Legal
Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how Prufing (“Prufing”, “we”, “us”) collects, uses, and protects information when you visit our website or use the Prufing service. If you use Prufing through your employer or another organization, that organization’s agreement with us governs how its data is handled, and this policy applies in addition to it.
Our roles
For account information and website data, Prufing is the data controller. For the documents, evidence, and findings inside a customer workspace (“Audit Content”), the customer is the controller and Prufing is a data processor: we handle Audit Content only on the customer’s instructions and only to provide the service. Enterprise customers can put a Data Processing Agreement in place with us; contact us at the address below.
Information we collect
- Account details — name, work email, organization, and role, provided when you sign up, are invited to a workspace, or contact us.
- Audit Content — the policies, exports, tickets, reports, and other evidence uploaded to a workspace, and the drafts, verdicts, citations, and workpapers produced from them.
- Usage and device data — log data (IP address, browser type, pages viewed, timestamps), and product events needed to operate, secure, and improve the service.
- Cookies and similar technologies — see “Cookies and analytics” below.
- Communications — messages you send us (support, sales, feedback) and our replies.
How we use information
We use personal data to:
- provide, operate, and maintain the service (performance of contract);
- run audits against uploaded evidence and generate cited findings (performance of contract, on the customer’s instructions);
- secure the platform, prevent abuse, and debug problems (legitimate interests);
- provide support and communicate about the service (performance of contract / legitimate interests);
- send product or marketing communications where permitted, with an opt-out in every message (consent / legitimate interests);
- comply with legal obligations.
We do not sell personal data, and we do not share Audit Content for advertising.
AI processing
Prufing uses large language models to read evidence, test controls, and draft findings. Three commitments apply:
- No training on your content. We do not use Audit Content to train our own models, and we contract with model providers on terms that prohibit them from using it to train theirs.
- Processing, not decision-making. Model output is a draft for a human auditor to review; nothing is auto-accepted. Findings do not produce legal effects about individuals without human review.
- Traceability. Findings cite the evidence they rest on, and the original documents are retained so any conclusion can be checked.
Sub-processors and sharing
We share personal data only with:
- Infrastructure and service providers — cloud hosting, storage, and email providers that help us run the service, bound by confidentiality and data-protection obligations;
- AI model providers — solely to process the specific content submitted for analysis, under no-training and confidentiality terms;
- Professional advisers and authorities — where required by law, to protect our rights, or in connection with a corporate transaction (with notice where legally possible).
A current list of sub-processors is available on request. For on-prem or private-cloud deployments, Audit Content stays in the customer’s environment and is not sent to us or our sub-processors.
International transfers
We are based in Singapore and use service providers that may process data in other countries. Where personal data subject to the GDPR or similar laws is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses.
Cookies and analytics
The website uses only the cookies needed to run it. Analytics (Google Tag Manager / GA4) load only after you accept the consent banner — we default all consent-mode categories to “denied” until you choose. You can change your choice by clearing the site’s stored data in your browser. The product itself uses a session cookie to keep you signed in.
Security and retention
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of audit data — workspace isolation, object-level authorization, and least-privilege access among them; see our Security page. We keep personal data only as long as needed for the purposes above: account data for the life of the account plus a short administrative period; Audit Content for as long as the customer keeps it in the service or as their agreement specifies; logs for a bounded operational window. On termination, customers can export Audit Content before deletion.
Your rights
Depending on where you live (including under Singapore’s PDPA, the EU/UK GDPR, and the California CCPA), you may have rights to access, correct, export, delete, or restrict the processing of your personal data, to object to processing, and to withdraw consent. To exercise them, contact us below; if your data is in a customer’s workspace, we may refer the request to that customer as controller. You also have the right to complain to your local data-protection authority.
Children
Prufing is a business service and is not directed at children under 16. We do not knowingly collect their data.
Changes
We will post any changes to this policy here and update the date above. For material changes affecting how we handle Audit Content, we will notify customers directly.
Contact
Privacy questions or requests: support@prufing.com.