Privacy Policy
Last updated: 1 August 2026 · Applies to euaiactchecklist.com
This Privacy Policy explains how HumanAudit Inc. ("we", "us", "our") collects, uses, discloses, and protects personal data when you visit euaiactchecklist.com (the "Site") or purchase our products. We are committed to processing personal data lawfully and transparently in accordance with the EU General Data Protection Regulation (GDPR, Regulation EU 2016/679) and the EU ePrivacy Directive.
1. Data Controller
The data controller responsible for personal data collected on this Site is:
HumanAudit Inc.
A Delaware Corporation
Email: hello@euaiactchecklist.com
Website: euaiactchecklist.com
2. What Personal Data We Collect
We collect personal data in the following contexts:
2.1 Lead Magnet Form, When you request our free EU AI Act 5-Point Express Compliance Check, we collect: full name; work email address; company name (optional); and job role (optional).
2.2 Contact Form, When you send us a message via our contact form, we collect: full name; work email address; subject; and the content of your message.
2.3 Purchase Data, When you purchase a product, payment and order data is processed by Stripe (our payment processor and merchant of record). We receive: your email address; purchase details; order ID; and billing address (for VAT compliance). We do not receive or store payment card data.
2.4 Analytics Data, With your consent, we use Google Analytics 4 (GA4) to collect anonymised data about how visitors use the Site, including: pages viewed; time on site; browser and device type; and approximate geographic location (country/region level). IP anonymisation is enabled. No personally identifiable information is sent to Google Analytics without consent.
2.5 Technical Data, Like all websites, our server processes your IP address and browser headers to deliver web pages. This data is not stored beyond what is necessary for security and performance.
3. Lawful Basis for Processing
| Processing Activity | Lawful Basis (GDPR Art. 6) |
|---|---|
| Sending requested free resources | Art. 6(1)(b), Performance of a contract / pre-contractual steps |
| Responding to contact form enquiries | Art. 6(1)(f), Legitimate interests (responding to your request) |
| Processing product purchases | Art. 6(1)(b), Performance of a contract |
| Analytics cookies (GA4) | Art. 6(1)(a), Consent (via cookie banner) |
| Security and fraud prevention | Art. 6(1)(f), Legitimate interests |
4. How We Use Your Data
We use personal data for the following purposes:
- To deliver the free compliance resource you requested
- To process your product purchase and deliver your order
- To respond to your contact form enquiries
- To understand how visitors use the Site and improve our content (analytics, with consent)
- To comply with legal obligations
- To protect the security and integrity of the Site
We do not sell your personal data to third parties. We do not use your data for automated decision-making that produces legal or similarly significant effects.
5. Cookies and Tracking
We use the following types of cookies:
Essential cookies, Required for the Site to function (e.g. session management, security). These cannot be disabled. No consent required under the ePrivacy Directive.
Analytics cookies, Google Analytics 4 (GA4) cookies to understand site usage. These are only set with your explicit consent via our cookie banner. You can withdraw consent at any time by clicking "Cookie Settings" in the site footer or declining analytics on your next visit.
We do not use advertising, remarketing, or social media tracking cookies.
6. Data Sharing
We share personal data only with the following categories of recipient:
- Stripe (payment processing, tax compliance, and merchant-of-record services), processes purchase, order, and tax data as a data processor under Stripe's Data Processing Agreement. Stripe acts as merchant of record for VAT compliance in the EU, UK, and 80+ other jurisdictions.
- Google Analytics (web analytics, with consent), processes anonymised usage data in accordance with Google's Privacy Policy
- Hosting provider (server infrastructure), processes technical access data
- Legal authorities, where required by applicable law
All third-party processors are required to process personal data only for the specified purpose and in accordance with our instructions.
7. International Transfers
Our primary service providers (Stripe, Google) may process personal data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c).
8. Data Retention
- Lead magnet enquiries: Retained for up to 24 months from submission, or until you request deletion
- Contact form messages: Retained for up to 12 months from submission, or until the enquiry is resolved
- Purchase records: Retained for 7 years to comply with financial record-keeping obligations
- Analytics data: Aggregated analytics data retained for up to 26 months (GA4 standard retention) where consent is given
9. Your Rights Under GDPR
You have the following rights regarding your personal data, exercisable by contacting us at hello@euaiactchecklist.com:
- Right of access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate personal data
- Right to erasure (Art. 17): Request deletion of your personal data (subject to legal retention obligations)
- Right to restriction (Art. 18): Request restriction of processing in certain circumstances
- Right to data portability (Art. 20): Receive your data in a machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)): Withdraw consent for analytics cookies at any time without affecting prior processing
You also have the right to lodge a complaint with your national Data Protection Authority. A list of EU DPAs is available at edpb.europa.eu.
We will respond to all data subject requests within 30 days, extendable by a further 60 days for complex requests.
10. Security
We implement appropriate technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include SSL/TLS encryption for all data transmissions, access controls, rate limiting on form submissions, and honeypot anti-spam measures. However, no internet transmission can be guaranteed 100% secure.
11. Children
This Site is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at hello@euaiactchecklist.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via a notice on the Site. The "last updated" date at the top of this page reflects when the policy was last revised. Continued use of the Site after any change constitutes acceptance of the updated policy.
13. Contact
For any privacy-related questions, data subject rights requests, or complaints, please contact:
HumanAudit Inc., Privacy
Email: hello@euaiactchecklist.com
Subject line: "Privacy Request, euaiactchecklist.com"