Skip to content
Book a Demo
PRV.00 / PRIVACY POLICY

Privacy Policy

Privacy is foundational to a governance, risk, and compliance platform — the organizations that trust AfriGRC with their own compliance data expect nothing less of how we handle it. This page explains what we collect, why, and the rights you have over it.

Last Updated
August 5, 2026
Effective Date
To be confirmed upon legal review
Version
0.1 (Draft)

This page is a working draft of our privacy documentation, published for transparency ahead of formal legal review. It does not constitute legal advice, and should not be treated as a final, legally approved policy until AfriGRC confirms it has completed that review.

PRV.01 / QUICK SUMMARY

The plain-language version.

A brief overview — the full detail follows in each section below.

  • What We Collect

    Information you provide directly, plus technical and usage information collected automatically — detailed in Information We Collect below.

  • Why We Collect It

    To provide and support the platform, keep it secure, meet legal obligations, and improve it — never for purposes unrelated to the product.

  • How We Use It

    Primarily to operate the service you or your organization has engaged us for — see How We Use Information for the full list of purposes.

  • Your Rights

    Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict use of your information — see User Rights below.

  • How to Reach Us

    Contact our Privacy Team using the details in Contact Information at the end of this page.

PRV.02 / DEFINITIONS

Terms used throughout this policy.

Personal Data
Any information relating to an identified or identifiable natural person — for example, a name, email address, or account identifier.
Processing
Any operation performed on Personal Data, whether or not by automated means — including collection, storage, use, disclosure, and deletion.
Controller
The entity that determines the purposes and means of Processing Personal Data. Depending on context, this may be AfriGRC or the customer organization using our Services.
Processor
An entity that Processes Personal Data on behalf of, and under the instructions of, a Controller. AfriGRC typically acts as a Processor for data our customers submit to the platform.
Cookies
Small text files placed on a device by a website or web application, used to remember information across visits — see Cookies & Tracking below.
Services
The AfriGRC platform, websites, and any related products or features made available by AfriGRC.
User
An individual who accesses or uses the Services, whether on their own behalf or on behalf of a Customer.
Customer
The organization that has entered into an agreement with AfriGRC to use the Services.
Visitor
An individual who interacts with AfriGRC's public website without an account — for example, someone reading this page.
AI Services
Features of the Services that use machine learning or artificial intelligence, such as AfriGRC's AI Copilot — see AI Governance in How We Use Information below.
PRV.03 / INFORMATION WE COLLECT

What we collect, and where it comes from.

Separated by source — nothing here describes a collection practice the product doesn't actually have.

TR.01

Information You Provide

Account details, business contact information, and content you submit while using the Services — such as a control, a policy document, or a risk entry.

TR.02

Information Collected Automatically

Device information, IP address, browser type, and pages visited, collected as part of operating and securing the Services.

TR.03

Technical Information

Log data, error reports, and diagnostic information used to keep the platform reliable and secure.

TR.04

Usage Analytics

Aggregated information about how features are used, to guide product improvement — see Product Improvement in How We Use Information.

TR.05

Business Account Information

Information about the Customer organization itself — such as company name, subscription tier, and authorized administrators.

TR.06

Support Requests

Information you share when contacting support, including the content of your request and any attachments you choose to provide.

PRV.04 / HOW WE USE INFORMATION

Purposes, not possibilities.

Only purposes that align with what the product actually does today.

  • Providing the Services

    Operating the platform's core governance, risk, and compliance functionality for the Customer that engaged us.

  • Customer Support

    Responding to support requests and resolving issues you report.

  • Security

    Detecting, investigating, and preventing security incidents, unauthorized access, and abuse.

  • Compliance

    Meeting our own legal and regulatory obligations, and supporting Customers in meeting theirs.

  • Fraud Prevention

    Identifying and preventing fraudulent or abusive use of the Services.

  • Product Improvement

    Understanding how features are used, to guide what we build and fix next.

  • Communication

    Sending service updates, security notices, and — where you've opted in — product or company news.

  • Analytics

    Aggregated, generally de-identified analysis of platform usage and performance.

  • AI Functionality

    Powering AI-assisted features such as the AI Copilot, held to the same evidence-cites-itself standard described in our Trust Centre.

PRV.06 / DATA SHARING

Categories of recipients, not a vendor list.

We name categories rather than specific providers below — this section will link to a published sub-processor list once one is finalized.

Stage 1

You Provide Information

Directly to AfriGRC, or through your organization's use of the Services.

Stage 2

AfriGRC Processes It

For the purposes described in How We Use Information above, under the safeguards in Security Measures.

Stage 3

Shared Only as Described Below

With categories of recipients necessary to operate the Services — never sold, never shared beyond what's listed here.

  • Cloud Infrastructure

    Hosting and storage providers that run the platform's underlying infrastructure.

  • Email Delivery

    Providers that deliver transactional and account-related email on our behalf.

  • Payment Providers

    Providers that process subscription billing, where applicable.

  • Analytics

    Providers that help us understand aggregated platform usage.

  • Professional Advisers

    Legal, audit, and other professional advisers, under confidentiality obligations.

  • Authorities

    Regulators or law enforcement, only where legally required to disclose.

PRV.07 / INTERNATIONAL DATA TRANSFERS

Transfer mechanisms depend on deployment and jurisdiction.

Depending on where a Customer deploys the Services and where its Users are located, Personal Data may be transferred between countries — for example, between an African jurisdiction and a cloud infrastructure region.

