How GRCEye handles personal data, and what rights you have over it.
Last updated: 8 September 2026
GRCEye provides a governance, risk and compliance (GRC) SaaS platform. This policy explains what personal data we process when you visit grceye.com or use the GRCEye application, why we process it, and how you can exercise your rights.
For any privacy question, or to exercise any of the rights described in section 7, contact privacy@grceye.com.
We do not sell personal data, and we do not use customer content to train general-purpose AI models.
GRCEye's AI features run on infrastructure under our or your control rather than being sent to a third-party AI provider. Content you submit to an AI feature — a contract for review, a policy to generate, controls to analyse — is processed to return that result and is not shared with an external model vendor. Self-hosted and on-premise deployments keep this processing entirely within your own environment.
We share personal data only with:
Account and customer content is retained for the life of your subscription. After termination we delete or return customer content within a commercially reasonable period, except where retention is required by law. Security and audit logs are retained for as long as needed for their security and compliance purpose.
Where the GDPR or an equivalent regime applies, you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time. Send requests to privacy@grceye.com; we respond within one month. You may also complain to your local supervisory authority.
If you are an end user of a GRCEye customer, direct your request to that organisation first — they are the controller of the data in their tenant, and we act on their instructions.
Where personal data is transferred outside its country of origin, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses. On-premise and self-hosted deployments involve no transfer to us at all.
The application uses strictly necessary cookies for authentication and session management, plus a preference cookie that remembers your language choice. These are required for the service to function and are not used for advertising or cross-site tracking.
Technical and organisational measures — encryption in transit, role-based access control, tenant isolation, multi-factor authentication and audit logging — are described on our security page.
We will update this policy as the service evolves and will revise the “last updated” date above. Material changes will be communicated to account holders directly.
Privacy: privacy@grceye.com · General: contact form