Privacy policy
How this application handles your data, and the short answer to why there is so little of it.
Audit NIS2 Complete collects nothing. It has no account system, contacts no server of ours, and contains no analytics, no advertising and no third-party SDK of any kind.
Audit NIS2 Complete is published by Ștefan Epistatu. Questions about this policy, or about anything the application does with data, go to the support address listed on the App Store product page.
Where you use the application to audit your own clients, you remain the controller of their data under Regulation (EU) 2016/679. The application is a tool running on your device; the developer neither receives nor processes that data and is therefore not a processor in respect of it.
Everything you enter is written to the application's private container on the device. Nothing in the list below leaves that container unless you deliberately export or share it.
| Data | Purpose | Location |
|---|---|---|
| Client records | Determining NIS2 applicability and running the audit file | On device |
| Evidence files | Chain of custody, integrity checks, control assessment | On device |
| Findings and CAPA | Audit conclusions and their treatment | On device |
| Audit trail | Tamper-evident record of every operation on the file | On device |
| Your profile | Name, role and organisation, printed on the reports you generate | On device |
If you have iCloud Backup enabled on your device, Apple's device backup may include the application's container, as it does for other applications. That backup is governed by Apple's privacy policy and by your own iCloud settings, not by us.
The application is bought once. An optional annual subscription delivers updated regulatory registries as national law changes.
Both are handled entirely by Apple through the App Store. Payment details are never seen by the application or by the developer. The application receives only whether a subscription is currently active and, where applicable, its renewal date. Apple's own privacy policy governs the transaction.
When you generate a report in PDF or Word, or send a document to a printer, the file is created on your device and handed to the system share or print sheet. Where it goes from there — a mail message, a cloud drive, a printer on your network — is your choice and is governed by whichever service you send it to.
Because no personal data reaches the developer, there is nothing held about you to access, rectify, port or erase. Your rights under Regulation (EU) 2016/679 nonetheless stand, and you may exercise them against us at any time — the honest answer will be that we hold no record of you.
Data held inside the application is under your control. Settings contains an option that permanently erases every client, audit, evidence item, finding, risk, incident and audit-trail entry from the device.
This is a professional tool for cybersecurity auditors and compliance officers. It is not directed at children and collects no data from anyone, including children.
If a future version of the application introduces anything that changes the answers above — synchronisation, a backend, a shared client portal — this policy will be revised before that version ships, and the version number and effective date at the top of this page will change with it.
Audit NIS2 Complete is published by Ștefan Epistatu, an independent developer established in Romania, in the European Union. For any question about this policy, or to exercise a right under Regulation (EU) 2016/679, write to privacy@support-remote.org.
No data protection officer is appointed: the developer carries out no processing of personal data that would require one under Article 37.