This policy explains what personal data AuditIQ processes, why, for how long, and with whom. AuditIQ serves audit firms ("Firms"); Firms invite client personnel ("Respondents") to answer required audit inquiries through secure links. For Respondent data, the Firm (and its client) determine the purposes of processing; AuditIQ processes that data on the Firm's behalf to provide the platform.
| Category | Data | Source |
|---|---|---|
| Firm accounts | Firm name, user name, work email, password (stored as a scrypt hash — never in plain text) | Provided at signup |
| Respondents | Name, title, work email, role type | Entered by the Firm |
| Interview content | Typed answers, transcripts, AI follow-up questions and summaries, risk flags, certifications, uploaded supporting documents | Generated during interviews |
| Recordings | Audio and (where separately consented) video recordings of spoken answers, with consent records including time and user-agent | Recorded only after explicit in-interview consent |
| Usage & billing | Metered usage events (engagements, interviewer turns), invoices, payment references | Generated by use of the Service |
| Operational logs | Access and activity events (link opened, response certified, review actions), IP-derived rate-limit counters held in memory only | Generated by use of the Service |
We do not collect data for advertising, we use no third-party analytics or tracking scripts, and the only cookie we set is a strictly necessary, HttpOnly session cookie.
Interview answers are sent to Anthropic's Claude API to generate neutral follow-up questions, summaries, and risk flags. Mandated questions are asked verbatim from a fixed library; escalation of sensitive matters is enforced by deterministic server-side rules independent of the model. Anthropic processes this data as a service provider under its commercial API terms, which do not permit training on API content.
Voice and video recording occur only after the Respondent grants explicit consent in the interview (video consent is separate from audio consent), and Respondents can always type instead. Each consent decision is logged. Recording content is retained for the engagement's configured retention period (default 365 days, configurable 1–3650 days by the Firm) and then purged automatically; the certified transcript is preserved as audit evidence.
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting and delivery | All traffic to the Service |
| Neon (Postgres) | Managed database | All stored platform data, encrypted at rest |
| Anthropic | AI interviewer (Claude API) | Interview transcripts being evaluated |
| Deepgram (optional) | Server-side speech-to-text | Audio of spoken answers, when configured |
| ElevenLabs (optional) | Interviewer voice synthesis | Interviewer question text, when configured |
| Resend (optional) | Invoice email delivery | Billing contact email, invoice PDF |
Controls include TLS for all traffic, encryption at rest in the managed database, scrypt password hashing, hash-only storage of session and link tokens, strict tenant isolation enforced on every query, consent-gated recording, rate limiting, security headers, and an append-only activity log. Details: Security overview.
Firm users can access and correct their account data in-app. Respondents should direct access, correction, or deletion requests to the audit firm that invited them (the controller for their data); AuditIQ supports Firms in fulfilling such requests. Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights to access, correct, delete, or restrict processing of your personal data, and to lodge a complaint with a supervisory authority.
Material changes to this policy are announced in-app or by email before taking effect. Questions or requests: contact your AuditIQ account contact or the platform operator.