HDI Audit

Data & security

Updated 5 October 2026

This page is for the quality, IT and procurement colleagues who review a supplier before the workshop. It sets out what HDI collects, where it goes, who can see it and how long we keep it. HDI Audit Platform is operated by DMM Consult SRL, Republic of Moldova, which is the controller of the data. The legal terms are in the privacy policy.

What data does the free screening collect?

Your work email, your company name if you give it, your industry, team size band, your answers to the questionnaire, the processes you select and the industry KPIs you enter. From these we calculate your scores. The screening does not ask for patient data, clinical records, batch numbers, product names, financial data or the names of your employees, and you should not enter them. If you open the screening from an automation partner's link, that partner receives this data too.

What data does the full audit collect?

The auditor, a certified person from your partner, records the workshop scores against the behavioural anchors, short notes and quotes that explain each score, and the role of each participant. Names are recorded only if you want follow-up questions to go to a specific person. The written report describes processes and roles. It does not attribute statements to named people, and it contains no patient data. If a document is needed to check an answer, the auditor looks at it with you in the session; the auditor does not ask you to send controlled documents.

Who processes the data?

A small number of service providers run parts of the service for us, under data-processing terms and on our instructions:

Some of them may process data outside the European Economic Area. Where they do, the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard. We do not sell data.

What happens when a partner is involved?

If you open the screening from an automation partner's link, the consent screen names that partner before the first question. Your answers, results and contact details go to that partner, which is an independent controller for its own use of them. A partner can receive them in its own CRM through the HDI integration, and it can read the results of its own clients only. If you open the screening without a partner link, no partner receives your data.

Who can see my results?

You, through the personal link in your results email or by signing in to the client portal; the partner whose link you used, and the certified auditors of that partner who run your audit, who sign in to a separate audit tool; and the people at HDI who operate the platform. The results link carries a signature tied to your email address, so changing the address in the link does not open someone else's results. Anyone you forward the link to can open it; if that happens by mistake, write to us and we will delete the results. All pages and services use HTTPS only.

How long do you keep it?

24 months after your last interaction with us or after the audit is completed, whichever is later. Then we delete it. You can ask us to delete it earlier at any time: write to audit@hdi-audit.com. A partner that received your data keeps its own copy under its own policy.

Is HDI a GxP computerised system?

No. HDI is an advisory assessment. It does not create, store or approve GxP records, and nobody uses it to make batch, release or quality decisions. That puts it outside the scope of EU GMP Annex 11 and 21 CFR Part 11, so it needs no computer system validation. Changes you make after the audit, such as a new workflow or a new system, go through your own change control and validation as usual.

Who agrees confidentiality terms, and who completes our supplier questionnaire?

The partner that runs your audit agrees confidentiality terms with you before the workshop. HDI is the platform that scores the answers, and it completes your supplier or information-security questionnaire about the platform. Send the questionnaire to audit@hdi-audit.com.

Start the free screening → · Privacy policy →