Audit It

Data Processing Agreement
Last updated24 July 2026
ProviderAudit It Limited โ€” Company No. 17258971
Registered office19A Singleton Court, Wonnastow Road, Monmouth, NP25 5JA, United Kingdom
Contactprivacy@auditit.io

1. Background

This Data Processing Agreement ("DPA") forms part of the agreement between Audit It Ltd ("Processor") and the customer ("Controller") and governs the processing of personal data by Audit It Ltd on behalf of the customer in connection with the Audit It platform. This DPA is incorporated into and subject to the Terms of Service.

2. Definitions

"Personal data", "data subject", "processing", "controller", and "processor" have the meanings given in UK GDPR. "Services" means the Audit It platform as described in the Terms of Service. "Customer data" means personal data submitted to the Service by or on behalf of the Controller.

3. Scope and purpose of processing

Audit It Ltd processes customer data solely to provide the Services as instructed by the Controller, including storing lead submissions, generating audit reports, and delivering emails on the Controller's behalf. We will not process customer data for any other purpose without the Controller's written instruction, except where required by law.

4. Google Ads API data

Where the Services involve processing data obtained through the Google Ads API, Audit It Ltd processes that data as a processor, strictly on the Controller's documented instructions and on a strictly read-only basis, solely to generate the requested audit report. This processing is consistent with, and governed by, the Google Ads Data Processing Terms (https://privacy.google.com/businesses/processorterms), and complies with the Google API Services User Data Policy, including its Limited Use requirements.

5. Processor obligations

Audit It Ltd shall: (a) process customer data only on documented instructions from the Controller; (b) ensure that persons authorised to process customer data are bound by confidentiality obligations; (c) implement appropriate technical and organisational security measures; (d) assist the Controller in responding to data subject rights requests; (e) delete or return customer data upon termination of the Services; and (f) provide all necessary information to demonstrate compliance with this DPA.

6. Sub-processors

The Controller grants general authorisation for Audit It Ltd to engage sub-processors. Current sub-processors include: Stripe (payment processing), Resend (email delivery), and our cloud hosting provider. We will notify Controllers of any intended changes to sub-processors and provide the opportunity to object. All sub-processors are bound by data processing agreements with equivalent obligations to this DPA.

7. Security

Audit It Ltd implements and maintains appropriate technical and organisational measures to protect customer data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include encryption at rest and in transit, access controls, and regular security reviews.

8. Data breach notification

In the event of a personal data breach affecting customer data, Audit It Ltd will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach, providing sufficient information for the Controller to meet its own notification obligations.

9. International transfers

Customer data will be processed within the UK or EEA where possible. Any transfers outside these territories will be subject to appropriate safeguards in accordance with UK GDPR requirements.

10. Term and termination

This DPA remains in effect for the duration of the Services. Upon termination, Audit It Ltd will, at the Controller's election, delete or return all customer data within 30 days, unless retention is required by applicable law.

11. Contact

To execute a countersigned DPA or for any data protection queries, contact us at privacy@auditit.io.

Last updated: 1 January 2025.