Acumen Bay Consultancy Limited

Audit-Here

Privacy Policy

End to End Compliance Platform: Web and Mobile Applications

Last updated: 01 Jan 2026  ·  Version 1.0
Home  /  Audit-Here  /  Privacy Policy
Field Detail
Effective date01 Jan 2026
Last updated01 Jan 2026
Version1.0
Applies toAudit-Here web application, iOS app, and Android app
Document ownerDinesh Singh
Review cycleAnnually, or on material change to processing

1 Introduction

This Privacy Policy explains how Acumen Bay Consultancy Limited ("Acumen Bay", "we", "us", or "our") collects, uses, stores, shares, and protects personal data in connection with the Audit-Here) end to end compliance platform, including its web application and its mobile applications for iOS and Android (together, the "Service" or the "App").

Audit-Here is a business-to-business (B2B) software-as-a-service product provided to organisations ("Customers"). It is used by employees, contractors, auditors, and other authorised personnel of those organisations ("Users", "you") to plan and execute audits, manage inspections and non-conformances, track risks and incidents, log manhours, and handle related compliance activities.

We are committed to protecting your privacy and handling personal data lawfully, fairly, and transparently.

Operating entities

  • Acumen Bay Consultancy Limited, a company registered in the United Kingdom, is the entity that provides the Service.
  • ACBAY IT INDIA PRIVATE LIMITED, our affiliate in India, supports development, delivery, and support operations.

2 Who is the data controller?

Because Audit-Here is a B2B platform, the roles under data protection law depend on the type of data:

  • Customer content and audit data. When your organisation uses Audit-Here to store audit records, inspection evidence, risk registers, incident reports, complaints, and similar information, your employer (the Customer) is generally the data controller and Acumen Bay acts as a data processor, processing that data on the Customer's documented instructions under a Data Processing Agreement (DPA). For questions about how your own organisation uses your data, please contact your organisation directly.
  • Account, technical, and support data. For certain limited data — such as account provisioning, authentication, security logging, billing, and support — Acumen Bay may act as a data controller.

This Policy describes our practices in both roles. Where we act as a processor, the Customer's own privacy notice also applies.

3 The personal data we collect

3.1 Data you or your organisation provide

  • Identity and account data: name, work email address, job title, role/permissions, organisation, and login credentials.
  • Profile and competency data: training records, competencies, roles, and qualifications where these are managed in the training matrix.
  • Content you create: audit plans, checklists, findings, non-conformances, inspection records, risk and HIRA/aspect-impact entries, incidents, customer complaints, permits, manhours, tasks, comments, and any attachments you upload.
  • Communications: messages you send to our support team.

3.2 Data collected automatically

  • Device and technical data: device model, operating system and version, app version, unique device/app identifiers, and language settings.
  • Usage data: features used, actions taken, timestamps, and session activity (including idle-timeout events).
  • Log and security data: IP address, access logs, authentication events, and error/diagnostic logs.

3.3 Data captured through device permissions

The mobile app can capture photos, files, and location data as evidence for audits and inspections. This is described in detail in Section 4 below.

We do not intentionally collect special-category data (such as health, biometric, or similar data) unless your organisation configures the platform to record it as part of its compliance processes. Where it does, your organisation is responsible for having a lawful basis.

4 Mobile app permissions

To let you capture and attach evidence in the field, the Audit-Here mobile app may request access to certain features of your device. All of these permissions are optional, are requested only when needed, and can be turned off at any time in your device settings. Turning off a permission may limit the related feature but does not otherwise stop you using the App.

The permissions are used only for the purposes described below. We do not use them for advertising, and we do not access your device in the background beyond what is stated here.

