Legal
Audr AI Limited. UK Company No. 17147583.
This page explains how Audr AI Limited itself approaches data protection, security, and AI governance, as a company and as the provider of the Audr Platform. It is separate from the in-product Compliance module, which helps your organisation track its own obligations. Neither this page nor the Compliance module certifies that you, or Audr, comply with any law or standard. Both are designed to help you build an accurate, evidence-based picture and take informed action, with your own legal and compliance advisers.
Audr exists to help organisations get clarity on where they stand with AI adoption and move forward with confidence, not to create urgency around a looming deadline. We apply the same discipline to our own posture: we describe what we actually do, we do not claim certifications we do not hold, and we treat AI governance as an ongoing practice rather than a one-time compliance event.
Audr AI Limited is the controller for account and profile data of people who use the Platform directly, and acts as a processor on behalf of Customer organisations for the data those organisations collect through the Platform, for example Clarity questionnaire responses and Academy activity. Full detail is in our Privacy Policy. Data processing terms are available to Customers on request; contact us at [contact email] to request our Data Processing Agreement.
Access within the Platform is scoped by role: Owner, Admin, and Employee for Customer organisations, with a separately access-controlled internal system for Audr staff. [Confirm current hosting region, encryption-at-rest posture, and backup approach against the live production build before publishing; these are pending confirmation from engineering.]
Joy is Audr's AI assistant, built into every module of the Platform. Joy supports human judgement; it does not make decisions about people on its own, and it is not positioned as a decision-maker. AI output, including anything Joy or the Compliance module generates, is provided to inform your own review, not to replace it. It is not legal, financial, tax, medical, or other professional advice, and it does not certify compliance with any law or standard.
Two features carry a live internal caveat that we are transparent about here: peer nomination (a sociometric mapping feature considered for Clarity) is not enabled for any Customer while its own GDPR assessment is outstanding, and a longer-term concept sometimes referred to internally as an autonomous "Joy CEO" capability is explicitly not part of the current Platform and is not being built ahead of a separate internal decision. Neither is offered, described, or sold as a current capability.
We design our platform and practices with recognised frameworks in mind, including UK GDPR and the Data Protection Act 2018, the EU AI Act, the UK's developing approach to AI regulation, ISO/IEC 42001, and the NIST AI Risk Management Framework. We help Customers understand which of these frameworks are relevant to their own organisation and build evidence toward them through the Compliance module. We do not present that guidance, or this page, as certification that Audr or any Customer complies with any of these frameworks.
On timing: the EU AI Act's high-risk obligations are staged over several years, with the relevant high-risk provisions not due to apply until December 2027. There is no August 2026 deadline for the obligations most relevant to Audr's customers, and a standalone UK AI statute has not been enacted as of the date of this page. We describe this as an ongoing governance posture to build toward, not a compliance deadline to race against, and we keep this section current as the regulatory timeline develops.
[List any certification, audit, or third-party report Audr actually holds here, for example a specific ISO 42001 certificate, and remove this note. Do not state a certification Audr does not hold. As of this draft, none is confirmed.]
Audr uses a small set of providers to deliver the Platform and website. The confirmed list is pending sign-off against the live production build, since the environment used during Lovable-based development is a demonstration environment without a live database or connected third-party services. The confirmed sub-processor list will be published here and in our Data Processing Agreement once verified. [Do not name specific providers on this page until confirmed.]
Customers and prospective customers can request our Data Processing Agreement and any available security documentation by contacting us at [contact email]. Our Terms of Service, Privacy Policy, and Cookie Policy are available on our website.
For questions about this page, our data protection practices, or our approach to AI governance, contact us at [contact email].