Back to MRRaudit

MRRaudit Privacy Policy

Last Updated: September 1, 2026

This Privacy Policy explains how mrraudit.com (“MRRaudit,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data in connection with the MRRaudit service (the “Service”). It should be read together with the MRRaudit Terms of Service, which define certain capitalized terms used here.

1. Controller

For Contact Data (such as your name, email address, and organization name) and other personal data we collect directly from you, the data controller is ChartMogul GmbH & Co. KG, a company registered in Germany with its registered office at c/o WeWork, Kemperplatz 1, 10785 Berlin, Germany.

Where we process Customer Data on behalf of your organization (for example, billing or subscription data relating to your organization's own customers), your organization acts as the controller of that data, and MRRaudit acts as a processor on your organization's behalf, in accordance with our Data Processing Agreement.

2. Data Protection Officer

Our appointed Data Protection Officer for the EEA and UK is ePrivacy GmbH, represented by Prof. Dr. Christoph Bauer and Stefanie Bauer, Bei den Mühren 5, 20457 Hamburg, Germany.

You can contact the appointed data protection officer directly, for example, regarding particularly sensitive matters. You can find their email address in the legal notice at: https://www.eprivacy.eu/impressum

If you wish to communicate directly with our data protection officer (because you have a particularly sensitive matter for example), please contact them by post, as communication by e-mail could always have security gaps. Please state in your request that your concern relates to the company ChartMogul.

You can also reach us directly at privacy@chartmogul.com.

3. Personal Data We Collect

Depending on how you use MRRaudit, we may collect the following data:

Contact Data
Name, email address, organization name, and other information you provide when contacting us or requesting an audit.
Customer Data
Billing, subscription, invoice, and revenue data you upload or connect via Stripe, ChartMogul, or CSV file, together with the Audit Results and reports generated from that data by the Service. This may include personal data about your own customers, such as names, email addresses, and payment amounts, contained within your billing records.
Usage Data
Technical information necessary to operate and secure the Service, such as IP address, browser and device information, log data, diagnostic information, and information about how you use and interact with the Service, such as pages viewed, requests submitted, and features used.
Communications
Records of correspondence if you contact us for support or other inquiries.

We do not knowingly collect any special categories of personal data (for example, health, biometric, or similar sensitive data). Please do not upload or otherwise provide special categories of personal data unless specifically requested by us.

4. How We Use Your Personal Data

We use personal data to:

  • provide and operate MRRaudit (performance of our contract with you, Art. 6(1)(b) GDPR);
  • perform billing data audits (performance of our contract with you, Art. 6(1)(b) GDPR);
  • generate Audit Results (performance of our contract with you, Art. 6(1)(b) GDPR);
  • improve, maintain, and secure the Service (legitimate interests, Art. 6(1)(f) GDPR);
  • provide customer support (performance of a contract / legitimate interests, Art. 6(1)(b)/(f) GDPR); and
  • comply with legal obligations (Art. 6(1)(c) GDPR).

We process only the Customer Data reasonably necessary to perform the audit requested by you and to provide the Service.

We do not sell or disclose Customer Data except as described in this Privacy Policy or as instructed by you.

5. AI Processing

MRRaudit uses artificial intelligence to help analyze Customer Data and generate Audit Results.

To provide these features, relevant portions of your Customer Data may be processed using foundation models accessed through Amazon Bedrock within our AWS environment. We do not use your Customer Data to train or fine-tune foundation AI models.

AI-generated outputs are intended to assist your review and should not be considered accounting, legal, tax, or financial advice.

6. Third-Party Services You Connect

MRRaudit may access data from third-party services, including services you connect directly, in order to perform the requested audit. When you connect a service, you authorize MRRaudit to access the information made available through that integration for the purpose of providing the requested audit.

MRRaudit is provided by ChartMogul, the same company that provides the ChartMogul product. If you connect an existing ChartMogul account to MRRaudit, your use of ChartMogul itself remains governed by ChartMogul's own Privacy Policy and Terms of Service, which you agreed to separately. This Privacy Policy governs only how MRRaudit, as a related but separate service, uses the data obtained through that connection to generate Audit Results.

If you connect Stripe, or another service that is not provided by us, that service processes your data under its own privacy policy and terms, and we do not control, and are not responsible for, how it independently processes your data.

7. Our Subprocessors

We currently engage the following subprocessors to provide the Service:

  • Amazon Web Services (AWS), including Amazon Bedrock — hosting and AI processing.
  • ChartMogul — for customers who do not already use ChartMogul, we may create a temporary ChartMogul account on your behalf solely to generate Audit Results.

We may update this Privacy Policy from time to time to reflect changes to our subprocessors or data processing practices.

8. Data Retention

Where MRRaudit creates a temporary ChartMogul account solely to perform an audit, that account and its associated data are deleted within approximately seven days after completion of the relevant audit, unless a longer retention period is required by law.

Customer Data is otherwise retained for as long as necessary to provide the Service and is deleted or returned as described in our Terms of Service, except where we are required by law to retain it longer.

Contact Data is retained for as long as reasonably necessary to respond to your inquiries, provide the Service, and comply with legal or recordkeeping obligations.

Where data is deleted under this Section, residual copies may remain for a limited time in encrypted backups as part of our standard backup and disaster-recovery process, and will be purged in the ordinary course.

9. International Data Transfers

MRRaudit's infrastructure is hosted within the European Union. Personal data may nonetheless be transferred outside the EEA or UK in limited circumstances, for example, where a subprocessor's support function is based outside the EEA, or where you connect a third-party service (such as Stripe) that itself transfers data internationally. Where this occurs, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to protect that data.

10. Security

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or disclosure. No system or method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.

11. Your Rights

Subject to applicable law, you may have the right to access the personal data we hold about you, request correction or deletion, restrict or object to our processing, request a copy of your data in a portable format, and lodge a complaint with your local data protection authority. To exercise these rights, contact us at privacy@chartmogul.com.

If MRRaudit processes personal data on behalf of your organization, please contact your organization directly regarding the exercise of your rights. We will assist our customers in responding to valid requests where required.

If you are located in California, you have similar rights under the California Consumer Privacy Act, including the right to know what personal information we collect and to request its deletion. We do not sell personal information.

If you are located in the United Kingdom, you may also lodge a complaint with the UK Information Commissioner's Office (ICO).

12. Cookies

MRRaudit uses only cookies and similar technologies that are necessary to operate and secure the Service.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last Updated” date and, where appropriate, provide additional notice.

14. Contact

Questions about this Privacy Policy can be directed to privacy@chartmogul.com.