Privacy Notice
Effective 1 January 2026
1. Scope
This notice describes how Aiudit Systems International processes personal data across the Aiudit governance platform, including telemetry ingested from customer-integrated agents, evidence packages, and rights-portal submissions.
2. Categories of data
Account identifiers, workspace membership, audit-log actor metadata, integration credentials (encrypted), and end-user submissions received through the public rights portal. We do not sell personal data.
3. Lawful basis
Processing is grounded in contract performance with enterprise customers, our legitimate interest in maintaining platform integrity, and — for rights-portal intake — the data subject's request.
4. Retention
Operational logs are retained for 400 days. Sealed evidence packages inherit the retention class of the originating workspace policy. Rights-portal records are retained for 24 months unless a longer statutory period applies.
5. International transfers
Aiudit operates regional deployments (US, EU, sovereign). Cross-region transfer is disabled by default and requires an explicit workspace administrator authorization backed by an audit-logged approval.
6. Rights
Data subjects may submit access, rectification, deletion, and portability requests through the Rights portal. Verified requests are acknowledged within 5 business days and completed within statutory timelines.
7. Contact
Data Protection Officer — privacy@aiudit.example. Requests routed to this address are triaged into the governed intake pipeline.