Summary of permissions

Permission Why it is requested Scope and limits
Camera Capture photos/video as audit, inspection, NC, incident, or QC evidence Foreground only, on your action; no background or continuous capture
Photos / Gallery Attach an existing image to a record Only the images you select; no library scanning or indexing
Files / Storage Attach documents and save or cache downloads Only the files you select; no browsing of other files
Location Tag a record with the site where it was carried out Foreground only, captured at the moment of submission; no background tracking

4.1 Camera

  • Why we ask: so you can take photos (and, where enabled, short videos) directly within the App to evidence an audit finding, an inspection, a non-conformance, an incident, or a quality-control check.
  • What we collect: the images or videos you deliberately capture, plus any caption or note you add. Images may include technical metadata (for example, timestamp).
  • What we do NOT do: we do not access the camera in the background, do not record continuously, and do not capture anything without your action.
  • How to control it: you can decline the camera prompt and attach existing files instead, or disable camera access in your device settings.

4.2 Photos / Gallery / Media

  • Why we ask: so you can attach an existing photo from your device's gallery to an audit, inspection, non-conformance, incident, or complaint record instead of taking a new one.
  • What we collect: only the specific images you choose to attach. We do not scan, index, or upload your photo library.
  • How to control it: on most devices you can grant access to selected photos only, or disable gallery access entirely, in your device settings.

4.3 Files / Storage

  • Why we ask: so you can attach documents and other files (for example PDFs, spreadsheets, evidence documents) to records, and so the App can save or cache files you download or generate.
  • What we collect: only the specific files you choose to attach or download. We do not browse, scan, or upload other files on your device.
  • How to control it: you can decline file access and simply not attach files, or disable storage/files access in your device settings.

4.4 Location

  • Why we ask: so an audit, inspection, or incident record can be tagged with the location where it was carried out, which supports the integrity and traceability of site-based compliance evidence.
  • What we collect: your device's location at the moment you create or submit a record, where you have granted permission. We request foreground ("while using the app") location only.
  • What we do NOT do: we do not track your location in the background, do not build a movement history, and do not use location for advertising.
  • Precision: where your device offers a choice, you may grant approximate rather than precise location; the feature will work with reduced accuracy.
  • How to control it: you can decline the location prompt or disable location access in your device settings at any time.

4.5 Withdrawing permissions

Granting a permission is your choice and can be reversed at any time through your device's operating-system settings (Settings → the Audit-Here app → Permissions on Android, or Settings → Privacy & Security / the Audit-Here app on iOS). Data already captured and submitted before you withdraw a permission remains stored as part of the relevant compliance record, subject to the retention and deletion terms in this Policy.

5 How we use personal data

We use personal data to:

  • provide, operate, and maintain the Service and its features;
  • authenticate users and manage access, roles, and permissions;
  • store, process, and display the audit, inspection, risk, and related records you create, including attached evidence;
  • generate reports, dashboards, analytics, and exports (for example PowerPoint and PDF outputs) for your organisation;
  • provide customer support and respond to your requests;
  • secure the Service, detect and prevent fraud, abuse, and security incidents, and maintain audit logs;
  • manage billing and administer our contract with your organisation;
  • comply with legal, regulatory, and contractual obligations;
  • improve and develop the Service (using aggregated or de-identified data wherever practicable).

6 Legal bases for processing (UK/EU GDPR)

Where UK GDPR or EU GDPR applies and Acumen Bay acts as a controller, we rely on the following legal bases:

  • Performance of a contract — to provide the Service to you and your organisation.
  • Legitimate interests — to secure, operate, support, and improve the Service, provided these interests are not overridden by your rights.
  • Legal obligation — to comply with applicable laws and lawful requests.
  • Consent — for optional device permissions (camera, photos, files, location) and where otherwise required. You may withdraw consent at any time.

Where we act as a processor, the legal basis for the underlying processing is determined by your organisation as controller.

