Privacy Policy
Last Updated: November 2025
ThinkGRC ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Governance, Risk & Compliance platform.
By accessing or using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
Personal Information
We collect information that you provide directly to us, including:
- Name, email address, and contact information
- Company name and business information
- Account credentials and authentication data
- Payment and billing information
- Professional role and job title
Usage Information
We automatically collect certain information when you use our platform:
- Device information (IP address, browser type, operating system)
- Usage data (pages visited, features used, time spent)
- Log data and analytics information
- Cookies and similar tracking technologies
GRC Data
When you use our platform, we collect and process:
- Risk assessments and mitigation plans
- Compliance requirements and evidence
- Audit findings and reports
- Issue and incident records
- Policy documents and procedures
We use the information we collect to:
- Provide Services: Operate, maintain, and improve our GRC platform
- Account Management: Create and manage your account, process payments
- Communication: Send you updates, notifications, and support messages
- Security: Detect, prevent, and address fraud, security issues, and technical problems
- Analytics: Understand how users interact with our platform to improve functionality
- Compliance: Comply with legal obligations and regulatory requirements
- Marketing: Send promotional materials (with your consent)
We implement industry-standard security measures to protect your information:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access controls and multi-factor authentication
- Monitoring: 24/7 security monitoring and intrusion detection
- Compliance: SOC 2 Type II, ISO 27001 certified infrastructure
- Regular Audits: Regular security assessments and penetration testing
- Data Backup: Automated backups with disaster recovery procedures
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
Your information may be transferred to and maintained on servers located outside of your country. We ensure appropriate safeguards are in place through:
- Standard Contractual Clauses approved by the European Commission
- EU-U.S. and Swiss-U.S. Privacy Shield frameworks (where applicable)
- Compliance with GDPR for EU data subjects
- Data Processing Agreements with all third-party processors
Depending on your location, you may have the following rights:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal information
- Portability: Receive a copy of your data in a portable format
- Restriction: Request restriction of processing
- Objection: Object to processing of your personal information
- Withdraw Consent: Withdraw consent at any time
To exercise these rights, please contact us at privacy@thinkgrc.com
We retain your personal information for as long as necessary to provide our services and comply with legal obligations:
- Account information: Duration of account plus 7 years
- GRC data: As long as required by applicable regulations
- Audit logs: Minimum 7 years for compliance purposes
- Marketing data: Until consent is withdrawn
We use cookies and similar technologies for:
- Essential functionality and authentication
- Analytics and performance monitoring
- Personalization and user preferences
- Marketing and advertising (with consent)
You can control cookie preferences through your browser settings. See our Cookie Policy for more details.
We may share information with trusted third-party service providers:
- Cloud infrastructure providers (AWS, Azure, Google Cloud)
- Payment processors
- Analytics services
- Customer support tools
- Email and communication platforms
All third-party providers are contractually bound to protect your data and use it only for specified purposes.
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
We may update this Privacy Policy periodically. We will notify you of any material changes by:
- Posting the new policy on this page
- Updating the "Last Updated" date
- Sending email notifications for significant changes
- Displaying in-app notifications
If you have questions about this Privacy Policy or our data practices, contact us:
Email: privacy@thinkgrc.com
Data Protection Officer: dpo@thinkgrc.com
Address: ThinkGRC Ltd, 123 Security Street, Suite 400, London, UK
Regional Compliance
Our Data Protection Officer handles all GDPR-related inquiries. EU users have additional rights under GDPR including data portability and the right to lodge complaints with supervisory authorities.
California residents have specific rights to know, delete, and opt-out of the sale of personal information. We do not sell personal information.
UK residents have rights under UK GDPR similar to EU GDPR, including the right to lodge complaints with the Information Commissioner's Office (ICO).
