Legal

Privacy Policy

How AiBizzApps Limited collects, uses and protects personal data in connection with the GRCxAI platform and this website.

Controller: AiBizzApps Limited
Company No. 16632419
Jurisdiction: England & Wales
Last updated: 11 August 2026

1. Who we are

GRCxAI is a governance, risk and compliance platform developed and operated by AiBizzApps Limited, a private limited company incorporated in England and Wales with company number 16632419 ("we", "us", "our").

This policy covers personal data we handle in connection with the grcxai.com website and the GRCxAI application at app.grcxai.com. It applies alongside — and does not replace — the Master Subscription Agreement, which governs the contractual relationship with our customers.

We process personal data in accordance with the UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation.

2. Our role: controller and processor

Our role depends on whose data is involved, and the distinction matters for your rights.

We act as a controller for data about our own website visitors, prospects, and the individuals who administer a customer account — account details, billing contacts, support correspondence, marketing enquiries. We decide why and how that data is used, and this policy explains it.

We act as a processor for the Customer Data our customers upload into the platform. Our customer is the controller of that data; they decide what goes in and why. We process it on their documented instructions under the data-processing terms in the Master Subscription Agreement.

If you are an employee of one of our customers and want to exercise rights over data held in their GRCxAI tenant, contact your own organisation in the first instance — they are the controller. We will support them in responding, and we will not act on such data without their instruction.

3. What personal data we collect

As a controller, we collect:

  • Account and identity data — name, work email address, job title, organisation, and the authentication identifiers associated with your login (including where you sign in via Google, Microsoft or your organisation's SAML identity provider).
  • Contact and enquiry data — information you provide when requesting a demo, contacting support, or corresponding with us.
  • Billing data — billing contact details and subscription records. Card details are handled by our payment processor and are not stored by us.
  • Usage and technical data — IP address, browser and device type, pages visited, and application audit events such as sign-in times and actions taken. Audit logging is a core compliance feature of the platform and is recorded at field level.
  • Assessment submissions — where you use a free tool on this website, such as the Provision 29 assessment, the responses you provide and any contact details you choose to give us.

We do not seek special category personal data through the website, and we ask that you do not send it to us in unstructured correspondence.

4. Why we use it, and our lawful bases

  • To provide the platform and fulfil our contract — creating and administering accounts, authenticating users, delivering support, and billing. Lawful basis: performance of a contract.
  • To keep the service secure — audit logging, fraud and abuse prevention, incident investigation, access control. Lawful basis: legitimate interests (securing our service and our customers' data), and legal obligation where security or breach-notification duties apply.
  • To improve the product — understanding which features are used, diagnosing faults, and prioritising development. Lawful basis: legitimate interests.
  • To respond to enquiries and market our services to business contacts, including following up on a demo request. Lawful basis: legitimate interests, or consent where the law requires it. You can opt out of marketing at any time.
  • To comply with law — accounting, tax and regulatory record-keeping. Lawful basis: legal obligation.

Where we rely on legitimate interests, we have considered the impact on you and concluded that our interests are not overridden by your rights. You can object — see Your rights.

5. Customer Data in the platform

"Customer Data" means any data, content, information or material uploaded to, processed by, or generated through the platform by or on behalf of a customer and its authorised users. It commonly includes risk registers, control evidence, audit findings, policy documents, vendor records, training completions and assessment responses — some of which will contain personal data about our customer's own staff and third parties.

For Customer Data:

  • We process it only on the customer's documented instructions, as set out in the Master Subscription Agreement.
  • Customer Data is held in a shared platform database and is logically separated by tenant, with access authorised on the server for every request. Data belonging to one customer is not accessible to another.
  • We do not use Customer Data to train machine learning models, and we do not sell it or share it for advertising.
  • We assist the customer, as controller, with data subject requests, impact assessments and breach notification.

6. How we use AI

The platform uses large language models to draft compliance documents, generate reports, answer clause-level questions and assist with risk analysis. Two commitments govern this:

  • Generation is scoped to your own organisation. When the platform drafts a document it draws only on your own records — not on other customers' data.
  • Customer Data is not used to train models. Content sent to a model provider for inference is processed to return that result, and is not used by us or by them to train or improve general-purpose models.

AI output is always presented as a draft for human review. Nothing is filed, approved or signed off automatically. Where AI assists with a judgement — a risk score, a finding, a vendor assessment — it is decision-support information, and accountability for the decision remains with the person making it.

7. Who processes data on our behalf

We do not sell personal data, and we do not share it with anyone for their own purposes. Two different things get grouped under this heading, and they are worth separating. Operating infrastructure is not the same as sharing data. Our server is a dedicated physical machine: the hosting provider supplies and houses it, but the data on it is not sent to them and they cannot read it. Only two providers actually receive anything — the model provider, which is sent the content you ask the platform to work on, and the payment processor, which is sent billing details. Each is engaged under a written contract requiring them to process data only on our instructions and to maintain appropriate security. We are required to name them, and do.

