Privacy Notice

GRCTrail AI (Early-Access Wait-list)

Last updated: June 28, 2025

1. Who we are

GRCTrail AI is a pre-launch project run by Serhii Vats (“we”, “us”).

We are not yet incorporated. Until the legal entity is formed you can reach the controller at:

Serhii Vats (GRCTrail AI)

[Valencia], [Spain]

sergey.vatz@gmail.com

We will update this notice with the new company name and registered address once incorporation is complete.

2. What data we collect (wait-list)

CategoryPurposeRequired?
Email addressConfirm your spot and send onboarding updates.Yes
Job titleTailor the product demo to your role.Yes
Company nameIdentify unique organisations.Yes
Company sizePrioritise features (SMB vs enterprise).Yes
IndustryCustomise compliance examples.Yes
Current compliance frameworkMatch you with relevant beta features.Optional
Biggest compliance challengeRefine roadmap.Optional
How you heard about usEvaluate marketing channels.Optional

We store form entries in an encrypted database hosted in the EU and US on AWS.

3. How we use your data

  • Early-access coordination – send confirmation, onboarding material, and beta invitations.
  • Product research – analyse aggregate trends (e.g., % of visitors already using ISO 27001).

Legal basis – Article 6(1)(b) GDPR (pre-contractual steps) and Article 6(1)(f) (legitimate interest in building our product).

4. Third-party processors

ProcessorPurposeSafeguards
AWS (Ireland / Virginia)Data hostingStandard contractual clauses
SendGrid (USA)Transactional emailDPA in place

We never sell or rent your information.

5. Your rights

Under GDPR you may access, correct, delete, or export your personal data at any time.

Email sergey.vatz@gmail.com with your request and we will respond within 30 days.

6. Data retention

We keep wait-list data for 12 months after the public launch or until you ask us to delete it, whichever comes first.

7. Future changes

We'll post any changes here and update the "Last updated" date. Significant changes will be emailed to all wait-list members.