Audnexa
SecurityModulesPricingFAQ
plPolski enEnglish deDeutsch frFrançais esEspañol itItaliano nlNederlands ptPortuguês csČeština skSlovenčina slSlovenščina hrHrvatski huMagyar roRomână bgБългарски elΕλληνικά daDansk svSvenska fiSuomi etEesti lvLatviešu ltLietuvių gaGaeilge mtMalti
Book a security walkthrough
SecurityModulesPricingFAQ For audit firms +48 12 200 27 10 Book a security walkthrough

Privacy Policy

Last updated: 24 June 2026

This policy describes how personal data of www.audnexa.com users is processed. Audnexa is a product of Virtline sp. z o.o., which is the data controller. We process data in accordance with the GDPR (Regulation (EU) 2016/679) and the Polish Personal Data Protection Act of 2018.

The site collects data: (1) voluntarily entered in the contact form, (2) automatically via server logs and cookies, (3) from connection parameters (IP address, browser and device information).

Data controller

The controller of personal data is Virtline sp. z o.o., ul. Wadowicka 8A, 30-415 Kraków, Poland, NIP 6751499701, KRS 0000502030.

Contact for data protection matters: biuro@virtline.com. Security matters: security@virtline.com. Phone: +48 12 200 27 10.

Purposes and legal bases of processing

We process data for the following purposes and on the following legal bases:

  • Handling contact-form enquiries and responding — Art. 6(1)(b) and (f) GDPR (steps taken at the data subject’s request; legitimate interest).
  • Operating and securing the website (logs, IP address, technical data) — Art. 6(1)(f) GDPR.
  • Traffic and quality analytics (Google Analytics 4) — Art. 6(1)(a) GDPR (consent given in the cookie banner).
  • Marketing communication — only on the basis of separate consent, Art. 6(1)(a) GDPR.
  • Contract performance, settlements and tax obligations for clients — Art. 6(1)(b) and (c) GDPR; pursuing claims — Art. 6(1)(f) GDPR.

Contact form

In the form we collect: name, organization, email, phone (optional), role, organization type and message content. The data is used solely to handle your enquiry and respond.

The submission is forwarded to the controller over a secure channel (a relay server / internal CRM or an email service). We do not use this data for marketing without separate consent.

Cookies and analytics

The site uses only essential mechanisms and — after consent — Google Analytics 4 (GA4). We do not use advertising cookies or marketing profiling.

GA4 loads only after you click “Accept” in the cookie banner; choosing “Essential only” does not start analytics. IP anonymization is enabled in GA4.

Your choice is stored locally in your browser (localStorage). You can withdraw consent at any time by clearing site data in your browser or blocking cookies in its settings. Restricting cookies may affect some site features.

Recipients and processors

Data may be entrusted to trusted processors solely under a contract, and disclosed to bodies authorized by law:

  • Cloudflare, Inc. — hosting and content delivery (CDN) of the site.
  • Google Ireland Ltd. — Google Analytics 4 (after consent).
  • The controller’s email provider / internal CRM — handling form submissions.
  • Public authorities and tax administration — where required by law.

Transfers outside the EEA

Some providers (e.g. Cloudflare, Google) may process data outside the European Economic Area. In such cases transfers rely on the Standard Contractual Clauses (SCC) approved by the European Commission or other GDPR-compliant mechanisms.

Retention periods

  • Correspondence and form submissions — for the time needed to handle the matter, then until any claims become time-barred.
  • Data processed on the basis of consent (analytics, marketing) — until consent is withdrawn.
  • Client data for tax and accounting purposes — 5 years from the end of the calendar year in which the payment deadline fell.
  • Data for pursuing claims — until the final conclusion of proceedings and the limitation of claims.

Your rights

You have the right to:

  • access your data and obtain a copy,
  • rectify (correct) your data,
  • erase your data,
  • restrict processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw consent at any time (without affecting the lawfulness of processing before withdrawal).

Complaints and automated decisions

You have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) if you believe processing infringes the GDPR.

We do not make decisions based solely on automated processing, including profiling, using your data.

Voluntary provision of data

Providing data is voluntary but necessary to achieve the stated purposes (e.g. answering your enquiry). For tax obligations, providing data may be required by law.

Changes to this policy

The controller reserves the right to amend this policy. Changes take effect upon publication on this page.

← Back to home

Audnexa

Auditable AI workspace for IT security and compliance reporting at regulated institutions.

Audnexa is a product of Virtline Sp. z o.o.

Product

Security Deployment Modules Pricing Trust Center

Company

Knowledge For audit firms Contact LinkedIn +48 12 200 27 10 biuro@virtline.com

Legal

Privacy policy DPA Terms security@virtline.com

Audnexa supports the work of auditors and compliance teams. It does not constitute a legal opinion, an auditor’s opinion, or a formal compliance decision.

© 2026 Virtline Sp. z o.o. All rights reserved. ul. Wadowicka 8A, 30-415 Kraków · NIP 6751499701

We use cookies for traffic analytics (GA4). Statistics load only after your consent. Privacy policy