Skip to content
AuditReady
Skip to content

Privacy policy

Effective date: 1 September 2026

AuditReady (“we”, “us”, or “our”) operates the AuditReady platform, which helps organisations achieve and maintain ISO 27001 certification. This policy explains what personal information we collect, why we collect it, and how we protect it.

Information we collect

Account information

When you register, we collect your name, work email address, and a hashed password. If you set up an organisation profile, we also collect your company name and industry.

Usage data

We log which pages you visit, actions you take inside the product (such as updating a control or completing a wizard step), and the timestamps of those events. This data helps us improve the product and diagnose issues.

Content you create

Policy text, evidence notes, control decisions, and other content you enter into the platform is stored on your behalf and treated as confidential.

Messages you send us

When you use the contact form or email one of our published addresses, we receive your name, your email address and whatever you write. The contact form posts to our own servers — it is not handled by a third-party form service — and the message is delivered to our support inbox by Resend, the same provider that sends every other email described below. We keep the correspondence for as long as we need it to answer you and to have a record of the answer.

How we use your information

  • To create and manage your account and organisation workspace.

  • To deliver the AuditReady service and notify you of changes to it.

  • To send transactional emails (email verification, password reset, team invitations).

  • To answer messages you send us through the contact form or to a published address, and to investigate support requests and fix bugs.

  • To produce anonymous, aggregated product analytics that inform our roadmap.

We do not sell, rent, or share your personal information with third parties for their own marketing purposes.

Third-party processors

We share data with a small number of trusted sub-processors to run the service:

  • Our hosting provider — the application server and the database, both located in the European Union.

  • Cloudflare, Inc. — the website and app front end (Cloudflare Pages), our DNS, the TLS certificate that secures your connection, and object storage (Cloudflare R2). Two separate storage buckets: one holds the files you upload as evidence, the other holds our encrypted daily database backups, which contain everything in your account. Both buckets are created with EU jurisdiction, so both the uploads and the backups are held in the European Union. Because your connection is secured at Cloudflare's edge, Cloudflare also handles traffic between you and us while it is in transit.

  • Lemon Squeezy, a Stripe company — payment processing. We never store card details; Lemon Squeezy acts as merchant of record.

  • Resend — email delivery. This covers transactional email (verification, password reset, team invitations) and the messages you send us through the contact form, which are delivered to our support inbox.

All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security measures.

Data security

We design AuditReady around the same ISO 27001 controls we help our customers implement. Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to authorised personnel and protected by multi-factor authentication. We conduct periodic risk assessments and respond promptly to security incidents.

No method of transmission over the internet is 100% secure. If you discover a vulnerability, email security@getauditready.co — our disclosure policy is published at /.well-known/security.txt. You can also use our contact page.

Data retention

AuditReady is a one-time purchase, not a subscription, so retention is not tied to a billing status: we retain your account data for as long as your account is open. After account closure, we delete personal data within 30 days, unless we are required by law to keep it longer. Anonymised usage analytics may be retained indefinitely.

Backups are the reason that is 30 days rather than immediate. We take an encrypted backup of the whole database once a day and keep each one for 30 days, so that a failure on our side cannot cost you your work. When you delete your account or a workspace, the data goes from the live service straight away and is gone from the backups once the last one containing it passes out of that window. Backups are never used to bring back an account somebody asked us to close — only to recover the service from a failure. A small number of the most recent backups is always kept, so that a backup job that quietly stopped cannot leave us holding none.

Your rights

Depending on your location, you may have the right to access, correct, port, restrict, or delete your personal data, or to object to certain processing. To exercise any of these rights, email privacy@getauditready.co or use our contact page. We will respond within 30 days.

Cookies and marketing analytics

We distinguish between two environments: the marketing site (pages you can reach without signing in) and the product (everything behind a login).

Marketing site

The marketing site (getauditready.co and its public pages) currently runs no analytics or advertising scripts, and sets no third-party cookies. If we add any, a consent banner will appear and they will load only if you accept it. Declining means no marketing cookies are set and your visit is not tracked by any third party.

Product (logged-in app)

The product has no third-party analytics, advertising, or tracking scripts of any kind. The only cookies set inside the app are the session cookie that keeps you logged in and a CSRF token. No marketing data is collected about your use of the product.

Your choices

If a consent banner is shown, you can change your answer at any time by clearing your browser storage for this site. You can also use your browser’s cookie controls to delete or block individual cookies. Declining or removing marketing cookies has no effect on your use of the product.

Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or by a notice in the product at least 14 days before they take effect.

Questions?

If you have any questions about this privacy policy or how we handle your data, email privacy@getauditready.co or reach out via our contact page.