AuditbyBureau← Back to site

Last updated July 2026

Privacy Policy

Draft — not legally validated

This document is a working draft under founder review. It is not legal advice and is not yet a binding legal notice. It will be finalised before Bureau Audit is offered to paying customers.

This policy explains how Bureau Audit (bureau-audit.ai) handles personal data on the public website and in administrator / organisation accounts, where Pillet Grenié Bureau (“Bureau”, “we”, “us”) is the data controller.

Bureau Audit is a business-to-business platform. When an organisation runs an audit of its own employees, that organisation is the controller of the employees’ (“participants’”) data and Bureau acts as its processor. How participant data is handled is governed by our Data Processing Agreement and by the privacy information shown to participants within the audit flow — not by this policy.

1.Who we are

The controller for the data described in this policy is Pillet Grenie Bureau L.L.C-FZ (“Bureau”), the entity operating the Bureau Audit service.

Free Zone Limited Liability Company · Meydan Free Zone, Dubai, U.A.E. · Formation no. 2647815 · Registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

For any privacy question or to exercise your rights, contact tom@pilletgreniebureau.com.

2.Data we collect

Website & administrator accounts (Bureau as controller)

  • Account identifiers: email address and authentication data managed through Supabase Auth, including optional Google sign-in.
  • Organisation details: organisation name, branding (colours, logo), and industry sector.
  • Billing identifiers: a Stripe customer identifier may be stored. Billing is dormant during early access (no charges).
  • Technical data: IP address (used transiently for rate-limiting) and error diagnostics captured by our monitoring tooling.

Participant data (Bureau as processor, on the client’s instruction)

When employees respond to an audit, we process — on behalf of the client organisation — their free-text responses, optional voice recordings and their transcripts, AI-generated individual profiles, and a hashed identity (see “Security”). This data is governed by the Data Processing Agreement. We describe it here for transparency only.

3.Why we use it, and on what legal basis

  • To provide the service (create and run audits, host the application) — performance of a contract.
  • To generate audit questions and analysis using AI models — performance of a contract and, for participant data, on the client’s documented instruction.
  • To send transactional email (team invitations, report-ready notices) — performance of a contract.
  • To keep the service secure (rate-limiting, error monitoring, abuse prevention) — our legitimate interest in operating a safe service.
  • Duty-of-care wellbeing escalation. On audits that use the dedicated wellbeing template, free-text responses are scanned for explicit signals of psychological distress; a match can trigger an alert email to the client’s administrators. This runs on the client’s instruction. It does not apply to other audit types.

We do not sell personal data and we do not use it for advertising.

4.Subprocessors

We use the following subprocessors to run the service. Where a region is marked “†”, data may be processed outside the EU, or the region / transfer safeguard is still being confirmed and formalised (see section 5).

SubprocessorPurposeRegion
SupabaseDatabase, authentication, and private file storage for voice recordings.EU (Frankfurt)
VercelApplication hosting and serverless compute. All requests transit Vercel.EU (Frankfurt)
Anthropic (Claude)AI generation of audit questions and analysis of responses into individual profiles.United States †
OpenAI (Whisper)Speech-to-text transcription of participant voice recordings.United States †
GoogleOptional sign-in identity provider for administrator accounts, brokered through Supabase Auth.Global (identity only)
Upstash (Redis)Rate-limiting counters for abuse prevention.EU
ResendTransactional email (team invitations, report-ready notices, wellbeing escalation alerts).EU-routed †
SentryApplication error monitoring (no analytics, no session replay).EU (Frankfurt)
InngestOrchestration of the AI analysis pipeline.Being formalised †
StripePayment processing. Configured but dormant during early access.Being formalised †
Bureau OS (internal)Bureau's own operations-monitoring database for cost/status dashboards. Read-only from the Audit application.EU

The list of subprocessors used for participant data, and the mechanism for notifying clients of changes, is set out in the Data Processing Agreement.

5.International data transfers

Personal data is stored in the EU (Frankfurt). Some subprocessors that perform processing on our behalf are based outside the EU — notably Anthropic, OpenAI, Inngest and Stripe (United States). The Bureau controlling entity is established in the United Arab Emirates.

Where data is transferred outside the EU/EEA, we rely on the transfer safeguards offered by each provider (such as Standard Contractual Clauses in their data processing terms). We are finalising and documenting these safeguards for Anthropic, OpenAI, Inngest and Stripe (United States), and confirming the email-routing region for Resend.commitment

6.How long we keep data

  • Raw responses: 18 months by default (a client may request a shorter period). commitment
  • Findings and verdicts: for the audit programme’s lifetime plus 24 months. commitment
  • Aggregated, k-anonymised results: retained indefinitely (they contain no individual data). commitment
  • Raw voice recordings: deleted 30 days after transcription; the transcript is kept under the response-retention rule above. commitment
  • Erasure log: kept for 3 years. commitment

These retention periods are our stated policy. Automated enforcement (scheduled deletion) is being implemented; until then, deletions are performed on request through a documented internal procedure.

7.Your rights

Subject to applicable law, you may request access to, correction of, deletion of, or a copy of your personal data, and you may object to or restrict certain processing.

  • Administrator / account data: contact us directly at tom@pilletgreniebureau.com.
  • Participants (employees): because your employer is the controller of your audit responses, please direct requests to your employer. Bureau will assist the employer in fulfilling them as its processor.

8.Cookies

Bureau Audit uses only strictly necessary cookies. There are no analytics, advertising, or third-party tracking cookies, so no cookie consent banner is required. The cookies we set are:

  • A participant session cookie (signed, HTTP-only, expires after 12 hours).
  • An administrator “acting organisation” cookie for super-admin support access (HTTP-only, expires after 4 hours).
  • Supabase authentication cookies for signed-in administrators.

We use Sentry for error monitoring. It does not set browsing or tracking cookies.

9.AI transparency

Bureau Audit uses AI models to run audits. For transparency:

  • Anthropic’s Claude models generate audit questions and analyse responses into individual profiles.
  • OpenAI’s Whisper model transcribes voice recordings into text.
  • On wellbeing-template audits only, a curated keyword detector scans free-text responses for signals of psychological distress (see section 3).

The platform does not make automated decisions producing legal effects about individuals; audit outputs are reviewed by the client organisation.

10.How we protect data

Security measures include row-level security on every database table, encryption in transit, hashed participant identities, a private storage bucket for voice recordings accessible only server-side, a k-anonymity gate on aggregated reporting (a floor of five distinct participants per band by default), rate-limiting, and a strict error-monitoring configuration that strips request bodies, cookies, and authorization headers. Full detail is in the Data Processing Agreement.

11.Changes & contact

We will update this policy as the service evolves and will revise the “last updated” date above. Questions: tom@pilletgreniebureau.com.