Effective date: 1 April 2026 | Last updated: 17 April 2026 | Applies to EU GDPR (2016/679) & UK GDPR (DPA 2018)
1. Who We Are
NextGen GRC Inc. ("NextGen GRC", "we", "us", or "our") operates the NextGen GRC platform. For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR, we act as the Data Controller for personal data collected through this website and the platform. Our registered address is: NextGen GRC Inc., 64 Siddapura Rd, A308 HILIFE RIO, Bengaluru, KA 560035, India.
2. Scope & Applicable Law
This policy applies to all personal data we process about visitors to this website and users of the platform. It is consistent with:
- EU GDPR (2016/679) — applies to processing of EU/EEA residents' personal data regardless of where processing occurs.
- UK GDPR & Data Protection Act 2018 — applies to processing of UK residents' personal data; the ICO (Information Commissioner's Office) is the lead supervisory authority.
- EU–US Data Privacy Framework (DPF, July 2023) — the replacement for Privacy Shield, enabling lawful data transfers from the EU to the US under adequacy decision; relevant for our US-based sub-processors.
- India DPDP Act 2023 — India's Digital Personal Data Protection Act; we comply as a data fiduciary processing data of Indian residents.
3. Personal Data We Collect
We collect personal data you provide directly and data collected automatically:
- Identity & Contact Data: first name, last name, work email address, company name, job title.
- Preference Data: ERP system in use, GRC area of interest, messages submitted through our contact form.
- Account Data: username, hashed password, access role, last login timestamp.
- Technical Data: IP address, browser type and version, time zone, pages visited, session duration — collected via server logs.
- Communications Data: records of correspondence if you contact us by email or contact form.
We do not process special categories of personal data (Art. 9 GDPR) or personal data of children under 16.
4. Lawful Basis for Processing (Art. 6 GDPR)
- Contract (Art. 6(1)(b)): Processing necessary to deliver the NextGen GRC platform under your subscription agreement or free trial.
- Legitimate Interests (Art. 6(1)(f)): Improving the platform, security monitoring, fraud prevention, direct marketing to existing customers. We have conducted a Legitimate Interests Assessment (LIA); you may request a copy.
- Legal Obligation (Art. 6(1)(c)): Retaining records as required by applicable tax, accounting, and regulatory law.
- Consent (Art. 6(1)(a)): Where we rely on consent (e.g., marketing emails to prospects), you have the right to withdraw at any time without affecting prior processing.
5. How We Use Your Personal Data
- To create and manage your account and deliver the platform features you have subscribed to.
- To respond to enquiries, provide product demos, and deliver technical support.
- To send product update notifications and relevant compliance content (opt-out available at any time).
- To monitor platform security, detect abuse, and prevent unauthorised access.
- To comply with legal and regulatory obligations and enforce our Terms of Service.
- To conduct internal analytics and improve product features (using pseudonymised or aggregated data where possible).
6. Your Rights Under GDPR (Arts. 15–22)
You have the following rights regarding your personal data. We will respond to verified requests within one calendar month (extendable by two months for complex requests, with notice):
- Right of Access (Art. 15): Obtain confirmation of whether we process your data and receive a copy.
- Right to Rectification (Art. 16): Have inaccurate personal data corrected without undue delay.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your personal data where it is no longer necessary, you withdraw consent, or there is no legitimate overriding interest.
- Right to Restriction of Processing (Art. 18): Restrict processing while accuracy is contested or an objection is pending.
- Right to Data Portability (Art. 20): Receive personal data you provided in a structured, machine-readable format (JSON/CSV) and transmit it to another controller.
- Right to Object (Art. 21): Object at any time to processing based on legitimate interests or for direct marketing purposes; we will cease unless we demonstrate compelling legitimate grounds.
- Rights Related to Automated Decision-Making (Art. 22): We do not make solely automated decisions with legal or similarly significant effects on individuals.
To exercise any of these rights, email support@nextgengrc.world with the subject line "GDPR Data Subject Request — [Right]".
7. International Data Transfers
Our platform is hosted on cloud infrastructure that may involve transfers of personal data outside the EEA/UK. We ensure appropriate safeguards for all transfers:
- Transfers to the US: sub-processors participating in the EU–US Data Privacy Framework (DPF) or covered by Standard Contractual Clauses (SCCs) (EU Commission Decision 2021/914).
- Transfers to India: covered by SCCs until an adequacy decision is issued; we conduct Transfer Impact Assessments (TIAs) for high-risk transfers.
- UK transfers: governed by the UK's International Data Transfer Agreement (IDTA) or Addendum to EU SCCs.
8. Data Retention
- Account data: retained for the duration of your subscription plus 12 months after termination for legal/contractual purposes, then deleted.
- Contact form submissions and marketing enquiries: 24 months from last contact.
- Financial and billing records: 7 years as required by applicable tax law.
- Security logs (IP, access timestamps): 90 days for operational security, up to 12 months where required by law.
9. Security Measures (Art. 32 GDPR)
We implement appropriate technical and organisational measures including: TLS 1.2+ encryption in transit; bcrypt-hashed credentials at rest; role-based access controls; regular vulnerability assessments; and access logs reviewed periodically. Our controls are aligned with ISO/IEC 27001:2022 Annex A.
10. Data Breach Notification (Art. 33–34 GDPR)
In the event of a personal data breach, we will notify the relevant supervisory authority (EDPB / ICO) within 72 hours of becoming aware where the breach is likely to result in a risk to individuals' rights and freedoms. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
11. Privacy by Design & by Default (Art. 25 GDPR)
We embed data protection principles into our product from the design stage. Default settings are privacy-protective: data minimisation is applied to all features; access to personal data within the platform is restricted to the minimum necessary for each role; and new features undergo a DPIA screening before launch.
12. Cookies & Tracking
We use only strictly necessary session cookies required for platform authentication. We do not use third-party advertising, analytics, or social tracking cookies. You can disable cookies in your browser settings, though this will affect platform login functionality. Our landing page does not set any cookies; cookies are only set upon platform login.
13. Third-Party Sub-Processors
We use a limited number of vetted sub-processors (cloud hosting, transactional email delivery). Each is bound by a Data Processing Agreement (DPA) under Art. 28 GDPR. A list of current sub-processors is available on request.
14. Data Protection Officer
We have appointed a Data Protection contact responsible for overseeing GDPR compliance. Contact: support@nextgengrc.world (subject: "DPO Enquiry"). We aim to respond to all DPO enquiries within 5 business days.
15. Supervisory Authority & Right to Complain (Art. 77 GDPR)
If you are an EU resident and believe we have infringed your GDPR rights, you have the right to lodge a complaint with your local supervisory authority (e.g., the CNIL in France, BfDI in Germany, or the EDPB). UK residents may contact the ICO at ico.org.uk. We encourage you to contact us first so we can resolve your concern directly.
16. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email to registered users and by posting the updated policy with a revised effective date. Continued use of the platform after the effective date constitutes acceptance.
17. Contact Us
For privacy enquiries, data subject requests, or to exercise your GDPR rights:
Email: support@nextgengrc.world
Address: NextGen GRC Inc., 64 Siddapura Rd, A308 HILIFE RIO, Bengaluru, KA 560035, India.