Privacy Policy

This Privacy Policy explains how Md R Rafi, operating under the trading name "Auditably.co" ("we", "us", "Auditably.co"), with business contact at 11 Jalan SS15/4, Subang Jaya, Selangor, Malaysia, collects, uses, and protects your personal data when you use the Auditably.co service (the "Service").

1. Who we are

The data controller for the purposes of applicable data protection law (including GDPR where relevant) is:

2. What data we collect

Information you provide directly

Information collected automatically

Information we do NOT collect

3. How we use your data

We process your data for the following purposes:

The lawful bases under GDPR (where applicable to you) are: performance of a contract, legitimate interests (operating and improving the Service), and compliance with legal obligations.

4. Who we share data with

We use the following third-party providers to operate the Service. Each is bound by their own privacy policy:

We do not sell your data to third parties. We do not share your data with advertisers.

5. International data transfers

Our service providers (Paddle, Supabase, Resend, Cloudflare, OpenAI, Anthropic) may process data outside of your country of residence, including in the United States, United Kingdom, and European Union. These providers contractually commit to data protection standards (e.g. Standard Contractual Clauses, SOC 2, GDPR compliance).

6. Data retention

We retain your data for as long as your account is active and for a reasonable period afterwards to comply with legal obligations (typically 7 years for financial records, per Malaysian tax law).

Specifically:

7. Your rights

Subject to applicable law (including GDPR for residents of the European Economic Area, UK GDPR for UK residents, and equivalent laws), you have the right to:

To exercise these rights, email [email protected]. We respond within 30 days.

8. Security

We take reasonable technical and organisational measures to protect your data:

However, no system is 100% secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities in accordance with applicable law.

9. Cookies and similar technologies

We use minimal browser storage to operate the Service:

We do not use analytics cookies, advertising cookies, or tracking pixels.

10. Children's privacy

The Service is intended for use by adults in a business context. We do not knowingly collect data from children under 16. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or via the Service. The "Last updated" date at the top reflects when this policy was last revised.

12. Contact

For privacy questions, data requests, or complaints: