Version 2.0, last updated [DATE]Download as file

Privacy Policy

Last updated: [DATE]

Audit Scoot B.V., [ADDRESS], KvK [KVK] (“we”, “us”) is committed to protecting personal data. This policy is drafted under Regulation (EU) 2016/679 (GDPR); for customers and visitors in the United Kingdom, references to the GDPR include the UK GDPR.

1. The local-first model — read this first

Audit Scoot is built so that client financial data never reaches our servers. General ledger files, trial balances, and related audit datasets (“Client Audit Data”) are ingested, stored, and analysed locally on the user’s own machine. We do not receive, host, or store Client Audit Data, and we cannot access it.

What the application does transmit to us:

Data Content Why
Schema mappings Column names and standardized category labels of the dataset (no transaction records) To power the AI analysis feature
AI questions The free-text question a user types (which may incidentally contain personal data, e.g. an employee’s name) To generate the analysis specification
Licence fingerprint A one-way cryptographic hash of the dataset Licensing integrity; cannot be reversed into data
Usage records Engagement counts, feature events, timestamps Billing and product improvement

For schema mappings and AI questions we act as processor under the Data Processing Agreement (DPA) that forms part of every subscription; the customer (audit firm) is controller. For everything in §2 we act as controller.

2. Personal data we process as controller

Category Examples Source
Account data Name, business email, role, firm, hashed credentials You / your firm admin
Billing data Firm billing details, VAT number, invoices, payment status Your firm
Prospect data Name, business email, role, firm, correspondence You, your firm’s website, professional networks, business registers
Usage data Portal log-ins, application usage events, support tickets Generated by use
Website data Aggregate, cookieless analytics (see Cookie Policy) Your visit

No special categories; no automated decision-making producing legal effects.

Purpose Legal basis
Providing and administering the Service, support Contract (b)
Invoicing, accounting, fiscal retention Legal obligation (c)
B2B direct marketing to relevant professional contacts Legitimate interest (f), with opt-out in every message
Product improvement, security, abuse prevention Legitimate interest (f)
Establishment or defence of legal claims Legitimate interest (f)

You can object to legitimate-interest processing at any time (§7); every marketing email has a one-click unsubscribe.

4. Recipients and subprocessors

  • Hosting (website, licensing backend, account data): [HOSTING PROVIDER], EU data centres.
  • AI provider: Google (Google Cloud, Vertex AI), used to convert the schema mapping and user question into an analysis specification. Processing is governed by Google’s Cloud Data Processing Addendum, under which submitted data is not used to train models. Requests are routed to the Google Cloud region nearest the user; where a request is processed outside the EEA/UK, transfers rely on the EU Standard Contractual Clauses and UK Addendum incorporated in that Addendum and on Google’s EU–US Data Privacy Framework certification. Google never receives Client Audit Data.
  • Email/productivity: [PROVIDER]. Payments: [PROVIDER]. Professional advisers under confidentiality.

We do not sell personal data. Current subprocessor list: auditscoot.com/subprocessors.

5. International transfers

Server-side personal data is stored in the EU. Where a subprocessor processes personal data outside the EEA/UK, we rely on an adequacy decision or Standard Contractual Clauses (EU SCCs; UK IDTA/Addendum where applicable) with supplementary measures; details on request.

6. Retention

Data Retention
Account data Subscription + 2 years
Billing data 7 years (Dutch fiscal duty)
Prospect data 18 months after last meaningful contact, or immediately upon objection
AI questions & schema mappings Processed transiently, never used for training; anonymised operational logs retained no more than 24 hours, then deleted
Usage/licensing records 7 years (billing evidence)
Client Audit Data Never held by us; resides only on your machines under your control

7. Your rights

Access, rectification, erasure, restriction, portability, and objection (including to direct marketing, always honoured): [EMAIL], answered within one month. Complaints: Autoriteit Persoonsgegevens (NL), the ICO (UK), or your local supervisory authority. Data subjects whose personal data appears in Client Audit Data should contact the relevant audit firm; the data is on that firm’s systems, not ours.

8. Security

Local-first processing is our primary safeguard: the sensitive dataset never leaves your environment. Server-side, we apply the measures summarised in DPA Schedule 1 (encryption in transit and at rest, MFA, least privilege, tenant isolation, logging).

9. Notice to United States residents (CCPA/CPRA and other state laws)

This section supplements the above for individuals in US states with comprehensive privacy laws (California, Virginia, Colorado, Connecticut, Utah, and successor or equivalent laws). Audit Scoot serves business customers only; most personal data we process is business-contact and account data.

  • We do not sell or share personal data, and have not done so in the preceding 12 months. “Sell” and “share” are used as defined under the CCPA/CPRA; we do not disclose personal data for cross-context behavioural advertising or for monetary or other valuable consideration.
  • No sensitive data for restricted purposes. We process no special-category or “sensitive” personal information for the purposes those laws restrict, and make no automated decisions producing legal or similarly significant effects.
  • Categories, purposes, sources, and retention are those set out in §2–§6 above; sources are you, your firm, and public professional registers.
  • Your rights. Residents of these states may request to know, access, correct, delete, and obtain a portable copy of their personal data, and will not be discriminated against for exercising them. Because we never hold Client Audit Data, any request concerning data inside a firm’s audit files must be directed to that firm, which controls it.
  • How to exercise. Contact [EMAIL]; we respond within the period the applicable law requires, and honour requests made through an authorised agent where the law permits.

10. Changes and contact

Material changes are notified to account holders. Questions and requests: [EMAIL].

Cookie settings

This site sets no analytics or marketing cookies. Strictly necessary storage only: portal cookies (session, CSRF) when you log in, and browser localStorage for your currency preference.

View Cookie Policy