1. Controller
A1 Audit App, a sole proprietorship established in the Netherlands and registered under KVK 42122780 and VAT ID NL005512205B05, is the controller for website accounts, direct website commerce, device-licence administration, security and support records. General contact: info@audita1.com. Customer support: support@audita1.com. The business registration and address details can be verified through the Dutch Chamber of Commerce register using KVK 42122780.
2. Scope
This notice covers the A1 Audit website, direct Windows and macOS commerce, device licensing, support and security operations, and account services shared with the Android and iPhone/iPad applications. Apple, Google, Microsoft and Stripe may also process information under their own legal responsibilities and privacy terms.
3. Information we process
Account and identity
- Name, display name, verified email address and authentication or recovery records.
- Passkey, OTP, login, session and security-event information.
- Organisation name, registration number, VAT number, billing country, purchaser name, business role and evidence of authority or legal acceptance where applicable.
Subscription and payment
- Selected Windows or macOS plan, device quantity, price, currency, subscription period, renewal and status.
- Stripe customer, checkout, payment-method and mandate references, invoice, payment, refund, dispute and tax references.
- Legal-document versions, acceptance timestamp, organisation or owner reference and user associated with the order.
- A1 Audit does not store complete card numbers, CVC values, bank-login credentials or full bank-account numbers.
Device licence and security
- Entitlement ID, platform, app version, public-key fingerprint, device display name, activation, validation, replacement and revocation status.
- Challenge, lease and security-event hashes and timestamps needed to prevent replay, licence abuse and unauthorised activation.
- The device private key remains on the licensed device and is not intended to be transmitted to A1 Audit.
Local audit information
Audit plans, questions, answers, findings, evidence, images, OCR results, reports and related records are designed to remain locally stored on the user’s device. A1 Audit does not centrally host normal audit content unless a user deliberately exports, shares or supplies material for support.
Website, communications and support
- Contact messages, support correspondence and information voluntarily supplied for troubleshooting.
- IP address, browser, device type, access time, request identifiers, security logs and hosting diagnostics.
- Delivery status for account, payment, renewal, security and support communications once customer transactional email is enabled.
4. Purposes
- Create, verify and secure accounts and organisations.
- Process and reconcile purchases, subscriptions, invoices, refunds and automatic renewals.
- Assign, activate, validate, transfer, replace, suspend and revoke desktop-device licences.
- Prevent fraud, replay, licence sharing, abuse and unauthorised access.
- Provide support, security updates, required notices and incident response.
- Meet accounting, tax, legal, sanctions, security and dispute obligations.
- Establish, exercise or defend legal claims.
5. Legal bases
Where the GDPR applies, processing is based on performance of a contract, steps requested before entering a contract, compliance with legal obligations, legitimate interests in secure and lawful operation, and consent where consent is specifically required. Payment mandates are administered by Stripe under the applicable payment framework.
6. Providers and recipients
Current or planned providers include Cloudflare for website delivery and security; Supabase for authentication, organisations, entitlement and legal-evidence services; Stripe for checkout, subscriptions, payments, mandates, invoices, tax and Customer Portal; Apple for iOS distribution, purchases and macOS notarisation services; Google for Android distribution and purchases; Microsoft for planned Windows Store distribution; GitHub for source control and CI; and an approved transactional email provider only after separate approval, DPA/provider assessment and domain authentication.
These organisations may act as processors, independent controllers or platform operators depending on the activity. A1 Audit maintains an internal provider/subprocessor register and does not authorise a new Production provider until its purpose, role, data, region, contract, transfer safeguards, security, retention and cost have been assessed.
7. International transfers
Some providers may process information outside the European Economic Area. Where required, A1 Audit will use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism and assess supplementary protections. Provider contracts and transfer evidence are maintained as part of Production governance.
8. Retention
- Account profiles: for the active account lifetime, followed by deletion or de-identification of eligible data after verified closure.
- Organisation, membership and purchasing-authority records: while active and generally for seven years after the relationship ends where needed for contract, fraud or legal-defence evidence.
- Invoices, payments, refunds, VAT/tax and core accounting records: seven years after the relevant financial year, subject to applicable law.
- Stripe subscription, payment-method and mandate references: while needed for the subscription and generally up to seven years where linked to financial or dispute records.
- Legal acceptance evidence: for the agreement lifetime and generally seven years after it ends.
- Entitlement and device history: for the entitlement lifetime and generally seven years after termination.
- Security events and abuse-prevention logs: normally 24 months; routine access/diagnostic logs under A1 control normally 30 days unless escalated into an incident record.
- Transactional email delivery records: normally 12 months, unless the message forms part of contract, payment or legal evidence.
- Ordinary support records: normally 24 months after closure; complaints, incidents, disputes and claims generally seven years after closure.
- Privacy and deletion request evidence: normally five years after completion, while identity documents are removed earlier when no longer needed.
- Release, security and technical-file evidence: normally ten years after the relevant release or longer published support period.
- Local audit content: on the customer’s device until the customer deletes it or removes their own exports/backups.
Retention may be extended for a legal hold, active dispute, fraud/security investigation, insurer requirement or mandatory platform/provider rule. A1 Audit reviews holds periodically and removes data when the lawful purpose ends.
9. Account deletion
Account deletion may end account-linked access and remove eligible profile and activation data. It does not automatically cancel a subscription, refund a payment, erase legally required payment, contract, security or tax records, or delete local audit files. Review the Delete Account page before submitting a request.
10. Security
A1 Audit uses access controls, verified authentication, encryption in transit where applicable, least-privilege administration, environment separation, security logging and incident handling. No system can be guaranteed completely secure. Users remain responsible for device protection, authorised access, software updates and verified exports or backups.
11. Personal-data incidents
A1 Audit will investigate suspected personal-data incidents, record decisions and notify competent authorities and affected individuals where required. Customers must promptly report suspected compromise and must not send unnecessary confidential audit evidence through ordinary support channels.
12. Privacy rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection and may withdraw consent where processing relies on consent. Requests may require identity and authority verification. Contact info@audita1.com or support@audita1.com. Individuals may also complain to the competent data-protection authority.
13. Customer role and data-processing agreements
For normal locally stored audit content, A1 Audit does not ordinarily receive the data. Where a business customer deliberately supplies personal data for A1 Audit to process on documented instructions, controller/processor roles must be assessed and an Article 28 GDPR data-processing agreement used where required.
14. Children
A1 Audit is intended for professional and business use and is not directed to children.
15. Changes
Material changes will be versioned and may be communicated through the application, website, email or platform listing. A new effective date will identify the applicable version.