AuditSeal

LEGAL

Privacy Policy

Last updated: August 22, 2026

Draft notice: This policy was prepared to accurately describe how AuditSeal currently handles data, but it is a draft template, not a substitute for legal advice. Before relying on it with real customers, have it reviewed by a Nigerian data protection professional — particularly regarding your own obligations as a data controller under the Nigeria Data Protection Act 2023 (DPO designation, DPIA where applicable, and NDPC compliance filing once you process data for more than 200 data subjects in a six-month period).

1. Who this policy covers

This Privacy Policy explains how AuditSeal ("AuditSeal," "we," "us") collects, uses, stores, and protects information when you use our compliance readiness assessment platform at getauditseal.com (the "Service"). It applies to account holders, the organizations they represent, and anyone whose information appears in documents submitted to the Service.

2. Information we collect

Account information: name, email address, and password (handled by our authentication provider, Supabase — we never see or store your raw password).

Organization information: your organization or consultancy name, and your role within it.

Assessment content: the policies, standard operating procedures, questionnaire answers, images, and PDF documents you submit for compliance gap analysis. This may include names, roles, and other personal data if your organization's documents contain them.

Payment information: if you subscribe to a paid plan, payment is processed directly by Paystack. We do not receive or store your card details — only the subscription status and transaction reference are recorded on our side.

Usage information: log data such as sign-in timestamps and general usage of the Service, used for security and service reliability.

3. How we use your information

We use the information above to:

  • Create and maintain your account and organization workspace
  • Run AI-assisted compliance gap analysis against the frameworks you select
  • Generate readiness reports and CAPA logs for you to download
  • Process payments and manage your subscription plan
  • Maintain the security, integrity, and reliability of the Service
  • Communicate with you about your account or the Service

We do not sell your information, and we do not use your assessment content for advertising of any kind.

4. Third parties who process your data

We rely on the following processors to operate the Service. Each only receives the data necessary for their specific function:

  • Supabase — hosts our database and handles authentication. Your account credentials, organization records, questionnaire answers, and AI-generated findings are stored here.
  • Anthropic (Claude API) — performs the AI gap analysis. Documents, images, and PDFs you upload for analysis are sent to Anthropic's API for that single request. Per Anthropic's commercial API terms, this content is not used to train their models, and is automatically deleted from their backend within 30 days of submission, except where flagged for a usage policy violation (extremely unlikely for ordinary business documents) or where required by law.
  • Paystack — processes subscription payments. We never receive your full card details; Paystack handles that directly under its own security standards.
  • Vercel — hosts the Service's application code and infrastructure.

5. What we actually store, and for how long

Uploaded documents themselves are not stored by AuditSeal. When you upload a PDF or image for gap analysis, it is sent directly to Anthropic's API for that one analysis request and is not retained afterward on our servers — only a filename and a short text preview are kept as a record that an assessment was run. The AI-generated findings (readiness scores, gap descriptions, and recommendations) are what we retain, since those are the actual deliverable of the Service.

You can request deletion of your assessment history, organization data, or account at any time by contacting us (see Section 8). Deleting an organization removes all assessments, findings, and reports associated with it.

6. Your rights under NDPR

If you are a Nigerian data subject, the Nigeria Data Protection Act 2023 gives you the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request erasure of your data, subject to legal retention requirements
  • Object to or restrict certain processing
  • Request a copy of your data in a portable format
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC)

To exercise any of these rights, contact us using the details in Section 8.

7. Data security

We rely on industry-standard practices provided by our infrastructure partners, including encrypted connections (HTTPS/TLS) for all data in transit, database-level access controls (Row Level Security) that keep each organization's data isolated from every other organization's, and password hashing handled entirely by our authentication provider. No system is completely immune to risk, and we encourage you not to submit documents containing information more sensitive than necessary for the compliance assessment itself.

8. Contact us

For any privacy question, data request, or concern, contact us at privacy@getauditseal.com.

9. Changes to this policy

We may update this policy as the Service evolves. Material changes will be reflected by updating the "Last updated" date above.

← Back to AuditSeal