data protection
Audit documents stay in the European Union.
foraudits hosts the database, storage, application hosting, extraction compute and AI review in the European Union. Models run on Google Vertex AI Model Garden in Frankfurt (europe-west3) under a data processing agreement, and on those terms content is not used to train models. The only transfer outside the EU is transactional email delivery, through Resend, with appropriate safeguards — the EU US Data Privacy Framework or the European Commission standard contractual clauses.
Why this matters in an audit
The documents an auditor collects from an audited client are not ordinary data: they are invoices, floor plans, contracts, org charts and, often, employee personal data. The auditor answers to the audited client for where those documents ended up. A useful answer names the processing location and the sub-processor; it does not stop at asserting GDPR compliance.
No model training
foraudits does not use the customer's personal data to train its AI models or those of third parties. Processing is carried out through Google Vertex AI Model Garden under a data processing agreement and, on those terms, content is not used to train models. foraudits does not authorise such use.
The exception, stated in full
Transactional email is delivered by Resend, in the United States. It is the only transfer of data outside the European Union anywhere in the product. Appropriate safeguards apply, for example the EU US Data Privacy Framework or standard contractual clauses. We would rather write that than publish a page claiming everything is in the EU and leave the reader to find the exception in a contract annex.
What foraudits is not
foraudits is not a certification body, does not issue certificates, does not sign audits and does not guarantee an outcome. It is also not a GDPR compliance badge: the platform processes data compliantly and documents that it does, but the controller's responsibility stays with the auditor.
Sub-processors and processing location.
Taken from the sub-processors page, which is the contractual version and prevails over this one.
| Sub-processor | Service | Processing location |
|---|---|---|
| Supabase | Database, authentication and storage | European Union |
| Vercel | Site hosting and content delivery | European Union |
| Alphabet | Model hosting via Google Vertex AI Model Garden, with a DPA | European Union, Frankfurt (europe-west3) |
| Resend | Transactional email | United States |
What people ask.
- Are the foraudits AI tools GDPR compliant?
- Processing takes place in the European Union, under a data processing agreement with the model provider, and content is not used to train models. foraudits acts as the auditor's processor; the auditor remains the controller. The data processing page sets out the purposes, data categories and retention periods.
- Where are documents uploaded by the audited client stored?
- In the European Union. Database, storage and extraction compute are in the EU, and the AI review runs in Frankfurt (europe-west3).
- Are our documents used to train AI models?
- No. Processing runs through Google Vertex AI Model Garden under a data processing agreement and, on those terms, content is not used to train models. foraudits does not authorise such use, for its own models or third-party ones.
- Is any data transferred outside the European Union?
- One thing is: transactional email delivery, through Resend in the United States, with appropriate safeguards such as the EU US Data Privacy Framework or standard contractual clauses. No audit document, extraction or review leaves the EU.
- Does foraudits sign or issue the certification?
- No. foraudits is not a certification body and is not accredited to certify. It reviews the report against the standard and returns the analysis; the decision and the signature stay with the competent body.
Need the DPA before you decide?
The data processing agreement and the sub-processor list are public and do not depend on a sales conversation. If you need to review them with your DPO, they are there.