Privacy policy
Effective date: 1 September 2026AuditReady (“we”, “us”, or “our”) operates the AuditReady platform, which helps organisations achieve and maintain ISO 27001 certification. This policy explains what personal information we collect, why we collect it, and how we protect it.
Information we collect
Account information
When you register, we collect your name, work email address, and a hashed password. If you set up an organisation profile, we also collect your company name and industry.
Usage data
We log which pages you visit, actions you take inside the product (such as updating a control or completing a wizard step), and the timestamps of those events. This data helps us improve the product and diagnose issues.
Content you create
Policy text, evidence notes, control decisions, and other content you enter into the platform is stored on your behalf and treated as confidential.
Messages you send us
When you use the contact form or email one of our published addresses, we receive your name, your email address and whatever you write. The contact form posts to our own servers — it is not handled by a third-party form service — and the message is delivered to our support inbox by Resend, the same provider that sends every other email described below. We keep the correspondence for as long as we need it to answer you and to have a record of the answer.
How we use your information
To create and manage your account and organisation workspace.
To deliver the AuditReady service and notify you of changes to it.
To send transactional emails (email verification, password reset, team invitations).
To answer messages you send us through the contact form or to a published address, and to investigate support requests and fix bugs.
To produce anonymous, aggregated product analytics that inform our roadmap.
We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
Third-party processors
We share data with a small number of trusted sub-processors to run the service:
Our hosting provider — the application server and the database, both located in the European Union.
Cloudflare, Inc. — the website and app front end (Cloudflare Pages), our DNS, the TLS certificate that secures your connection, and object storage (Cloudflare R2). Two separate storage buckets: one holds the files you upload as evidence, the other holds our encrypted daily database backups, which contain everything in your account. Both buckets are created with EU jurisdiction, so both the uploads and the backups are held in the European Union. Because your connection is secured at Cloudflare's edge, Cloudflare also handles traffic between you and us while it is in transit.
Lemon Squeezy, a Stripe company — payment processing. We never store card details; Lemon Squeezy acts as merchant of record.
Resend — email delivery. This covers transactional email (verification, password reset, team invitations) and the messages you send us through the contact form, which are delivered to our support inbox.
All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security measures.
Data security
We design AuditReady around the same ISO 27001 controls we help our customers implement. Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to authorised personnel and protected by multi-factor authentication. We conduct periodic risk assessments and respond promptly to security incidents.
No method of transmission over the internet is 100% secure. If you discover a vulnerability, email security@getauditready.co — our disclosure policy is published at /.well-known/security.txt. You can also use our contact page.
Data retention
AuditReady is a one-time purchase, not a subscription, so retention is not tied to a billing status: we retain your account data for as long as your account is open. After account closure, we delete personal data within 30 days, unless we are required by law to keep it longer. Anonymised usage analytics may be retained indefinitely.
Backups are the reason that is 30 days rather than immediate. We take an encrypted backup of the whole database once a day and keep each one for 30 days, so that a failure on our side cannot cost you your work. When you delete your account or a workspace, the data goes from the live service straight away and is gone from the backups once the last one containing it passes out of that window. Backups are never used to bring back an account somebody asked us to close — only to recover the service from a failure. A small number of the most recent backups is always kept, so that a backup job that quietly stopped cannot leave us holding none.
Your rights
Depending on your location, you may have the right to access, correct, port, restrict, or delete your personal data, or to object to certain processing. To exercise any of these rights, email privacy@getauditready.co or use our contact page. We will respond within 30 days.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or by a notice in the product at least 14 days before they take effect.
Questions?
If you have any questions about this privacy policy or how we handle your data, email privacy@getauditready.co or reach out via our contact page.