Last updated: 14 July 2026
This summary DPA applies where GRCorb processes personal data on behalf of your organisation (the "Controller"). A signable long-form DPA is available for enterprise customers.
You are the Controller of the personal data you upload; GRCorb is the Processor and acts only on your documented instructions.
Subject matter: provision of the GRC platform. Data subjects: your personnel and contacts. Data types: names, work contact details, and the content of records and evidence you choose to store.
Access is scoped per organisation and role; authentication is passwordless with single-use codes; administrative actions are logged in an append-only audit trail; sessions expire and can be revoked. Encryption of evidence at rest and formal backups are being rolled out as part of our platform hardening programme.
Anthropic (AI), Stripe (payments), and Resend (email). We will inform Controllers of material changes to this list.
Standard deployments may process data outside your country. Regional data residency — including hosting within Saudi Arabia for PDPL alignment — is available for enterprise deployments on request.
We assist you in responding to data subject requests and will notify you without undue delay on becoming aware of a personal data breach affecting your data.
On termination we will delete or return personal data at your choice, subject to legal retention requirements.
To request the signable DPA or a residency option: contact us.