Legal
Privacy Policy
Effective: September 16, 2026. This version replaces the policy dated February 2026.
At a glance. This website, auditsuisse.com, including its French and Spanish editions and its campaign landing pages, is maintained and operated by Auditsuisse Assurance NA PC, a licensed US CPA firm, 1001 S Main St, Suite 500, Kalispell, MT 59901-5635, United States. It is a business-to-business website: we provide audit and attestation services to organizations and have no products or services for individual consumers. Auditsuisse Assurance NA PC alone operates the website and is responsible for the personal information collected through it, under United States federal and state privacy law. Our Swiss affiliate, Auditsuisse Assurance AG, does not operate this website and is responsible only for the engagements it delivers (Section 2). Questions and requests: [email protected].
1. Who operates this website
The website at auditsuisse.com (the "Website") is maintained and operated by Auditsuisse Assurance NA PC ("we," "us" or "our"), a professional corporation licensed as a Certified Public Accounting firm in the United States and enrolled in the AICPA Peer Review program. Our address is 1001 S Main St, Suite 500, Kalispell, MT 59901-5635, United States.
The Website includes the English pages at the site root, the French edition under /fr/, the Spanish edition under /es/ and the campaign landing pages under /lp/. This policy is written in English. The French and Spanish editions link to this English text, which is the version that applies.
A website for businesses
The Website is directed at businesses and the people who represent them: founders and compliance, security, finance, legal and procurement professionals evaluating audit and attestation services for their organizations. We offer no products or services to individuals acting in a personal or household capacity, we do not market to consumers, and the Website is not intended for anyone under 18. We do not knowingly collect information from children. Almost all of the personal information we handle is business contact information: a name, a work email address, a job title and an employer.
Applicable law
Auditsuisse Assurance NA PC operates the Website from the United States and processes Website information there. Our Website practices are governed by United States federal and state privacy and consumer-protection law, including Section 5 of the Federal Trade Commission Act and the state privacy laws that apply to us. Because we also serve organizations in the European Union, the United Kingdom and Switzerland, Sections 4, 7 and 9 describe the additional rules we follow when we process personal data of people located there, including the lawful bases we rely on and the authorities you can complain to.
Our Swiss affiliate
Auditsuisse Assurance AG, Badenerstrasse 47, 8004 Zurich, Switzerland, is a Swiss-registered Expert Auditor and licensed CPA firm affiliated with Auditsuisse Assurance NA PC. It does not maintain or operate the Website. It receives information collected through the Website only when it will deliver, or is delivering, an engagement for your organization, as described in Sections 2 and 6.
2. Who is responsible for your information
Each activity below has one responsible entity (the "controller" in European terms, the "business" in US state privacy laws). Where two entities are involved, the table says so.
| Activity | Responsible entity | Notes |
|---|---|---|
| Visiting the Website, including analytics, session replay, visitor identification and security logging | Auditsuisse Assurance NA PC | Operated from the United States. Auditsuisse Assurance AG does not operate the Website. |
| Enquiries, consultation bookings, quotes and proposals | Auditsuisse Assurance NA PC | If the engagement will be delivered by Auditsuisse Assurance AG, we pass your enquiry to it and it becomes responsible from that point. |
| Marketing communications | Auditsuisse Assurance NA PC | Sent with your consent or to existing business contacts, with an opt-out in every message. |
| Delivering an audit or attestation engagement | The entity named in your engagement letter | Auditsuisse Assurance NA PC contracts and issues reports for engagements performed under AICPA standards. Auditsuisse Assurance AG contracts the engagements it performs as a Swiss-licensed audit firm. Where both entities contribute to one engagement, the engagement letter names the responsible entity and the other entity acts on its behalf. |
| Professional recordkeeping, peer review and regulatory oversight | Each entity for its own obligations | Auditsuisse Assurance NA PC: the AICPA Peer Review program and state boards of accountancy. Auditsuisse Assurance AG: the Swiss Federal Audit Oversight Authority. |
| Job applications | The entity hiring for the role | Auditsuisse Assurance NA PC for roles in the United States; Auditsuisse Assurance AG for roles in Switzerland. |
3. Information we collect
When you visit the Website
Our systems and the service providers listed in Section 6 automatically receive: your IP address and the approximate location and network operator derived from it; browser and device characteristics such as browser type, operating system, screen size, language and time zone; the pages you view, how you reached them (the referring site and any campaign parameters in the link), the language edition you use and how long you stay; clicks, scrolling and other interactions with the page; and, for session replay, a reconstruction of your movements on the page with form fields masked. The visitor identification service described in Section 5 also produces the name of the organization your network connection is registered to. It identifies organizations, not people. Your privacy choice, once made, is stored in your browser and read locally, as Section 5 explains.
