AuditBull Privacy Policy
Effective date: August 2, 2026 Last updated: August 2, 2026
This Privacy Policy explains how personal data is collected, used, shared, stored, and deleted in connection with AuditBull (the "Service"). It is published publicly at auditbull.com and requires no login to read.
1. Who We Are
AuditBull is operated by Magnataur Consulting, LLC ("Magnataur", "we", "us", "our"), a Delaware limited liability company. Our corporate contact domain is magnataur.com.
AuditBull is a multi-tenant Governance, Risk & Compliance (GRC) SaaS platform distributed through Microsoft Teams and a companion web application. It helps organizations manage their systems, vendors, risks, personnel access reviews, and compliance workflows.
Our role with respect to your data. Most of the data in the Service is entered or generated by the organization that subscribes (the "Customer") in the course of running its own compliance program. For that data, the Customer is the Controller — it decides what data to put into the Service and why — and Magnataur acts as the Processor, handling the data on the Customer's instructions under our customer agreement and Data Processing Addendum. For a limited set of data that we collect for our own purposes — for example, the billing contact for a subscription, or basic analytics about how the Service is used — Magnataur acts as the Controller. This policy describes both roles; where the distinction matters for your rights, we call it out.
If you are an individual whose data appears in the Service because your employer subscribes to AuditBull, and you want to exercise a privacy right, the fastest path is usually through your organization (the Customer). See Section 9.
2. Scope
This policy applies to personal data Processed through the AuditBull Service — the web application, the Microsoft Teams application and bot, and the underlying APIs — and to the auditbull.com marketing and documentation site.
It does not cover:
- The internal privacy practices of a Customer organization that uses AuditBull to run its own compliance program. The Customer is responsible for how it configures the Service and what data it chooses to put in.
- Third-party products or services that a Customer connects to, or that link to us, which have their own privacy policies.
- Microsoft Teams, Microsoft Entra ID, or Microsoft 365 themselves, which are governed by Microsoft's own terms and privacy statements.
Defined terms used throughout — "Customer", "Customer Data", "Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Service", "Agreement" — carry the meanings given in our customer Agreement and Data Processing Addendum.
3. What Data We Collect
We collect the following categories of data. Much of it is entered by the Customer; some is generated automatically as the Service runs.
a. Account and identity data. When a user signs in, we receive identity information from the identity provider — typically a name, work email address, a stable user identifier (object ID), and the organization (tenant) the user belongs to. Authentication is handled by Microsoft Entra ID (customer single sign-on) and by Clerk (Google and email sign-in). AuditBull does not store customer passwords — credentials are held by the identity provider, not by us.
b. Organization and personnel records. Customer Data includes the structure of the Customer's organization — departments, teams, and personnel records (names, roles, work contact details, reporting relationships) — that the Customer creates or imports to run access reviews, onboarding, offboarding, and ownership assignments.
c. GRC content the Customer enters. The substantive content of the compliance program: systems and their metadata, vendors and vendor risk records, risk registers and individual risks, assessments and responses, policies, attestations, findings, notes, and similar records. This is the Customer's own compliance data. It may incidentally contain personal data (for example, the name of a system owner or a note that mentions an individual).
d. Usage and telemetry data. As the Service runs, we generate operational records — telemetry events, error logs, request logs, and feature-usage metrics — used to keep the Service reliable, diagnose problems, measure adoption, and enforce usage limits. This data can include user and tenant identifiers, timestamps, and the action taken, but is not used to build advertising profiles.
e. Microsoft Teams / Microsoft Graph directory data. When a Customer installs AuditBull in Microsoft Teams and a Customer administrator grants the required permissions (admin consent), the Service reads limited directory information from Microsoft Graph — such as users, group memberships, and profile fields — in order to map the Customer's directory to personnel records, resolve identities, and route notifications. We read only the directory data needed to provide the Service, under the permissions the Customer's administrator consents to, and we do not read the content of the Customer's Teams messages beyond the messages directed to the AuditBull bot.
f. Billing and subscription data. For paid subscriptions, payment is processed by Stripe, Inc. We receive and retain subscription and billing-status information (plan, entitlement, billing contact) but do not store full payment-card numbers — those are handled by Stripe. See Section 6.
g. AI feature inputs (only if enabled). If and when a Customer uses an AI-assisted feature (for example, the assessment engine), the relevant content is sent to our AI Sub-processor to generate the result. See Sections 4 and 6.
We do not intentionally collect special categories of data (such as health, biometric, or government-ID data), and the Service is not designed to hold them. Customers should not enter such data into free-text fields.
