Legal
Last updated: July 30, 2026
This addendum forms part of the agreement between Auditmark and your organization (the customer) and applies whenever the content your organization stores in Auditmark includes personal data. For that data, your organization is the controller and Auditmark is the processor. Where the GDPR applies, this addendum is the data processing agreement required by Article 28; it is also written to satisfy the Israeli Privacy Protection Law and the Data Security Regulations.
Auditmark processes customer personal data only on the customer's documented instructions: the agreement, this addendum, and the configuration the customer's administrators set in the product. Auditmark tells the customer if, in its view, an instruction breaks data-protection law, and may pause that instruction until it is resolved. Auditmark does not sell customer personal data and does not use it for advertising or to train AI models.
People authorized to process customer personal data are bound by confidentiality obligations and receive access only to the extent their role requires. Administrative access to production systems is limited and logged.
Auditmark applies the technical and organizational measures in the annex below, and keeps them under review as risk and technology change. A summary written for a wider audience is on the security page.
The customer gives general authorization for the subprocessors listed at auditmark.io/subprocessors. Auditmark imposes data-protection obligations on each subprocessor equivalent to this addendum and remains responsible for their performance. Auditmark announces additions or replacements at least 30 days before they take effect; a customer that objects on reasonable data-protection grounds may terminate the affected service and receive a pro-rated refund of prepaid fees.
Taking the nature of the processing into account, Auditmark assists the customer with data subject requests (access, correction, deletion, portability, objection), with security and breach obligations, and with data protection impact assessments. Where a data subject contacts Auditmark directly about data controlled by a customer, Auditmark routes the request to that customer.
Auditmark notifies the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. The notice describes the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, and is updated as the investigation progresses.
Customer personal data is processed in Israel, the European Economic Area, and the United States, by Auditmark and the listed subprocessors. Israel holds a European Commission adequacy decision. Where a transfer requires an additional safeguard, the parties rely on the European Commission's standard contractual clauses, which are incorporated into this addendum for that transfer.
During the subscription, the customer deletes data through the product. When the subscription ends, the customer has 30 days to export its content, after which Auditmark deletes customer personal data from production systems, with backups expiring on their normal rotation. Auditmark retains data past that point only where law requires it.
Auditmark makes available the information reasonably necessary to demonstrate compliance with this addendum, starting with documentation and completed security questionnaires. Where that is not sufficient, the customer may audit once per 12 months, on at least 30 days' notice, during business hours, without access to other customers' data, and at its own cost.
Liability under this addendum is governed by the liability section of the terms of service. If this addendum conflicts with the terms on a data-protection matter, this addendum wins.
Questions about this addendum, or a signed copy for your records: hello@auditmark.io.