Last updated: 14 July 2026
GRCorb ("we") provides a governance, risk and compliance platform. This policy explains what personal data we process and why.
Account data (name, work email, company, country); content you create (risk registers, assets, projects, policies); evidence files you upload; and technical data (IP address, timestamps) recorded for security and auditing.
To provide the Service, authenticate you, secure the platform, maintain an audit trail, and process payments. We rely on your organisation's instructions and our legitimate interest in operating a secure service.
When you use AI validation or generation, the relevant content you submit is sent to our AI provider (Anthropic) to produce the output. It is not used to train third-party models. You control when AI features are invoked; avoid submitting unnecessary personal data.
We use a limited set of processors, including our AI provider (Anthropic), payment processor (Stripe), and email provider (Resend). Each processes data only to deliver their part of the Service.
Data is access-controlled and scoped to your organisation. Administrative actions are logged. We are progressively moving evidence and personal data to encrypted storage. Data residency options (including Saudi Arabia for PDPL) are available on request for enterprise deployments.
We keep account and content data for as long as your account is active, and delete or anonymise it on request, subject to legal retention obligations.
Depending on your jurisdiction you may request access, correction, export, or deletion of personal data. Contact us to exercise these rights.
Privacy enquiries: contact us.