Privacy Policy

πŸ“… Effective date: 1 January 2025 πŸ”„ Last updated: 1 January 2025 🌍 Applies to: auditxa.com
πŸ”’ The short version β€” plain English first Your firewall and network configuration files never leave your browser and are never sent to our servers. We only collect your email address to manage your account and send you login codes. We do not sell your data. We do not show you ads. This policy explains in full what we collect, why, and what your rights are.

Contents

  1. Who we are
  2. What data we collect and why
  3. Your configuration files β€” a special note
  4. Legal basis for processing (GDPR)
  5. How we use your data
  6. Who we share data with
  7. How long we keep your data
  8. How we protect your data
  9. Cookies and tracking
  10. Your rights
  11. Children's privacy
  12. International data transfers
  13. California residents (CCPA)
  14. Changes to this policy
  15. Contact us

1. Who we are

AuditXA ("we," "us," or "our") operates the website at auditxa.com and provides a browser-based network security auditing tool for firewall and VPN configuration analysis.

For the purposes of data protection law, including the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller of the personal data described in this policy.

Contact for privacy matters:
Email: [email protected]
Address: [Your Company Name], [Your Address], [City, Country]

2. What data we collect and why

Data Why we collect it How long kept
Email address To create and manage your account; to send one-time login codes (MFA); to notify you of subscription changes Until you delete your account + 30 days
One-time login codes (OTP) Stored as a one-way cryptographic hash (not the code itself) to verify your identity at login. Never stored in plain text. Automatically deleted after use or after 1 hour, whichever is sooner
Subscription status and plan To determine whether you have an active subscription and which features to enable Until you delete your account + 7 years (tax/legal requirement)
Payment provider customer ID To link your subscription to your account and process billing events Duration of subscription + 7 years
Login timestamps and IP address Security logging β€” to detect suspicious access patterns and protect your account 90 days, then automatically deleted
Audit activity log Records which audit tool you used and your audit score (not the config content) for your audit history feature Until you clear your history or delete your account
Rate limit records To prevent abuse of the login system (max 5 OTP requests per 15 minutes per IP) 24 hours, then automatically deleted
We do not collect: your firewall configuration file content, device hostnames, IP addresses from your configs, passwords or secrets from your configs, browser fingerprints, or advertising identifiers. We do not use analytics platforms like Google Analytics.

3. Your configuration files β€” a special note

This is the most important part of this policy for our users.

Your firewall and VPN configuration files are processed entirely within your web browser. They are never uploaded to, transmitted to, or stored on our servers.

When you paste or upload a configuration file:

You can verify this yourself by opening your browser's developer tools (F12 β†’ Network tab) and observing that no configuration content is transmitted when you run an audit.

This design is intentional. Network configuration files often contain sensitive information such as pre-shared keys, management IP ranges, and authentication settings. We believe this data should never leave your environment, so we architected the tool so that it technically cannot.

5. How we use your data

We use the data we collect strictly to:

We do not: sell your data, share it for advertising purposes, use it for profiling or automated decision-making, or process it for any purpose beyond what is described in this policy.

6. Who we share data with

We share your data with the following third-party service providers only to the extent necessary to operate the service:

Provider Purpose Data shared Location
Supabase
supabase.com
Database hosting β€” stores account and subscription data Email, subscription status, OTP hashes, login logs AWS us-east-1 (USA) or EU region depending on your project settings
Resend
resend.com
Transactional email β€” sends your one-time login codes Your email address and the one-time code USA
Stripe
stripe.com
PayPal
paypal.com
Payment processing and subscription management Email address, subscription data. Payment details are processed exclusively by Stripe or PayPal β€” we never see or store your card or PayPal credentials. USA
Vercel
vercel.com
Web hosting and serverless API functions IP addresses in server logs (standard web server logs, retained per Vercel's policy) USA / globally distributed CDN

All third-party providers are contractually required to handle your data securely and only for the purposes we specify. We do not share your data with any other parties except where required by law.

