My Audit Corner application privacy policy
Last updated: 1 October 2026
This policy is for users of the My Audit Corner application (app.myauditcorner.com, the "Solution"). It explains what personal data we process, why, for how long, with whom, and how to exercise your rights.
We process two types of data, in two different roles:
- Your account data and your use of the Solution: My audit corner is the controller. This is the main subject of this policy.
- Personal data contained in your company's documents: your company (the Customer) is the controller, and My audit corner acts on its behalf as processor. This processing is governed by the Terms and conditions and the data processing agreement entered into with the Customer (see section 3).
Use of the myauditcorner.com website is covered by a separate policy.
1. Data controller
- My audit corner SAS, 14 rue de la Cressonnière, 31270 Cugnaux, France
- Contact regarding your data: dpo@myauditcorner.com
2. Your account data and use of the Solution
| Data | Why | Legal basis |
|---|---|---|
| Account: first name, last name, business email (login), company, job title | Create and manage your account, identify you, manage access rights | Performance of the contract with your company |
| Login and security: IP address, login dates and times, browser, technical logs | Secure the Solution, prevent misuse, fix incidents | Legitimate interest (security) |
| Usage: actions performed, credit consumption | Run the Solution, show your consumption, provide support, improve the Solution | Performance of the contract; legitimate interest (improvement) |
| Notifications: email, content of notifications (weekly summary, alerts) | Keep you informed about your account | Performance of the contract |
| Support: your exchanges with our team | Answer your requests | Performance of the contract |
| Billing: your company's billing details | Invoice and collect payment | Performance of the contract; legal accounting obligations |
We do not collect civil status data, date of birth or identity documents. We never sell data and do not use Solution data for advertising.
3. Data contained in your company's documents
The documents your company connects or uploads (procedures, records, technical files, reports) may contain personal data: names, job titles, signatures, contact details of employees, suppliers or other people.
- My audit corner processes them solely on behalf of the Customer and according to its instructions: analysis by the Solution, production of assessments, action plans, answers and documents, delivery of results.
- No training: this data is never used to train or improve any artificial intelligence model, whether by us or by our providers.
- No human review of the content, except at the Customer's request (support, performance of a service) or where technically necessary for maintenance, by authorised people bound by confidentiality.
- It is hosted and processed in the European Union, on Google Cloud Platform; the AI models (Gemini, via Vertex AI) run in Belgium.
- The Customer remains responsible for the lawfulness of the data it entrusts to the Solution. The Solution is not designed to process patient health data.
To exercise your rights over this data, contact the Customer (your employer or the company concerned); we will help it respond.
4. Retention periods
- Account and usage: for the duration of the Customer's contract, then deleted no later than 60 days after it ends (30 days of reversibility, then 30 days for deletion).
- Login and security logs: 12 months.
- Data contained in the Customer's documents: for the duration of the contract, then deleted within the same timeframes. Connected documents remain in the Customer's own tools.
- Invoices: 10 years (legal obligation).
- Support exchanges: 3 years after the last exchange.
Residual copies may remain in backups for a few weeks before automatic rotation.
5. Recipients and processors
Your data is accessible only to authorised My audit corner staff. We use the following providers:
| Provider | Role | Data location |
|---|---|---|
| Google Cloud (Google Ireland Limited) | Hosting of the Solution and data; Gemini AI models via Vertex AI | European Union (AI runs in Belgium) |
| SMTP2GO | Sending the Solution's emails (weekly summary, notifications). Receives the recipient's address and the email content; has no access to documents | European Union (Netherlands); company established in New Zealand, a country recognised as providing adequate protection |
| Stripe | Only for customers still paying by card. My audit corner never has access to card numbers | European Union and United States (Data Privacy Framework) |
We may also disclose data to authorities where required by law.
6. Transfers outside the European Union
Customer documents and Solution data remain in the European Union. The only possible transfers concern card payments (Stripe, certified under the EU–US Data Privacy Framework) and SMTP2GO's New Zealand entity, covered by a European Commission adequacy decision.
7. Application cookies
The Solution only uses cookies that are strictly necessary for it to work: keeping your session open, securing your login, remembering your display preferences. They do not require your consent. The Solution sets no advertising or audience measurement cookies.
8. Security
- Hosting on Google Cloud Platform in the European Union.
- Encryption in transit and at rest; each customer's data is isolated.
- Access limited to those who need it, and logged.
- ISO 27001 process under way; penetration tests carried out by independent providers.
- The Solution only contacts external services to read the document repositories connected by the Customer and to consult public databases such as EUDAMED.
If a data breach is likely to result in a high risk to your rights, we will inform you as soon as possible. For your part, choose a strong password used only for the Solution, and do not share it.
9. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, and may set instructions regarding your data after your death. Some of your information can be changed directly in your account settings. For anything else, write to dpo@myauditcorner.com; we reply within one month and may ask you to prove your identity.
If you consider that your rights have not been respected, you may lodge a complaint with the CNIL (www.cnil.fr) or the supervisory authority of your country.
10. Changes
We may update this policy. In the event of a significant change, we notify users by email at least thirty (30) days before it takes effect. The date of the last update appears at the top of the page.