Where a cross-border transfer requires a specific legal mechanism — such as an adequacy decision or standard contractual clauses under GDPR — the applicable mechanism depends on the jurisdictions involved and the specifics of a given deployment. This section will be expanded with the specific mechanisms AfriGRC relies on once that analysis has been completed as part of formal legal review.

PRV.08 / DATA RETENTION

Retention periods vary by category and agreement.

Specific periods depend on legal obligations, the terms of a Customer's agreement, and operational requirements — the schedule below is a placeholder structure, not final periods.

Data Retention Schedule — Placeholder, Pending Legal Review
Data CategoryTypical Basis for RetentionStatus
Account & Business InformationDuration of the Customer agreement, plus a limited period afterSchedule pending legal review
Platform Content (controls, policies, risk records)Duration of the Customer agreement, per the Customer's own retention settingsSchedule pending legal review
Support CommunicationsAs needed to resolve the request and for a limited period afterSchedule pending legal review
Technical & Security LogsAs needed for security, audit, and legal obligationsSchedule pending legal review
Marketing CommunicationsUntil you withdraw consent or opt outSchedule pending legal review
PRV.09 / SECURITY MEASURES

How we protect the information described above.

A summary only — see our Security & Trust Centre for the full architecture.

TR.01

Encryption

Encryption at rest across primary data stores and in transit, the same standard described in our Trust Centre.

TR.02

Access Controls

Role-based access control enforced at the API layer, not just the interface.

TR.03

Monitoring

Continuous monitoring for anomalous activity across infrastructure and the application layer.

TR.04

Secure Development

Security requirements scoped before a feature is built, not retrofitted after.

TR.05

Incident Response

A defined process for detecting, containing, and communicating about a security incident — see Security Operations in our Trust Centre.

PRV.10 / COOKIES & TRACKING

Five categories — click any to see examples.

Built to support a future cookie preference center; today, only Essential cookies are actually in use.

Always Active

Essential

Required for the Services to function — such as maintaining your session and keeping you signed in.

  • Session identifier
  • Authentication token
  • Security/CSRF protection
Not Yet In Use

Functional

Remember preferences you've set, such as display settings, to avoid asking again on your next visit.

  • Display and layout preferences
  • Language preference
Not Yet In Use

Analytics

Help us understand aggregated usage patterns, so we know which parts of the Services are working and which need attention.

  • Page view counts
  • Feature usage patterns
Not Yet In Use

Performance

Measure load times and technical performance, to help us keep the Services fast and reliable.

  • Page load timing
  • Error rate monitoring
Not Yet In Use

Marketing

Would support measuring marketing campaign effectiveness, if AfriGRC ever introduces marketing cookies.

  • Not currently used on this site
PRV.11 / USER RIGHTS

Select a jurisdiction to see the rights that apply.

Organized by jurisdiction, expanded as our regulatory coverage grows — see our Frameworks library for the frameworks behind each.

EU / EEA

GDPR

General Data Protection Regulation — applies where AfriGRC processes personal data of individuals in the EU/EEA.

Nigeria

NDPA

Nigeria Data Protection Act — applies to processing of personal data connected to Nigeria.

South Africa

POPIA

Protection of Personal Information Act — applies to processing of personal data connected to South Africa.

Other Markets

Other African Privacy Laws

Additional African data protection frameworks, expanded as our regulatory coverage grows — see our Frameworks library.

  • Right to Access

    Request confirmation of whether we process your personal data, and a copy of it.

  • Right to Rectification

    Request correction of inaccurate or incomplete personal data.

  • Right to Erasure

    Request deletion of your personal data, subject to legal and contractual limits.

  • Right to Restrict Processing

    Request that we limit how your personal data is processed in certain circumstances.

  • Right to Data Portability

    Request a copy of your data in a structured, commonly used format.

  • Right to Object

    Object to processing based on legitimate interests, including for direct marketing.

PRV.12 / CHILDREN'S PRIVACY

The Services are not directed to children.

The Services are enterprise governance, risk, and compliance software, intended for use by business professionals and not directed to children. We do not knowingly collect Personal Data from children.

If you believe a child has provided us with Personal Data, please contact our Privacy Team using the details in Contact Information below, and we will take appropriate steps to review and, where necessary, delete that information.

PRV.13 / THIRD-PARTY SERVICES

Categories of services we integrate.

The Services may link to, or integrate with, third-party services — for example, an identity provider a Customer chooses to use for single sign-on, or a cloud storage integration a Customer configures. This Privacy Policy does not cover the practices of those third-party services; we encourage you to review their own privacy notices.

Where AfriGRC has not yet publicly named a specific integration category as generally available, it is not listed here. See Data Sharing above for the categories of recipients AfriGRC itself shares data with.

PRV.14 / CHANGES TO THIS POLICY

Every revision, in one place.

We’ll update this section as this policy changes — not just the "Last Updated" date in the header.

  • Establishes the page structure: Quick Summary, Definitions, Information We Collect, and the sections that follow.
  • All retention periods, sub-processor names, and jurisdiction-specific rights are placeholders pending legal review.
PRV.15 / CONTACT INFORMATION

Questions about this policy.

Privacy Team

General questions about this policy or how AfriGRC handles personal data.

Contact Privacy Team

Data Protection Officer

A named DPO has not yet been appointed — inquiries are routed to our Privacy Team in the meantime.

Contact Privacy Team

Legal Contact

Legal notices, data processing agreements, and formal correspondence.

Contact Legal
PRV.16 / GET IN TOUCH

Questions about how we handle data?

Reach our Privacy Team directly, explore the full security architecture, or talk to Sales about a specific deployment.

Privacy Policy — AfriGRC