4. How We Use Data
We use the data described above to:
- Provide and operate the Service — authenticate users, isolate each Customer's data, and deliver the GRC features the Customer subscribes to.
- Maintain security and integrity — enforce tenant isolation, detect and investigate abuse or errors, and keep an append-only audit trail of significant actions (see Section 7).
- Support and communicate — respond to support requests and send service-related notices (for example, review reminders, security notices, or changes to the Service).
- Bill and administer subscriptions — manage entitlements, enforce usage limits, and process payment through our billing Sub-processor.
- Improve and maintain the Service — diagnose problems, measure feature adoption in aggregate, and prioritize engineering work.
- Deliver AI-assisted features — only when a Customer chooses to use an AI feature, and only for that feature's purpose.
- Comply with law — meet legal, regulatory, and contractual obligations.
We do not sell personal data, and we do not use Customer Data to train AI models for third parties. We do not use Customer Data for advertising.
5. Legal Bases for Processing
At launch, the Service is offered to US-based Customers and stores Customer Data in the United States only. The applicable data-protection laws are therefore applicable U.S. state privacy laws (for example, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CPRA), where applicable). The EU and UK General Data Protection Regulation are not currently applicable given this US-only scope, and will be addressed if and when EU/UK Customers or data subjects are onboarded.
Where the EU or UK General Data Protection Regulation applies, our legal bases for Processing are, depending on the context:
- Performance of a contract — to provide the Service to the Customer under the Agreement, and to administer accounts and billing.
- Legitimate interests — to secure the Service, prevent abuse, maintain the audit trail, and improve reliability, balanced against the rights of data subjects.
- Legal obligation — to comply with applicable law.
- Consent — where required, for example certain optional features; consent can be withdrawn at any time.
For Customer Data where the Customer is the Controller, the Customer is responsible for establishing the legal basis for the data it puts into the Service and for the instructions it gives us as Processor.
6. How We Share Data, and Our Sub-processors
We share personal data only as needed to run the Service:
- With the Customer. Data belongs to the Customer's tenant and is accessible to that Customer's authorized users, subject to the Customer's own access controls within the Service.
- With Sub-processors. We use a small set of vetted third-party service providers ("Sub-processors") to host and operate the Service. Each is bound by contract to protect the data and to Process it only to provide their service to us.
- For legal and safety reasons. We may disclose data if required by law, to enforce our Agreement, or to protect the rights, safety, and integrity of the Service, our Customers, or the public.
- In a business transfer. If Magnataur is involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction, subject to this policy and applicable law.
We do not sell personal data.
Sub-processors
The current list of Sub-processors is maintained in the companion document SUBPROCESSORS.md, which is the canonical, versioned list. As of the date of this policy, all Sub-processors are US-based:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Corporation | Azure cloud hosting (compute, PostgreSQL, Key Vault); Microsoft Entra ID (authentication); Microsoft Teams / Bot Framework (distribution + chat); Microsoft Graph (directory reads) | United States |
| Cloudflare, Inc. | Edge network — DNS, CDN, WAF, Zero Trust Access, tunnel | United States |
| Stripe, Inc. | Payment processing / subscription billing | United States |
| Clerk, Inc. | Authentication / identity provider (Google + email sign-in) | United States |
| Anthropic, PBC | AI-assisted features (e.g., the assessment engine) — invoked only if and when a Customer enables and uses an AI feature | United States |
The AI Sub-processor (Anthropic) is engaged only if and when AI features are enabled and used; the AI substrate is newly shipping and may not be active for every Customer.
Please refer to SUBPROCESSORS.md for the most current list and for how we notify Customers of changes.
7. Data Storage, Retention & Deletion
Where data is stored. The Service is hosted on Microsoft Azure in a United States region (US-East) only. At launch we do not offer EU or APAC data residency; all Customer Data is stored and Processed in the United States. See Section 10 on international transfers.
How long we keep data. We retain Customer Data for as long as the Customer maintains an active subscription, so the Customer can run and evidence its compliance program. Usage and telemetry logs are retained for operational and security purposes and then aged out on a rolling basis.
Deletion on request. Deletion is performed manually by Magnataur, not automatically. This is a deliberate design choice: the blast radius of an automated cross-tenant deletion is too high to risk, and verified deletion requests in a B2B context are infrequent, so a person-in-the-loop process is safer than automation.
On a verified Customer request submitted in-platform, we revoke access and delete that Customer's tenant data within 90 days.
What deletion means for backups. Deletion happens on our live production systems. Copies of data inside our encrypted backups are not edited in place — backups expire on a rolling rotation schedule, within 35 days after the deletion from live systems. Until they expire, backups stay encrypted and access-restricted and are used only for disaster recovery. If we ever restore from a backup taken before a deletion, we re-apply that deletion to the restored data.
