Legal
Privacy Policy
Effective date: 1 January 2026 · Last updated: 1 January 2026
1. Who We Are
AiR — Audit It Right (“AiR”, “we”, “us”, “our”) is an independent internal audit firm operating in India and internationally. Our registered office is located at [REGISTERED OFFICE ADDRESS], India.
This Privacy Policy explains how we collect, use, and protect personal information submitted through our website www.audititright.com (“Site”), in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable data protection laws.
2. Data We Collect
We collect only the personal data you voluntarily provide via our contact form:
- First name and last name
- Email address
- Phone number (optional)
- Company / organisation name (optional)
- Nature of requirement (selected from a list)
- Message / enquiry text
We do not collect any sensitive personal data as defined under the DPDP Act. We do not use tracking cookies or analytics tools that collect personal identifiers.
3. Purpose of Processing
We process your personal data solely to:
- Respond to your enquiry
- Contact you to discuss your requirements
- Fulfil any subsequent engagement you enter into with us
We process your data on the basis of your explicit consent, given at the time of form submission. You may withdraw this consent at any time by contacting us at hello@audititright.com.
4. Data Sharing
We do not sell, rent, trade, or share your personal data with any third party except:
- Service providers — We use Formspree (formspree.io) to route contact form submissions to our inbox. Formspree acts as a data processor on our behalf and is subject to its own privacy policy.
- Legal obligation — We may disclose data if required by law, court order, or a competent regulatory authority.
5. Data Retention
We retain your personal data for no longer than 3 years from the date of your last interaction with us, or for the duration of any engagement, whichever is longer. After this period, data is securely deleted or anonymised.
6. Your Rights
Under the DPDP Act, 2023, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Erasure of your personal data (“right to be forgotten”)
- Withdraw consent at any time
- Nominate another person to exercise these rights on your behalf
To exercise any of these rights, email us at hello@audititright.com. We will respond within 30 days.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our Site uses HTTPS encryption for all data in transit.
8. Cookies
Our Site does not currently use cookies that collect personal data. If we introduce analytics or tracking tools in the future, we will update this policy and display an appropriate consent notice.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page will reflect the most recent update. Continued use of the Site after changes constitutes acceptance of the updated policy.
10. Contact
For any questions, concerns, or data rights requests:
AiR — Audit It Right
[REGISTERED OFFICE ADDRESS], India
Email: hello@audititright.com
Website: www.audititright.com