When you book a consultation or contact us
When you book a call through the "Book a Call" and "Request Consultation" links, the scheduling service (Cal.com) collects the name, email address, company and any notes you enter, and the time you choose. The link carries the page and language edition you came from, so that we know which page led to the booking. When you email us, we keep your message and our reply.
When you complete a form on a campaign landing page
Forms on our landing pages are provided by HubSpot. We receive the fields you enter, typically your name, work email address, company and answers about your compliance needs, together with the page the form was on.
During an engagement
Clients provide the information we need to perform the audit: system descriptions, policies and procedures, control evidence, personnel and vendor lists, access and change logs and similar records. These often contain personal information about the client's employees, contractors or customers. We process this information under the engagement letter and the professional standards that apply to the engagement, not through the Website. Requests about it should go to the client organization, which we will assist.
From other sources
To confirm who a company is and find the right people to speak with, we may combine the information above with publicly available business information, such as company websites, corporate registers and professional networking profiles, and with data from business information providers.
4. Why we use information, and our lawful basis
The table lists each purpose, the information involved and, for people located in the European Economic Area, the United Kingdom or Switzerland, the lawful basis under the GDPR, the UK GDPR or the Swiss Federal Act on Data Protection. For US residents, these are the business purposes for which we collect and use personal information.
| Purpose | Information | Lawful basis (EEA, UK, Switzerland) |
|---|---|---|
| Answering enquiries and scheduling consultations | Contact details, your message, booking details | Steps you ask us to take before entering a contract; our legitimate interest in responding to business enquiries |
| Preparing proposals and engagement letters | Contact and company details, scoping information | Steps taken at your request before entering a contract |
| Delivering audit and attestation engagements | Engagement information (Section 3) | Performance of our contract with the client; compliance with professional standards (legal obligation); our legitimate interest, and the client's, in performing the engagement where the information concerns the client's staff or customers |
| Operating, securing and improving the Website, including analytics and session replay | Website visit information | Your consent if you are in the EEA, the UK or Switzerland, which we ask for before these tools run; elsewhere, our legitimate interest in understanding how the Website is used, fixing problems and preventing abuse, with an opt-out (Section 5) |
| Identifying the organizations that visit the Website and following up with them | IP address, device and browser characteristics, pages viewed | Your consent if you are in the EEA, the UK or Switzerland, which we ask for before this tool runs; elsewhere, our legitimate interest in understanding which organizations are interested in our services, with an opt-out. Identification is at the organization level and the identifiers are short-lived (Section 5) |
| Sending industry updates and service information | Contact details, your history with us | Your consent, or our legitimate interest in keeping in touch with existing business contacts, always with an opt-out |
| Security, fraud prevention and defending legal claims | Logs, correspondence, records of requests | Our legitimate interest in protecting our systems, clients and rights; legal obligation |
| Professional recordkeeping, peer review, regulatory inspections, tax and accounting | Engagement records, invoices, correspondence | Legal obligation; our legitimate interest in demonstrating compliance with professional standards |
| Recruitment | Application materials | Steps taken at your request before entering a contract; our legitimate interest in assessing candidates |
We do not sell personal information, we do not share it for targeted (cross-context behavioral) advertising, and we do not make decisions about you by automated means that have legal or similarly significant effects.
5. Analytics, session replay and visitor identification
The Website does not set cookies. Apart from the record of your own privacy choice, described under "The privacy preferences bar" below, it stores nothing in your browser without your consent. It uses three measurement services, each of which processes data in the United States. The first two run only as your privacy choice allows:
- Product analytics and session replay (PostHog, Inc.). PostHog records page views, clicks and other interactions, and session replays that reconstruct how you move through a page; form fields are masked in replays. We run PostHog in memory-only mode: it does not use cookies or browser storage, and the identifier it assigns is discarded when you close the page, so visits are not linked across sessions. PostHog collects nothing when your browser sends a Do Not Track signal.
- Visitor identification (Clay Labs Inc., through its Claydar script). This service uses your IP address together with browser and device characteristics to identify the organization your connection belongs to, and records the pages viewed, the referring site, the time spent and your browser's user-agent string. It identifies organizations, not individuals. It stores a device identifier and a session identifier in your browser's session storage, which your browser clears when you close the tab; it does not set cookies. Form entries, clicks and downloads are not captured.
- Cloudflare Web Analytics (Cloudflare, Inc.). Cloudflare, which hosts the Website, measures page views and performance without cookies or persistent identifiers, and keeps security logs of requests in order to protect the Website.
