Privacy Policy
Privacy is foundational to a governance, risk, and compliance platform — the organizations that trust AfriGRC with their own compliance data expect nothing less of how we handle it. This page explains what we collect, why, and the rights you have over it.
- Last Updated
- August 5, 2026
- Effective Date
- To be confirmed upon legal review
- Version
- 0.1 (Draft)
This page is a working draft of our privacy documentation, published for transparency ahead of formal legal review. It does not constitute legal advice, and should not be treated as a final, legally approved policy until AfriGRC confirms it has completed that review.
The plain-language version.
A brief overview — the full detail follows in each section below.
What We Collect
Information you provide directly, plus technical and usage information collected automatically — detailed in Information We Collect below.
Why We Collect It
To provide and support the platform, keep it secure, meet legal obligations, and improve it — never for purposes unrelated to the product.
How We Use It
Primarily to operate the service you or your organization has engaged us for — see How We Use Information for the full list of purposes.
Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict use of your information — see User Rights below.
How to Reach Us
Contact our Privacy Team using the details in Contact Information at the end of this page.
Terms used throughout this policy.
- Personal Data
- Any information relating to an identified or identifiable natural person — for example, a name, email address, or account identifier.
- Processing
- Any operation performed on Personal Data, whether or not by automated means — including collection, storage, use, disclosure, and deletion.
- Controller
- The entity that determines the purposes and means of Processing Personal Data. Depending on context, this may be AfriGRC or the customer organization using our Services.
- Processor
- An entity that Processes Personal Data on behalf of, and under the instructions of, a Controller. AfriGRC typically acts as a Processor for data our customers submit to the platform.
- Cookies
- Small text files placed on a device by a website or web application, used to remember information across visits — see Cookies & Tracking below.
- Services
- The AfriGRC platform, websites, and any related products or features made available by AfriGRC.
- User
- An individual who accesses or uses the Services, whether on their own behalf or on behalf of a Customer.
- Customer
- The organization that has entered into an agreement with AfriGRC to use the Services.
- Visitor
- An individual who interacts with AfriGRC's public website without an account — for example, someone reading this page.
- AI Services
- Features of the Services that use machine learning or artificial intelligence, such as AfriGRC's AI Copilot — see AI Governance in How We Use Information below.
What we collect, and where it comes from.
Separated by source — nothing here describes a collection practice the product doesn't actually have.
Information You Provide
Account details, business contact information, and content you submit while using the Services — such as a control, a policy document, or a risk entry.
Information Collected Automatically
Device information, IP address, browser type, and pages visited, collected as part of operating and securing the Services.
Technical Information
Log data, error reports, and diagnostic information used to keep the platform reliable and secure.
Usage Analytics
Aggregated information about how features are used, to guide product improvement — see Product Improvement in How We Use Information.
Business Account Information
Information about the Customer organization itself — such as company name, subscription tier, and authorized administrators.
Support Requests
Information you share when contacting support, including the content of your request and any attachments you choose to provide.
Purposes, not possibilities.
Only purposes that align with what the product actually does today.
Providing the Services
Operating the platform's core governance, risk, and compliance functionality for the Customer that engaged us.
Customer Support
Responding to support requests and resolving issues you report.
Security
Detecting, investigating, and preventing security incidents, unauthorized access, and abuse.
Compliance
Meeting our own legal and regulatory obligations, and supporting Customers in meeting theirs.
Fraud Prevention
Identifying and preventing fraudulent or abusive use of the Services.
Product Improvement
Understanding how features are used, to guide what we build and fix next.
Communication
Sending service updates, security notices, and — where you've opted in — product or company news.
Analytics
Aggregated, generally de-identified analysis of platform usage and performance.
AI Functionality
Powering AI-assisted features such as the AI Copilot, held to the same evidence-cites-itself standard described in our Trust Centre.
Which basis applies depends on your jurisdiction.
Not every basis below is available, or required, in every jurisdiction — this list is illustrative, not a jurisdiction-by-jurisdiction determination.
Consent
Where you have given clear permission for a specific Processing activity, such as opting in to marketing communications.
Contract
Where Processing is necessary to perform our agreement with a Customer, or to take steps at your request before entering one.
Legal Obligation
Where Processing is necessary to comply with a legal or regulatory requirement we are subject to.
Legitimate Interests
Where Processing is necessary for a legitimate business interest — such as security or fraud prevention — that does not override your rights.
Categories of recipients, not a vendor list.
We name categories rather than specific providers below — this section will link to a published sub-processor list once one is finalized.
Stage 1
You Provide Information
Directly to AfriGRC, or through your organization's use of the Services.
Stage 2
AfriGRC Processes It
For the purposes described in How We Use Information above, under the safeguards in Security Measures.
