Data Residency & Sovereignty

Where your data lives, how it's protected, and how we comply with data sovereignty laws across SADC and beyond.

Effective Date: 1 January 2026 Β· Version 2.0

1. Data Hosting Regions

CertiGuard GRC is hosted on enterprise-grade cloud infrastructure with the following regional distribution. Customer data is stored in the primary region unless a specific data localisation arrangement is in place.

πŸ‡©πŸ‡ͺ

Primary (EU-West)

Frankfurt, Germany

Primary application & database hosting

GDPR-compliant EU data centre
πŸ‡ΊπŸ‡Έ

Secondary (US-East)

Virginia, USA

CDN & static asset delivery

No customer data stored
πŸ”’

Backup Storage

Multi-region encrypted

Encrypted backup snapshots

AES-256 encrypted, 35-day retention

2. Data Categories & Storage

Data CategoryDescriptionEncryptedRetention
Customer DataControls, risks, policies, evidence, tasks, vendors, incidents AES-256Active subscription + 90 days post-termination
Authentication DataEmail, hashed passwords, session tokens, OAuth tokens AES-256Active account lifetime
Audit TrailImmutable hash-chained event logs (IGGL) AES-2567 years (regulatory requirement)
Evidence FilesUploaded documents, screenshots, certificates AES-256Active subscription + 90 days post-termination
Usage AnalyticsAggregated, anonymised platform metrics AES-25613 months

3. Data Sovereignty Compliance

POPIA (South Africa)

Compliant with the Protection of Personal Information Act. Data subjects can exercise access, correction, and erasure rights via the Privacy Request portal.

GDPR (European Union)

Compliant with the General Data Protection Regulation. Lawful basis, data minimisation, and purpose limitation principles applied throughout.

SADC Data Sovereignty

We support data localisation requirements for SADC member states. Government and financial sector clients can request in-region data residency consultations.

Cross-Border Transfer Controls

All cross-border data transfers use TLS 1.3 encryption and Standard Contractual Clauses (SCCs). No data is transferred to jurisdictions without adequate protection.

Data Minimisation

We collect only the data necessary to deliver the GRC platform. No secondary use of customer data for advertising or training external models.

Right to Erasure

Customers can initiate full data export and erasure at any time via the Data Privacy portal. Erasure is completed within 30 days with cryptographic verification.

SADC Government & Financial Sector Data Localisation

We understand that SADC government ministries, central banks (including the Bank of Botswana), and financial regulators may require data to be stored within national borders. CertiGuard GRC offers:

Dedicated in-region deployment consultations for government and banking clients
Data processing agreements (DPAs) tailored to national data protection laws
Independent security assessments and right-to-audit provisions for enterprise contracts
Sub-processor disclosure and contractual flow-down of data protection obligations
Data localisation attestations and hosting region certificates upon request

4. Encryption Standards

Data at Rest

All database records, file uploads, and backups are encrypted using AES-256-GCM. Encryption keys are managed via the cloud provider's Key Management Service (KMS) with automatic key rotation every 90 days.

Data in Transit

All network communication uses TLS 1.3 with HSTS, certificate pinning, and forward secrecy. API endpoints reject connections below TLS 1.3. No plaintext protocols are used anywhere in the platform.

5. Data Subject Rights

Data subjects (individuals whose personal data is processed on the platform) have the following rights, exercisable through the in-app Privacy Request portal or by contacting the Data Protection Officer:

Right of Access

Right to Rectification

Right to Erasure

Right to Portability

Right to Object

Right to Restriction

Right to Withdraw Consent

Right to Complain