Privacy Policy
Last updated: July 2026
1. Who We Are
NovaGRC ("we", "us", "our") provides an enterprise risk management platform for tracking risks, running business impact analyses, building continuity plans, and managing compliance. This policy explains how we collect, use, and protect your personal data when you use our services.
2. Data We Collect
- Account information: your name, email address, and an encrypted password when you register or are added to a workspace.
- Workspace content: the risk, BIA, BCP, compliance, and task records you and your team create within the platform.
- Usage data: pages visited and features used, to help us improve the service.
3. How We Use Your Data
- Provide and maintain your NovaGRC account and workspace.
- Send account, security, and workflow notifications (such as task assignments and password resets).
- Power optional AI-assisted features you choose to use.
- Respond to support requests and improve the platform.
We do not sell your personal data to third parties.
4. Data Sharing
We share data only with service providers that help us operate the platform — including Abacus.AI for hosting, AI-powered features, and email notifications. All providers are bound by data protection agreements.
5. AI Features & Your Data
Several NovaGRC features are AI-assisted (for example, drafting risk descriptions, summarizing controls, or suggesting remediation steps). These features are optional — they run only when you actively choose to use them.
- Not used to train models. Content you submit to an AI feature is never used to train, fine-tune, or improve any AI model — not by us and not by our AI provider.
- Processed transiently. Your input is sent to our AI provider (Abacus.AI) solely to generate the output you requested and is not retained by the provider for training after the request completes.
- You control what is saved. AI output is stored in your workspace only when you explicitly save it (for example, accepting a generated description onto a risk). Saved output is then treated like any other workspace data under this policy.
- No third-party advertising or profiling. AI data is never shared for advertising or sold to third parties.
6. Cookies
- Essential cookies: required for sign-in and core site functionality.
- Preference cookies: remember settings such as your light/dark theme.
You can disable cookies in your browser settings, but this may affect how the platform works.
7. Data Security
- Encryption of data in transit.
- Encrypted database storage.
- Secure password hashing (bcrypt).
- Optional multi-factor authentication and role-based access controls.
8. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we remove your personal data and the records you own, except where we are legally required to retain it.
9. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, contact us using the details below.
10. Changes to This Policy
We may update this policy from time to time. We'll notify you of significant changes by email or a notice within the platform.
11. Contact Us
For privacy-related questions, reach us through our contact page.
