Legal
Privacy Policy
Last updated: July 13, 2026 · Maintained by Securewise GRC LTD
1. Introduction
Securewise GRC LTD, a company registered in Jamaica, trading as "SecureWise AI" ("SecureWise", "we", "us"), provides a governance, risk, and compliance (GRC) platform that helps organizations manage controls, evidence, audits, policies, and regulatory frameworks. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our website, applications, and services (collectively, the "Services"). This page is maintained by Securewise GRC LTD to answer common privacy questions about the Services and is not an independent certification.
2. Controller status
Securewise GRC LTD is the data controller for personal data you provide to us directly (e.g., account information, communications) and for the personal data contained in the Customer Data you upload to your workspace. For payment transactions handled by Paddle (see Section 6), Paddle acts as the seller of record and the controller for the payment-related personal data it processes.
3. Data we collect
- Account data: name, work email, organization, role, and authentication identifiers.
- Workspace content: controls, policies, risks, evidence files, audit findings, questionnaire responses, and other content you upload.
- Usage data: pages viewed, features used, timestamps, IP address, browser, device, and diagnostic logs.
- AI interaction data: prompts you submit to the AI assistant and outputs generated in your workspace.
- Communications: support messages, demo requests, and correspondence with our team.
- Cookies & similar tech: strictly necessary cookies for authentication and session management; optional analytics cookies where enabled.
4. How we use data & legal bases (GDPR / UK GDPR)
- Provide and operate the Services — including account provisioning, authentication, multi-tenant isolation, and support. Legal basis: performance of a contract.
- AI-assisted compliance workflows — running the assistant, gap analysis, control mapping, policy drafting, and evidence scanning grounded in your workspace data. Legal basis: performance of a contract.
- Security, fraud prevention, and abuse detection. Legal basis: legitimate interests and compliance with legal obligations.
- Service improvement and product analytics. Legal basis: legitimate interests (and consent, where required for optional analytics).
- Communication about your account, product updates, and security notices. Legal basis: performance of a contract and legitimate interests. Marketing emails are sent only with your consent, where required.
- Legal, regulatory, tax, and accounting obligations. Legal basis: legal obligation.
5. AI features
Our AI features send your prompts and relevant workspace data to third-party AI model providers under contractual data protection commitments. We do not use Customer Data to train third-party foundation models. You are responsible for the prompts you submit and for reviewing AI outputs before relying on them for compliance, audit, or regulatory decisions.
6. Sharing & subprocessors
We do not sell personal data. We share data only with vetted recipients under contractual data protection commitments, including:
- Paddle.com — our Merchant of Record for the sale of subscriptions, payment processing, subscription management, tax compliance, invoicing, and refunds.
- Cloud infrastructure, database, storage, and email delivery providers.
- AI model providers used to power in-product AI features on your workspace data.
- Analytics, error monitoring, and customer support tooling.
- Professional advisers (legal, accounting, auditors) where necessary.
- Authorities where required by law.
7. International transfers
Personal data may be processed in countries other than where you reside, including the United States, the United Kingdom, and the European Economic Area. Where required, we rely on Standard Contractual Clauses, the UK IDTA, adequacy decisions, or equivalent transfer mechanisms to ensure an adequate level of protection.
8. Retention
We retain personal data only for as long as necessary to provide the Services, meet legal, tax, audit, or accounting obligations, or resolve disputes. Workspace content is retained for the life of your subscription and deleted within 30 days after termination, unless a longer retention period is required by law. Billing and transactional records held by Paddle are retained according to Paddle's own policies and applicable tax law.
9. Security
We implement administrative, technical, and organizational safeguards including encryption in transit (TLS 1.2+), encryption at rest, tenant isolation via row-level security, least-privilege access controls, audit logging, and continuous monitoring. See our Security page for more detail. No system can guarantee absolute security.
10. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. Under the GDPR and UK GDPR you also have the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact privacy@securewise.io. We will respond within one month, subject to extension where legally permitted.
11. Cookies
We use strictly necessary cookies to authenticate users and keep your session active. Where enabled, we may also use optional analytics cookies to understand how the Services are used. You can manage cookie preferences through your browser settings; blocking strictly necessary cookies may prevent parts of the Services from functioning.
12. Children
The Services are not directed to children under 16, and we do not knowingly collect personal data from children.
13. Changes
We may update this Policy from time to time. Material changes will be communicated via the Services or by email. Continued use of the Services after an update constitutes acceptance of the revised Policy.
14. Contact
Data Controller: Securewise GRC LTD (Jamaica) · privacy@securewise.io · Contact us
