Privacy Notice
Last updated: June 23, 2026
1. Who we are
This Privacy Notice describes how Unified GRC ("Unified GRC", "we", "us", "our") collects, uses, shares, retains and protects personal data when you visit our website, create an account, or use the Unified GRC service (the "Service"). Unified GRC is the controller of the personal data described in this Notice, except where we act as a processor on behalf of a customer (see section 8 below).
For any privacy question or request, contact us at unifiedgrc.support@unifiedgrc.ai.
2. Personal data we collect
We collect the following categories of personal data:
- Account data — name, email address, password (hashed), organisation, role, and authentication identifiers (including multi-factor authentication factors).
- Profile and contact data — billing email, business name, country, and any details you add to your profile.
- Customer content — records, policies, risks, controls, audits, evidence and other data you choose to enter or upload to the Service.
- Usage and telemetry data — pages visited, features used, API requests, timestamps, audit-log events, error reports and performance metrics.
- Device and technical data — IP address, browser type and version, operating system, device identifiers and language preferences.
- Support data — emails and attachments you send to our support address and any related correspondence.
- Payment-related data — limited transaction metadata (plan, status, currency, last four digits of the card where surfaced to us). Full card details are handled by our payment provider (see section 5) and are not stored by us.
3. How we use personal data
We use personal data to:
- Create and operate your account, including authentication and multi-factor authentication.
- Provide, maintain and improve the Service and develop new features.
- Process subscriptions, renewals, cancellations and one-off purchases through our Merchant of Record (Paddle).
- Provide email-based customer support and respond to your requests.
- Send service communications (security notices, billing notices, material changes to these terms).
- Monitor performance, detect and prevent fraud, abuse and security incidents, and enforce our Terms of Service.
- Comply with legal, regulatory and tax obligations.
4. Legal bases for processing (EEA / UK)
Where the EU or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you have signed up for and to process your payments.
- Legitimate interests — to keep the Service secure, prevent fraud and abuse, improve our products, and run our business; we balance these interests against your rights and freedoms.
- Legal obligation — to comply with applicable laws (for example, accounting, tax, lawful disclosure requests).
- Consent — where we ask for it (for example, non-essential cookies or optional marketing communications); you can withdraw consent at any time.
5. Who we share personal data with
We share personal data only with the categories of recipients listed below:
- Merchant of Record — Paddle. Paid subscriptions and one-time purchases are sold and processed by Paddle.com Market Limited acting as Merchant of Record. Paddle handles the order, payment processing, billing, invoicing, fraud screening, sales tax/VAT/GST, refunds and chargebacks, and receives the personal data needed for those purposes (such as your name, email, billing address and transaction details). Paddle's privacy notice is available at paddle.com/legal/privacy.
- Hosting and infrastructure providers — cloud platforms that host the application, database and storage that runs the Service, under contractual confidentiality and data-protection obligations.
- Email and notification providers — services that deliver transactional emails (sign-up confirmations, password resets, billing emails, support replies).
- Security and monitoring tools — providers that help us detect errors, monitor uptime and protect the Service against abuse.
- Professional advisers — accountants, auditors and lawyers, where reasonably necessary.
- Authorities — where we are required to do so by law or to protect our rights, your safety, or the safety of others.
- Successors — in the context of a merger, acquisition or sale of assets, subject to equivalent protections.
We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.
6. International transfers
The Service is operated globally. Personal data may be transferred to, stored in, or processed in countries outside your country of residence, including outside the EEA and the UK. Where we transfer personal data internationally, we rely on appropriate safeguards, such as adequacy decisions or Standard Contractual Clauses (with any additional measures required by applicable law).
7. Data retention
We keep personal data only for as long as we need it for the purposes set out in this Notice, or for longer if required to comply with a legal, accounting, regulatory or tax obligation.
- Account data — for as long as your account is active, and a reasonable period after closure to handle billing reconciliation and disputes.
- Customer content — for the duration of the subscription. After termination, you should export any data you wish to keep; we may then delete it in line with our Terms of Service, subject to legal obligations.
- Billing and tax records — typically retained by us and by Paddle for the period required by applicable accounting and tax laws.
- Audit-log and security events — retained for a limited period to support investigations, security monitoring and customer audit-trail requirements.
- Support correspondence — retained for a reasonable period after the matter is closed.
8. When we act as a processor on your behalf
When you upload customer content (records, policies, risks, controls, evidence, etc.) to the Service, you act as the controller of that personal data and Unified GRC acts as a processor on your behalf. In that role we process customer content only on your documented instructions and in accordance with our Terms of Service and, where applicable, a Data Processing Agreement (DPA).
You are responsible for having a lawful basis to upload that personal data and for responding to data-subject requests relating to it. We will provide reasonable assistance to help you meet those obligations.
9. Your rights
Depending on where you live, you may have the following rights:
- Access to the personal data we hold about you.
- Rectification of inaccurate or incomplete personal data.
- Erasure ("right to be forgotten") in certain circumstances.
- Restriction of processing in certain circumstances.
- Portability of personal data you provided to us.
- Objection to processing carried out on the basis of legitimate interests.
- Withdrawal of consent at any time, where processing is based on consent.
- The right to lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at unifiedgrc.support@unifiedgrc.ai. We will respond within one month, and may need to verify your identity before acting on the request.
10. Security
We apply industry-standard technical and organisational measures to protect personal data, including encryption in transit, encryption at rest where supported, access controls, row-level security in the database, multi-factor authentication for accounts, regular patching, audit logging and least-privilege administration. No method of transmission or storage is completely secure, but we continuously work to maintain a strong security posture.
11. Cookies and similar technologies
We use a small number of strictly necessary cookies and local-storage entries to keep you signed in, remember your preferences and operate the Service. We do not use advertising cookies. If we ever introduce optional analytics or marketing cookies, we will request your consent first where required by law.
12. Children
The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this Notice
We may update this Privacy Notice from time to time. The "Last updated" date at the top of the page indicates when it was last revised. Where changes are material, we will provide additional notice (for example, by email or in-application notice).
14. Contact
For privacy questions, data-subject requests, or to contact our privacy team, please email unifiedgrc.support@unifiedgrc.ai.
This Notice describes Unified GRC's practices in operating the Service. It does not constitute legal advice. Customers with specific regulatory needs should obtain qualified legal counsel for their jurisdiction.
