This privacy notice explains how PROOF RESEARCH LIMITED (“we”, “us”) handles personal data when you use Oditable, our UK B2B audit-readiness service, and related websites and support channels. It is written for organisations and the people who use Oditable on their behalf.
01 Who we are
Oditable is provided by PROOF RESEARCH LIMITED, a company registered in England and Wales (company number 16999522), whose registered office is 284 Water Road, Wembley, England, HA0 1HX.
Privacy questions and data-protection requests: admin@proofresearch.info.
02 Controller and processor roles
Proof Research Limited is the controller for account, billing, website, product-usage, support, security and direct-marketing data. That includes the records we need to create and manage accounts, take payment, operate the product, secure it, and respond to support requests.
Customer organisations are normally the controllers for audit queries, documents, evidence, auditor details and accounting data they place in Oditable. In those cases, Proof Research Limited processes that material to provide the Oditable service. Roles can vary with a customer’s instructions, contracts or how a particular feature is used — we do not make an absolute determination for every scenario.
03 Data we process
Depending on how Oditable is used, we may process:
- Identity, account, contact, organisation and role data (for example name, email, organisation name, workspace role).
- Audit queries, drafted and approved responses, documents, evidence, citations, controls, approvals and audit-trail records.
- Connected accounting-system data and encrypted connection tokens when a customer connects Xero, QuickBooks or Sage.
- Billing and subscription references handled with Stripe. Card numbers are processed by Stripe; we do not store card numbers on Oditable systems.
- Security, device, browser, IP address, sign-in and diagnostic data.
- Support and service communications.
- Product analytics where you have consented to analytics cookies.
Sources include users, their organisations, invited auditors, connected providers (when configured), and automatic service and security logging.
04 Purposes and lawful bases
We process personal data for these purposes and bases:
- Contract — to provide Oditable, authenticate users, host customer content, run workflows, bill subscriptions and deliver transactional messages you need to use the service.
- Legal obligation — where we must keep records for tax, accounting, regulatory or similar duties, or respond to lawful requests.
- Legitimate interests — to secure, operate, support and improve the service (including preventing abuse, diagnosing faults, and understanding product reliability), balanced against your rights.
- Consent — for non-essential analytics cookies and, where used, direct marketing. You can withdraw consent at any time without affecting processing that relies on another lawful basis.
05 AI assistance and human review
Oditable uses AI to extract and index evidence, retrieve relevant material and draft responses to audit queries. Relevant content may be sent to configured AI processors such as Anthropic, Voyage AI, LlamaIndex/LlamaParse and Cohere.
AI drafts are not sent to auditors automatically; authorised people must review and approve them first. Oditable does not make solely automated decisions with legal or similarly significant effects about individuals.
06 Who we share data with
We use service providers to operate Oditable. Depending on configuration and customer choices, recipients may include:
- Railway — hosting, PostgreSQL, Redis, object storage and related infrastructure.
- Anthropic, Voyage AI, LlamaIndex/LlamaParse and Cohere — AI and document processing when those integrations are configured.
- Resend — transactional email.
- Stripe — billing and subscription payments.
- PostHog — product analytics, only after analytics consent.
- Sentry — error and diagnostic monitoring when configured.
- Xero, QuickBooks and Sage — only when a customer connects those services.
- Professional advisers or authorities where we are legally required to disclose information.
Oditable does not sell personal data. We do not use personal data for behavioural advertising.
07 Cookies and similar technologies
- Necessary cookies for authentication, security and remembering essential preferences (for example theme or language where stored locally for the product to function).
- PostHog analytics cookies only after you give positive consent.
You can change preferences using the cookie control or banner in the product (including Cookie preferences under Settings → Security). Declining analytics does not block the core Oditable service.
08 International transfers
Some providers may process personal data outside the United Kingdom. Where that happens, we rely on UK adequacy regulations or contractual safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or Standard Contractual Clauses, as applicable. For more detail about the safeguards that apply to a specific transfer, contact admin@proofresearch.info.
09 How long we keep data
We retain active-account and customer content while it is needed to provide the service and to meet contractual, legal and security obligations. Exact periods depend on account state, the purpose of processing and applicable law.
When a customer schedules organisation deletion, there is a 14-day cancellation period, after which tenant data and stored files are deleted by the product workflow. Limited deletion, audit, transaction, security or legal records may remain where required. Backups expire on routine cycles and are not restored except for recovery, security or legal compliance needs.
Customers should set appropriate retention for audit material they upload or generate in Oditable.
10 Security
We apply technical and organisational measures appropriate to a multi-tenant B2B service, including access controls, tenant separation, encryption for sensitive integration tokens, and audit trails for key approval and send actions. No method of transmission or storage is completely secure; we do not claim an absolute guarantee against unauthorised access.
11 Your UK data protection rights
Under UK data protection law you have rights of access, correction, erasure, restriction, objection, portability and the right to withdraw consent, subject to legal limits. We may need to verify your identity before responding. We normally respond within one month.
To exercise these rights, email admin@proofresearch.info.
You can also complain to the Information Commissioner's Office (ICO). See the ICO data-protection complaints page.
12 Contractual necessity, age limit and updates
Some personal data is necessary to enter into or perform a contract for Oditable (for example account credentials and billing contacts). If you do not provide it, we may be unable to provide the service.
Oditable is not directed at people under 18. We do not knowingly collect personal data from children for this service.
We may update this notice from time to time. The “Last updated” date at the top will change when we do. Material changes may also be highlighted in the product or by email where appropriate.
13 Contact
PROOF RESEARCH LIMITED
Company number 16999522
284 Water Road, Wembley, England, HA0 1HX
Email: admin@proofresearch.info