Stage 3
Shared Only as Described Below
With categories of recipients necessary to operate the Services — never sold, never shared beyond what's listed here.
Cloud Infrastructure
Hosting and storage providers that run the platform's underlying infrastructure.
Email Delivery
Providers that deliver transactional and account-related email on our behalf.
Payment Providers
Providers that process subscription billing, where applicable.
Analytics
Providers that help us understand aggregated platform usage.
Professional Advisers
Legal, audit, and other professional advisers, under confidentiality obligations.
Authorities
Regulators or law enforcement, only where legally required to disclose.
Transfer mechanisms depend on deployment and jurisdiction.
Depending on where a Customer deploys the Services and where its Users are located, Personal Data may be transferred between countries — for example, between an African jurisdiction and a cloud infrastructure region.
Where a cross-border transfer requires a specific legal mechanism — such as an adequacy decision or standard contractual clauses under GDPR — the applicable mechanism depends on the jurisdictions involved and the specifics of a given deployment. This section will be expanded with the specific mechanisms AfriGRC relies on once that analysis has been completed as part of formal legal review.
Retention periods vary by category and agreement.
Specific periods depend on legal obligations, the terms of a Customer's agreement, and operational requirements — the schedule below is a placeholder structure, not final periods.
| Data Category | Typical Basis for Retention | Status |
|---|---|---|
| Account & Business Information | Duration of the Customer agreement, plus a limited period after | Schedule pending legal review |
| Platform Content (controls, policies, risk records) | Duration of the Customer agreement, per the Customer's own retention settings | Schedule pending legal review |
| Support Communications | As needed to resolve the request and for a limited period after | Schedule pending legal review |
| Technical & Security Logs | As needed for security, audit, and legal obligations | Schedule pending legal review |
| Marketing Communications | Until you withdraw consent or opt out | Schedule pending legal review |
How we protect the information described above.
A summary only — see our Security & Trust Centre for the full architecture.
Encryption
Encryption at rest across primary data stores and in transit, the same standard described in our Trust Centre.
Access Controls
Role-based access control enforced at the API layer, not just the interface.
Monitoring
Continuous monitoring for anomalous activity across infrastructure and the application layer.
Secure Development
Security requirements scoped before a feature is built, not retrofitted after.
Incident Response
A defined process for detecting, containing, and communicating about a security incident — see Security Operations in our Trust Centre.
Select a jurisdiction to see the rights that apply.
Organized by jurisdiction, expanded as our regulatory coverage grows — see our Frameworks library for the frameworks behind each.
EU / EEA
GDPR
General Data Protection Regulation — applies where AfriGRC processes personal data of individuals in the EU/EEA.
Nigeria
NDPA
Nigeria Data Protection Act — applies to processing of personal data connected to Nigeria.
South Africa
POPIA
Protection of Personal Information Act — applies to processing of personal data connected to South Africa.
Other Markets
Other African Privacy Laws
Additional African data protection frameworks, expanded as our regulatory coverage grows — see our Frameworks library.
Right to Access
Request confirmation of whether we process your personal data, and a copy of it.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data, subject to legal and contractual limits.
Right to Restrict Processing
Request that we limit how your personal data is processed in certain circumstances.
Right to Data Portability
Request a copy of your data in a structured, commonly used format.
Right to Object
Object to processing based on legitimate interests, including for direct marketing.
The Services are not directed to children.
The Services are enterprise governance, risk, and compliance software, intended for use by business professionals and not directed to children. We do not knowingly collect Personal Data from children.
If you believe a child has provided us with Personal Data, please contact our Privacy Team using the details in Contact Information below, and we will take appropriate steps to review and, where necessary, delete that information.
Categories of services we integrate.
The Services may link to, or integrate with, third-party services — for example, an identity provider a Customer chooses to use for single sign-on, or a cloud storage integration a Customer configures. This Privacy Policy does not cover the practices of those third-party services; we encourage you to review their own privacy notices.
Where AfriGRC has not yet publicly named a specific integration category as generally available, it is not listed here. See Data Sharing above for the categories of recipients AfriGRC itself shares data with.
Every revision, in one place.
We’ll update this section as this policy changes — not just the "Last Updated" date in the header.
- Establishes the page structure: Quick Summary, Definitions, Information We Collect, and the sections that follow.
- All retention periods, sub-processor names, and jurisdiction-specific rights are placeholders pending legal review.
Questions about this policy.
Privacy Team
General questions about this policy or how AfriGRC handles personal data.
Contact Privacy TeamData Protection Officer
A named DPO has not yet been appointed — inquiries are routed to our Privacy Team in the meantime.
Contact Privacy TeamQuestions about how we handle data?
Reach our Privacy Team directly, explore the full security architecture, or talk to Sales about a specific deployment.