Overview
This policy explains how CardinalGRC (“we”, “us”) handles personal data collected through this website. It covers visitors to the site, not the data our customers process inside the platform, which is governed by the agreement between us and that customer, and by the customer’s own privacy notices. As a provider of governance, risk and compliance software, we hold ourselves to the standards we help our customers meet.
Information we collect
- Information you give us. When you request a demo or contact us, you may provide your name, work email, organisation, role and any message you send.
- Technical and usage data. Aggregate, privacy-preserving analytics about how the site is used (for example, pages viewed and approximate region). We use a cookie-less analytics provider and do not build advertising profiles.
How we use it
- To respond to demo requests and enquiries, and to arrange and follow up on sessions.
- To operate, secure and improve the website.
- To comply with our legal and regulatory obligations.
Legal bases
Where data-protection law applies (including the Nigeria Data Protection Act 2023 and the EU/UK GDPR), we rely on your consent, our legitimate interests in operating and securing the site, and the steps necessary to respond to your request.
Sharing and sub-processors
We do not sell personal data. We share it only with service providers that help us run the site and respond to you (for example, hosting, email delivery and analytics), under contracts that require appropriate safeguards. A current list of sub-processors is available on request via our Trust Center.
International transfers
Where personal data is transferred across borders, we put appropriate safeguards in place as required by applicable law.
Retention
We keep enquiry data for as long as needed to respond and for a reasonable period afterwards, then delete or anonymise it.
Security
We apply technical and organisational measures appropriate to the data we hold, including encryption in transit, access controls and audit logging. No system is perfectly secure, but we treat the protection of personal data as a first-class obligation.
Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, and withdraw consent. To exercise a right, contact us at the address below.
Changes
We may update this policy from time to time. We will revise the “last updated” date above when we do.
Contact
Questions or requests about this policy can be sent to hello@cardinalgrc.com.