AuditBadger AuditBadger

Legal

Privacy Policy

Current Humadroid Privacy Policy.

Version 2.0
Effective June 23, 2026

Privacy Policy

This Privacy Policy explains what personal data we collect, why we collect it, and the choices you have. It covers both the auditbadger.com marketing website and the AuditBadger compliance application (the "Service").

1. Who we are

The Service is operated by AuditBadger ("AuditBadger", "we", "us", or "our"). AuditBadger was formerly known as Humadroid; you may still see the Humadroid name on some legal documents while we complete the rebrand.

Data controller: Prograils Sp z o.o., Sczanieckiej 9a/9, 60-215 Poznań, Poland. For any privacy question or to exercise your rights, contact us at privacy@auditbadger.com.

2. Scope of this policy

This policy describes two related but distinct relationships:

  • The website — when you visit auditbadger.com, read our blog, subscribe to our newsletter, contact us, or use our free policy generator. Here AuditBadger is the controller of your data.
  • The application — when your organisation uses the AuditBadger compliance platform. For the content you put into a workspace, AuditBadger acts as a processor on behalf of your organisation (the customer), which is the controller. Our handling of that data is governed by the customer agreement and Data Processing Agreement (DPA).

3. Information we collect

3.1 When you use the website

  • Contact form: your name, email address, optional phone number, company name, company size, the subject of your enquiry, and your message.
  • Newsletter: your email address.
  • Free policy generator: your name, work email, company name and website URL, a description of your company and product, your tech stack, and your marketing consent choice. We fetch and analyse the public content at the company URL you provide to tailor the generated policies. Generated policy PDFs are made available through a private download link that expires after 24 hours.
  • Analytics: aggregate, anonymous usage statistics (see Section 6). We do not build advertising profiles and we do not track you across other websites.
  • Technical data: when you load a page or submit a form, our servers and error monitoring receive standard technical information such as IP address, browser type, and request metadata. We use this for security, rate limiting, and diagnosing errors.

3.2 When your organisation uses the application

Within the AuditBadger application we process the data your organisation chooses to put in, which may include account and authentication details, user profile and role data, and the compliance records you manage — controls, evidence, policies, risks, vendors, assessments, incidents, training records, audit logs, and uploaded documents. We process this data to provide the Service under your customer agreement; we do not sell it or use it for advertising.

Under the GDPR we rely on the following legal bases:

  • To respond to your enquiries and provide the policy generator — our legitimate interest, and steps taken at your request prior to a contract.
  • To send you our newsletter — your consent, which you can withdraw at any time using the unsubscribe link in every email.
  • To provide and secure the Service — performance of our contract with your organisation, and our legitimate interest in keeping the Service safe and reliable.
  • To follow up on policy generator and demo requests — our legitimate interest in contacting people who have expressed interest in AuditBadger.
  • To comply with legal obligations — where the law requires us to retain or disclose data.

5. AI processing

AuditBadger uses large language models to assist with compliance work and to power features such as the policy generator. Prompts and the context selected for a task are sent to our AI sub-processor, Anthropic, to generate a response. Our agreement with Anthropic provides that data submitted through the API is not used to train their models. AI-generated output is intended to support, not replace, human review.

6. Cookies and analytics

We keep tracking to a minimum. The website uses only essential cookies (for your session and to remember your light/dark theme preference) and Plausible Analytics, which is privacy-friendly and does not use cookies or collect personal data. We do not use Google Analytics, advertising pixels, or cross-site trackers. For full details, see our Cookie Policy.

7. Who we share data with (sub-processors)

We share data with a small set of vetted service providers who process it on our behalf, under contract and appropriate safeguards. For the website, these include:

  • Mailjet — newsletter and marketing email lists.
  • Mailgun — transactional and notification email delivery.
  • Amazon Web Services (S3, EU region) — storage of generated policy PDFs.
  • Anthropic — AI processing for the policy generator (see Section 5).
  • AppSignal — application performance and error monitoring.
  • Plausible Analytics — cookieless, aggregate website analytics.
  • Google Fonts — delivery of the website's typefaces; your browser requests fonts from Google, which receives your IP address.
  • Cal.com — scheduling when you book a product demo.

For the AuditBadger application, the complete and current list of sub-processors — including our hosting, database, network, email, AI, and e-signature providers — is published and kept up to date at auth.auditbadger.com/legal/data-processors.

We do not sell your personal data. We may disclose data if required by law or to protect our rights, and to a successor entity in the event of a merger or acquisition.

8. International transfers

Our primary infrastructure is located in the European Union. Some sub-processors (for example, Anthropic and certain e-signature and network providers) process data in the United States or across a global network. Where data leaves the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the providers' Data Processing Agreements.

9. How long we keep data

  • Newsletter: until you unsubscribe.
  • Contact enquiries: for as long as needed to handle your request and for a reasonable period afterwards for our records.
  • Policy generator leads: retained to follow up on your request and for our business records; download links expire after 24 hours.
  • Application data: retained for the life of your organisation's account and deleted or returned in line with the customer agreement and DPA.

10. Security

We protect data with encryption in transit (TLS) and at rest, role-based access controls, tenant isolation in the application, and audit logging. No system is perfectly secure, but we work to protect your data and to limit who can access it. You can read more on our Security page.

11. Your rights

Subject to applicable law, you have the right to access, correct, delete, or restrict the processing of your personal data; to object to processing; to data portability; and to withdraw consent at any time. To exercise any of these rights, email privacy@auditbadger.com. If AuditBadger processes your data on behalf of your organisation (application data), we will direct your request to that organisation. You also have the right to lodge a complaint with your local data protection supervisory authority.

12. Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.

13. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be communicated through the Service or by email where appropriate.

14. Contact us

Questions about this policy or how we handle your data? Email privacy@auditbadger.com and we will get back to you.

Previous versions

Version 1.0
Effective August 01, 2025