GRCEye

Privacy Policy

How GRCEye handles personal data, and what rights you have over it.

Last updated: 8 September 2026

1. Who we are

GRCEye provides a governance, risk and compliance (GRC) SaaS platform. This policy explains what personal data we process when you visit grceye.com or use the GRCEye application, why we process it, and how you can exercise your rights.

For any privacy question, or to exercise any of the rights described in section 7, contact privacy@grceye.com.

2. Data we collect

Data you give us

  • Account data β€” name, work email address, organisation name and role, provided when you register or when an administrator creates your account.
  • Contact data β€” anything you type into the contact form or send to one of our published email addresses.
  • Customer content β€” the risks, controls, policies, evidence, audit records and vendor information you enter into the platform. We process this on your instructions as a processor; you remain the controller.

Data we collect automatically

  • Authentication and session data β€” needed to keep you signed in and to enforce access control.
  • Activity logs β€” the platform records actions taken in your tenant. This is a compliance feature: an audit trail is required by most of the frameworks GRCEye supports.
  • Technical data β€” IP address, browser and device type, and request timestamps, retained for security monitoring and abuse prevention.

3. Why we process it

  • To provide the service (performance of a contract) β€” authentication, delivering platform functionality, support.
  • To secure the service (legitimate interest) β€” detecting abuse, investigating incidents, maintaining the audit trail.
  • To communicate with you (legitimate interest, or consent where required) β€” service notices, and replies to enquiries you send us.
  • To meet legal obligations β€” where retention or disclosure is required by applicable law.

We do not sell personal data, and we do not use customer content to train general-purpose AI models.

4. AI processing

GRCEye's AI features run on infrastructure under our or your control rather than being sent to a third-party AI provider. Content you submit to an AI feature β€” a contract for review, a policy to generate, controls to analyse β€” is processed to return that result and is not shared with an external model vendor. Self-hosted and on-premise deployments keep this processing entirely within your own environment.

5. Sharing

We share personal data only with:

  • Infrastructure and email providers acting as our sub-processors, under contract and only as needed to run the service.
  • Other users in your tenant, according to the role-based access control your administrator configures.
  • Authorities, where we are legally compelled to disclose.

6. Retention

Account and customer content is retained for the life of your subscription. After termination we delete or return customer content within a commercially reasonable period, except where retention is required by law. Security and audit logs are retained for as long as needed for their security and compliance purpose.

7. Your rights

Where the GDPR or an equivalent regime applies, you have the right to access, rectify, erase, restrict and port your personal data, and to object to processing based on legitimate interest. Where processing rests on consent, you may withdraw it at any time. Send requests to privacy@grceye.com; we respond within one month. You may also complain to your local supervisory authority.

If you are an end user of a GRCEye customer, direct your request to that organisation first β€” they are the controller of the data in their tenant, and we act on their instructions.

8. International transfers

Where personal data is transferred outside its country of origin, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses. On-premise and self-hosted deployments involve no transfer to us at all.

9. Cookies

The application uses strictly necessary cookies for authentication and session management, plus a preference cookie that remembers your language choice. These are required for the service to function and are not used for advertising or cross-site tracking.

10. Security

Technical and organisational measures β€” encryption in transit, role-based access control, tenant isolation, multi-factor authentication and audit logging β€” are described on our security page.

11. Changes

We will update this policy as the service evolves and will revise the β€œlast updated” date above. Material changes will be communicated to account holders directly.

12. Contact

Privacy: privacy@grceye.com Β· General: contact form