Article 50 transparency: enforceable 2 August 2026. High-risk moved to 2027 — this didn't. EU-facing chatbots and generative features are in scope. What applies to you →

Privacy Policy

Effective 2 August 2026 · HumanAudit Inc., Delaware C-Corporation · Data controller for humanaudit.ai

Short version. We collect the minimum needed to answer you and run the site: what you type into a form, and anonymous analytics. We do not sell data, we do not run advertising, and we do not use your engagement content to train AI models. Analytics cookies only load after you accept them.

1. Who we are

HumanAudit Inc. is a Delaware C-Corporation at 1111B S Governors Ave, STE 47918, Dover, Delaware 19904, USA. For the purposes of the UK GDPR and EU GDPR we are the data controller for personal data collected through humanaudit.ai.

Data protection contact: truth@humanaudit.ai.

2. What we collect, and why

DataWhere fromWhyLawful basis
Name, email, company, messageContact formTo answer your questionLegitimate interests (Art. 6(1)(f)) — responding to an enquiry you initiated
Email addressRegulatory Watch signupTo send the regulatory briefConsent (Art. 6(1)(a)), withdrawable at any time
Name, email, company, call notesCal.com bookingTo hold and prepare for the callSteps prior to contract (Art. 6(1)(b))
Client documentation and system detailsEngagement intakeTo produce your deliverablesContract (Art. 6(1)(b))
Pages viewed, referrer, approximate region, device typeGoogle Analytics 4To understand which pages helpConsent (Art. 6(1)(a)) — analytics load only after you accept
IP address, request logsServer and CloudflareSecurity, abuse prevention, deliveryLegitimate interests (Art. 6(1)(f))

We do not knowingly collect special category data. Please do not include health, biometric, or other sensitive personal data in a contact form. If your engagement requires it, we will agree the handling in a separate Data Processing Agreement first.

3. What we do not do

4. Who else processes your data

We use a small number of processors. Each is bound by a data processing agreement and processes only on our instructions.

ProcessorPurposeLocation
Cloudflare, Inc.CDN, security, form handling (form.humanaudit.ai)USA / global edge
Google LLC (Analytics 4)Website analytics, IP anonymisation onUSA / EU
Cal.com, Inc.Call schedulingUSA
Postmark (ActiveCampaign LLC)Transactional emailUSA
Stripe, Inc.Payment processing for toolkit purchasesUSA / EU

Where a processor is outside the UK/EEA, transfers rely on the UK IDTA, the EU Standard Contractual Clauses, or the EU–US Data Privacy Framework as applicable. A current subprocessor list is available on request, and we will give notice before adding a new one that processes client engagement data.

5. How long we keep it

DataRetention
Contact form enquiries24 months from last contact, then deleted
Regulatory Watch subscribersUntil you unsubscribe, then removed within 30 days
Engagement records and deliverables7 years, for professional and tax reasons
Analytics14 months (GA4 default), then aggregated
Server logs90 days

6. Your rights

Under the UK and EU GDPR you have the right to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. Email truth@humanaudit.ai. We respond within 30 days and do not charge a fee.

If you are in the EEA or UK you may complain to your supervisory authority. In Ireland that is the Data Protection Commission; in the UK, the Information Commissioner's Office. We would rather you told us first, but you are not required to.

California residents have rights under the CCPA/CPRA to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the right to know and delete applies and uses the same contact address.

7. Cookies

See our Cookie Notice for the full list. In summary: no cookies load until you choose. Essential cookies remember your cookie choice. Analytics cookies load only if you accept them, and you can change your mind at any time.

8. Security

The site is served over HTTPS with HSTS. Form submissions are transmitted over TLS to a Cloudflare Worker. Access to engagement data is limited to the founder and the named specialists assigned to your engagement, who are under written confidentiality obligations.

We are not certified to ISO/IEC 27001 and do not claim to be. If your procurement process requires that of a supplier, tell us on the call rather than after.

9. Changes

Material changes are announced on this page with a revised effective date. We do not apply material changes retroactively to data already collected without telling you.