← Back to Home
LegalLast updated: April 17, 2026

Privacy Policy

1. Who We Are

NextGen GRC Inc. ("NextGen GRC", "we", "us", or "our") operates the NextGen GRC platform. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR, we act as the Data Controller for personal data collected through this website and the platform. Our registered address is: NextGen GRC Inc., 64 Siddapura Rd, A308 HILIFE RIO, Bengaluru, KA 560035, India.

2. Scope & Applicable Law

This policy applies to all personal data we process about visitors to this website and users of the platform. It is consistent with:

3. Personal Data We Collect

We collect personal data you provide directly and data collected automatically:

We do not process special categories of personal data (Art. 9 GDPR) or personal data of children under 16.

4. Lawful Basis for Processing (Art. 6 GDPR)

5. How We Use Your Personal Data

6. Your Rights Under GDPR (Arts. 15–22)

You have the following rights regarding your personal data. We will respond to verified requests within one calendar month (extendable by two months for complex requests, with notice):

To exercise any of these rights, email support@nextgengrc.world with the subject line "GDPR Data Subject Request — [Right]".

7. International Data Transfers

Our platform is hosted on cloud infrastructure that may involve transfers of personal data outside the EEA/UK. We ensure appropriate safeguards for all transfers:

8. Data Retention

9. Security Measures (Art. 32 GDPR)

We implement appropriate technical and organisational measures including: TLS 1.2+ encryption in transit; bcrypt-hashed credentials at rest; role-based access controls; regular vulnerability assessments; and access logs reviewed periodically. Our controls are aligned with ISO/IEC 27001:2022 Annex A.

10. Data Breach Notification (Art. 33–34 GDPR)

In the event of a personal data breach, we will notify the relevant supervisory authority (EDPB / ICO) within 72 hours of becoming aware where the breach is likely to result in a risk to individuals' rights and freedoms. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.

11. Privacy by Design & by Default (Art. 25 GDPR)

We embed data protection principles into our product from the design stage. Default settings are privacy-protective: data minimisation is applied to all features; access to personal data within the platform is restricted to the minimum necessary for each role; and new features undergo a DPIA screening before launch.

12. Cookies & Tracking

We use only strictly necessary session cookies required for platform authentication. We do not use third-party advertising, analytics, or social tracking cookies. You can disable cookies in your browser settings, though this will affect platform login functionality. Our landing page does not set any cookies; cookies are only set upon platform login.

13. Third-Party Sub-Processors

We use a limited number of vetted sub-processors (cloud hosting, transactional email delivery). Each is bound by a Data Processing Agreement (DPA) under Art. 28 GDPR. A list of current sub-processors is available on request.

14. Data Protection Officer

We have appointed a Data Protection contact responsible for overseeing GDPR compliance. Contact: support@nextgengrc.world (subject: "DPO Enquiry"). We aim to respond to all DPO enquiries within 5 business days.

15. Supervisory Authority & Right to Complain (Art. 77 GDPR)

If you are an EU resident and believe we have infringed your GDPR rights, you have the right to lodge a complaint with your local supervisory authority (e.g., the CNIL in France, BfDI in Germany, or the EDPB). UK residents may contact the ICO at ico.org.uk. We encourage you to contact us first so we can resolve your concern directly.

16. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be notified via email to registered users and by posting the updated policy with a revised effective date. Continued use of the platform after the effective date constitutes acceptance.

17. Contact Us

For privacy enquiries, data subject requests, or to exercise your GDPR rights:
Email: support@nextgengrc.world
Address: NextGen GRC Inc., 64 Siddapura Rd, A308 HILIFE RIO, Bengaluru, KA 560035, India.