Privacy Policy
Last updated: [DATE]
Audit Scoot B.V., [ADDRESS], KvK [KVK] (“we”, “us”) is committed to protecting personal data. This policy is drafted under Regulation (EU) 2016/679 (GDPR); for customers and visitors in the United Kingdom, references to the GDPR include the UK GDPR.
1. The local-first model — read this first
Audit Scoot is built so that client financial data never reaches our servers. General ledger files, trial balances, and related audit datasets (“Client Audit Data”) are ingested, stored, and analysed locally on the user’s own machine. We do not receive, host, or store Client Audit Data, and we cannot access it.
What the application does transmit to us:
| Data | Content | Why |
|---|---|---|
| Schema mappings | Column names and standardized category labels of the dataset (no transaction records) | To power the AI analysis feature |
| AI questions | The free-text question a user types (which may incidentally contain personal data, e.g. an employee’s name) | To generate the analysis specification |
| Licence fingerprint | A one-way cryptographic hash of the dataset | Licensing integrity; cannot be reversed into data |
| Usage records | Engagement counts, feature events, timestamps | Billing and product improvement |
For schema mappings and AI questions we act as processor under the Data Processing Agreement (DPA) that forms part of every subscription; the customer (audit firm) is controller. For everything in §2 we act as controller.
2. Personal data we process as controller
| Category | Examples | Source |
|---|---|---|
| Account data | Name, business email, role, firm, hashed credentials | You / your firm admin |
| Billing data | Firm billing details, VAT number, invoices, payment status | Your firm |
| Prospect data | Name, business email, role, firm, correspondence | You, your firm’s website, professional networks, business registers |
| Usage data | Portal log-ins, application usage events, support tickets | Generated by use |
| Website data | Aggregate, cookieless analytics (see Cookie Policy) | Your visit |
No special categories; no automated decision-making producing legal effects.
3. Purposes and legal bases (Art. 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing and administering the Service, support | Contract (b) |
| Invoicing, accounting, fiscal retention | Legal obligation (c) |
| B2B direct marketing to relevant professional contacts | Legitimate interest (f), with opt-out in every message |
| Product improvement, security, abuse prevention | Legitimate interest (f) |
| Establishment or defence of legal claims | Legitimate interest (f) |
You can object to legitimate-interest processing at any time (§7); every marketing email has a one-click unsubscribe.
4. Recipients and subprocessors
- Hosting (website, licensing backend, account data): [HOSTING PROVIDER], EU data centres.
- AI provider: Google (Google Cloud, Vertex AI), used to convert the schema mapping and user question into an analysis specification. Processing is governed by Google’s Cloud Data Processing Addendum, under which submitted data is not used to train models. Requests are routed to the Google Cloud region nearest the user; where a request is processed outside the EEA/UK, transfers rely on the EU Standard Contractual Clauses and UK Addendum incorporated in that Addendum and on Google’s EU–US Data Privacy Framework certification. Google never receives Client Audit Data.
- Email/productivity: [PROVIDER]. Payments: [PROVIDER]. Professional advisers under confidentiality.
We do not sell personal data. Current subprocessor list: auditscoot.com/subprocessors.
5. International transfers
Server-side personal data is stored in the EU. Where a subprocessor processes personal data outside the EEA/UK, we rely on an adequacy decision or Standard Contractual Clauses (EU SCCs; UK IDTA/Addendum where applicable) with supplementary measures; details on request.
6. Retention
| Data | Retention |
|---|---|
| Account data | Subscription + 2 years |
| Billing data | 7 years (Dutch fiscal duty) |
| Prospect data | 18 months after last meaningful contact, or immediately upon objection |
| AI questions & schema mappings | Processed transiently, never used for training; anonymised operational logs retained no more than 24 hours, then deleted |
| Usage/licensing records | 7 years (billing evidence) |
| Client Audit Data | Never held by us; resides only on your machines under your control |
7. Your rights
Access, rectification, erasure, restriction, portability, and objection (including to direct marketing, always honoured): [EMAIL], answered within one month. Complaints: Autoriteit Persoonsgegevens (NL), the ICO (UK), or your local supervisory authority. Data subjects whose personal data appears in Client Audit Data should contact the relevant audit firm; the data is on that firm’s systems, not ours.
8. Security
Local-first processing is our primary safeguard: the sensitive dataset never leaves your environment. Server-side, we apply the measures summarised in DPA Schedule 1 (encryption in transit and at rest, MFA, least privilege, tenant isolation, logging).
9. Notice to United States residents (CCPA/CPRA and other state laws)
This section supplements the above for individuals in US states with comprehensive privacy laws (California, Virginia, Colorado, Connecticut, Utah, and successor or equivalent laws). Audit Scoot serves business customers only; most personal data we process is business-contact and account data.
- We do not sell or share personal data, and have not done so in the preceding 12 months. “Sell” and “share” are used as defined under the CCPA/CPRA; we do not disclose personal data for cross-context behavioural advertising or for monetary or other valuable consideration.
- No sensitive data for restricted purposes. We process no special-category or “sensitive” personal information for the purposes those laws restrict, and make no automated decisions producing legal or similarly significant effects.
- Categories, purposes, sources, and retention are those set out in §2–§6 above; sources are you, your firm, and public professional registers.
- Your rights. Residents of these states may request to know, access, correct, delete, and obtain a portable copy of their personal data, and will not be discriminated against for exercising them. Because we never hold Client Audit Data, any request concerning data inside a firm’s audit files must be directed to that firm, which controls it.
- How to exercise. Contact [EMAIL]; we respond within the period the applicable law requires, and honour requests made through an authorised agent where the law permits.
10. Changes and contact
Material changes are notified to account holders. Questions and requests: [EMAIL].