Your data

What happens to what you put in here.

Audit evidence is commercially sensitive. This tool is built to hold as little of it as possible, for as short a time as possible, and to let you destroy it the moment you no longer need it.

What is stored

  • The audit's name, type and any reference you give it.
  • The two email addresses in the audit — one manufacturer, one auditor.
  • Each request: what was asked for, any detail, and the due date.
  • The files uploaded in answer to those requests, exactly as supplied.
  • The discussion on each request.
  • A dated record of every action taken, and who took it.

What is not stored

  • No passwords. Sign-in is a one-time link sent to your email address.
  • No payment details. The tool is free to use.
  • No analytics, advertising or tracking of any kind. There are no third-party scripts on any page that handles audit evidence.
  • No cookie banner, because there is nothing to consent to. Two cookies are set and both are strictly functional: one keeps you signed in, and one remembers whether you chose the light or dark appearance. Neither is shared with anyone, and neither is used to identify or follow you.
  • No copies of your files anywhere else. They are not sent to any other service, and they are never used to train anything.

Where it is held

  • In the European Union — Supabase, hosted on AWS in Ireland (eu-west-1). Data is not replicated outside the EU.
  • Files are stored privately. There is no public URL for any document. When you open one, the tool mints a link that works for sixty seconds and is never stored.

Who can reach it

  • Only the two people in that audit — the manufacturer and the auditor who accepted the invitation.
  • This is enforced by the database itself, not by the interface. Every query is filtered by audit membership in Postgres, so there is no request, valid or otherwise, that returns another audit's data.
  • An invitation only works for the email address it was sent to. Forwarding it does not pass on access.
  • The auditor sees only what has been attached in answer to their own requests. There is no file browser and nothing is shared until the manufacturer deliberately submits it.

How long it is kept

  • While an audit is open, nothing is deleted automatically.
  • Closing an audit freezes it and schedules everything in it — requests, files, discussion and the record — for destruction thirty days later.
  • Either party can delete an audit outright at any time, without waiting. That removes the files from storage and the records from the database. It cannot be undone, and there is no backup we can restore from on request.
  • Before deleting, you can download the complete record as a single page to file or print.

Who else is involved

  • Supabase — database, file storage and sign-in links (EU region).
  • Vercel — runs the application.
  • Resend — delivers invitation and sign-in emails. Sees the recipient address and the message, not your audit contents.
  • That is the complete list. No analytics provider, no advertising network, no customer-messaging tool.

Questions, or want something removed?

You can delete any audit you are part of yourself, from its Settings page, without asking anyone. For anything else, contact hello@theotherconsultants.com.