Privacy Policy

How CertiGuard GRC collects, uses, and protects your data

Last updated: 8 September 2026

1. Introduction

CertiGuard GRC ("CertiGuard", "we", "us", or "our") is a governance, risk, and compliance platform operated by Ethical Edge GRC Consulting (Pty) Ltd, registered in Gaborone, Botswana. We are committed to protecting the privacy and personal data of our users and their stakeholders in accordance with the Protection of Personal Information Act (POPIA) of South Africa, the General Data Protection Regulation (GDPR), and applicable data protection laws across the SADC region.

This Privacy Policy explains what personal data we collect, how we use it, and the rights you have over your data. By using CertiGuard, you agree to the practices described in this policy.

2. Data We Collect

  • Account data: name, email address, role, and authentication credentials when you register or are invited to a tenant.
  • Tenant & billing data: company name, industry, country, billing email, and payment references (we do not store full card numbers — payments are processed by our PCI-compliant payment providers).
  • Content data: the compliance controls, risks, policies, evidence files, and other records you and your team create within the platform.
  • Usage data: login times, feature usage, and IP addresses for security auditing and service improvement.
  • Directory data: if you connect an identity provider (e.g. Google Workspace, Azure AD), we sync user names, emails, and group memberships you configure — only with your explicit authorisation.

3. How We Use Your Data

We process your personal data to:

  • Provide, maintain, and secure the CertiGuard platform and its features.
  • Provision and administer your tenant account, users, and subscription.
  • Run automated compliance checks, evidence collection, and reporting workflows that you configure.
  • Detect, prevent, and respond to security incidents and fraudulent activity.
  • Communicate with you about your account, service updates, and support requests.
  • Comply with legal obligations and cooperate with regulators or auditors where required.

5. Data Sharing & Sub-processors

We do not sell your personal data. We share data only with trusted sub-processors who support our service delivery, under written agreements that meet GDPR and POPIA requirements. Key sub-processors include:

  • Cloud infrastructure: hosting and database providers for application runtime and storage.
  • Payment processors: DPO Pay and PayPal for subscription billing.
  • Email & notifications: providers for transactional and notification emails.
  • Integrations: third-party services (Google Workspace, Slack, Jira, etc.) that you explicitly connect — data is shared only with those connectors you authorise.

A current list of sub-processors is available on request. We may also disclose data when required by law or to protect our legal rights.

6. Data Retention

We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Upon account termination, we delete or anonymise your data within 90 days, except where retention is required by law (e.g. audit trail records, which are retained on an immutable, append-only basis for the regulatory retention period applicable to your jurisdiction).

7. Data Security

We implement industry-leading security measures to protect your data:

  • AES-256 encryption at rest and TLS 1.3 in transit.
  • Strict multi-tenant isolation with row-level security enforcing per-tenant data separation.
  • Role-based access control and least-privilege principles across all systems.
  • Cryptographic hash-chained immutable audit trails for every system event.
  • Regular security assessments, vulnerability scanning, and penetration testing.
  • Secure/HttpOnly/SameSite=Strict session cookies and enforced password complexity.

8. Your Data Protection Rights

Under GDPR and POPIA, you have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your personal data ("right to be forgotten").
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Restriction: request that we restrict processing of your data in certain circumstances.
  • Withdraw consent: where processing is based on consent, withdraw it at any time.

To exercise any of these rights, contact us at privacy@ethicaledgegrcconsulting.com. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. International Data Transfers

Your data may be processed in countries outside your jurisdiction. Where this occurs, we ensure appropriate safeguards are in place, such as standard contractual clauses or other transfer mechanisms approved under GDPR and POPIA. We prioritise data residency options for clients with specific regulatory requirements.

10. Cookies

We use essential cookies to maintain your authenticated session and remember your preferences. We do not use cookies for third-party advertising. You can control cookies through your browser settings, but disabling essential cookies may affect platform functionality.

11. Children's Privacy

CertiGuard is a business-to-business platform and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via email or an in-app notification and update the "last updated" date above. Continued use of CertiGuard after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or your data rights, please contact our Information Officer: