasks, evidence or poll data.
- Uranium. See clause 4.1a — the Customer chooses where its own installation runs.
5. Retention
| Data | Retained |
|---|---|
| Enquiries and correspondence | 14 days after the matter is closed, then deleted |
| Contract, invoices, accounting records | 5 years from the end of the tax year, per Polish tax law |
| Trial organizations not converted to a subscription | 30 days after the trial ends, then deleted, with a reminder e-mail before |
| Account and organization data | For the term of the contract, then 30 days for export, then the organization and all its data are deleted. On suspension for non-payment: 12 months after suspension, with 14 days' notice |
| Customer Data inside an Organization | Per the customer's instruction and the DPA; export available for 30 days after the contract ends |
| Marketing consent and withdrawal records | Until consent is withdrawn, then kept as evidence of the withdrawal for 3 years |
| Server logs, including reverse-proxy logs with IP addresses | 14 days; on platinum the individual contract may set a longer period |
| Backups | 14 days, point-in-time, after which they roll off |
5.1. Deletion from production systems does not delete data from backups immediately. Deleted data may persist in backups for up to 14 days. Backups are not restored selectively to recover deleted data.
5.2. Audit records are designed to survive erasure. The application keeps versioned history of organizations, teams, audits, answers, tasks, assignments and evidence, written in the same transaction as the change. Those rows are built to stay interpretable after a person has been erased, which is what lets an erasure request coexist with keeping a defensible audit trail. Evidence that a reviewer may have judged keeps its stored file even when the live record is removed.
5.3. What erasure reaches depends on the plan. On silver and gold, erasure removes or pseudonymises identifying attributes in structured fields; free-text answers, photographs, signatures and uploaded documents are retained as entered and may still identify someone. Platinum organizations have their own database and identity realm, so targeted hard deletion — including free text and evidence files — is available on written request under the individual contract. On uranium the customer performs deletion itself. This is set out in full in §9 of the DPA.
6. Your rights
6.1. You have the right to: access your data; rectify it; erase it; restrict processing; object to processing based on legitimate interest; and data portability. Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of what was done before.
6.2. These rights are not absolute. We may lawfully refuse a request in some situations — for example where we must keep the data to establish or defend claims, or to meet a legal obligation. You will always be told why.
6.3. Right to object: you may object at any time to processing based on our legitimate interest, on grounds relating to your particular situation. We may continue only if we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or grounds for establishing or defending claims.
6.4. To exercise a right, write to privacy@auditee.com. If your data sits inside a customer's Organization, see §2.2 — the request belongs with your organization.
6.5. You may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.
7. Anonymity inside the product, stated precisely
We state this here as well as in the product because it changes what a customer must tell its own people.
7.1. Anonymous audits are anonymous at display level. The submitter's identity is stored and hidden on every read surface. No one — not the organization's administrators, not Effiware — can drill into a single anonymous submission. Alert e-mails, reminders, identity-carrying exports and per-person analytics are unavailable on an anonymous audit. Someone with direct database access could re-identify a submitter: on silver and gold that is Effiware's authorised personnel, on platinum and uranium also the customer's own administrators. Polls are different: nothing identifying is stored, so no level of database access reveals a respondent. We do not claim that we fail to record who answered. Results stay withheld until distinct submitters reach the greater of 5 and 20% of those assigned.
7.2. Polls are anonymous at storage level. No user identifier, name, e-mail address or IP address is stored with a poll answer. Access codes are 32 cryptographically random characters and only a one-way hash is kept, so we cannot reconstruct a code. The join link carries the code after the #, which browsers never transmit, so it cannot appear in access logs, traces or proxy records. When you submit, and at the latest when the poll closes, the link between your code and your answers is removed in the same transaction. The export carries no respondent axis at all and rows are shuffled. Once a response is submitted, or the poll closes, no one can link a poll answer to a person: not your organization, not Effiware, not an authority. Until then the code is joined to the draft so you can resume it, and an invitation may still sit in our outbound mail queue for up to 3 days (see 7.3). That is the only window in which a link exists, and after it the mail queue can show that a code was sent to an address, never what was answered with it.
7.3. Where poll invitations are sent by e-mail, the outbound mail queue briefly holds an address next to a link. Those rows are pruned within 3 days and the code table never stores a recipient.
8. Security
8.1. Sign-in is OAuth2 / OpenID Connect against an identity provider operated by Effiware. The Application never handles your password, and the identity provider stores only a salted hash of it. Sessions are server-side and short-lived. Every record and file is scoped to its organization, files are served only after a permission check, uploads are validated and user-written content is sanitised before display.
8.2. Data is encrypted in transit and at rest by the hosting platform.
8.3. We are undergoing certification of our information-security practices; until it is complete we hold no security or compliance certificate and publish no penetration test. We describe our practices at https://auditee.com/security and answer security questionnaires directly.
8.4. On the silver and gold plans, separation between organizations is logical, not physical: one database and one identity realm, with every row scoped to its organization. Platinum and uranium have their own database and identity realm.
PART II — COOKIES AND SIMILAR TECHNOLOGIES
9. The website
9.1. https://auditee.com sets no cookies. It loads no analytics, no advertising tags, no social plugins and no third-party fonts or scripts. It makes no request to any third party.
9.2. The site stores one value in your browser's localStorage: your chosen interface language, under the key auditee.lang. It is not a cookie, it is never transmitted to us, and clearing your browser data removes it.
9.3. Because we set no cookies and run no tracking on the website, no cookie banner is displayed and no consent is collected. If that ever changes, this section changes with it and consent is collected before anything is set.
10. The application
10.1. The application at https://app.auditee.com uses strictly necessary cookies only, to keep you signed in and to protect the session. None of them lasts longer than 24 hours. Platinum instances run on their own domain with the same cookies. They cannot be switched off without breaking sign-in, and no consent is required for them under Art. 173(3) of the Polish Electronic Communications Law / the ePrivacy Directive.
| Cookie | Set by | Purpose | Duration |
|---|---|---|---|
auditee-app-v1-session | Application | Session | ≤ 24 h |
AUTH_SESSION_ID | Identity provider | Authentication | ≤ 24 h |
KEYCLOAK_SESSION | Identity provider | Single sign-on | ≤ 24 h |
10.2. The application uses no analytical, marketing, advertising or social-media cookies.
10.3. You can block or delete cookies in your browser settings, but sign-in will not work without the necessary ones. Instructions are published by each browser vendor: Firefox, Chrome, Edge, Safari.
11. Changes to this Policy
11.1. We may amend this Policy. The current version is always published at https://auditee.com/privacy, with its effective date. Material changes are notified to customers by e-mail and in the application before they take effect.
11.2. Previous versions are kept at https://auditee.com/legal/.
11.3. This Policy is drawn up in Polish and published together with translations into English, Czech, German, Spanish, French and Portuguese. In case of discrepancy, the Polish version prevails, as under clause 18.3 of the Terms of Service.