IgniteHub, LLC d/b/a SimpleAudit ("SimpleAudit," "we," "us") is the data controller for the personal data described in this policy, except for accounts managed by a partner, where the partner is the controller and SimpleAudit acts as a processor (see "Partner-Managed Accounts" below). SimpleAudit acts as a data controller for account, marketing, analytics, and website-visitor data. For the compliance content you create within the Service (including evidence files, access-review records, and vendor-respondent data), SimpleAudit acts as a data processor on your behalf under our Data Processing Agreement.
1. Information We Collect
We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support. This includes:
Account Information
- Name and email address
- Company profile details you provide during onboarding, including infrastructure configuration (cloud providers, identity systems, deployment tools), security practices (access controls, incident response, encryption), business continuity parameters (recovery objectives, backup frequency), and organizational structure (team size, work model, contractor usage). This information is used to customize your AI-powered compliance guidance.
- Job title and role
Compliance Data
- Policies, risk assessments, and vendor information you create within the platform
- Evidence files you upload to the Evidence Vault
- AI chat conversations related to compliance guidance
- We maintain detailed audit trails of changes to your compliance data — including who made changes, when, and what was modified — to support your audit readiness.
Access Review Data
- Application inventory records (application names, owners, user counts)
- Access review schedules and completion records
- Privileged access designations
Action Item Data
- Remediation tasks and action plans
- Owner assignments, due dates, and priority levels
- Recurrence schedules and status history
Control & Exception Data
- Control matrix mappings and evidence coverage records
- Control exception records including deviation descriptions and root cause analysis
- Exception approval decisions and audit period associations
Audit Artifact Data
- System descriptions, management assertions, and audit reports
- Versioned changelog entries and approval records
- Audit period definitions and associated documentation
Vendor Assessment Responses
- Third-party vendor responses to security assessment questionnaires
- Assessment template configurations and risk level classifications
- OTP access records for vendor respondents
Company Insights
- Persistent context stored by the AI assistant about your company (such as infrastructure details, team structure, and compliance goals)
- Insight categorizations (infrastructure, security, compliance, people, vendors, applications, policy preferences, business context)
Help Feedback
Help feedback ratings and optional comments you submit when rating AI responses. A brief excerpt of the AI response may be stored alongside your feedback to improve our service.
Marketing Email Subscriber Data (BlogSubscriber)
- Email address, the source (blog article, guide, or other marketing surface) you opted in from, and any UTM parameters attached to that visit
- Consent timestamp, IP address, and browser user-agent string captured at the moment of opt-in
- Double-opt-in verification timestamp and one-click unsubscribe status
Payment Information
Billing details processed securely by Stripe (via Clerk Billing). We never store credit card numbers on our servers.
Automatically Collected Information
- Browser type, device type, and operating system
- IP address and approximate geographic location
- Pages visited, time spent, and interaction patterns (only with analytics consent)
Information We Collect from Third Parties
Vendor Respondent Data
Our customers may invite vendor respondents to complete security assessment questionnaires on the SimpleAudit platform. When a vendor respondent participates in an assessment, we collect:
- Name and email address (provided by the inviting customer)
- Assessment questionnaire responses
- Access timestamps and session activity
- OTP verification codes (stored as hashed values only)
- This data is collected solely for the purpose of completing security assessments on behalf of our customers. Assessment data is retained for the duration of the inviting customer's account.
- Vendor respondents may contact us at privacy@simpleaudit.io regarding their data.
Partner-Managed Accounts
Some SimpleAudit accounts are provisioned and managed by a partner organization — such as a managed service provider, consultant, or reseller — on behalf of a client. If your account is managed by a partner:
- Your partner is the controller of the compliance data in your account. SimpleAudit acts as a processor on your partner's behalf and under their instructions.
- Your partner's authorized administrators can access, create, modify, export, and delete all data in your account, including policies, risk assessments, Evidence Vault files, and AI chat history. Every action a partner administrator takes on your account is recorded in an access audit log.
- Your account may display your partner's branding (name, logo, and colors) in place of SimpleAudit's. The underlying Service is provided by SimpleAudit as described in this policy.
- To exercise your data rights, contact your partner first. You may also contact us at privacy@simpleaudit.io and we will coordinate with your partner.
- Billing is handled by your partner. SimpleAudit does not collect payment information directly from partner-managed clients.
- If the partner relationship ends, your account may enter a grace period before the partner loses access or the account is closed; data is then retained or deleted in accordance with the Data Retention section below.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Power AI-assisted compliance guidance customized to your company
- Process transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze trends, usage, and activities (with consent)
- Measure advertising effectiveness and optimize ad campaigns (with marketing consent)
- Detect, investigate, and prevent security incidents
- Send automated compliance reminders, such as policy review due date notifications and access review schedules, to help you maintain your compliance posture
- Compliance data you create within the platform — such as policies, risk assessments, vendor information, and company profile details — may be processed by our AI service to provide personalized compliance guidance. This processing occurs in real-time during your AI chat sessions. The models are stateless and do not retain your data; any limited, short-term processing Microsoft performs for trust-and-safety purposes stays within Microsoft's Azure environment and is never shared with the model providers.