Legal disclosure

We may disclose your data if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7. How long we keep your data

We keep your data only for as long as necessary for the purposes described in this policy:

When data reaches its retention limit, it is permanently deleted from our database. Backups containing the data are also purged within 30 days of the live deletion.

8. How we protect your data

We implement industry-standard technical and organisational measures to protect your personal data:

No method of transmission or storage is 100% secure. If you become aware of any security vulnerability in our service, please report it responsibly to [email protected].

9. Cookies and tracking

We use no advertising cookies, no analytics cookies, and no third-party tracking of any kind.

What we do use

sessionStorage (not a cookie, but similar) β€” we store your login session token in your browser's sessionStorage. This is automatically cleared when you close your browser tab. It is never sent to third parties. This is strictly necessary for the service to function.

What we do not use

Our hosting provider (Vercel) and font provider (Google Fonts) may set standard infrastructure cookies as part of CDN delivery. These are outside our control but do not track you for advertising purposes.

Because we use no tracking or analytics cookies beyond session management, we do not display a cookie consent banner. If we ever add optional tracking (which we will always announce), we will implement a full consent mechanism before doing so.

10. Your rights

Depending on your location, you have the following rights regarding your personal data. To exercise any of these rights, email us at [email protected]. We will respond within 30 days (EEA/UK: within 1 calendar month as required by GDPR).

πŸ“‹ Right of access

You can request a copy of all personal data we hold about you.

✏️ Right to rectification

You can ask us to correct inaccurate or incomplete data we hold about you.

πŸ—‘οΈ Right to erasure

You can ask us to delete your personal data ("right to be forgotten"), subject to our legal retention obligations.

⏸️ Right to restriction

You can ask us to restrict processing of your data in certain circumstances (e.g. while a dispute is resolved).

πŸ“¦ Right to portability

You can request your data in a structured, machine-readable format (JSON or CSV).

🚫 Right to object

You can object to processing based on legitimate interests. We will stop unless we have compelling grounds.

πŸ€– Automated decisions

We do not make any automated decisions that significantly affect you. No profiling is performed.

πŸ›οΈ Right to complain

You have the right to lodge a complaint with your national data protection authority (e.g. ICO in the UK, your local EU supervisory authority).

How to delete your account

Email [email protected] with the subject line "Delete my account" from your registered email address. We will delete your account data within 30 days and confirm when done. Billing records required by law (7 years) will be retained but isolated from the main account database.

11. Children's privacy

AuditXA is a professional tool intended exclusively for adults (18 years or older) working in IT, network security, or related fields. We do not knowingly collect personal data from anyone under the age of 18.

If you believe a person under 18 has provided us with personal data, please contact us at [email protected] and we will delete that data promptly.

12. International data transfers

Our service providers are primarily based in the United States. If you are located in the European Economic Area (EEA) or the United Kingdom, your personal data may be transferred to and processed in the USA.

We ensure such transfers comply with applicable data protection law through the following safeguards:

13. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you specific rights regarding your personal information.

Categories of personal information collected

We collect: Identifiers (email address, IP address). We do not collect: financial information (handled exclusively by Stripe or PayPal), biometric data, geolocation, internet activity beyond login logs, or sensitive personal information.

Your California rights

To exercise your California rights, email [email protected]. We will respond within 45 days.

"Do Not Sell or Share My Personal Information"

We do not sell or share your personal information for advertising purposes. No opt-out is necessary, but we honor this right regardless.

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

When we make material changes (changes that significantly affect your rights or how we process your data), we will:

We encourage you to review this policy periodically. Your continued use of AuditXA after the effective date of any changes constitutes acceptance of the updated policy.

Previous versions of this policy are available on request by emailing [email protected].

15. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy & Data Protection Contact

πŸ“§ Email: [email protected] πŸ” Sec