Privacy Policy
Last updated: August 2026
Easy Audit is a product of Golden Phi. References to “we”, “us”, or “the operator” mean Golden Phi, which provides and operates this platform.
This Privacy Policy explains what information Golden Phi (“we”, “us”) collects when you use Easy Audit (“the platform”), why we collect it, who else can see it, and what you can ask us to do about it. It is written to be read, not to be skimmed past — if anything here is unclear, ask us and we will explain it.
Easy Audit is a cloud platform purpose-built for food, pharmaceutical, and regulated supply-chain organizations — including manufacturers, suppliers of raw materials, and producers of packaging & packaging materials (food-contact and pharma-contact). Manage compliance evidence, certificates, batch traceability, and audit readiness in one place — without spreadsheets and scattered files. Adjacent industries with comparable quality and traceability needs may also use the platform when its features match their operations.
When your company registers or is onboarded, you select an industry / sector. That choice tailors company profile templates, smart suggestions, and analytics to your business type.
1. Definitions
- Personal data — information that identifies a person, directly or indirectly.
- Controller — whoever decides why and how personal data is processed.
- Processor — whoever processes personal data on a controller's instructions.
- Customer — the organization that holds a subscription or account.
- Customer data — what your organization puts into the platform: audits, checklists, documents, assessments, action plans, traceability records and uploaded files.
- Sub-processor — a third party we use that processes data on our behalf.
2. Controller and processor — which is which
Both roles apply, in different places, and the difference decides who you should ask about what:
- We are the controller for account and billing data — the email and name used to sign in, login and security logs, subscription records, and messages you send us directly.
- We are the processor for customer data. Your organization decides what to put into the platform, who may see it, and how long to keep it. We act on its instructions and do not use it for our own purposes.
So if your question is about an audit record, a checklist answer, an assessment result, or your access inside a company workspace, your organization's administrator is the right first contact. If it is about your login, your subscription, or this policy, ask us.
3. Information we collect
3.1 Account information
Name, email address, password (stored as a hash — we never see or store it in readable form), role assignments, and whether two-factor authentication is enabled. We record sign-in activity and failed sign-in attempts to protect accounts against guessing.
3.2 Company information
Company name, industry sector, contact details you enter, company profile content, and — where you choose to publish it — the profile shown in the Community directory. The industry sector is stored to tailor templates and suggestions to your sector.
3.3 Audit, checklist and assessment data
Everything your organization records in the product: audits and checklist runs, findings, corrective actions (CAPA), action plans, quality documents and certificates, traceability and batch records, and assessment campaigns and their responses. Assessment responses can include the participant details your campaign asks for, such as name, department, job title, branch and time in position.
3.4 Open assessment links and integrity checks
An assessment campaign can be run as an open link — a single address shared with a group rather than a personal invitation per person. Because anyone holding that link can answer, we record two things with each response so the results can be trusted: the email address the participant enters, which identifies them and is what a later answer from the same person replaces, and the network (IP) address the answer was submitted from.
The network address is used only to review the integrity of the results — for example, several answers submitted under different email addresses from the same address are shown to the campaign owner for review. It is not used to block anyone: people attending the same training session or working in the same office normally share one network address, and refusing them would be wrong. It is not used for advertising, profiling or location tracking.
An open campaign may also be marked anonymous. The email address is still required there, because it is the only way to tell one participant from another on a link everyone shares — but in an anonymous campaign it is used solely to keep one answer per person, and it is not shown against the answers in any list, report or export the campaign owner can produce. Participants are told exactly that on the page where they enter it.
Participants are told this before they answer, on the page where they enter their details. The campaign owner — your organization, or the external auditor running the training — is the controller of these responses; retention follows section 10.
3.5 Uploaded files
Documents, images, certificates and evidence you upload. These are stored on the infrastructure described in section 6 and are visible only according to the permissions your organization sets.
3.6 Device and technical information
IP address, browser type and version, and session identifiers. These are used to keep the service running and secure — rate limiting, abuse prevention and troubleshooting — and are recorded in security logs.
3.7 Usage information on our public pages
On our public marketing pages (not inside your workspace) we record which page was visited, when, the referring page, the browser's user-agent string, and a one-way hash of the IP address rather than the address itself. This is used to count interest in the product. We do not use Google Analytics or any other third-party analytics service — this counting is done by our own software and the data stays with us.
