Back

Privacy Policy

AuditOwl · Last updated 6 October 2026

This Privacy Policy explains how AdaptifyAI Spółka z ograniczoną odpowiedzialnością (AdaptifyAI sp. z o.o.) ("AdaptifyAI", "we", "us") collects and uses personal data when you use AuditOwl. We act in accordance with the EU GDPR, and the UK GDPR where we offer services to people in the United Kingdom.

1. Who we are (data controller)

AdaptifyAI Spółka z ograniczoną odpowiedzialnością (AdaptifyAI sp. z o.o.), with its registered office at ul. Franciszka Żwirki i Stanisława Wigury 6C, 38-400 Krosno, Poland (KRS: 0001207220 · NIP: 6842685622 · REGON: 543319899), is the data controller for the account data of AuditOwl users. You can contact us about privacy at office@adaptifyaipl.com.

2. Our two roles

As a controller: for the personal data of the people who hold AuditOwl accounts (you and your colleagues).

As a processor: AuditOwl lets agencies store information about their own clients. For that client data the agency is the controller and we process it only on the agency's instructions. Agencies are responsible for having a lawful basis and, where required, a data processing agreement with us.

3. What data we collect

  • Account & identity: email address, first and last name, agency name.
  • Authentication: password (stored only as a salted BCrypt hash), Google sign-in identifier (if you use Google), two-factor secret (stored encrypted) and backup codes (hashed).
  • Security & sessions: IP address and browser user-agent recorded with each sign-in session, API key metadata. Visits and submissions on public share links also record the visitor's IP address and user-agent (abuse prevention and view counting).
  • Billing (when enabled): subscription status and identifiers held by our payment provider (Stripe). We never store card numbers.
  • Client/business data you enter: the audit and client records you create (processed on your behalf, see section 2).
  • One-time audit (no account): if you order a one-time report, we collect your email address, company name, questionnaire answers, financial figures and the generated report, all tied to a private access link.
  • Feedback: if you send feedback, we store the message, the page it was sent from, your browser user-agent and — only if you choose to give it — your email.
  • Diagnostics: when a request fails on our side, we record a technical error report — the time, which part of the service failed, the type of error, a reference code (shown to you next to the error, so you can quote it to us) and the ID of your account if you were signed in. If the app fails in your browser, it sends the same kind of report: the page address (with private links removed), the error and your browser and its version (for example “Chrome 128 · Windows”). Reports do not include form contents, passwords, documents or your IP address, and e-mail addresses, codes and links are removed from error messages before they are stored.

4. Legal bases

  • Performance of a contract — to provide your account and the service.
  • Legitimate interests — security, fraud prevention, keeping the service working (including error diagnostics) and service improvement.
  • Consent — we currently rely on this for nothing: we set no optional cookies or storage, so there is nothing to consent to (see the Cookie Policy). If that changes, we will ask first.
  • Legal obligation — to meet accounting and tax requirements for payments.

5. How we use your data — and what we never do

We use personal data only for the purposes described above. In particular:

  • We never sell your personal data.
  • Client data you enter is processed only to provide the service, on your instructions (we act as your processor) — never for our own purposes.
  • We never train AI models on your or your clients' data; our AI provider processes submitted content only to generate the requested response.
  • We do not repurpose your data for unrelated marketing or profiling.
  • AI features and automated decisions: the service uses AI to help draft audit content and to suggest a lead score. These are suggestions to a human — no decision producing legal or similarly significant effects about any person is made automatically by the service.
  • Any new purpose would require a compatible legal basis and, where needed, your consent.

6. Who we share data with (processors)

  • Hostinger (VPS hosting) — runs the server and the self-hosted database that store your data.
  • Google AI (Gemini) — when you use the AI features (opportunity scoring, business-case refinement, solution generation, report-narrative generation), the audit/client content you submit is sent to Google's Gemini API to be processed. AI prompts never include contact e-mail addresses or contact-person names. If no AI key is configured, a deterministic on-server fallback runs instead and nothing is sent to Google.
  • Google (Sign-In) — only if you choose Google sign-in, to verify your identity.
  • Stripe — payment processing and invoicing (only when billing is enabled).
  • Resend (email) — to send verification and notification emails.

We do not sell your personal data. The full, current list is on our sub-processors page.

7. International transfers

Your data is hosted in the EEA, where we are also established. Where data goes outside the EEA (our US providers: Google, Resend, Stripe), we rely on appropriate safeguards — the EU-US Data Privacy Framework and/or Standard Contractual Clauses.

8. How long we keep data

We keep account data for as long as your account is active. When you delete your account it is deactivated immediately and you lose access at once; we then permanently erase your personal data within up to 90 days (residual copies in rotating backups disappear within a further 14 days), except where we must retain certain records to meet legal obligations (e.g. tax records). One-time audits (ordered without an account) are erased automatically 90 days after creation on the same terms. Error reports (diagnostics) are deleted automatically after 30 days, and together with the rest of your data if you delete your account.

9. Your rights

You have the right to access, rectify, erase, restrict and port your personal data, and to object to certain processing. You can:

  • download your data from Settings → Your data (right of access);
  • delete your account from Settings → Delete account (right to erasure);
  • contact us at office@adaptifyaipl.com for any other request — including all requests about a one-time audit, which has no account or settings screen (write from the e-mail address you ordered with).

You also have the right to lodge a complaint with a data protection authority — our lead authority is the President of the Personal Data Protection Office (UODO) in Poland, and you may equally complain to your own local supervisory authority.

10. Changes

We may update this policy. Material changes will be reflected by the "last updated" date and, where appropriate, by asking for your consent again.

AdaptifyAI Spółka z ograniczoną odpowiedzialnością (AdaptifyAI sp. z o.o.)

ul. Franciszka Żwirki i Stanisława Wigury 6C, 38-400 Krosno, Poland

KRS: 0001207220 · NIP: 6842685622 · REGON: 543319899 · Registered by the District Court in Rzeszów, XII Commercial Division of the National Court Register · Share capital: PLN 5,000.00 · EU VAT: PL6842685622