Data Processing Agreement

Last updated: 14 July 2026

This summary DPA applies where GRCorb processes personal data on behalf of your organisation (the "Controller"). A signable long-form DPA is available for enterprise customers.

1. Roles

You are the Controller of the personal data you upload; GRCorb is the Processor and acts only on your documented instructions.

2. Scope of processing

Subject matter: provision of the GRC platform. Data subjects: your personnel and contacts. Data types: names, work contact details, and the content of records and evidence you choose to store.

3. Security measures

Access is scoped per organisation and role; authentication is passwordless with single-use codes; administrative actions are logged in an append-only audit trail; sessions expire and can be revoked. Encryption of evidence at rest and formal backups are being rolled out as part of our platform hardening programme.

4. Sub-processors

Anthropic (AI), Stripe (payments), and Resend (email). We will inform Controllers of material changes to this list.

5. International transfers & residency

Standard deployments may process data outside your country. Regional data residency — including hosting within Saudi Arabia for PDPL alignment — is available for enterprise deployments on request.

6. Data subject requests & breach

We assist you in responding to data subject requests and will notify you without undue delay on becoming aware of a personal data breach affecting your data.

7. Deletion & return

On termination we will delete or return personal data at your choice, subject to legal retention requirements.

8. Contact

To request the signable DPA or a residency option: contact us.

Terms of Service · Privacy Policy