7 Sharing and disclosure

We do not sell personal data. We share it only as necessary:

  • With your organisation (the Customer): administrators and authorised users within your organisation may access records you create, in line with the platform's roles and permissions.
  • With service providers / sub-processors: trusted vendors who process data on our behalf under contract, including our cloud hosting and content-delivery provider (Amazon Web Services — AWS S3 and CloudFront) and other infrastructure, email, and support providers. A current list of sub-processors is available on request at info@acumenbay.com
  • Within the Acumen Bay group: with ACBAY IT INDIA PRIVATE LIMITED and our delivery hubs, for development, delivery, and support, under appropriate safeguards.
  • For legal reasons: where required by law, regulation, legal process, or an enforceable governmental request, or to protect our rights, users, or the security of the Service.
  • In a corporate transaction: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

8 International data transfers

Acumen Bay operates from and works with delivery hubs in the United Kingdom, India. Your personal data may therefore be transferred to, stored in, or accessed from countries outside the country in which you are located, including countries that may not provide the same level of data-protection law.

Where we transfer personal data out of the UK or the European Economic Area, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) / Addendum and the EU Standard Contractual Clauses (SCCs), together with any additional measures required. A copy of the relevant safeguards is available on request.

Primary hosting for the Service is provided via AWS in EMEA.

9 Data retention

We retain personal data for as long as necessary to provide the Service and to fulfil the purposes described in this Policy, including retention required for compliance record-keeping, legal, tax, and regulatory obligations.

Where we act as a processor, retention of Customer content is governed by our agreement with your organisation and by your organisation's instructions. On termination of a Customer's subscription, we will delete or return Customer content in accordance with the DPA, subject to any legal retention requirement.

Indicative retention periods:

Data category Suggested period
Customer content (audit records, inspections, NCs, risks, attachments) Customer-configurable; default 30 days post-termination retrieval window, then deletion within 90 days
Account & user profile data Life of subscription + 6 months
Billing, invoicing, tax records 6 years from end of the financial year
Contracts, DPAs, order forms 6 years after termination
Security & access logs (auth events, admin actions) 12 months
Application & diagnostic logs (errors, crashes) 90 days
Backups 35-day rolling cycle
Support tickets 24 months
Marketing & prospect data 24 months from last engagement
Breach records 6 years
DSAR records 3 years
Cookies Session, or 13 months max for persistent

10 Security

We implement technical and organisational measures appropriate to the risk, including:

  • encryption in transit (TLS) and encryption at rest for stored data and attachments;
  • multi-tenant data isolation using separate database schemas per tenant;
  • access controls, role-based permissions, and least-privilege administration;
  • authentication controls and automatic idle-timeout of inactive sessions;
  • secure cloud hosting and content delivery via AWS S3 and CloudFront;
  • logging, monitoring, and vulnerability-management processes.

No method of transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security. Please keep your login credentials confidential and report any suspected compromise to us.

11 Your rights

Subject to applicable law, you may have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request erasure ("right to be forgotten");
  • restrict or object to certain processing;
  • request portability of your data;
  • withdraw consent where processing is based on consent (including device permissions);
  • lodge a complaint with a supervisory authority.

Because Audit-Here is a B2B service, much of the data is controlled by your organisation. If your request concerns audit records or other Customer content, we will generally refer you to, or act on the instructions of, your organisation as the data controller. For data where Acumen Bay is the controller, contact us using the details in Section 15.

  • UK/EU users may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or their local EU supervisory authority.
  • India users: rights under the Digital Personal Data Protection Act, 2023 apply as implemented.
  • California/US users: applicable state privacy rights (such as the right to know, delete, correct, and opt out of "sale"/"sharing" — which we do not do) apply where relevant.

12 Cookies and similar technologies (web application)

The Audit-Here web application uses no cookies.

13 Children

Audit-Here is a workplace tool intended for use by professionals and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.

14 Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify Customers or provide notice within the App. Your continued use of the Service after an update constitutes acceptance of the revised Policy.

15 Contact us

If you have questions about this Policy or wish to exercise your rights, contact us:

Contact detail

Acumen Bay Consultancy Limited
EntityAcumen Bay Consultancy Limited
Data Protection contactDinesh Singh
Postal address71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK
Company registration number10391706
ICO registration numberC1433520
For matters concerning audit records and other content stored in Audit-Here, please also contact your own organisation, which is the controller of that data.