Legal
Last updated: June 23, 2026
Last Updated: June 20, 2026
AuditFlo ("AuditFlo," "we," "our," or "us") respects your privacy and is committed to protecting your information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access or use the AuditFlo platform, website, applications, APIs, and related services (collectively, the "Services").
By using the Services, you acknowledge and agree to the practices described in this Privacy Policy.
This Privacy Policy applies to information collected through:
This Privacy Policy does not apply to third-party websites, services, or applications that may be connected to AuditFlo.
We may collect information that you voluntarily provide, including:
When authorized by you or your organization, AuditFlo may collect information from connected systems, including:
Examples of information collected through integrations may include:
AuditFlo collects only the information necessary to provide the Services requested by customers.
When you use the Services, we may automatically collect:
AuditFlo uses cookies and similar technologies to:
You may configure your browser to reject cookies; however, some functionality may be limited.
We use collected information to:
We do not use customer compliance evidence for advertising purposes.
When organizations use AuditFlo, AuditFlo generally acts as a service provider and data processor on behalf of the customer.
Customers determine:
Customers remain responsible for ensuring their use of AuditFlo complies with applicable privacy and data protection laws.
Where applicable under data protection laws, AuditFlo processes information based on one or more of the following legal grounds:
AuditFlo does not sell personal information.
We may share information with:
Trusted vendors that assist us in operating the Services, including:
We may disclose information when required to:
If AuditFlo participates in a merger, acquisition, financing, reorganization, bankruptcy, or asset sale, information may be transferred as part of that transaction.
Information may be processed and stored in countries where AuditFlo or its service providers operate.
Where required by law, AuditFlo implements appropriate safeguards for international data transfers.
AuditFlo retains information only for as long as necessary to:
Unless otherwise agreed:
Backup systems may retain information for a limited period as part of normal disaster recovery processes.
AuditFlo maintains administrative, technical, and organizational safeguards designed to protect information, including:
No system can guarantee absolute security. Users are responsible for protecting account credentials and maintaining appropriate security practices.
Depending on your location, you may have rights that include:
Requests may be submitted to:
We may need to verify identity before fulfilling requests.
Residents of California may have additional rights under applicable California privacy laws, including rights relating to:
AuditFlo does not sell personal information.
Individuals located in the European Economic Area, Switzerland, and the United Kingdom may have additional rights under applicable data protection laws.
Where AuditFlo acts solely as a processor on behalf of a customer, requests regarding customer-controlled data should generally be directed to the relevant customer organization.
AuditFlo is intended for business and professional use.
The Services are not directed toward children under the age of thirteen (13), and AuditFlo does not knowingly collect personal information from children.
If we become aware that such information has been collected, we will take reasonable steps to delete it.
The Services may contain links to or integrations with third-party services.
AuditFlo is not responsible for the privacy practices, content, or security of third-party services.
Users should review the privacy policies of those providers separately.
AuditFlo may update this Privacy Policy from time to time.
Material changes will be communicated through the Services, email notifications, or website notices.
Continued use of the Services following the effective date of revised policies constitutes acceptance of those changes.