Fonts are served from our own servers, so loading a page sends no request to a font provider. The booking pages at Cal.com and the forms provided by HubSpot are governed by those providers' privacy policies as well as by this one.
The privacy preferences bar
A privacy preferences bar decides whether analytics, session replay and visitor identification may run. It works like this:
- Where you are decides which version you see. When you first arrive with no stored choice, the page asks the edge server of our hosting provider, Cloudflare, which already handles your request, which country your connection comes from. Your browser reads the reply and keeps only the two-letter country code. If you are in the European Economic Area, the United Kingdom or Switzerland, or if the country cannot be determined, nothing runs until you choose: the bar offers "Accept all", "Decline all" and "Customize", which lets you allow analytics and visitor identification separately and save your choices. Elsewhere, including the United States, these tools run and a one-time notice offers "OK" and "Opt out"; an opt-out takes effect from your next page.
- Browser signals are honored. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a decline and show no bar. Nothing is stored in that case: the signal is read again on every page, so if you stop sending it you are asked in the ordinary way.
- What is stored. Your choice is kept in your browser's local storage under the name "as_consent". It records whether each of the two purposes is allowed, which version of the bar you saw, the country code that was returned, whether you made the choice yourself or it follows from the one-time notice shown outside the consent regions, and the time. It is never sent to us or to anyone else; the page reads it locally to decide what may run. It is the only thing the Website stores without asking you first, and remembering your choice is the only reason it exists.
- How long it lasts. Six months, after which the bar returns. If we change the tools we use or the purposes they serve, we ask everyone again.
- Changing your mind. The "Privacy preferences" control in the footer of every page reopens the bar, where you can change or withdraw your choice at any time. On pages without the standard footer, the same control appears in the bottom-left corner of the page.
- What the bar does not control. Cloudflare Web Analytics uses no identifiers and cannot be switched off from the bar; a content blocker stops it if you prefer. Our hosting provider's security logging is necessary to serve the Website.
To have visitor identification records about your organization deleted, email [email protected].
6. Who receives your information
| Recipient | Who | Location | Why |
|---|---|---|---|
| Our affiliate | Auditsuisse Assurance AG, Badenerstrasse 47, 8004 Zurich | Switzerland | Delivering the engagements it is responsible for; shared engagement staff; group administration |
| Hosting, delivery and security | Cloudflare, Inc. | United States, with a global network | Hosting the Website (Cloudflare Pages), protecting it, cookieless web analytics |
| Product analytics and session replay | PostHog, Inc. | United States | See Section 5 |
| Visitor identification | Clay Labs Inc. | United States | See Section 5 |
| Scheduling | Cal.com, Inc. | United States | Booking consultations |
| Forms, contact records and email | HubSpot, Inc. | United States | Landing-page forms; storing enquiry and marketing contact records; sending updates |
| Professional reviewers | AICPA peer reviewers (Auditsuisse Assurance NA PC); the Swiss Federal Audit Oversight Authority (Auditsuisse Assurance AG) | United States; Switzerland | Peer review and oversight of licensed audit firms, which includes inspection of engagement files |
| Regulators, courts and authorities | State boards of accountancy, tax authorities, courts, law enforcement | Where required | When the law requires it, to respond to lawful requests, or to protect our rights |
| Professional advisers and insurers | Lawyers, accountants, insurers | United States; Switzerland | Advice, audits of our own firm, insurance and claims |
| A successor business | A buyer or successor of our practice | Depends on the transaction | If our practice or part of it is sold or merged, subject to this policy |
Providers act on our documented instructions under contracts that restrict what they may do with the information and require appropriate security. We do not sell personal information.
7. Where information is processed, and international transfers
Information collected through the Website is processed in the United States by Auditsuisse Assurance NA PC and the providers listed in Section 6. Engagement information is processed in the United States, in Switzerland or in both, depending on the entity named in the engagement letter and where the engagement team works.
If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data therefore leaves your country. We protect it as follows:
- Transfers to Switzerland. The European Commission and the United Kingdom recognize Switzerland as providing adequate protection, so no additional safeguard is needed.
- Transfers to the United States. Where a recipient is certified under the EU-US Data Privacy Framework, its UK Extension or the Swiss-US Data Privacy Framework, we rely on that certification. Otherwise our contracts with providers incorporate the European Commission's Standard Contractual Clauses, with the UK Addendum and the adaptations recognized by the Swiss Federal Data Protection and Information Commissioner where relevant. Transfers between Auditsuisse Assurance AG and Auditsuisse Assurance NA PC are made under an intra-group agreement based on the same clauses.
