Data Processing Agreement
Last Updated: 16 September 2026
Standard Contractual Clauses (SCCs)
This Data Processing Agreement (DPA) supplements our Terms of Service and incorporates the European Commission's Standard Contractual Clauses to ensure full GDPR compliance for international data transfers.
This Data Processing Agreement ("DPA") is entered into by and between you ("Customer" or "Data Controller") and GRC Copilot Pro ("Processor"). This agreement outlines the data protection obligations of both parties regarding the processing of personal data in connection with the services provided.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller.
- "Data Protection Laws" means all applicable and binding privacy and data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR) and the California Consumer Privacy Act (CCPA).
- "Zero-Retention AI Architecture" means our proprietary processing mechanism where uploaded text is processed entirely in ephemeral memory (RAM) and destroyed immediately after output generation.
2. Processing of Personal Data
We process Personal Data strictly in accordance with your documented instructions to provide the GRC Copilot Pro services. We will not sell, rent, or lease your data.
Data Hosting
All persistent database data (e.g., Risk Registers, Vendor Logs) is hosted on secure SOC 2 Type II certified cloud infrastructure.
Ephemeral AI Generation
Document uploads sent to our LLM API are never stored on disk and are never used to train foundational AI models.
3. Sub-processors
You authorize us to engage third-party Sub-processors to assist in providing the services. A full list of our current authorized sub-processors is maintained securely and is available to active customers upon request. We will notify you of any intended changes concerning the addition or replacement of Sub-processors as required by applicable law.
4. Security Measures
We implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage. This includes AES-256 encryption at rest and TLS 1.3 encryption in transit.
5. Deletion or Return of Data
Upon termination of your account, you may request the deletion of all Personal Data. We will securely delete all applicable data from our production systems within 30 days, except where required by law to retain it.
To execute a countersigned copy of this DPA for your vendor risk management files, please contact privacy@grccopilot.pro.