- We do not use your compliance data (policies, risk assessments, evidence) to train AI models. Our AI runs through Microsoft Azure AI Foundry, which hosts the OpenAI and Anthropic models we use. Microsoft acts as the data processor: your prompts and the AI's responses are processed within Microsoft's Azure environment, are not shared with OpenAI or Anthropic, and are not used by Microsoft or those providers to train or improve any AI models. Your data is used solely to provide you with compliance guidance within your account. See Microsoft's data, privacy & security documentation for Azure AI Foundry models, OpenAI's enterprise privacy statement, and Anthropic's model-training policy.
Marketing Email Opt-In
- If you submit your email through a blog article, guide, or other marketing surface to receive updates from SimpleAudit, we use a double-opt-in process. After you submit the form we send a confirmation email; your subscription is not active until you click the verification link in that email. We record your consent timestamp, IP address, and browser user-agent as evidence of opt-in (required for CAN-SPAM and GDPR compliance).
- Your right to unsubscribe: Every marketing email we send includes a one-click unsubscribe link in the footer. Unsubscribing is immediate, does not require you to log in or provide any additional information, and removes you from further marketing emails. You can re-subscribe at any time by submitting the form again on any blog article or guide.
- Retention: We retain marketing email subscriber records (the BlogSubscriber dataset described above) for as long as we maintain the subscriber list, to preserve audit evidence of consent as expected under CAN-SPAM record-keeping. You may request deletion of these records at any time by contacting privacy@simpleaudit.io.
3. Data Retention
We retain your account and compliance data for as long as your account remains open. We do not currently operate an automated, time-based deletion pipeline; account data, compliance content, AI chat history, operational logs, and related records are retained for the life of the account.
To have your data deleted, submit a verified written request to privacy@simpleaudit.io. We will delete the requested data within 30 days of verifying your request, except where we are required by law to retain it. Deleted Evidence Vault files are destroyed immediately upon deletion and cannot be recovered.
Billing and payment records are held by our payment processors (Stripe and Clerk) under their own retention schedules; we store only your subscription status and tier. Platform telemetry is retained for approximately 90 days. We do not currently operate a legal-hold process.
Marketing email subscriber records (BlogSubscriber) are retained on the same request-based basis as all other data: kept while the subscriber list is maintained, and deleted on verified request.
4. Third-Party Sub-Processors
We use the following third-party services to operate SimpleAudit™. Each processes data only as necessary to provide their service. The authoritative, always-current list is maintained at simpleaudit.io/subprocessors:
List of third-party sub-processors| Provider | Purpose | Data Processed |
|---|
| Clerk | Authentication, user management, billing; webhook delivery via its subprocessor Svix | Name, email, session tokens, payment info |
| Microsoft Corporation (Azure) | Cloud hosting, database, file storage, transactional email, AI services, security scanning, telemetry — see "Microsoft Azure service detail" below | All application data (encrypted at rest and in transit), including uploaded evidence files, email content, compliance data context for AI processing, and pseudonymous telemetry |
| Stripe | Payment processing (via Clerk Billing) | Billing address, payment method, transaction history |
| Google LLC | Website analytics and advertising conversion tracking (both consent-required) | Page views, device info, IP address (anonymized), conversion events, hashed email (Enhanced Conversions), advertising identifiers |
| Cloudflare | Bot protection (Turnstile) on sign-up and video hosting (Stream) | Visitor IP addresses |
| Svix (via Clerk) | Webhook delivery | Webhook event payloads (may include user email addresses) |
Microsoft Azure service detail
All Microsoft services below operate under the same Microsoft Products and Services Data Protection Addendum and within the same Azure trust boundary. Within Microsoft Azure, SimpleAudit uses:
- Azure App Service, Database for PostgreSQL, and Blob Storage — application hosting, database, and file storage for all application data
- Azure Communication Services — transactional email (email addresses and email content)
- Azure AI Foundry (hosts the OpenAI and Anthropic models we use) — AI-powered compliance guidance over compliance data context (policies, risks, vendors). Prompts and outputs are processed by Microsoft as data processor, are not shared with the model providers, and are not used for model training. Some processing may occur in Azure regions outside the United States.
- Azure AI Document Intelligence — text extraction (OCR) from uploaded evidence files (PDF, PNG, JPEG)
- Azure AI Content Safety — prompt-injection screening (Prompt Shields) of text extracted from uploaded content
- Microsoft Defender for Storage — malware scanning of uploaded evidence files, with scan verdicts delivered via Azure Event Grid
- Azure Monitor (Application Insights) — server-side telemetry and error monitoring (performance metrics, error traces, request timing, and pseudonymous account and company identifiers)
We provide at least 30 days’ advance notice of any new or replacement sub-processor, during which you may object on reasonable data-protection grounds (30-day objection window). Enterprise customers and partners may request a Data Processing Agreement (DPA) by contacting privacy@simpleaudit.io.
