Applications you create with Aha! Builder handle data in compliance with Aha!'s enterprise privacy standards. Run privacy reviews to evaluate how your application handles personal data, then share the results with your compliance team.
Click any of the following links to skip ahead:
Privacy reviews
Navigate to Operate → Documents → Security → Privacy to access four on-demand reviews:
PII data review: Identifies personal data your application collects, processes, and stores
GDPR review: Assesses compliance with the General Data Protection Regulation
CCPA review: Assesses compliance with the California Consumer Privacy Act
Cookie usage review: Analyzes the cookies your application uses, including their purposes and lifespans
Click Run review to generate results for a review you have not run before. After a review completes, click Repeat review on that same review to generate fresh results.
Run these reviews before deploying to production, and whenever you add new data-handling functionality to your application.
Each completed review lists its Review date, Status, and a View report link, so you can open any past result.
Did your application fail a review or pass with a low score? Give the Report to Elle (the AI assistant) and ask for suggested improvements, then rerun the review.
Review exceptions
Not every finding calls for a change to your application. When a finding reflects accepted risk or a known limitation in how your application handles data, record an exception on the review so later reviews account for it.
-
Hover over the review, then click Add exception.
The button stays hidden until you hover, and sits to the left of Run review or Repeat review.
Describe the accepted risk, known limitation, or other context the review should weigh.
Click Save exception to store the context, or Save and rerun review to generate a new review that incorporates it immediately.
The exception belongs to that review on that application. It persists across later runs and appears on the review page, so the next person who reads the report sees why the finding stands.
Administrators control whether you can record exceptions through the Allow review exceptions governance rule, which covers both privacy and security reviews. The rule is on by default.
Data isolation
Each application you create in Aha! Builder gets its own PostgreSQL database and data model. Aha! isolates application data at the database level. It does not share data across applications or with other customers' data.
Compliance
Aha! is GDPR compliant and participates in the EU-U.S. Data Privacy Framework. These commitments extend to the infrastructure that runs Aha! Builder applications. Aha! does not sell the personal data of application users.
Data ownership and portability
You own all data stored in your Aha! Builder applications. You can view and download the underlying application code — including the database configuration — at any time. You can export the complete codebase and use it independently of Aha! software.