Legal
Privacy Policy
GDPR-ready B2B SaaS · Editable via Admin Content Manager
1. Data We Collect
Colonnade Audit operates PAMS and adheres to international data protection principles, including GDPR standards, for B2B SaaS operations. Privacy contact: hello@colonnadeaudit.com. Jurisdiction: Delaware, USA.
- Account Data: Full name, work email, encrypted password hash — used for authentication, session management, and report attribution.
- Project Metadata: Project name, reference code, sector label, phase label, baseline budget, finish date — used for audit reports and dashboard indexing.
- Audit Responses: Answers (Yes/Partial/No/NA), red-flag toggles, HSE toggles, evidence notes — used to calculate project health scores and generate the CAP.
- Technical Telemetry: IP address, browser user-agent, session timestamps, error logs — used for security monitoring and system performance.
2. Legal Basis for Processing
- Contractual necessity: processing project inputs to generate audit calculations and deliver requested 4-page PDF exports.
- Legitimate interest: maintaining platform security, preventing unauthorized access, and debugging system errors.
- No third-party data selling: PAMS will never sell, monetize, or rent customer project data or email lists to third-party advertisers.
3. Encrypted Storage (Supabase / PostgreSQL)
Project and audit records are stored in a managed PostgreSQL database (Supabase or equivalent). Traffic is encrypted in transit with HTTPS / TLS 1.3. Database tables and automated backups are encrypted at rest using AES-256. Application queries enforce user/tenant isolation so one auditor cannot read another account's projects.
4. GDPR Data Subject Rights
Users have the right to:
- Access & Export: export historical projects, findings, and audit records in PDF, JSON, or CSV.
- Rectification: correct inaccurate project metadata or user account details.
- Erasure (Right to be Forgotten): request permanent deletion of the account and all associated project audit histories.
Draft audits may be deleted immediately. Completed audits remain locked until an explicit erasure request is processed. Active accounts retain audit records indefinitely until the user or organization requests deletion.
5. Contact, GDPR Requests & Jurisdiction
Colonnade Audit is the operator of this PAMS deployment. Privacy and GDPR data-subject requests, including access, rectification, and erasure, may be sent to hello@colonnadeaudit.com. This processing is governed by the laws of Delaware, USA.