Legal · AudRI

Privacy Policy

How AudRI collects, processes and safeguards customer data.

Last updated · 21 April 2026

This Privacy Policy describes how AudRI ("we", "our") processes personal data when you use our SaaS platform. AudRI is a B2B service for automating GxP audits in life sciences; the bulk of data we process is regulated customer content submitted by authorised users at our enterprise customers.

1. Data we process

  • Account data: name, work email, organisation, role, authentication metadata.
  • Customer content: SOPs, URS, IQ/OQ/PQ, change controls, deviations and any documents you upload for audit.
  • Audit outputs: extracted rules, requirements, traceability matrices, findings, CAPAs and e-signatures.
  • Operational logs: IP address, user agent, audit trail of actions performed in the platform.

2. Purposes and legal basis

We process the data above to provide the service (performance of a contract), to keep it secure (legitimate interest) and to comply with legal obligations — including 21 CFR Part 11 audit-trail requirements.

3. Sub-processors

AudRI uses a limited set of sub-processors to operate the service (cloud hosting, managed database, AI inference, object storage, email delivery). {{TODO: insert current sub-processor list — vendor, role, region}}.

4. International transfers

{{TODO: describe transfer mechanism — Standard Contractual Clauses, UK IDTA, regional data residency options.}}

5. Retention

Customer content is retained for the duration of the subscription and deleted within 30 days of termination unless a longer period is required by law or by the customer's GxP records retention policy.

6. Security

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access control (QA Auditor, QA Manager, Admin, Observer, System Owner).
  • 21 CFR Part 11–style audit trail: every mutation is recorded with user, timestamp, and action.
  • SHA-256 integrity hashing for every uploaded document.

7. Your rights

You may request access, rectification, deletion, restriction, or portability of personal data relating to you. End-user rights are generally exercised through the Admin at your organisation; we assist our customers in fulfilling them.

8. Contact

Data Protection Officer · {{TODO: name}} · privacy@audri.app.

Questions? Email legal@audri.app.