Skip to content

Legal

Privacy Policy

What we collect, why we hold it, how long we keep it, and what you can ask us to do with it.

Last updated: 13 August 2026

1. Who this policy covers

This policy applies to the Auditwithus website and to the Auditwithus application your business signs in to. Throughout, “we” means the operator of Auditwithus, and “you” means either a visitor to this site or a user of the application.

Where your employer holds an account, your employer is the owner of the business records inside it, and we process that data on their instructions.

2. What we collect

Information you give us

  • Account details — the name, role and branch your administrator sets up for you, and your activation key, of which we store only a one-way hash. The key itself is held nowhere, by us or by anyone.
  • Business records — the sales, purchases, stock movements, party balances, payroll entries and ledger postings you create while using the application.
  • Contact enquiries — the name, email address, company and message you submit through the contact form on this site.

Information collected automatically

  • Session cookie — signing in sets a cookie named itp_session that identifies your session. It expires after eight hours.
  • Technical logs — IP address, browser type and timestamps of requests, kept for security and troubleshooting.

This marketing site stores nothing in your browser at all.

3. Why we hold it

  • To operate the application and keep your business records available to you.
  • To authenticate you and enforce the permissions your role grants.
  • To detect and investigate misuse, fraud or technical failure.
  • To answer enquiries you send us.
  • To meet accounting and tax record-keeping obligations that apply to you.

We do not sell your data, and we do not use your business records to build advertising profiles.

4. Cookies

The application uses one strictly necessary cookie, itp_session, to keep you signed in. Without it you cannot use the application. Blocking it in your browser will prevent sign-in.

This marketing site sets no tracking or advertising cookies.

5. Sessions and devices

A company account may be open in one place at a time. If the same company is signed in elsewhere, the earlier session ends immediately and that device is signed out. This is deliberate: it makes it obvious when an account is being used somewhere you did not expect.

6. Who we share it with

We share data only where one of the following applies:

  • Hosting and infrastructure providers who run the servers on our behalf, under contract.
  • Your own organisation — administrators in your company can see the records their role permits.
  • Legal obligation — where we are required by law or a valid order to disclose information.

7. How long we keep it

Business records are kept for as long as your company account is active, and afterwards for as long as accounting and tax law requires you to retain them. Technical logs are kept for a short period for security purposes. Contact enquiries are kept only as long as needed to deal with them.

8. Security

Access is controlled by role and branch, and permissions are checked on the server rather than merely hidden in the interface. Approved vouchers are locked against editing and deletion so the audit trail cannot be quietly rewritten.

No system is perfectly secure. If you believe an account has been misused, contact us at [email protected] straight away.

9. Your rights

You may ask us to give you a copy of the personal data we hold about you, to correct it if it is wrong, or to delete it where we are not required to keep it. If your employer owns the account, we will pass your request to them, as the records belong to their business.

10. Changes to this policy

If this policy changes materially we will update the date at the top of this page and, where the change affects you directly, tell you inside the application.

11. Contact

Questions about this policy, or about data we hold, can be sent to [email protected].