How this reconciles with the append-only audit trail. AuditBull's audit trail is append-only by design — audit and compliance records are never hard-deleted, because their integrity is what makes them trustworthy evidence. To honor a deletion request while preserving that integrity, audit-log records that contain personal data are pseudonymized — personal identifiers are removed or hashed — rather than deleted row-by-row. The compliance history remains intact and auditable, but the personal data within it is erased.
Export. Customers can export their audit log as CSV from within the Service today. Broader data-portability export is available on request and is operator-assisted. We do not currently offer a fully self-serve export of all Customer Data beyond the audit-log CSV; we describe here only what exists.
8. Security
We take the security of Customer Data seriously and apply layered technical and organizational controls. In plain language:
- Per-tenant isolation. Each Customer's data lives in a shared PostgreSQL database protected by Row-Level Security (RLS), which enforces on every tenant-scoped query that a Customer can only see its own tenant's data. Tenant isolation is a core invariant of the system, not an optional setting.
- Encryption. Data is encrypted in transit using TLS 1.2 or higher, and at rest using Azure-managed encryption.
- Secrets and least privilege. Application secrets are held in Azure Key Vault. Database access uses least-privilege roles, and staff administrative access runs on a separate admin plane (corporate Microsoft Entra sign-in, restricted to a staff group, and device-gated).
- No customer passwords. Authentication is delegated to Microsoft Entra ID and Clerk; AuditBull does not store customer passwords.
- Append-only audit trail. Significant actions are written to an append-only audit log, so the record of who did what cannot be silently altered.
No system can guarantee absolute security, and we do not claim to. We work to protect Customer Data using the controls above and to improve them over time.
Breach notification. If we confirm a personal-data breach affecting Customer Data, we will notify affected Customers without undue delay, targeting notification within 72 hours of confirmation, consistent with our Agreement and applicable law.
9. Your Rights
Depending on where you live and the applicable law, you may have rights to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete personal data;
- Delete your personal data ("right to erasure");
- Export / port your data in a portable form;
- Object to or restrict certain Processing; and
- Withdraw consent where Processing is based on consent.
How to exercise your rights. Because most personal data in the Service belongs to a Customer's tenant (with the Customer acting as Controller), the primary way to exercise these rights is through an in-platform request to your organization, which can act on the data it controls. Where Magnataur is the Controller, or where you cannot reach the Customer, you may contact us at the address in Section 14, and we will respond consistent with applicable law and, where relevant, direct the request to the appropriate Customer.
We will verify requests before acting on them. Deletion requests are fulfilled through the manual, verified process described in Section 7 (including pseudonymization of the append-only audit trail). We do not charge for exercising these rights except where permitted by law for manifestly unfounded or excessive requests.
You also have the right to lodge a complaint with a supervisory authority.
10. International Transfers
The Service is hosted in the United States only. If you access the Service from outside the United States, your personal data will be transferred to and Processed in the United States, where data-protection laws may differ from those in your country.
International transfer mechanisms — such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement (IDTA), the Swiss addendum, and the EU–US Data Privacy Framework — are not currently applicable, because the Service stores Customer Data in the United States only and is offered to US-based Customers. If Magnataur begins processing EU/UK personal data or onboarding EU/UK Customers, the parties will execute the applicable transfer mechanism (EU SCCs / UK IDTA) at that time.
We do not offer EU or APAC data residency at launch.
11. Cookies and Tracking
The AuditBull web application uses cookies and similar technologies that are strictly necessary to operate the Service — for example, to keep you signed in and to maintain your session securely. We do not use advertising cookies, and we do not sell data collected through cookies.
The marketing site at auditbull.com runs no analytics and sets no cookies.
We honor browser "Do Not Track" and Global Privacy Control signals to the extent required by applicable law.
12. Children
The Service is a business tool intended for use by organizations and their personnel. It is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16 (or the applicable age of digital consent). If you believe a child's personal data has been provided to us, please contact us and we will take appropriate steps to delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make a material change, we will update the "Last updated" date above and, where appropriate, notify Customers through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy, to the extent permitted by law. Prior versions are available on request.
14. Contact Us
Questions, concerns, or privacy requests can be sent to:
Privacy — Magnataur Consulting, LLC Email: privacy@auditbull.com
This document is a companion to the AuditBull customer Agreement, Data Processing Addendum, and the Sub-processor list at SUBPROCESSORS.md. In the event of a conflict between this policy and a signed Agreement or DPA with a Customer, the signed contract controls for that Customer.