1. Introduction
CertiGuard GRC ("CertiGuard", "we", "us", or "our") is a governance, risk, and compliance platform operated by Ethical Edge GRC Consulting (Pty) Ltd, registered in Gaborone, Botswana. We are committed to protecting the privacy and personal data of our users and their stakeholders in accordance with the Protection of Personal Information Act (POPIA) of South Africa, the General Data Protection Regulation (GDPR), and applicable data protection laws across the SADC region.
This Privacy Policy explains what personal data we collect, how we use it, and the rights you have over your data. By using CertiGuard, you agree to the practices described in this policy.
2. Data We Collect
- Account data: name, email address, role, and authentication credentials when you register or are invited to a tenant.
- Tenant & billing data: company name, industry, country, billing email, and payment references (we do not store full card numbers — payments are processed by our PCI-compliant payment providers).
- Content data: the compliance controls, risks, policies, evidence files, and other records you and your team create within the platform.
- Usage data: login times, feature usage, and IP addresses for security auditing and service improvement.
- Directory data: if you connect an identity provider (e.g. Google Workspace, Azure AD), we sync user names, emails, and group memberships you configure — only with your explicit authorisation.
3. How We Use Your Data
We process your personal data to:
- Provide, maintain, and secure the CertiGuard platform and its features.
- Provision and administer your tenant account, users, and subscription.
- Run automated compliance checks, evidence collection, and reporting workflows that you configure.
- Detect, prevent, and respond to security incidents and fraudulent activity.
- Communicate with you about your account, service updates, and support requests.
- Comply with legal obligations and cooperate with regulators or auditors where required.
4. Legal Basis for Processing
Under GDPR, we rely on the following legal bases:
- Contract: processing necessary to deliver the service under our Terms of Service.
- Legal obligation: compliance with applicable laws and regulatory requirements.
- Legitimate interests: security monitoring, service improvement, and fraud prevention.
- Consent: for optional analytics and marketing communications, which you can withdraw at any time.
Under POPIA, we process personal information for the lawful purposes described above and in accordance with the conditions for lawful processing.
6. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Upon account termination, we delete or anonymise your data within 90 days, except where retention is required by law (e.g. audit trail records, which are retained on an immutable, append-only basis for the regulatory retention period applicable to your jurisdiction).
7. Data Security
We implement industry-leading security measures to protect your data:
- AES-256 encryption at rest and TLS 1.3 in transit.
- Strict multi-tenant isolation with row-level security enforcing per-tenant data separation.
- Role-based access control and least-privilege principles across all systems.
- Cryptographic hash-chained immutable audit trails for every system event.
- Regular security assessments, vulnerability scanning, and penetration testing.
- Secure/HttpOnly/SameSite=Strict session cookies and enforced password complexity.
8. Your Data Protection Rights
Under GDPR and POPIA, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data ("right to be forgotten").
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at privacy@ethicaledgegrcconsulting.com. We respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. International Data Transfers
Your data may be processed in countries outside your jurisdiction. Where this occurs, we ensure appropriate safeguards are in place, such as standard contractual clauses or other transfer mechanisms approved under GDPR and POPIA. We prioritise data residency options for clients with specific regulatory requirements.
11. Children's Privacy
CertiGuard is a business-to-business platform and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email or an in-app notification and update the "last updated" date above. Continued use of CertiGuard after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or your data rights, please contact our Information Officer: