Privacy Policy
Effective date: 2 August 2026
Version: 1.0
Data Controller: HumanAudit Inc., Delaware, USA
1. Who we are
HumanAudit Inc. is a Delaware-incorporated C-Corporation operating the website iso42001toolkit.com. We sell downloadable documentation products relating to ISO/IEC 42001:2023 (AI Management Systems).
For the purposes of this Privacy Policy and applicable data-protection law (including the EU General Data Protection Regulation, GDPR, the UK GDPR, and the California Consumer Privacy Act / California Privacy Rights Act, CCPA/CPRA), HumanAudit Inc. is the data controller of Personal Data collected through the site and associated services.
Contact for privacy matters: hello@iso42001toolkit.com
2. What Personal Data we collect
We collect the following categories of Personal Data:
a) Data you provide directly - Name, email address, company name, country (at checkout and when contacting support). - Billing address and VAT/Tax ID (to the extent required for invoicing). - Correspondence you send us via email or contact forms.
b) Data collected automatically - IP address, browser type, operating system, referring URL, device identifiers. - Pages viewed, time on page, click events (via privacy-friendly analytics, see Section 7). - Cookies and similar technologies (see Section 7 and the separate Cookie Notice).
c) Data collected by payment processors - Payment card details are handled directly by Stripe; we do not see or store full card numbers. We receive from the processor a token and transaction metadata (partial card identifiers, amount, currency, country).
d) Data you choose to provide in documents - If you send us draft documents or questions that include information about your organisation or staff, that content becomes part of our support-channel records. Do not send Personal Data of third parties to support unless you have the lawful basis to do so.
We do not collect, and do not ask for, so-called "special category" Personal Data (health data, racial or ethnic origin, religious beliefs, biometric data, etc.) in the normal course of the service.
3. Why we collect it (purposes and lawful bases)
| Purpose | Lawful basis (GDPR) |
|---|---|
| Deliver purchased products to the purchaser | Contract performance (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Contract performance; legal obligation for tax (Art. 6(1)(b), (c)) |
| Provide customer support | Contract performance; legitimate interest (Art. 6(1)(b), (f)) |
| Send transactional emails (receipts, download links, update notifications within the 24-month window) | Contract performance (Art. 6(1)(b)) |
| Send marketing emails about new products and updates | Consent (Art. 6(1)(a)), opt-in; withdrawable any time |
| Prevent fraud, chargebacks, abuse | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal, accounting, and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Measure and improve site performance | Legitimate interest (Art. 6(1)(f)); consent for non-essential analytics where required |
For California residents under CCPA/CPRA, the business purposes above correspond to "providing the Service", "securing the Service", and "complying with legal obligations".
4. Who we share Personal Data with
We share Personal Data only with service providers (processors) who perform specific functions on our behalf. Current categories:
- Payment processors, Stripe, Inc. (United States) and/or Lemon Squeezy (Stripe, USA; also acting as Merchant of Record for certain jurisdictions). Processing: payment authorisation, fraud screening, tax collection/remittance, subscription billing, chargeback handling. Their own privacy notices apply in addition.
- Hosting and email, Cloudways (managed cloud hosting) and the applicable email provider for transactional mail. Processing: delivering the site and emails to you.
- Analytics, see Section 7. Configured for IP-anonymisation where technically available.
- Domain and DNS, Hostinger. No direct access to Personal Data beyond what is necessary to operate DNS.
- Professional advisers, accountants, lawyers, insurers, and auditors under confidentiality and only where necessary.
- Authorities, where legally compelled (court order, valid law-enforcement request, tax authority request). We will notify you where lawful to do so.
We do not sell Personal Data (as defined under CCPA/CPRA).
We do not share Personal Data for cross-context behavioural advertising as defined under CPRA.
We do not use Personal Data to train AI models.
5. International transfers
HumanAudit Inc. is based in the United States. Some of our service providers are also in the United States. Where Personal Data of EU/EEA or UK residents is transferred to the US or to another "third country" under GDPR:
- We rely on the European Commission's Standard Contractual Clauses (SCCs) with our processors, and on the UK's International Data Transfer Addendum where applicable;
- Where our service providers are certified under the EU–US Data Privacy Framework (DPF) and UK/Swiss extensions, we rely on that certification as a permitted transfer mechanism;
- We apply additional technical and organisational measures where warranted by a transfer risk assessment.
For a copy of the specific transfer safeguards applicable to a particular processing activity, contact hello@iso42001toolkit.com.
6. How long we keep Personal Data
| Category | Retention |
|---|---|
| Account and purchase records | Duration of account + 7 years after last activity (for accounting / tax compliance) |
| Billing and transactional records | 7–10 years depending on applicable tax law |
| Support correspondence | 3 years after resolution |
| Marketing contact records | Until you opt out + 30 days for suppression list |
| Analytics data (aggregated / anonymised) | Up to 26 months; aggregate indefinitely |
| Server access logs | 90 days |
After the retention period, Personal Data is deleted, anonymised, or securely archived with restricted access.
7. Cookies and tracking technologies
We use a small number of cookies and similar technologies. Details are in our Cookie Notice (linked from the site footer). Categories we currently deploy:
- Strictly necessary, session management, checkout state, cart persistence. These are always active because the site cannot function without them.
- Analytics, privacy-friendly analytics (currently Google Analytics 4 with IP anonymisation; consider Plausible or Fathom for a cookieless alternative). For visitors in the EU/EEA and UK, we request consent via a cookie banner before loading non-essential analytics.
- Functional, language preference, dismissed-banner state.
- Marketing/advertising, none at time of writing. If we add them in future, we will update this Policy and the Cookie Notice and request consent where required.
You can manage cookie consent via the banner on the site and via your browser settings. Disabling strictly-necessary cookies will break site functionality including checkout.
8. Your rights
Under GDPR, UK GDPR, and similar laws you have the right to:
- Access, request a copy of the Personal Data we hold about you.
- Rectification, correct inaccurate or incomplete data.
- Erasure, request deletion where the legal basis no longer applies ("right to be forgotten").
- Restriction, restrict processing while we resolve a dispute.
- Portability, receive your data in a machine-readable format.
- Objection, object to processing based on legitimate interest, including direct marketing (we will always honour marketing objections).
- Withdraw consent, where processing is based on consent, withdraw at any time (does not affect prior lawful processing).
- Complain, lodge a complaint with a supervisory authority. In the EU/EEA this is the Data Protection Authority in your country of residence or of alleged infringement. In the UK, the Information Commissioner's Office (ICO).
Under CCPA/CPRA (California residents) you have the right to:
- Know what Personal Data we collect, disclose, or share, and how it is used.
- Delete Personal Data we hold about you (subject to legal retention exceptions).
- Correct inaccurate Personal Data.
- Opt out of sale or sharing (noting that we do neither).
- Limit use of sensitive Personal Information (we do not process sensitive PI for inference or profiling).
- Non-discrimination for exercising your rights.
To exercise any of these rights, email hello@iso42001toolkit.com with enough information to verify your identity. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA), extendable where permitted.
9. Security
We apply reasonable technical and organisational measures to protect Personal Data, including:
- TLS/HTTPS for all site traffic;
- Access controls and MFA for administrative accounts;
- Payment processing through PCI-DSS-compliant third parties (we do not store full card data);
- Principle of least-privilege for internal access;
- Regular backups and vendor security reviews.
No system is fully immune from compromise. If a breach affecting your Personal Data occurs and is likely to result in risk to your rights, we will notify you and the relevant supervisory authority as required by GDPR (Art. 33, 34) and applicable US state breach-notification laws.
10. Children
The site and products are intended for business users and are not directed at children under 16. We do not knowingly collect Personal Data from children. If you believe we have collected data from a child, contact us and we will delete it.
11. Do Not Track
Some browsers transmit a "Do Not Track" signal. Because there is no industry consensus on how to interpret DNT, our site does not change behaviour based on DNT. You can control cookies via the consent banner described in Section 7.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email and/or a prominent banner for at least 30 days before the effective date. The "Effective date" at the top reflects the current version.
13. Contact
HumanAudit Inc.
Delaware, USA
Email (privacy queries and rights requests): hello@iso42001toolkit.com
For GDPR purposes we have assessed that we are not required to appoint an EU representative under Article 27(2)(a) because our processing is occasional and does not involve large-scale processing of special categories of data, and is unlikely to result in a risk to rights and freedoms of data subjects. This assessment should be re-validated by privacy counsel before production deployment; if volumes grow or the nature of processing changes, appointment of an Article 27 representative may be required.
v1.0 · draft · 2026-04-23 · pending independent legal counsel review before production deployment. The GDPR Article 27 assessment should be specifically re-verified.