How AiBizzApps Limited collects, uses and protects personal data in connection with the GRCxAI platform and this website.

GRCxAI is a governance, risk and compliance platform developed and operated by AiBizzApps Limited, a private limited company incorporated in England and Wales with company number 16632419 ("we", "us", "our").
This policy covers personal data we handle in connection with the grcxai.com website and the GRCxAI application at app.grcxai.com. It applies alongside — and does not replace — the Master Subscription Agreement, which governs the contractual relationship with our customers.
We process personal data in accordance with the UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation.
Our role depends on whose data is involved, and the distinction matters for your rights.
We act as a controller for data about our own website visitors, prospects, and the individuals who administer a customer account — account details, billing contacts, support correspondence, marketing enquiries. We decide why and how that data is used, and this policy explains it.
We act as a processor for the Customer Data our customers upload into the platform. Our customer is the controller of that data; they decide what goes in and why. We process it on their documented instructions under the data-processing terms in the Master Subscription Agreement.
If you are an employee of one of our customers and want to exercise rights over data held in their GRCxAI tenant, contact your own organisation in the first instance — they are the controller. We will support them in responding, and we will not act on such data without their instruction.
As a controller, we collect:
We do not seek special category personal data through the website, and we ask that you do not send it to us in unstructured correspondence.
Where we rely on legitimate interests, we have considered the impact on you and concluded that our interests are not overridden by your rights. You can object — see Your rights.
"Customer Data" means any data, content, information or material uploaded to, processed by, or generated through the platform by or on behalf of a customer and its authorised users. It commonly includes risk registers, control evidence, audit findings, policy documents, vendor records, training completions and assessment responses — some of which will contain personal data about our customer's own staff and third parties.
For Customer Data:
The platform uses large language models to draft compliance documents, generate reports, answer clause-level questions and assist with risk analysis. Two commitments govern this:
AI output is always presented as a draft for human review. Nothing is filed, approved or signed off automatically. Where AI assists with a judgement — a risk score, a finding, a vendor assessment — it is decision-support information, and accountability for the decision remains with the person making it.
We do not sell personal data, and we do not share it with anyone for their own purposes. Two different things get grouped under this heading, and they are worth separating. Operating infrastructure is not the same as sharing data. Our server is a dedicated physical machine: the hosting provider supplies and houses it, but the data on it is not sent to them and they cannot read it. Only two providers actually receive anything — the model provider, which is sent the content you ask the platform to work on, and the payment processor, which is sent billing details. Each is engaged under a written contract requiring them to process data only on our instructions and to maintain appropriate security. We are required to name them, and do.
| Provider | Relationship | What they receive | Location |
|---|---|---|---|
| Hetzner Online GmbH | Infrastructure. Supplies and houses the dedicated physical server the platform runs on — single-tenant hardware, not shared with any other of their customers, and not a virtual slice of a shared host | Nothing is sent to them. Data resides on hardware they house. The machine, operating system, database and encryption are operated by us; they hold no logical access and no credentials | European Economic Area |
| Cloudflare, Inc. | Edge network in front of the application — CDN, WAF and DDoS protection | Traffic in transit passes through the edge. No Customer Data is stored there | Global network; UK/EEA edge |
| Anthropic, PBC (current LLM provider) | Large language model inference for document generation and chat | Receives content you ask the platform to work on, to return that result. Not used to train models. The provider may change — for resilience, availability or capability — under the notice process below | US, with EU routing where available |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing | Receives billing details — name, business contact and payment information. No platform Customer Data | Ireland / UK |
This list can change. We give not less than 30 days’ notice of any addition or replacement, during which you may object on reasonable grounds; if no substitute can be agreed, either side may terminate and we refund the unused part of any pre-paid fees (Schedule 4, clause 6 of the MSA). That flexibility is deliberate: it lets us move provider if access, availability or capability requires it, without leaving you uninformed.
The application and its database run on dedicated infrastructure within the United Kingdom and/or the European Economic Area. We operate the database ourselves rather than using a managed database service. Cloudflare sits in front of the application as the edge and content-delivery layer. The authoritative and contractually binding sub-processor list is Schedule 4 of the Master Subscription Agreement; where this page and Schedule 4 differ, Schedule 4 governs. Customers are notified of changes to the sub-processor list in accordance with that Schedule.
We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims.
Where personal data is transferred outside the United Kingdom or the European Economic Area, we ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, as applicable, together with any supplementary measures required.
We apply technical and organisational measures appropriate to the risk, including: encryption in transit and at rest; logical tenant separation enforced on every request; role-based access control; SAML single sign-on and TOTP two-factor authentication; field-level audit logging; enforced security headers including a strict Content Security Policy and HSTS; restricted CORS; dependency scanning against published vulnerability advisories; and periodic security assessment of the production application.
Our security page sets out the specific controls in more detail.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office and affected controllers without undue delay, in accordance with our legal obligations.
Under the UK GDPR you have the right to:
To exercise a right, email [email protected]. We will respond within one month, and will tell you if we need longer because the request is complex. We may ask you to verify your identity first.
If your data sits in a customer's tenant, please see section 2 — that organisation is the controller, and your request should go to them.
This website uses only what it needs. We use strictly necessary cookies and storage to make the site and application work — including keeping you signed in and maintaining session security. These cannot be switched off without breaking the service.
We use privacy-preserving aggregate analytics to understand how the website is used — page views, referrers and approximate location at country level. We do not use advertising cookies, we do not build cross-site profiles, and we do not share analytics data with advertising networks.
You can block or delete cookies through your browser settings; strictly necessary cookies being blocked may prevent sign-in from working.
We may update this policy to reflect changes in the platform, our sub-processors or the law. The "last updated" date at the top of this page always shows the current version. Where a change materially affects how we handle your personal data, we will take reasonable steps to notify you — and for contractual changes, the notice provisions of the Master Subscription Agreement apply.
For privacy questions or to exercise a right:
If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 • ico.org.uk/make-a-complaint
AiBizzApps Limited • Company No. 16632419 • Registered in England & Wales • See also the Master Subscription Agreement and our security page.