5. Data Residency
The Service is available only to users in the United States. Your data is stored in Microsoft Azure US regions.
Our third-party processors (Clerk, Stripe, Google Analytics) may process limited data in other locations in accordance with their own privacy policies. AI processing runs through Azure AI Foundry, which hosts the OpenAI and Anthropic models we use; some AI processing may occur in Azure regions outside the United States. This currently applies to both the primary and the fallback AI models, which run on Azure “Global Standard” deployments that Microsoft may route outside the United States. We are migrating to US-only AI deployments and will update this section upon completion.
6. Cookies & Tracking Technologies
We use cookies and similar technologies categorized as follows:
Necessary Cookies (Always Active)
- __clerk_session: Clerk authentication session token
- __client_uat: Clerk client state for seamless authentication
- cookie_consent: Records your cookie consent preference
Analytics Cookies (Consent Required)
_ga, _ga_*: Google Analytics 4 measurement cookies for page views and feature usage
Marketing Cookies (Consent Required)
- _gcl_au: Google Ads conversion linker cookie for attributing conversions to ad clicks
- _gcl_aw: Stores Google Ads click information (GCLID) when a user arrives via an ad
- _gac_*: Contains campaign information for Google Ads conversion measurement
- When you sign up after clicking a Google Ad, we use Google Ads Enhanced Conversions to improve attribution accuracy. This sends a hashed (SHA-256) version of your email address to Google so they can match the conversion across devices. Google handles the hashing automatically and does not receive your plain text email for advertising purposes.
- We also process purchase conversion events server-side using the Google Analytics Measurement Protocol to measure advertising effectiveness. This uses your GA4 client identifier, transaction identifier, subscription tier, billing period, and price.
- You can manage your cookie preferences at any time using the Cookie Settings link in our site footer. We implement Google Consent Mode v2, which ensures no tracking occurs on public pages until you provide explicit consent. On authenticated pages (the portal and onboarding), analytics and conversion tracking are enabled under your acceptance of our Terms of Service (section 22). You may withdraw this consent at any time via the Cookie Settings link in our footer.
7. Data Security
We implement industry-standard security measures to protect your data:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest (Azure managed keys)
- Azure Virtual Network isolation for application services
- Timing-safe secret comparison to prevent side-channel attacks
- Zod schema validation on all API inputs to prevent injection
- Clerk-managed authentication with webhook signature verification
- Regular security reviews and dependency audits
- As a SOC 2 compliance product, we hold ourselves to the same standards we help our customers achieve. We regularly review our own security practices against SOC 2 Trust Services Criteria.
8. Your Data Rights
You have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you
- Right to Correction: Request correction of inaccurate or incomplete personal data
- Right to Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Right to Portability: Request your data in a structured, machine-readable format
- To exercise any of these rights, contact us at privacy@simpleaudit.io. We will respond within 30 calendar days. We may ask for identity verification before processing your request to protect your data.
- If your account is partner-managed, see "Partner-Managed Accounts" above — direct your rights requests to your partner first.
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Categories of Personal Information Collected
- Identifiers (name, email, IP address)
- Commercial information (billing history, subscription tier)
- Internet activity (pages visited, feature usage — with consent only)
- Advertising identifiers (Google Ads click IDs, conversion data — with marketing consent only)
- Professional information (job title, company name)
Your CCPA Rights
- Right to Know: You can request what personal information we have collected, the sources, the business purpose, and the categories of third parties we share it with.
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions (legal obligations, security, completing transactions). Where analytics data collected by Google Analytics is associated with you, we will submit a deletion request to Google on your behalf.
- Right to Correct: You can request correction of inaccurate personal information we hold about you.
- Right to Opt-Out: You can opt out of the sale of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- We do not sell your personal information. However, when you grant marketing consent, we share limited data (hashed email, conversion events) with Google Ads for advertising measurement. Under the CCPA, this disclosure of personal information to a third party for cross-context behavioral advertising purposes may constitute “sharing” as defined in Cal. Civ. Code § 1798.140(ah). This data is used solely to measure whether our ads led to signups.
- Your Right to Opt Out of Sharing: You may opt out of this sharing at any time by adjusting your cookie preferences via the “Cookie Settings” link in our website footer, or by using the cookie consent banner when it appears. When you opt out of marketing cookies, we immediately cease sharing your data with Google Ads.
- To exercise any of your CCPA rights, contact us at privacy@simpleaudit.io. If your account is partner-managed, see "Partner-Managed Accounts" above — direct your rights requests to your partner first.
10. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users without undue delay after becoming aware of the breach. Notification will include the nature of the breach, the data affected, steps we are taking to address it, and recommended actions for you. We will also notify relevant supervisory authorities as required by applicable law.
For partner-managed accounts, where SimpleAudit acts as a processor, we notify the managing partner (the controller), who is responsible for notifying affected end users as required by applicable law.
11. Children's Privacy
SimpleAudit is a business-to-business service designed for use by adults in a professional context. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have collected personal information from a child, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@simpleaudit.io.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will also notify you via email. Your continued use of SimpleAudit after any changes constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact our Privacy Contact: