This policy explains what information AuditPro collects through this system, why, how it is protected, and the rights you have over it. It is written to align with the Kenya Data Protection Act, 2019.
We collect a few categories of information in the course of operating this certification system. The first is account information: your full name, email address, phone number, national ID or passport number, role, and country. The second is audit records — details of the organisation being audited, compliance findings, non-conformities, evidence documents and photos uploaded during an audit, review comments, KPI assessment scores, and the resulting certification decisions. Once an audit is certified, we also keep certification records: the issued certificate itself, the certifier's signature, and the certificate's validity period. Finally, we keep a record of system activity — login and logout times, IP addresses, and other security-relevant actions — as part of the system's audit trail.
This information is used to operate the certification audit workflow end to end: assigning audits, conducting them, reviewing the findings, and certifying the result. We also use it to verify your identity whenever you sign in, including sending a one-time passcode to your registered email as part of login. Beyond the audit itself, the information is used to generate audit reports and certificates, and to maintain a security and compliance audit trail covering activity across the system.
Each client organisation's data is stored in its own isolated database, kept completely separate from every other organisation using this system. Passwords are never stored in a readable form — only as one-way cryptographic hashes that cannot be reversed back into the original password. Access to records is restricted by role, so auditors, reviewers, certifiers, and administrators can each see only what their role actually requires. All traffic to this system is encrypted in transit over HTTPS, sessions expire automatically, and an administrator can immediately suspend an account if access ever needs to be revoked.
We do not sell your information. It is shared only as needed to deliver the service — for example, with email/SMS providers to deliver login verification codes, and with the certification body as part of the audit and certification process itself.
Information is retained for as long as your account is active and for as long as audit and certification records are required to be kept for regulatory and certification-body purposes. You may request deletion of your account; certification records may need to be retained for a defined period even after account closure, as required by certification standards.
You may request access to, correction of, or deletion of your personal information by contacting your organisation's system administrator or the certification body directly.
This policy may be updated from time to time. The effective date above reflects the most recent update.