Where your data lives, how it's protected, and how we comply with data sovereignty laws across SADC and beyond.
Effective Date: 1 January 2026 Β· Version 2.0
CertiGuard GRC is hosted on enterprise-grade cloud infrastructure with the following regional distribution. Customer data is stored in the primary region unless a specific data localisation arrangement is in place.
Frankfurt, Germany
Primary application & database hosting
Virginia, USA
CDN & static asset delivery
Multi-region encrypted
Encrypted backup snapshots
| Data Category | Description | Encrypted | Retention |
|---|---|---|---|
| Customer Data | Controls, risks, policies, evidence, tasks, vendors, incidents | AES-256 | Active subscription + 90 days post-termination |
| Authentication Data | Email, hashed passwords, session tokens, OAuth tokens | AES-256 | Active account lifetime |
| Audit Trail | Immutable hash-chained event logs (IGGL) | AES-256 | 7 years (regulatory requirement) |
| Evidence Files | Uploaded documents, screenshots, certificates | AES-256 | Active subscription + 90 days post-termination |
| Usage Analytics | Aggregated, anonymised platform metrics | AES-256 | 13 months |
POPIA (South Africa)
Compliant with the Protection of Personal Information Act. Data subjects can exercise access, correction, and erasure rights via the Privacy Request portal.
GDPR (European Union)
Compliant with the General Data Protection Regulation. Lawful basis, data minimisation, and purpose limitation principles applied throughout.
SADC Data Sovereignty
We support data localisation requirements for SADC member states. Government and financial sector clients can request in-region data residency consultations.
Cross-Border Transfer Controls
All cross-border data transfers use TLS 1.3 encryption and Standard Contractual Clauses (SCCs). No data is transferred to jurisdictions without adequate protection.
Data Minimisation
We collect only the data necessary to deliver the GRC platform. No secondary use of customer data for advertising or training external models.
Right to Erasure
Customers can initiate full data export and erasure at any time via the Data Privacy portal. Erasure is completed within 30 days with cryptographic verification.
We understand that SADC government ministries, central banks (including the Bank of Botswana), and financial regulators may require data to be stored within national borders. CertiGuard GRC offers:
All database records, file uploads, and backups are encrypted using AES-256-GCM. Encryption keys are managed via the cloud provider's Key Management Service (KMS) with automatic key rotation every 90 days.
All network communication uses TLS 1.3 with HSTS, certificate pinning, and forward secrecy. API endpoints reject connections below TLS 1.3. No plaintext protocols are used anywhere in the platform.
Data subjects (individuals whose personal data is processed on the platform) have the following rights, exercisable through the in-app Privacy Request portal or by contacting the Data Protection Officer:
Right of Access
Right to Rectification
Right to Erasure
Right to Portability
Right to Object
Right to Restriction
Right to Withdraw Consent
Right to Complain