Privacy Policy
How AudRI collects, processes and safeguards customer data.
This Privacy Policy describes how AudRI ("we", "our") processes personal data when you use our SaaS platform. AudRI is a B2B service for automating GxP audits in life sciences; the bulk of data we process is regulated customer content submitted by authorised users at our enterprise customers.
1. Data we process
- Account data: name, work email, organisation, role, authentication metadata.
- Customer content: SOPs, URS, IQ/OQ/PQ, change controls, deviations and any documents you upload for audit.
- Audit outputs: extracted rules, requirements, traceability matrices, findings, CAPAs and e-signatures.
- Operational logs: IP address, user agent, audit trail of actions performed in the platform.
2. Purposes and legal basis
We process the data above to provide the service (performance of a contract), to keep it secure (legitimate interest) and to comply with legal obligations — including 21 CFR Part 11 audit-trail requirements.
3. Sub-processors
AudRI uses a limited set of sub-processors to operate the service (cloud hosting, managed database, AI inference, object storage, email delivery). {{TODO: insert current sub-processor list — vendor, role, region}}.
4. International transfers
{{TODO: describe transfer mechanism — Standard Contractual Clauses, UK IDTA, regional data residency options.}}
5. Retention
Customer content is retained for the duration of the subscription and deleted within 30 days of termination unless a longer period is required by law or by the customer's GxP records retention policy.
6. Security
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access control (QA Auditor, QA Manager, Admin, Observer, System Owner).
- 21 CFR Part 11–style audit trail: every mutation is recorded with user, timestamp, and action.
- SHA-256 integrity hashing for every uploaded document.
7. Your rights
You may request access, rectification, deletion, restriction, or portability of personal data relating to you. End-user rights are generally exercised through the Admin at your organisation; we assist our customers in fulfilling them.
8. Contact
Data Protection Officer · {{TODO: name}} · privacy@audri.app.