Privacy Policy

Last updated: 14 July 2026

1. Who we are

GRCorb ("we") provides a governance, risk and compliance platform. This policy explains what personal data we process and why.

2. Data we process

Account data (name, work email, company, country); content you create (risk registers, assets, projects, policies); evidence files you upload; and technical data (IP address, timestamps) recorded for security and auditing.

3. Why we process it

To provide the Service, authenticate you, secure the platform, maintain an audit trail, and process payments. We rely on your organisation's instructions and our legitimate interest in operating a secure service.

4. AI processing

When you use AI validation or generation, the relevant content you submit is sent to our AI provider (Anthropic) to produce the output. It is not used to train third-party models. You control when AI features are invoked; avoid submitting unnecessary personal data.

5. Sub-processors

We use a limited set of processors, including our AI provider (Anthropic), payment processor (Stripe), and email provider (Resend). Each processes data only to deliver their part of the Service.

6. Storage & security

Data is access-controlled and scoped to your organisation. Administrative actions are logged. We are progressively moving evidence and personal data to encrypted storage. Data residency options (including Saudi Arabia for PDPL) are available on request for enterprise deployments.

7. Retention

We keep account and content data for as long as your account is active, and delete or anonymise it on request, subject to legal retention obligations.

8. Your rights

Depending on your jurisdiction you may request access, correction, export, or deletion of personal data. Contact us to exercise these rights.

9. Contact

Privacy enquiries: contact us.

Terms of Service · Data Processing Agreement