Privacy Policy
Last updated: March 1, 2026
At ZapAudit ("we," "our," or "us"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our audit management platform and related services (collectively, the "Service"). Please read this policy carefully.
1. Information We Collect
We collect information that you provide directly to us, as well as information that is automatically gathered when you use our Service.
Personal Information
When you create an account, request a demo, or contact us, we may collect your name, email address, phone number, company name, job title, and other information you choose to provide.
Usage Data
We automatically collect information about your interaction with our Service, including IP address, browser type, operating system, referring URLs, pages visited, time spent on pages, click patterns, and other diagnostic data.
Audit Data
In the course of using our platform, you may upload or create audit observations, reports, risk assessments, and other audit-related content. This data is stored securely and treated as confidential information.
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve our audit management platform and services
- To process your requests, including demo requests and account creation
- To send you technical notices, updates, security alerts, and support messages
- To respond to your comments, questions, and customer service requests
- To power our AI-driven risk analysis and audit insights features
- To monitor and analyze usage trends and preferences to improve user experience
- To detect, investigate, and prevent fraudulent transactions and other illegal activities
- To comply with legal obligations and enforce our terms of service
3. Data Security
We implement industry-standard security measures to protect your personal information and audit data. These measures include:
- AES-256 encryption for data at rest and TLS 1.3 for data in transit
- SOC 2 Type II compliance with regular third-party audits
- Role-based access controls and multi-factor authentication
- Regular security assessments, penetration testing, and vulnerability scanning
- Data centers with physical security controls and redundancy
- Incident response procedures and breach notification protocols
While we strive to use commercially acceptable means to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to continuously improving our protections.
4. Third-Party Services
We may use third-party services that collect, monitor, and analyze information to improve our Service's functionality. These third-party service providers have their own privacy policies and may include:
- Cloud infrastructure providers for hosting and data storage
- Analytics services for understanding usage patterns
- Payment processors for handling subscription transactions
- Communication tools for email delivery and customer support
- AI and machine learning services for powering our intelligent features
We only share the minimum information necessary with these providers and require them to maintain appropriate security measures.
5. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: You can request a copy of the personal information we hold about you.
- Correction: You can request that we correct inaccurate or incomplete information.
- Deletion: You can request that we delete your personal information, subject to certain legal exceptions.
- Portability: You can request a copy of your data in a structured, machine-readable format.
- Objection: You can object to the processing of your personal information in certain circumstances.
- Withdrawal of Consent: Where processing is based on consent, you can withdraw your consent at any time.
To exercise any of these rights, please contact us using the information provided below. We will respond to your request within 30 days.
6. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: