A
AuditIQ
Audit inquiry platform
Terms · Security

Privacy Policy

Effective date: July 24, 2026

This policy explains what personal data AuditIQ processes, why, for how long, and with whom. AuditIQ serves audit firms ("Firms"); Firms invite client personnel ("Respondents") to answer required audit inquiries through secure links. For Respondent data, the Firm (and its client) determine the purposes of processing; AuditIQ processes that data on the Firm's behalf to provide the platform.

1. Data we process

CategoryDataSource
Firm accountsFirm name, user name, work email, password (stored as a scrypt hash — never in plain text)Provided at signup
RespondentsName, title, work email, role typeEntered by the Firm
Interview contentTyped answers, transcripts, AI follow-up questions and summaries, risk flags, certifications, uploaded supporting documentsGenerated during interviews
RecordingsAudio and (where separately consented) video recordings of spoken answers, with consent records including time and user-agentRecorded only after explicit in-interview consent
Usage & billingMetered usage events (engagements, interviewer turns), invoices, payment referencesGenerated by use of the Service
Operational logsAccess and activity events (link opened, response certified, review actions), IP-derived rate-limit counters held in memory onlyGenerated by use of the Service

We do not collect data for advertising, we use no third-party analytics or tracking scripts, and the only cookie we set is a strictly necessary, HttpOnly session cookie.

2. How we use data

  • To operate the inquiry workflow: deliver questions, evaluate answers, store evidence, and make it reviewable and exportable by the Firm.
  • To meter usage and produce invoices for the Firm.
  • To secure the Service: authentication, tenant isolation, rate limiting, audit trails.
  • We do not use Firm or Respondent data to train AI models, and we do not sell or share personal data for advertising.

3. AI processing

Interview answers are sent to Anthropic's Claude API to generate neutral follow-up questions, summaries, and risk flags. Mandated questions are asked verbatim from a fixed library; escalation of sensitive matters is enforced by deterministic server-side rules independent of the model. Anthropic processes this data as a service provider under its commercial API terms, which do not permit training on API content.

4. Recordings and consent

Voice and video recording occur only after the Respondent grants explicit consent in the interview (video consent is separate from audio consent), and Respondents can always type instead. Each consent decision is logged. Recording content is retained for the engagement's configured retention period (default 365 days, configurable 1–3650 days by the Firm) and then purged automatically; the certified transcript is preserved as audit evidence.

5. Subprocessors

SubprocessorPurposeData involved
VercelApplication hosting and deliveryAll traffic to the Service
Neon (Postgres)Managed databaseAll stored platform data, encrypted at rest
AnthropicAI interviewer (Claude API)Interview transcripts being evaluated
Deepgram (optional)Server-side speech-to-textAudio of spoken answers, when configured
ElevenLabs (optional)Interviewer voice synthesisInterviewer question text, when configured
Resend (optional)Invoice email deliveryBilling contact email, invoice PDF

6. Retention and deletion

  • Interview evidence (transcripts, certifications, documents, flags) is retained while the Firm's account is active, because it constitutes audit evidence subject to professional retention duties (typically 7 years under PCAOB rules) — deletion timing is directed by the Firm.
  • Recording content follows the per-engagement retention setting and is purged automatically.
  • Respondent links expire automatically (default 14 days) and can be revoked at any time.
  • Sessions expire after 12 hours.
  • On termination, Firm Data is deleted within 30 days of written request.

7. Security

Controls include TLS for all traffic, encryption at rest in the managed database, scrypt password hashing, hash-only storage of session and link tokens, strict tenant isolation enforced on every query, consent-gated recording, rate limiting, security headers, and an append-only activity log. Details: Security overview.

8. Your rights

Firm users can access and correct their account data in-app. Respondents should direct access, correction, or deletion requests to the audit firm that invited them (the controller for their data); AuditIQ supports Firms in fulfilling such requests. Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights to access, correct, delete, or restrict processing of your personal data, and to lodge a complaint with a supervisory authority.

9. Changes and contact

Material changes to this policy are announced in-app or by email before taking effect. Questions or requests: contact your AuditIQ account contact or the platform operator.

© 2026 AuditIQ · Terms · Privacy · Security