AuditFlow

Privacy Policy

Last updated: August 2026

1. Introduction

AuditFlow is the trade name of Phoenix Cyber Audit, a business registered in the Netherlands. Where Phoenix Cyber Audit determines the purposes and means of processing personal data described in this Privacy Policy, Phoenix Cyber Audit acts as the data controller.

Where Phoenix Cyber Audit processes personal data contained in Customer Content solely on behalf of a business customer and according to that customer's documented instructions, the customer acts as controller and Phoenix Cyber Audit acts as processor for that processing. The respective responsibilities for such processing are governed by the applicable Data Processing Agreement.

AuditFlow provides automated security, privacy and compliance assessment services. Privacy enquiries and data-subject requests can be sent to contact@auditflowapp.nl.

2. Information We Process

Depending on how you use AuditFlow, we may process account and authentication information, contact information, organization and website information, documents submitted for assessment, assessment results and generated reports, billing and purchase-related information, and usage, technical and security logs.

3. Purposes and Legal Bases

We process personal data only where a valid legal basis applies. Depending on the activity, this includes contract and pre-contractual steps, legitimate interests in securing and reliably operating the platform, compliance with applicable legal obligations, and consent where consent is specifically requested.

4. Uploaded Documents and Assessment Data

Documents submitted to AuditFlow are processed for the assessment requested by the user. Users should submit personal or confidential information only where they are authorized to process and disclose it.

5. Service Providers and Recipients

AuditFlow uses service providers where necessary to operate the platform, including hosting and infrastructure, authentication and database services, payment processing and business communications.

Material service providers currently include Supabase for authentication, database and platform-data services; Stripe for payment processing where a user makes a purchase; Render for backend infrastructure and application hosting; Vercel for frontend hosting and delivery; and Namecheap Private Email for business email communications. The personal data processed by each provider depends on the relevant service and processing activity. Personal data may also be disclosed where required by law or necessary to establish, exercise or defend legal claims.

6. International Processing

Some service providers may process personal data outside the Netherlands or the European Economic Area. Where applicable law requires a transfer mechanism, AuditFlow relies on an applicable adequacy decision or appropriate safeguards such as European Commission Standard Contractual Clauses, as appropriate to the relevant transfer. Information about applicable safeguards can be requested through the AuditFlow privacy contact channel.

7. Data Retention

Retention is determined by the purpose and category of the data. Account and service data is retained while needed to maintain and provide the relevant account or service and thereafter only where necessary for applicable legal, security, fraud-prevention or dispute-resolution purposes. Customer Content, assessment data and generated reports are retained while needed to provide the requested service and manage the customer relationship, subject to applicable deletion requests and legal obligations. Billing and transaction records are retained as required by applicable accounting, tax and other legal obligations. Technical, security and audit records are retained only for as long as reasonably necessary for platform security, abuse prevention, troubleshooting and incident investigation. When personal data is no longer required for an applicable purpose, it is deleted, anonymized or otherwise made unavailable, subject to legal retention requirements and applicable backup processes.

8. Providing Personal Data

Some information is necessary to create an account, provide a requested assessment, generate reports, process a purchase or respond to support. If required information is not provided, AuditFlow may be unable to provide the relevant service or complete the requested transaction. Information not necessary for a requested service is optional unless otherwise explained at collection.

9. Data Security

AuditFlow uses reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, loss and misuse. No internet-based service can guarantee absolute security.

10. Your Data Protection Rights

Where applicable under the GDPR or other data protection law, you may have rights to access, rectification, erasure, restriction of processing, data portability, objection to processing and withdrawal of consent. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

11. Exercising Your Rights

Privacy and data-subject requests may be sent to contact@auditflowapp.nl. Please provide enough information for us to understand the request and, where necessary, verify your identity. We will respond without undue delay and within the period required by applicable data protection law.

12. Complaints

If you believe your personal data has been processed in violation of applicable data protection law, you may contact us and you also have the right to lodge a complaint with a competent supervisory authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens.

13. Changes to This Policy

We may update this Privacy Policy when the service, processing activities or legal requirements change. The current version and update date will be published on this page.

14. Automated Assessment and Decision-Making

AuditFlow uses automated processing to analyse submitted information and generate security, privacy and compliance assessments, scores, findings and reports.

These outputs support user review and decision-making. AuditFlow does not use these assessment outputs to make decisions about individuals that produce legal effects or similarly significant effects on them solely through automated processing.

15. Contact

Questions concerning privacy, personal data or data-subject rights can be sent to contact@auditflowapp.nl.

HomePrivacyTermsCookiesContact