Everything your legal and security teams will ask for
Buying compliance software means a diligence review. This page exists to make that review short: what documentation exists, how to get it, and straight answers to the questions that normally take three email rounds.
Documentation
| Document | Status | How to get it |
|---|---|---|
| ISO 27001 certificate | Held | On request |
| SOC 2 report | Held | On request, under NDA |
| Privacy notice | Published | Read it now |
| Sub-processor list | Published | Read it now |
| Accessibility statement | Published | Read it now |
| Data Processing Agreement | In preparation | Ask and we will tell you where it stands |
| Security questionnaire response | Completed on request | Send us yours |
Where the Data Processing Agreement stands. The privacy notice establishes that your organisation is the data fiduciary for case, survey, training and attendance records and that we process them on your instructions — a relationship that requires a DPA. Ours is being drafted with counsel. We would rather say that than send you a template we have not had reviewed.
The questions procurement actually asks
- Where does our data live?
- In India. Production runs in the AWS Mumbai region, and an automated check fails the build if a non-Indian region is ever configured — so residency is enforced rather than promised.
- Can our HR team see an employee’s harassment complaint?
- No. Only the Internal Committee can open a PoSH case. HR, Compliance and the Data Protection Officer cannot, and that boundary is enforced in the database rather than in application code.
- Is our data used to train AI models?
- No. EECly contains no artificial-intelligence feature at all, so nothing an employee writes is sent to an AI provider.
- Who is the data fiduciary — you or us?
- It depends on the record, and the privacy notice sets out each one. For harassment, whistleblower, grievance, survey, training and attendance data the employer is the fiduciary and we process on your instructions. For employee wellbeing data we are the fiduciary and answer to the employee directly.
- What happens to data when we leave?
- Wellbeing and counselling data is destroyed irreversibly. Statutory records are retained because the law obliges you to hold them, and a legal hold pauses deletion while a case is open. We will walk the exit path with you before you sign, not after.
Reporting a security issue
If you have found a vulnerability, tell us at legal@annotatory.com and we will work with you on it. We do not pursue legal action against good-faith research. Our machine-readable contact is published at /.well-known/security.txt.