Audit It
| Last updated | 7 August 2026 |
|---|---|
| Provider | Audit It Limited โ Company No. 17258971 |
| Registered office | 19A Singleton Court, Wonnastow Road, Monmouth, NP25 5JA, United Kingdom |
| Contact | contact@auditit.io |
1. Background
This Data Processing Agreement ("DPA") forms part of the agreement between Audit It Ltd ("Processor") and the customer ("Controller") and governs the processing of personal data by Audit It Ltd on behalf of the customer in connection with the Audit It platform. This DPA is incorporated into and subject to the Terms of Service.
2. Definitions
"Personal data", "data subject", "processing", "controller", and "processor" have the meanings given in UK GDPR. "Services" means the Audit It platform as described in the Terms of Service. "Customer data" means personal data submitted to the Service by or on behalf of the Controller.
3. Scope and purpose of processing
Audit It Ltd processes customer data solely to provide the Services as instructed by the Controller, including storing lead submissions, generating audit reports, and delivering emails on the Controller's behalf. We will not process customer data for any other purpose without the Controller's written instruction, except where required by law.
4. Google Ads API data
Where the Services involve processing data obtained through the Google Ads API, Audit It Ltd processes that data as a processor, strictly on the Controller's documented instructions and on a strictly read-only basis, solely to generate the requested audit report. This processing is consistent with, and governed by, the Google Ads Data Processing Terms (https://privacy.google.com/businesses/processorterms), and complies with the Google API Services User Data Policy, including its Limited Use requirements.
5. Processor obligations
Audit It Ltd shall: (a) process customer data only on documented instructions from the Controller; (b) ensure that persons authorised to process customer data are bound by confidentiality obligations; (c) implement appropriate technical and organisational security measures; (d) assist the Controller in responding to data subject rights requests; (e) delete or return customer data upon termination of the Services; and (f) provide all necessary information to demonstrate compliance with this DPA.
6. Sub-processors
The Controller grants general authorisation for Audit It Ltd to engage sub-processors. Current sub-processors are: Replit, Inc. (cloud hosting and infrastructure), Stripe, Inc. / Stripe Payments Europe Ltd (payment processing), Zoho Corporation (business email hosting), Resend, Inc. (transactional email delivery), and Google LLC (Google Analytics 4 for product usage analytics). We will notify Controllers of any intended changes to sub-processors and provide the opportunity to object. All sub-processors are bound by data processing agreements with equivalent obligations to this DPA.
7. Security
Audit It Ltd implements and maintains appropriate technical and organisational measures to protect customer data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include encryption at rest and in transit, access controls, and regular security reviews.
8. Data breach notification
In the event of a personal data breach affecting customer data, Audit It Ltd will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach, providing sufficient information for the Controller to meet its own notification obligations.
9. International transfers
The Services are hosted in the United States by our infrastructure sub-processor, Replit, Inc., and some other sub-processors listed in Section 6 also process data in the United States. Where we transfer personal data internationally, we rely on appropriate safeguards, including the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it, or otherwise the UK International Data Transfer Agreement or the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum.
10. Term and termination
This DPA remains in effect for the duration of the Services. Upon termination, Audit It Ltd will, at the Controller's election, delete or return all customer data within 30 days, unless retention is required by applicable law.
11. Contact
To execute a countersigned DPA or for any data protection queries, contact us at contact@auditit.io.
Last updated: 7 August 2026.