AuditRailsAuditRails

Privacy Policy

Last updated: March 2026

1. Introduction

AuditRails Inc. ("AuditRails", "we", "us") is committed to protecting your privacy. This policy covers two categories of data: (a) data about you as a visitor or customer of auditrails.io, and (b) audit log data you submit through our Service as a customer.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Name and email address
  • Organization name
  • Billing information (processed by Stripe, we do not store card numbers)
  • IP address and browser information

2.2 Audit Log Data (Customer Data)

As a data processor, we receive and store audit log events submitted by your applications via our API. This data may include action names, actor identifiers, resource identifiers, and metadata you choose to include. We process this data solely to provide the Service.

2.3 Usage Data

We collect anonymized usage analytics: pages visited, features used, API call volumes. We use privacy-friendly analytics (no cross-site tracking).

3. How We Use Your Data

  • Service delivery: Process and store audit logs, power search and dashboards
  • Account management: Authentication, billing, support
  • Service improvement: Anonymized usage patterns to improve features
  • Communication: Service updates, security alerts, billing notices
  • Legal compliance: Respond to lawful requests from authorities

4. Data Processing (GDPR)

When you use AuditRails to store audit logs, we act as a data processor under GDPR. You are the data controller. Our processing activities are governed by our Data Processing Agreement (DPA), available at auditrails.io/dpa.

Legal bases for our processing:

  • Contract performance: Processing necessary to provide the Service
  • Legitimate interest: Service improvement, security, fraud prevention
  • Consent: Marketing communications (opt-in only)

5. Data Sharing

We share data only with:

  • AWS: Audit log storage and message queue (S3, SQS)
  • Stripe: Payment processing
  • MaxMind: Geo-IP lookups (IP addresses only)

We do not sell your data. We do not use your data for advertising.

6. Data Retention

  • Account data: Retained while your account is active + 30 days after deletion
  • Audit log data: Retained per your subscription plan and any compliance frameworks you have enabled, see our pricing page for current retention terms
  • Usage analytics: Retained for 12 months in anonymized form

7. Your Rights

Under GDPR and applicable privacy laws, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data (subject to retention obligations)
  • Portability: Export your data in a machine-readable format
  • Objection: Object to processing based on legitimate interest
  • Restriction: Request restricted processing

To exercise these rights, contact privacy@auditrails.io.

8. Security

We protect your data with:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • API key hashing (SHA-256, raw keys are never stored)
  • Multi-tenant data isolation at every layer
  • WORM storage (S3 Object Lock) for audit log immutability
  • Access controls and audit logging of our own systems

9. International Transfers

Data is processed in AWS US (us-east-1) by default. Enterprise customers can opt for EU-only processing (eu-west-1). International transfers are governed by EU Standard Contractual Clauses incorporated into our DPA.

10. Children

AuditRails is a B2B service not directed at individuals under 16. We do not knowingly collect personal data from children.

11. Changes

We may update this Privacy Policy with 30 days’ notice. Material changes are communicated via email to account holders.

12. Contact

Data Protection Officer: privacy@auditrails.io
AuditRails Inc., Wilmington, Delaware, USA