3.8 Email addresses typed by visitors
If someone types an email address into our sign-in or contact forms without having an account, that address is recorded together with the form it came from, a hash of the IP address and the browser's user-agent. We use it to understand where interest in the platform comes from. We do not send marketing email to these addresses. If you would like an address like this deleted, ask us and we will remove it.
3.9 Communications
Messages you send through Contact Us, support requests, and the community messages and chat requests you send other users of the platform.
3.10 Payment information
Payments are handled by Paddle, which acts as merchant of record. Card details are entered on Paddle's own checkout and go to Paddle, not to us. We do not receive or store complete payment card numbers. We keep the subscription and invoice records Paddle returns to us — plan, amount, status, billing country.
4. How we use information
- To provide and operate the platform and the features you use.
- To authenticate users and enforce the permissions your organization sets.
- To send operational email: invitations, password resets, expiry and task reminders, assessment invitations, and notifications you have not switched off.
- To keep audit trails, detect abuse, and investigate security incidents.
- To take payment and manage subscriptions.
- To answer support requests.
- To understand which parts of our public site draw interest, in aggregate.
- To comply with legal obligations.
We do not sell personal data, and we do not use customer data to train machine-learning models.
5. Legal bases for processing
Egyptian law governs our processing: Personal Data Protection Law No. 151 of 2020 and its Executive Regulations issued by Decree No. 816 of 2025. It applies to everything we do, not only to some customers, because Golden Phi is established in Egypt.
We do not rely on consent for things that keep the service running. Asking for consent to log a failed sign-in, or to hash a password, would be asking a question we could not honour a "no" to — and treating consent that way makes it worthless in the two places where it is real.
5.1 What we rely on, activity by activity
| What we do | Why we are allowed to |
|---|---|
| Create and run your account; sign you in; two-factor authentication | Performance of the contract. There is no service without it. |
| Send you a password reset code | Performance of the contract, at your request. |
| Service email — notifications, reminders, approval requests | Performance of the contract. These are the product working, not marketing, and they are not switched off by unsubscribing from marketing. |
| Security logging, failed sign-in records, rate limits, lockouts | Legitimate interest in keeping accounts and customer data safe. We weighed this against your interests and kept only what an investigation actually needs, for the period in section 10. |
| Storing and processing what your organization puts in the platform — audits, assessments, files, corrective actions | On your organization's instructions. They are the controller and the basis is theirs to determine; we act on it and nothing else. |
| Sending an assessment invitation to an employee, supplier or customer of one of our customers | On that organization's instructions. They decide who is asked and why. If you received one and want to know why, ask them — they can answer it and we cannot. |
| Counting visits to our public pages | Legitimate interest in knowing which pages are read. We store a hash of the IP address rather than the address, so the count cannot be turned back into a person. |
| Recording an email address typed into a sign-in or contact form by someone with no account | Legitimate interest in understanding where interest comes from. See section 3.8 — we do not send marketing to these addresses, and we will delete one on request. |
| Marketing email | Consent, and you can withdraw it in one click — see section 14.1. |
| Backups | Legitimate interest in being able to restore the service and your data after a failure. |
| Invoices, tax and accounting records | Legal obligation. This is the one period we cannot shorten at your request. |
| Responding to a lawful request from an authority | Legal obligation. We disclose only what the request actually requires. |
5.2 Where the GDPR also applies
Where the GDPR applies as well — see section 20 — we rely on these bases:
- Contract — providing the platform to you and your organization, managing accounts, and taking payment.
- Legitimate interests — keeping the service secure, preventing abuse, and understanding interest in our public pages. We balance these against your interests, which is why the public-page counting uses a hashed IP address rather than the address itself.
- Legal obligation — tax, accounting, and responding to lawful requests from authorities.
- Consent — where we ask for it explicitly. You can withdraw consent at any time; withdrawing it does not affect processing already carried out.
For customer data we process on your organization's instructions, the legal basis is your organization's to determine as controller.
6. Where the platform runs, and who else touches data
We use a small number of sub-processors. Each one is listed here with what it does and where it runs:
- Amazon Web Services (AWS) — hosts the application servers and stores uploaded files. Region: Europe (Stockholm).
- Neon — managed PostgreSQL database hosting, running on AWS infrastructure in Europe (London).