To obtain a copy or a summary of the safeguards used for a particular transfer, email [email protected].
8. How long we keep information
| Record | How long | Why |
|---|---|---|
| Your privacy choice | Six months in your own browser, or until we change the tools we use. It is never transmitted to us | Remembering what you chose |
| Website analytics events | Identifiers exist only in memory during your visit. Event data is kept for up to 26 months, then deleted or aggregated | Comparing usage over like periods |
| Session replays | No longer than 90 days | Diagnosing usability problems; replays are not needed after that |
| Visitor identification records | Up to 26 months | Understanding which organizations are interested in our services over a sales cycle |
| Security and access logs | Up to 12 months | Investigating incidents |
| Enquiries and bookings that do not lead to an engagement | 24 months after our last contact with you | Following up on the enquiry and answering questions about it |
| Marketing contact records | Until you opt out, or 24 months after your last interaction with us. Opt-out records are kept so that we continue to honor them | Keeping only active business contacts |
| Engagement working papers and evidence | Auditsuisse Assurance NA PC: at least seven years after the report date. Auditsuisse Assurance AG: ten years, as Swiss law requires | Professional standards and audit oversight rules; a client's engagement letter may set a longer period |
| Contracts, invoices and accounting records | Seven years (United States) or ten years (Switzerland) after the end of the relationship | Tax and commercial law |
| Records of privacy requests and complaints | 24 months | Demonstrating how we handled them |
| Job applications | 12 months after the decision, unless you agree to longer or join us | Answering questions about the decision; considering you for similar roles |
When a period ends we delete the information or make it anonymous. Where a legal hold, dispute or regulatory inquiry requires it, we keep the relevant records until the matter is closed.
9. Your rights and how to exercise them
Everyone
Wherever you are, you can ask what personal information we hold about you, ask us to correct or delete it, and opt out of marketing at any time by using the link in any message or by emailing us. Email [email protected] or write to Auditsuisse Assurance NA PC, Attn: Privacy, 1001 S Main St, Suite 500, Kalispell, MT 59901-5635, United States. Tell us which organization you contacted us from, so that we can find your records; we verify requests by replying to the email address on file. We respond within 30 days. If a request is complex we may take longer where the law allows, and we will tell you. There is no fee unless a request is manifestly unfounded or excessive. An authorized agent may act for you if you give us written authority.
If your information reached us as part of an engagement for your employer or another client organization, please contact that organization first: it is responsible for the information, and we will help it respond.
If you are in the EEA, the UK or Switzerland
You also have the right to restrict our processing, to receive the data you gave us in a portable format, to object to processing based on our legitimate interests, and to withdraw consent at any time without affecting earlier processing, including consent to analytics and visitor identification through the "Privacy preferences" control (Section 5). If you are unhappy with our response, you may complain to a supervisory authority: in the EEA, the authority of the country where you live or work, for example the CNIL in France or the AEPD in Spain; in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (edoeb.admin.ch). We would appreciate the chance to resolve your concern first.
If you are a US resident
Several US states give residents the right to know what personal information a business collects, to access, correct and delete it, to opt out of the sale or sharing of personal information and of targeted advertising, to appeal a refusal, and not to be discriminated against for exercising these rights. Many of these laws apply only to businesses above certain size thresholds and exclude information about people acting in a business or employment capacity, so they may not apply to us or to your information. We extend these rights to all US residents anyway, subject to the retention obligations in Section 8. We do not sell personal information or use it for targeted advertising, and we treat a Global Privacy Control signal as an opt-out request. If we refuse a request, you may appeal by replying to our decision; if you remain dissatisfied, you may contact the attorney general of your state or the Federal Trade Commission.
10. Security
We protect personal information with measures appropriate to its sensitivity: encryption in transit and at rest, multi-factor authentication and role-based access for our staff, logging and monitoring, vendor due diligence and staff confidentiality obligations. Client engagement evidence is exchanged through access-controlled platforms rather than email wherever possible, and access is restricted to the engagement team. No method of transmission or storage is completely secure; if a breach affects your information we will notify you and the relevant authorities as the law requires.
11. Changes to this policy
We will post any changes here with a new effective date. If a change materially reduces your rights, we will notify active clients and contacts by email before it takes effect. Earlier versions are available on request.
12. Contact
Auditsuisse Assurance NA PCAttn: Privacy
1001 S Main St, Suite 500
Kalispell, MT 59901-5635
United States
Email: [email protected]
For matters concerning an engagement delivered by our Swiss affiliate:
Auditsuisse Assurance AGBadenerstrasse 47
8004 Zurich
Switzerland
Email: [email protected]