Application privacy

Aha! Builder

Applications you create with Aha! Builder handle data in compliance with Aha!'s enterprise privacy standards. Run privacy reviews to evaluate how your application handles personal data, then share the results with your compliance team.

Click any of the following links to skip ahead:

Privacy reviews

Navigate to Operate → Documents → Security → Privacy to access four on-demand reviews:

  • PII data review: Identifies personal data your application collects, processes, and stores

  • GDPR review: Assesses compliance with the General Data Protection Regulation

  • CCPA review: Assesses compliance with the California Consumer Privacy Act

  • Cookie usage review: Analyzes the cookies your application uses, including their purposes and lifespans

Click Run review to generate results for a review you have not run before. After a review completes, click Repeat review on that same review to generate fresh results.

Run these reviews before deploying to production, and whenever you add new data-handling functionality to your application.

Each completed review lists its Review date, Status, and a View report link, so you can open any past result.

Did your application fail a review or pass with a low score? Give the Report to Elle (the AI assistant) and ask for suggested improvements, then rerun the review.

Top

Review exceptions

Not every finding calls for a change to your application. When a finding reflects accepted risk or a known limitation in how your application handles data, record an exception on the review so later reviews account for it.

  • Hover over the review, then click Add exception.

    • The button stays hidden until you hover, and sits to the left of Run review or Repeat review.

  • Describe the accepted risk, known limitation, or other context the review should weigh.

  • Click Save exception to store the context, or Save and rerun review to generate a new review that incorporates it immediately.

The exception belongs to that review on that application. It persists across later runs and appears on the review page, so the next person who reads the report sees why the finding stands.

Administrators control whether you can record exceptions through the Allow review exceptions governance rule, which covers both privacy and security reviews. The rule is on by default.

Top

Data isolation

Each application you create in Aha! Builder gets its own PostgreSQL database and data model. Aha! isolates application data at the database level. It does not share data across applications or with other customers' data.

Top

Compliance

Aha! is GDPR compliant and participates in the EU-U.S. Data Privacy Framework. These commitments extend to the infrastructure that runs Aha! Builder applications. Aha! does not sell the personal data of application users.

Top

Data ownership and portability

You own all data stored in your Aha! Builder applications. You can view and download the underlying application code — including the database configuration — at any time. You can export the complete codebase and use it independently of Aha! software.

Top

Feedback received!

Error submitting feedback, please try again later