GDPR Compliance

How ThinkGRC protects your personal data under GDPR

Our GDPR Commitment

ThinkGRC Ltd is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page outlines how we comply with GDPR requirements and protect your personal data.

Your Rights Under GDPR
  • Right to Access: You can request a copy of your personal data we hold.
  • Right to Rectification: You can request correction of inaccurate personal data.
  • Right to Erasure: You can request deletion of your personal data ("right to be forgotten").
  • Right to Restrict Processing: You can request that we limit how we use your data.
  • Right to Data Portability: You can request your data in a machine-readable format.
  • Right to Object: You can object to certain types of processing, including direct marketing.
  • Rights Related to Automated Decision Making: You have rights regarding automated decision-making and profiling.
Legal Basis for Processing

We process your personal data under the following legal bases:

  • Consent: When you have given clear consent for specific processing activities.
  • Contract: When processing is necessary to fulfill our contractual obligations to you.
  • Legal Obligation: When we must process data to comply with legal requirements.
  • Legitimate Interests: When processing is necessary for our legitimate business interests, balanced against your rights.
Data Protection Measures
  • End-to-end encryption for data in transit and at rest
  • Regular security audits and vulnerability assessments
  • Staff training on data protection and privacy
  • Data Processing Agreements (DPAs) with all sub-processors
  • Privacy by Design and Privacy by Default principles
  • Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Incident response and breach notification procedures
Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding Corporate Rules where applicable
Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account data: Retained while your account is active and for 2 years after closure
  • Transaction records: Retained for 7 years for accounting and legal compliance
  • Marketing data: Retained until you withdraw consent
  • Support tickets: Retained for 3 years after resolution
Exercising Your Rights

To exercise any of your GDPR rights, please contact us:

  • Email: privacy@thinkgrc.com
  • Subject line: "GDPR Rights Request"
  • Include: Your full name, email address, and specific request

We will respond to your request within one month. If your request is complex or we receive multiple requests, we may extend this period by two months, and we will inform you.

Complaints

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you live, work, or where the alleged infringement occurred.

For the UK: Information Commissioner's Office (ICO)
Website: ico.org.uk

Last updated: November 2025

We Value Your Privacy

We use cookies to enhance your experience, analyze site traffic, and personalize content. By clicking "Accept All," you consent to our use of cookies. You can customize your preferences or learn more in our Cookie Policy.