Privacy policy
1. Who we are
This policy describes how Optywise (“we”, “us”), a company incorporated in India with its registered office at 513, Ambrosia Galaxy, Pancard Club Road, Baner, Pune 411045, India, handles personal data in connection with the Auditwyse platform and this website.
2. Scope
This policy covers two different kinds of data, and our role differs between them.
- Customer content. Documents, evidence and records that a customer organisation uploads to Auditwyse. We process this on the customer's instructions, as a data processor. The customer decides what is uploaded and why.
- Account and website data. Information about the individuals who administer or use an Auditwyse account, and visitors to this website. We act as a data controller for this.
3. What we collect
- Account data. Name, work email address, organisation, and role.
- Customer content. The documents and evidence uploaded to the platform, and any assessment output derived from them.
- Service logs. Records of activity in the platform, including which documents were assessed and which review decisions were recorded, retained so that an audit trail exists.
- Technical data. IP address and request metadata generated when the platform is accessed.
- Chat history. What you type in the console chat and what the orchestrator replies, kept so you can return to earlier conversations. It is visible only to your own account, deleted with it, retained for one year, and never used to train any model.
We do not ask for, and Auditwyse is not intended to receive, special category personal data. Customers are responsible for what they choose to upload.
4. Why we process it
- To provide the platform and produce the assessments a customer has asked for.
- To maintain the audit trail that makes an assessment defensible, including who reviewed what and when.
- To secure the service, investigate incidents, and prevent misuse.
- To meet our legal and contractual obligations.
Where the Digital Personal Data Protection Act 2023, or the GDPR for customers in scope, requires a lawful basis, we rely on the performance of our contract with the customer, our legitimate interest in securing and improving the service, and consent where consent is the appropriate basis.
5. Subprocessors
We use third parties to host the platform and to perform document analysis: Amazon Web Services (hosting, United States), Neo4j AuraDB (graph database, United States) and OpenAI (document analysis, United States).
We will give customers notice before adding a subprocessor that processes customer content, in the manner set out in the applicable agreement.
6. Where data is stored
Customer content is stored in the United States. Where data is transferred outside that region, we put in place the safeguards required by applicable law, including standard contractual clauses where they apply.
7. Retention
Customer content is retained for the term of the customer's agreement and then deleted within 30 days of termination, unless the customer asks for earlier deletion or we are required to keep it for longer by law. Service logs forming part of the audit trail are retained for 12 months, because deleting them would undermine the record they exist to provide.
8. Security
We apply access control, encryption in transit, and least privilege on the integrations Auditwyse holds. Cloud integrations are read only, and the write operations of the services they connect to are explicitly denied rather than merely unused. Specific technical and organisational measures are set out at optywise.com/security.
9. Your rights
Subject to the law that applies to you, you may request access to your personal data, correction of it, erasure, a copy in portable form, or that we restrict or stop certain processing. You may also withdraw consent where processing relies on consent.
If you are an employee of a customer organisation and your request concerns customer content, we will refer you to that organisation, because they determine how that content is used and we act on their instructions.
10. Grievance officer
Questions, requests and complaints about this policy can be sent to our grievance officer at consulting@optywise.com. We respond within 30 days. If you are not satisfied with our response, you may complain to the relevant supervisory authority.
11. Cookies and this website
Browsing these public pages sets no cookies at all. We run no analytics, no tracking scripts and no third-party embeds, and we load no fonts or assets from another domain. Visiting this site does not create a profile of you, and needs no consent banner because there is nothing to consent to.
Signing in to the Auditwyse console sets exactly one cookie, named
ecip_session. It holds a random session identifier and nothing else: no
name, no email address, and no account identifier. Its only purpose is to keep you
signed in between requests, which makes it strictly necessary for a service you asked
for, so it does not require consent either. It is marked HttpOnly so scripts on the
page cannot read it, SameSite=Lax so another site cannot cause it to be sent, and
Secure so it travels only over HTTPS. It is deleted when you log out, and expires on
its own within an hour.
We set no other cookies, for any purpose, at any point. Our hosting provider may keep standard server logs containing IP addresses for security purposes.
12. Changes
If we change this policy we will update the effective date above, and we will tell customers directly where the change is material.
13. Contact
Write to consulting@optywise.com or to the registered office given in section 1.