- Paddle — payment processing and merchant of record. See Paddle's own privacy notice for how it handles payment data.
- Namecheap Private Email — delivery of outgoing email sent by the platform: invitations, password resets, reminders and notifications. The message and the recipient's address pass through this service. Assessment campaign invitations are sent from a separate sending domain from the rest of our mail, so that a large campaign cannot delay or affect delivery of the messages someone is waiting on, such as a password reset. It is the same provider and the same handling either way; only the address the message comes from differs.
- Legal authorities — we disclose data where we are legally required to. This is not a routine sharing arrangement; we disclose only what the request actually requires.
We do not share customer data with advertisers, data brokers, or any third party for their own marketing.
7. International data transfers
The platform's servers and database are in the European Economic Area. Two transfers out of it are inherent to how the service runs, and we would rather name them than leave them implied:
- To us, in Egypt. Our staff administer and support the platform from Egypt, so data on those servers is accessible from there.
- To our email provider. Outgoing messages and the recipient's address pass through a provider established in the United States.
For each of these we rely on the transfer terms in the agreement with the provider concerned — in practice the European Commission's Standard Contractual Clauses, which those providers incorporate by default. If you need a copy of the terms covering a specific sub-processor for your own records, ask us and we will send what we hold.
8. Cookies
We use cookies that are necessary for the platform to work:
- Session cookie — keeps you signed in between pages.
- CSRF token — protects forms against being submitted from another site.
We do not use advertising cookies, and we do not embed third-party tracking cookies. Because our own page counting uses a hashed IP address rather than a cookie, there is nothing here to opt into or out of — but blocking the session cookie will stop you being able to sign in.
9. Multi-tenant separation
Each organization's data is separated by tenant. A user can reach only the companies and modules their membership or external grant allows, and every request is checked against those permissions. External auditors and certification bodies see only what a company has explicitly granted them, for as long as that grant is active. We do not read customer data except where it is necessary to provide support you have asked for, or to investigate a security incident.
10. Data retention
While an account is active we keep what the account needs. When it ends, these are the periods we commit to:
-
Customer data — kept for as long as your organization has an
open account with us. Your organization can delete records inside the
product at any time, according to the permissions it sets, and a company
administrator can close the account from inside the product in one of two
ways:
- Deactivate — the account is locked and nothing is deleted. Everyone at your organization is signed out; your administrators can still reach one page, the one that reopens it, and reopening restores access immediately. We keep the data for 90 days from the day it closes, we write to you 14 days before that period ends, and then we delete it.
- Delete — we write you a full export first, wait 14 days during which you can still call it off, and then permanently delete the company and everything in it. We email you when it has been carried out.
Both are requested from inside the product by a company administrator, and both ask that person to confirm before the request reaches us. We review every request before anything happens; nothing is carried out automatically on the strength of the request alone.
- Account data — name, email and role — is kept while the account exists and deleted with it.
- Security and audit logs — kept for 12 months. They are how a security incident is investigated after the fact, which is rarely the same week it happened.
- Email addresses typed by visitors — kept for 12 months from the last time we saw the address, and deleted sooner if you ask. See section 3.8.
- Public page visits — kept for 12 months. The row holds a hash of the IP address rather than the address itself.
- Our record of email we sent you — the address, the subject and whether it arrived, kept for 90 days. It is how we answer "did that message ever leave", and that question has never been asked about something older.
- Password reset codes — a code expires in 20 minutes; the record that one was issued is deleted after 7 days.
- If you unsubscribe from marketing — we keep your address indefinitely, and only for that purpose. It is the record that stops a later campaign reaching you, so deleting it would undo the very thing you asked for.
- Billing records — kept for as long as tax and accounting law requires, which is longer than the periods above and is not ours to shorten.
- What "deleted" means, and when — every period above is the day the data leaves the live system. Copies taken while it was still there go on existing until those copies are replaced, and there are two kinds: your own archives, a rolling set of by default the ten most recent per company and configurable by your organization, and our nightly database backup, which keeps 14 days.
- So the honest answer is two dates — the day it leaves the live system, and up to 14 days later when the last copy holding it is overwritten. Closing your account covers the archives too.
- Why we do not edit old backups — we could reach into them and cut a record out. We do not. A backup that has been edited is one we can no longer promise will restore, and we would rather be able to bring your data back than be able to say the tidying was perfect.
