Data Processing Agreement
Last updated: 14 July 2026
This summary DPA applies where GRCorb processes personal data on behalf of your organisation (the "Controller"). A signable long-form DPA is available for enterprise customers.
1. Roles
You are the Controller of the personal data you upload; GRCorb is the Processor and acts only on your documented instructions.
2. Scope of processing
Subject matter: provision of the GRC platform. Data subjects: your personnel and contacts. Data types: names, work contact details, and the content of records and evidence you choose to store.
3. Security measures
Access is scoped per organisation and role; authentication is passwordless with single-use codes; administrative actions are logged in an append-only audit trail; sessions expire and can be revoked. Encryption of evidence at rest and formal backups are being rolled out as part of our platform hardening programme.
4. Sub-processors
Anthropic (AI), Stripe (payments), and Resend (email). We will inform Controllers of material changes to this list.
5. International transfers & residency
Standard deployments may process data outside your country. Regional data residency — including hosting within Saudi Arabia for PDPL alignment — is available for enterprise deployments on request.
6. Data subject requests & breach
We assist you in responding to data subject requests and will notify you without undue delay on becoming aware of a personal data breach affecting your data.
7. Deletion & return
On termination we will delete or return personal data at your choice, subject to legal retention requirements.
8. Contact
To request the signable DPA or a residency option: contact us.