growGRC PRIVACY POLICY
Version: v1.2.0
Effective Date: May 4, 2026
NOTICE: This Privacy Policy is written in English. In case of translation, the English version prevails.
1. WHO WE ARE
Global Modern Services, located at 5204 NW 103 AVE. DORAL, FL 33178, USA, operates the growGRC platform, a Software-as-a-Service (SaaS) solution for Governance, Risk, and Compliance (GRC).
2. SCOPE OF THIS POLICY
This Privacy Policy applies to:
- Registered users and subscribers of growGRC
- Enterprise customers and their authorized users (tenants)
- Users within corporate customer organizations
- Visitors to growGRC websites and landing pages
- Users of free tools and diagnostics offered by growGRC
3. INFORMATION WE COLLECT
We collect information necessary to operate, maintain, and deliver the Service:
- Account Information: Name, email address, job title, and organization details.
- Tenant & GRC Operational Data: Risk registers, audit workflows, control matrices, compliance evidence, policies, and action plans uploaded or configured by your organization.
- Technical & Usage Information: IP addresses, browser types, audit logs, authentication timestamps, and interaction analytics.
- Billing Metadata: Paddle transaction IDs, subscription tier status, and billing contact details. (Payment card details are collected directly by our Merchant of Record, Paddle, and are never processed or stored on our servers).
4. HOW WE USE YOUR INFORMATION
We use information for the following purposes:
- To provide, operate, and maintain the growGRC platform
- To manage user accounts, multi-tenant isolation, and authentication
- To deliver GRC workflows, risk assessments, and compliance reporting
- To provide customer and technical support
- To ensure platform security and prevent abuse
- To analyze platform telemetry and optimize performance
5. ARTIFICIAL INTELLIGENCE
growGRC may use artificial intelligence technologies to assist with compliance analysis, control suggestions, and operational insights. Customer data submitted to AI features is processed strictly under corporate confidentiality standards and is not used to train public foundational AI models.
6. DATA ROLES: PROCESSOR VS. CONTROLLER
- Customer as Data Controller: In relation to operational corporate risk data, employee lists, or internal audit files uploaded by Customer into the platform ("Customer Data"), Customer acts as the Data Controller.
- Global Modern Services as Data Processor: We process Customer Data solely upon instructions from the Customer, in accordance with our Data Processing Agreement (DPA) and these terms.
7. SHARING OF INFORMATION & SUBPROCESSORS
We may share information with vetted third-party service providers essential for platform operations:
- Cloud hosting and database infrastructure (e.g., Supabase / AWS)
- Monitoring, error reporting, and observability tools
- AI infrastructure providers under strict enterprise data-protection commitments
- Merchant of Record & Payment Fulfillment: Paddle.com Market Ltd ("Paddle"), which acts as independent Controller/Merchant of Record for order processing, sales tax compliance, and payment operations.
We do not sell, rent, or trade personal data or Customer GRC data to third parties.
8. GDPR COMPLIANCE (EEA & UK)
For individuals located in the European Economic Area (EEA) and the United Kingdom (UK), we adhere to Regulation (EU) 2016/679 (GDPR) and the UK GDPR:
- Legal Bases: We process personal data based on contractual performance, legitimate business interests, statutory legal obligations, or consent.
- Data Subject Rights: You have the right to access, rectify, port, restrict, or erase your personal data, or object to processing. To exercise these rights, email legal@growgrc.app.
- International Transfers: Data transfers from the EEA/UK to the United States or other jurisdictions are protected using European Commission Standard Contractual Clauses (SCCs) and appropriate technical safeguards.
9. CCPA / CPRA COMPLIANCE (CALIFORNIA RESIDENTS)
Under the California Consumer Privacy Act (CCPA) as amended by the CPRA:
- No Sale or Sharing: growGRC does not "sell" personal information or "share" personal information for cross-context behavioral advertising.
- Consumer Rights: California residents have the right to request disclosure of categories and specific pieces of personal information collected, the right to request deletion, and the right to non-discrimination for exercising privacy rights.
- Requests: Submit CCPA requests by contacting legal@growgrc.app.
10. GRC DATA SECURITY & ENCRYPTION
Because growGRC handles mission-critical enterprise risk and compliance information, we enforce strict security controls:
- Encryption: All Customer Data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
- Multi-Tenant Isolation: Database row-level security (RLS) and strict tenant isolation ensure zero data exposure between organizations.
- Access Controls: Role-based access control (RBAC), multi-factor authentication, and immutable audit logs.
- Industry-standard alignment with ISO 27001 and SOC 2 security principles.
11. COOKIES AND SIMILAR TECHNOLOGIES
We use strictly necessary and functional cookies for authentication, session integrity, and user preferences. Users may control non-essential cookies via browser settings.
12. FREE TOOLS & DIAGNOSTICS
When utilizing free diagnostic calculators or assessments:
- Information submitted is processed solely to generate the requested analysis or benchmark.
- Marketing communications are sent only if explicit opt-in consent is provided.
13. CHILDREN’S PRIVACY
growGRC is an enterprise B2B platform and is not directed to individuals under 18 years of age.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically. Material modifications will be notified through the platform or via email prior to becoming effective.
15. CONTACT
Global Modern Services
5204 NW 103 AVE. DORAL, FL 33178, USA
Official support channel of growGRC
Email: legal@growgrc.app / privacy@growgrc.app
Paddle Buyer Support: https://paddle.net
*© 2026 Global Modern Services. All rights reserved.*