Legal
Privacy Policy
Privacy Policy for the Auda compliance platform, a solution from IoT Research & Development LLC.
Effective date: July 2026
Scope of this Privacy Policy
This Privacy Policy is issued by IoT Research and Development LLC (trade name "IoT R&D"), a company organized under the laws of the State of Washington, United States, and applies to the personal information IoT R&D collects as a data controller through audasystems.com and related websites, and through interactions such as sales inquiries, product demonstrations, customer support, and events (collectively, the "Sites").
A separate Master Subscription Agreement and Data Processing Addendum ("DPA") govern the Auda subscription services. This Policy does not apply where IoT R&D processes personal information as a processor on behalf of a customer — that is, data a customer uploads to or generates within the platform ("Customer Information"), such as information about a customer's own employees, vendors, or data subjects, evidence records, or records processed under any compliance framework supported by the platform from time to time. Customer Information is governed by the applicable Master Subscription Agreement and DPA agreed with that customer. For customers subject to HIPAA, protected health information contained in Customer Information is handled under the applicable DPA and Business Associate terms, not this Policy.
This Policy also does not apply to third-party services, connectors, or integrations that a customer chooses to connect to the platform; those are governed by the third party's own privacy notice.
1. Information We Collect and Receive
1.1. Information you provide to us
- Account data: name, business email, phone number, company, job role, authentication credentials, and billing contact details.
- Billing data: information provided to our payment processor to purchase a subscription.
- Website and form submissions: information you submit through contact forms, demo requests, or the ROI calculator.
- Support and customer service requests: information you provide when you contact us for help.
- Communications: records of calls, meetings, and other communications, including recordings where you have consented.
1.2. Information collected automatically
- Usage data and services metadata: for example, which connectors and compliance frameworks a customer account has enabled.
- Log data: IP address, browser type and settings, referring page, date and time of access, and cookie data.
- Device information: device type, operating system, and unique identifiers.
- Approximate location: derived from IP address or business address.
- Cookies and similar technologies: used for site functionality and analytics; you can control these through your browser settings.
1.3. Information from other sources
We may receive information about you from business partners, resellers, event organizers, and publicly available or commercial databases.
2. Payment Processing
Payments for Auda subscriptions are processed by Stripe, Inc. We do not receive or store full payment card numbers. Stripe collects and processes card data directly under its own privacy policy and maintains PCI-DSS certification for handling cardholder data. We receive only limited billing metadata from Stripe, such as the last four digits of a card, the card brand, and payment status, which we use for invoicing and account administration.
3. How We Use Information
We use the information described above to: provide, update, maintain, and protect our Sites, the Auda platform, and our business; administer billing and accounts; provide customer support; communicate with you, including about new features and supported compliance frameworks; develop new products and features; conduct marketing, with the ability to opt out at any time; detect, prevent, and investigate fraud, abuse, and security incidents; and comply with applicable law.
Where the General Data Protection Regulation ("GDPR") applies, our legal bases for processing include: performance of a contract with you or your organization; our legitimate interests in operating and improving our business, provided those interests are not overridden by your rights; your consent, where obtained; and compliance with a legal obligation.
We may aggregate or de-identify information so that it no longer identifies a specific individual, and we may use such aggregated or de-identified data for any business purpose. We do not sell personal information, and we do not use Customer Information to train artificial intelligence models.
4. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, including to satisfy our legitimate business interests, complete audits, comply with legal and regulatory obligations, resolve disputes, and enforce our agreements. Evidence and compliance-related records are retained in accordance with applicable contractual commitments and legal holds.
5. How We Share and Disclose Information
- Service providers and subprocessors: we share information with vendors that support our business, including Stripe (payments), Google Firebase (authentication), Resend (transactional email), Sentry (error monitoring), and our cloud hosting provider. This list of subprocessors may be updated from time to time as our services evolve.
- Third-party connectors: where a customer enables an integration between the Auda platform and a third-party system, information may flow to that third party subject to its own terms.
- Corporate transactions: information may be disclosed in connection with a merger, acquisition, financing, or sale of assets.
- Aggregated or de-identified data: we may share data that does not identify you.
- Legal compliance: we may disclose information to comply with law, regulation, legal process, or governmental request. Where a government or other third party seeks Customer Information, we will direct the request to the relevant customer and, unless legally prohibited, notify the customer before disclosing it.
- Protection of rights: to enforce our agreements, prevent fraud, and protect the safety of our users and the public.
- With your consent.
We do not sell personal information.
6. Security
We maintain industry-standard technical and organizational measures designed to protect personal information, including encryption in transit and at rest, least-privilege access controls, private-network databases, secrets management, and audit logging. Because Auda is itself a compliance automation platform, we apply the same operational disciplines that our platform helps customers achieve under the frameworks it supports. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Age Limitations
Our Sites and services are directed to businesses and are not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a minor in violation of this Policy, we will delete it.
8. International Data Transfers
We are based in the United States, and personal information we collect is primarily processed in the United States. Where we process personal information originating from Chile, Brazil, the European Economic Area, the United Kingdom, or other jurisdictions with data protection laws that restrict international transfers, we implement appropriate safeguards, such as contractual protections in our Data Processing Addendum and, where applicable, the European Commission's Standard Contractual Clauses.
9. Your Rights and How to Exercise Them
Depending on your jurisdiction, you may have the right to: access the personal information we hold about you; request correction of inaccurate information; request deletion; request restriction of, or object to, certain processing (including direct marketing); request portability of your data; withdraw consent where processing is based on consent; opt out of the sale or sharing of personal information, where applicable; and appeal a decision we make in response to your request.
To exercise these rights, contact us at contact@audasystems.com. Requests concerning Customer Information will be referred to the relevant customer, who acts as the data controller for that information.
This includes rights available under U.S. state privacy laws (such as the CCPA/CPRA and similar laws in other states); Chile's Law 19.628 and Law 21.719, which grant rights of Access, Rectification, Cancellation, Objection, and Portability (ARCO+); Brazil's LGPD; and the GDPR for individuals in the EEA and UK, including the right to lodge a complaint with your local supervisory authority.
10. Your California Privacy Rights
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), gives California residents specific rights regarding their personal information. The table below summarizes the categories of personal information we have collected in the preceding 12 months, consistent with the categories defined by the CCPA.
| Category | Examples |
|---|---|
| Identifiers | Name, email address, phone number, account ID |
| Commercial information | Subscription plan, billing history |
| Internet or network activity | Browsing activity on our Sites, log data |
| Geolocation data | Approximate location derived from IP address |
| Professional information | Job title, employer, business role |
| Inferences | Preferences inferred from usage of our Sites |
| Audio/visual information | Call or meeting recordings, where consented |
We do not sell or share personal information for cross-context behavioral advertising, and we do not knowingly sell the personal information of minors under 16. To exercise your CCPA rights, submit a request to contact@audasystems.com. We will verify your request using information reasonably necessary to confirm your identity. You may designate an authorized agent to submit a request on your behalf by providing us with written authorization.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date. If we make material changes, we will provide additional notice, such as by email or a prominent notice on our Sites.
12. Contacting Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
IoT Research and Development LLC
Attn: Privacy
Email: contact@audasystems.com
Mailing address: [U.S. address]