Free·Your free medtech regulatory watch: complete report in 10 minutesGet my report →

My Audit Corner application privacy policy

Last updated: 1 October 2026

This policy is for users of the My Audit Corner application (app.myauditcorner.com, the "Solution"). It explains what personal data we process, why, for how long, with whom, and how to exercise your rights.

We process two types of data, in two different roles:

  • Your account data and your use of the Solution: My audit corner is the controller. This is the main subject of this policy.
  • Personal data contained in your company's documents: your company (the Customer) is the controller, and My audit corner acts on its behalf as processor. This processing is governed by the Terms and conditions and the data processing agreement entered into with the Customer (see section 3).

Use of the myauditcorner.com website is covered by a separate policy.

1. Data controller

  • My audit corner SAS, 14 rue de la Cressonnière, 31270 Cugnaux, France
  • Contact regarding your data: dpo@myauditcorner.com

2. Your account data and use of the Solution

DataWhyLegal basis
Account: first name, last name, business email (login), company, job titleCreate and manage your account, identify you, manage access rightsPerformance of the contract with your company
Login and security: IP address, login dates and times, browser, technical logsSecure the Solution, prevent misuse, fix incidentsLegitimate interest (security)
Usage: actions performed, credit consumptionRun the Solution, show your consumption, provide support, improve the SolutionPerformance of the contract; legitimate interest (improvement)
Notifications: email, content of notifications (weekly summary, alerts)Keep you informed about your accountPerformance of the contract
Support: your exchanges with our teamAnswer your requestsPerformance of the contract
Billing: your company's billing detailsInvoice and collect paymentPerformance of the contract; legal accounting obligations

We do not collect civil status data, date of birth or identity documents. We never sell data and do not use Solution data for advertising.

3. Data contained in your company's documents

The documents your company connects or uploads (procedures, records, technical files, reports) may contain personal data: names, job titles, signatures, contact details of employees, suppliers or other people.

  • My audit corner processes them solely on behalf of the Customer and according to its instructions: analysis by the Solution, production of assessments, action plans, answers and documents, delivery of results.
  • No training: this data is never used to train or improve any artificial intelligence model, whether by us or by our providers.
  • No human review of the content, except at the Customer's request (support, performance of a service) or where technically necessary for maintenance, by authorised people bound by confidentiality.
  • It is hosted and processed in the European Union, on Google Cloud Platform; the AI models (Gemini, via Vertex AI) run in Belgium.
  • The Customer remains responsible for the lawfulness of the data it entrusts to the Solution. The Solution is not designed to process patient health data.

To exercise your rights over this data, contact the Customer (your employer or the company concerned); we will help it respond.

4. Retention periods

  • Account and usage: for the duration of the Customer's contract, then deleted no later than 60 days after it ends (30 days of reversibility, then 30 days for deletion).
  • Login and security logs: 12 months.
  • Data contained in the Customer's documents: for the duration of the contract, then deleted within the same timeframes. Connected documents remain in the Customer's own tools.
  • Invoices: 10 years (legal obligation).
  • Support exchanges: 3 years after the last exchange.

Residual copies may remain in backups for a few weeks before automatic rotation.

5. Recipients and processors

Your data is accessible only to authorised My audit corner staff. We use the following providers:

ProviderRoleData location
Google Cloud (Google Ireland Limited)Hosting of the Solution and data; Gemini AI models via Vertex AIEuropean Union (AI runs in Belgium)
SMTP2GOSending the Solution's emails (weekly summary, notifications). Receives the recipient's address and the email content; has no access to documentsEuropean Union (Netherlands); company established in New Zealand, a country recognised as providing adequate protection
StripeOnly for customers still paying by card. My audit corner never has access to card numbersEuropean Union and United States (Data Privacy Framework)

We may also disclose data to authorities where required by law.

6. Transfers outside the European Union

Customer documents and Solution data remain in the European Union. The only possible transfers concern card payments (Stripe, certified under the EU–US Data Privacy Framework) and SMTP2GO's New Zealand entity, covered by a European Commission adequacy decision.

7. Application cookies

The Solution only uses cookies that are strictly necessary for it to work: keeping your session open, securing your login, remembering your display preferences. They do not require your consent. The Solution sets no advertising or audience measurement cookies.

8. Security

  • Hosting on Google Cloud Platform in the European Union.
  • Encryption in transit and at rest; each customer's data is isolated.
  • Access limited to those who need it, and logged.
  • ISO 27001 process under way; penetration tests carried out by independent providers.
  • The Solution only contacts external services to read the document repositories connected by the Customer and to consult public databases such as EUDAMED.

If a data breach is likely to result in a high risk to your rights, we will inform you as soon as possible. For your part, choose a strong password used only for the Solution, and do not share it.

9. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and may set instructions regarding your data after your death. Some of your information can be changed directly in your account settings. For anything else, write to dpo@myauditcorner.com; we reply within one month and may ask you to prove your identity.

If you consider that your rights have not been respected, you may lodge a complaint with the CNIL (www.cnil.fr) or the supervisory authority of your country.

10. Changes

We may update this policy. In the event of a significant change, we notify users by email at least thirty (30) days before it takes effect. The date of the last update appears at the top of the page.