GDPR Compliance
How ThinkGRC protects your personal data under GDPR
ThinkGRC Ltd is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page outlines how we comply with GDPR requirements and protect your personal data.
- Right to Access: You can request a copy of your personal data we hold.
- Right to Rectification: You can request correction of inaccurate personal data.
- Right to Erasure: You can request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing: You can request that we limit how we use your data.
- Right to Data Portability: You can request your data in a machine-readable format.
- Right to Object: You can object to certain types of processing, including direct marketing.
- Rights Related to Automated Decision Making: You have rights regarding automated decision-making and profiling.
We process your personal data under the following legal bases:
- Consent: When you have given clear consent for specific processing activities.
- Contract: When processing is necessary to fulfill our contractual obligations to you.
- Legal Obligation: When we must process data to comply with legal requirements.
- Legitimate Interests: When processing is necessary for our legitimate business interests, balanced against your rights.
- End-to-end encryption for data in transit and at rest
- Regular security audits and vulnerability assessments
- Staff training on data protection and privacy
- Data Processing Agreements (DPAs) with all sub-processors
- Privacy by Design and Privacy by Default principles
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- Incident response and breach notification procedures
When we transfer personal data outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Binding Corporate Rules where applicable
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Account data: Retained while your account is active and for 2 years after closure
- Transaction records: Retained for 7 years for accounting and legal compliance
- Marketing data: Retained until you withdraw consent
- Support tickets: Retained for 3 years after resolution
To exercise any of your GDPR rights, please contact us:
- Email: privacy@thinkgrc.com
- Subject line: "GDPR Rights Request"
- Include: Your full name, email address, and specific request
We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two months, and we will inform you.
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you live, work, or where the alleged infringement occurred.
For the UK: Information Commissioner's Office (ICO)
Website: ico.org.uk
