Legal

Privacy policy

How we collect, use, retain and protect data.

Last updated: July 2026 · This summary is provided for transparency and is not legal advice.

1. Scope

This policy explains how ToneAudit (“we”, “us”) processes data when you use our supplier-compliance platform and website. It covers data about your account and workspace, and the business data we screen on your behalf.

2. Data we process

  • Account data — name, work email, role and workspace membership, used to authenticate you and operate your account.
  • Supplier & screening data — the supplier names and identifiers you submit, and the records returned from official and public sources during a check.
  • Evidence — source snapshots, content hashes and access timestamps preserved to support the audit trail.
  • Usage data — logs of source access, reviewer actions and system events, used for security, reliability and the audit trail.

We focus on publicly available business data and minimise personal data. Where a source (for example a sanctions or ownership record) contains personal data, we process only what is necessary for the due-diligence purpose.

3. How we use data

  • To resolve supplier identity and screen it across the sources relevant to your checks.
  • To produce, store and export evidence packs and reports.
  • To operate, secure, monitor and improve the service.
  • To communicate with you about your account and support requests.

We do not sell personal data, and we do not use your supplier data to train models for other customers.

4. Lawful basis

Where the GDPR applies, we rely on: performance of a contract (operating your workspace); legitimate interests (securing the service, and processing business data for due diligence); and, where required, consent. Screening of publicly available business information is carried out in the context of your legitimate compliance obligations.

5. Sources & access

We access official APIs where available and respect robots.txt and rate limits so public and government sources are not overloaded. We only access sources relevant to a check and record each access for the audit trail.

6. Retention

Evidence, source snapshots and audit logs are retained to keep supplier files defensible over time. Retention periods are configurable per workspace; account data is kept for the life of the account and deleted or anonymised afterwards, subject to legal requirements.

7. Sharing & subprocessors

We share data only with vetted subprocessors that help us run the service (for example hosting and email delivery), under contractual data-protection obligations, and where required by law. Your evidence and supplier data are scoped to your workspace and not shared with other customers.

8. International transfers

Where data is transferred across borders, we use appropriate safeguards (such as standard contractual clauses) consistent with applicable data-protection law.

9. Security

Data is encrypted in transit and at rest, access is scoped and least-privilege, and every source access and reviewer decision is logged. See our Security & trust page for details.

10. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict or port your data, and to object to certain processing. To exercise these rights, contact privacy@toneaudit.com. You may also complain to your local data-protection authority.

11. Cookies

We use essential cookies to keep you signed in and to remember preferences (such as theme). We do not use advertising cookies.

12. Changes

We may update this policy as the service evolves. Material changes will be reflected here with a new “last updated” date.

13. Contact

Questions about this policy or your data: privacy@toneaudit.com.