ProviderRelationshipWhat they receiveLocation
Hetzner Online GmbH Infrastructure. Supplies and houses the dedicated physical server the platform runs on — single-tenant hardware, not shared with any other of their customers, and not a virtual slice of a shared host Nothing is sent to them. Data resides on hardware they house. The machine, operating system, database and encryption are operated by us; they hold no logical access and no credentials European Economic Area
Cloudflare, Inc. Edge network in front of the application — CDN, WAF and DDoS protection Traffic in transit passes through the edge. No Customer Data is stored there Global network; UK/EEA edge
Anthropic, PBC (current LLM provider) Large language model inference for document generation and chat Receives content you ask the platform to work on, to return that result. Not used to train models. The provider may change — for resilience, availability or capability — under the notice process below US, with EU routing where available
Stripe Payments Europe Ltd. Subscription billing and payment processing Receives billing details — name, business contact and payment information. No platform Customer Data Ireland / UK

This list can change. We give not less than 30 days’ notice of any addition or replacement, during which you may object on reasonable grounds; if no substitute can be agreed, either side may terminate and we refund the unused part of any pre-paid fees (Schedule 4, clause 6 of the MSA). That flexibility is deliberate: it lets us move provider if access, availability or capability requires it, without leaving you uninformed.

The application and its database run on dedicated infrastructure within the United Kingdom and/or the European Economic Area. We operate the database ourselves rather than using a managed database service. Cloudflare sits in front of the application as the edge and content-delivery layer. The authoritative and contractually binding sub-processor list is Schedule 4 of the Master Subscription Agreement; where this page and Schedule 4 differ, Schedule 4 governs. Customers are notified of changes to the sub-processor list in accordance with that Schedule.

We may also disclose personal data where required by law, court order or a regulator, or to establish, exercise or defend legal claims.

8. International transfers

Where personal data is transferred outside the United Kingdom or the European Economic Area, we ensure an appropriate transfer mechanism is in place — the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, as applicable, together with any supplementary measures required.

9. How long we keep data

  • Customer Data is retained for the duration of the subscription. On termination or expiry, you may request an export within 30 days, and the data is then made available in a commonly used machine-readable format for 90 days, after which it may be deleted or anonymised subject to our lawful retention obligations (clause 14.3 of the Master Subscription Agreement). You can also export your data in standard formats at any time during the subscription.
  • Account and billing records are kept for as long as needed to administer the relationship, and afterwards for the period required by accounting and tax law.
  • Audit logs are retained as required to serve their compliance purpose — deleting them on request would defeat the control they exist to provide.
  • Enquiry and marketing data is kept until you ask us to stop, or until it is no longer relevant.

10. How we protect data

We apply technical and organisational measures appropriate to the risk, including: encryption in transit and at rest; logical tenant separation enforced on every request; role-based access control; SAML single sign-on and TOTP two-factor authentication; field-level audit logging; enforced security headers including a strict Content Security Policy and HSTS; restricted CORS; dependency scanning against published vulnerability advisories; and periodic security assessment of the production application.

Our security page sets out the specific controls in more detail.

No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the Information Commissioner's Office and affected controllers without undue delay, in accordance with our legal obligations.

11. Your rights

Under the UK GDPR you have the right to:

  • be informed about how your data is used — this policy;
  • access a copy of the personal data we hold about you;
  • have inaccurate data rectified;
  • have data erased in certain circumstances;
  • restrict processing in certain circumstances;
  • port your data to another provider, where technically feasible;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions — AI output in the platform is always reviewed by a person.

To exercise a right, email [email protected]. We will respond within one month, and will tell you if we need longer because the request is complex. We may ask you to verify your identity first.

If your data sits in a customer's tenant, please see section 2 — that organisation is the controller, and your request should go to them.

12. Cookies and analytics

This website uses only what it needs. We use strictly necessary cookies and storage to make the site and application work — including keeping you signed in and maintaining session security. These cannot be switched off without breaking the service.

We use privacy-preserving aggregate analytics to understand how the website is used — page views, referrers and approximate location at country level. We do not use advertising cookies, we do not build cross-site profiles, and we do not share analytics data with advertising networks.

You can block or delete cookies through your browser settings; strictly necessary cookies being blocked may prevent sign-in from working.

13. Changes to this policy

We may update this policy to reflect changes in the platform, our sub-processors or the law. The "last updated" date at the top of this page always shows the current version. Where a change materially affects how we handle your personal data, we will take reasonable steps to notify you — and for contractual changes, the notice provisions of the Master Subscription Agreement apply.

14. How to contact us and complain

For privacy questions or to exercise a right:

If you are unhappy with how we have handled your personal data, please tell us first so we can put it right. You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113  •  ico.org.uk/make-a-complaint


AiBizzApps Limited  •  Company No. 16632419  •  Registered in England & Wales  •  See also the Master Subscription Agreement and our security page.