You can ask us to delete your data sooner; see Your rights below. Where the law requires us to keep something — an invoice, a record under investigation — we keep that and delete the rest.
11. Data security
What we actually do:
- HTTPS/TLS for all traffic in production.
- Passwords stored as salted hashes; optional two-factor authentication.
- Role-based permissions checked on every request, with tenant separation.
- A Content Security Policy that does not permit inline scripts, which limits the damage a cross-site scripting attempt could do.
- Rate limiting and lockouts on sign-in and other sensitive endpoints.
- Security logging of sign-ins, permission denials and administrative actions.
- Regular backups, which the organization can restore.
No system is completely secure, and we do not claim otherwise. We do not currently hold an ISO 27001 or SOC 2 certification, and this policy should not be read as claiming one.
12. If something goes wrong
If a personal data breach occurs, we will investigate, contain it, and notify affected customers without undue delay so that they can meet their own obligations as controllers. Where the law requires us to notify a supervisory authority, we will.
13. Customer responsibilities
Much of what happens to data in the platform is decided by the customer, not by us. If you administer an organization here, it is on you to:
- Give each person only the access their job needs, and remove it when they leave.
- Decide what data is appropriate to put into the platform, and tell your own staff that you are doing so.
- Have your own legal basis for the personal data you enter about employees, auditors, suppliers and assessment participants.
- Keep credentials confidential, and use two-factor authentication where it matters.
- Answer your own people's data requests about the records you control.
- Take care with public profile links and shared documents — what you publish, you publish.
14. Your rights
Depending on where you live, you may have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete.
- Deletion — ask for data to be erased, where no legal or contractual reason requires us to keep it.
- Portability — receive data you gave us in a structured, machine-readable format. The product's own export features cover much of this already.
- Restriction — ask us to limit how we use data while a dispute about it is resolved.
- Objection — object to processing we base on legitimate interests.
- Withdraw consent — where processing is based on consent.
- Complain — to the Egyptian Personal Data Protection Center, the authority that supervises us, or to your own local data protection authority if you are outside Egypt. You do not have to come to us first, though we would rather you did — most complaints are something we can simply fix.
Make a privacy request You do not need an account, and we answer within 30 days of you confirming your address.
Where to ask. If the data belongs to a company workspace — audits, assessments, your account inside an organization — contact that organization's administrator first; they control it and we act on their instructions. For anything we control, contact us directly and we will respond within the time the applicable law allows.
14.1 Withdrawing consent, and stopping marketing email
Marketing email is the one thing we send you on the strength of consent, and every marketing message carries an Unsubscribe link in its footer. Opening it and pressing the button is all it takes; you do not need an account, and you do not need to sign in. We keep a record of the address so that no later campaign reaches it — that record is the only reason the request keeps working, which is why we do not delete it.
Withdrawing consent does not affect anything we did before you withdrew it, and it does not stop the email the service has to send you: a password reset you asked for, a notification from an organization you work with, or an assessment your employer asked you to complete. Those are the product doing its job, not marketing, and they are governed by section 5.1 rather than by consent. If you want those to stop, the answer is with the organization that set them up.
For anything else you consented to, write to us at the address in section 19 and say so — there is no form to find.
15. Children's privacy
The platform is a business tool and is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us and we will delete it.
16. Third-party services and links
The platform loads Paddle's checkout when you subscribe, and our pages may link to other websites. Those services have their own privacy policies, and this one does not cover them.
17. Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significant effects. Scores calculated by the platform — assessment results, checklist scores — are produced for your organization, which decides what to do with them.
18. Changes to this policy
We may update this policy. When we do, the date at the top changes, and material changes will be communicated to account holders. Continuing to use the platform after a change means you accept the revised policy.
19. Contact
Questions about privacy, or a request about your data? Email help@geteasyaudit.org, or use our Contact Us page.
20. Who we are, and where
Golden Phi is established in Egypt. The servers and database that run the platform are in the European Economic Area (see section 6).
The GDPR sections of this policy apply to processing carried out when the platform is offered to people in the European Economic Area or the United Kingdom. Where that applies, Article 27 requires a representative inside those territories; we will appoint one and name them here before offering the service to customers established there.
We have not appointed a Data Protection Officer. Our processing is not the large-scale systematic monitoring, nor the special-category data, that makes one mandatory. Privacy questions and requests go to the contact above and are answered by us directly.