GRC Sage Privacy Policy

Last updated: 28/ Sep 2026

This policy explains how CyberSage Solutions Ltd ("we", "us") collects and uses personal data when you use GRC Sage, including the GRC Career Readiness Scorecard, the GRC Readiness Report, the founding cohort list, calls you book with us, and our courses.

Who we are

CyberSage Solutions Ltd is the controller of your personal data.

  • Registered in Ireland,

  • Registered address: Drogheda Ireland

  • Contact for anything in this policy: [email protected]

What we collect

When you take the scorecard

  • Your answers to the 20 questions

  • Your overall score and your score in each of the five domains

  • Your name and email address

  • Whether you ticked the box to receive GRC Sage updates

When you join the founding cohort list

  • Your name and email address

  • Your phone number and organisation, if you choose to give them

  • Your consent choices

When you book a call

  • The time you book, and your answers to the booking questions (your current field, the role you are aiming for, the hours you have available)

  • Your phone number, if you give it for reminders

When you enrol

  • Your name, email and billing details

  • Payment is handled by Stripe. We never see or store your full card number.

Automatically

  • Your time zone and basic technical details of the device and browser you use

  • Which of our pages and forms you visit

  • Whether you open our emails and which links you click

  • Our scorecard and forms can remember your name and email on the same device, so you do not have to type them again

Why we use it, and our legal basis

What we do Legal basis Calculate your scores, show your results and email you the GRC Readiness Report You asked for it (steps taken at your request, GDPR Art. 6(1)(b)) Email you about the founding cohort after you join the list You asked for it (Art. 6(1)(b)) Send you wider GRC Sage updates, such as future cohorts and new content Your consent (Art. 6(1)(a)). You can withdraw it at any time Send SMS reminders for a call you booked Your consent (Art. 6(1)(a)) Run your course and provide what you paid for Our contract with you (Art. 6(1)(b)) Keep financial records Legal obligation under Irish tax law (Art. 6(1)(c)) Understand which emails and pages are useful, and improve them Our legitimate interest in running and improving the service (Art. 6(1)(f))

What we do not do

  • We do not share your scorecard answers or scores with employers or anyone else.

  • We do not sell your personal data.

  • We will never put you forward to an employer without asking you first. If we offer that in future, it will be a separate, clearly explained choice that you opt into, and you can withdraw at any time.

Your scores are calculated automatically from your answers. The result is guidance for you only. It has no legal or similarly significant effect on you.

Who processes your data for us

We use a small number of service providers who process data on our instructions under written agreements.

Provider What they do Where HighLevel Inc. (with Mailgun for sending) Scorecard, forms, contact records, email and SMS United States Google (Google Workspace) Our email inbox EU and United States. Stripe Payments EU and United States [confirm] Vercel Hosting our website United States

Where data leaves the European Economic Area, we rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses.

How long we keep it

  • Scorecard and list data: until you unsubscribe or ask us to delete it, or 24 months after your last contact with us, whichever comes first.

  • Call booking details: 12 months after the call, unless you enrol.

  • Student records: for the duration of your course and 2 years after it ends.

  • Financial records: 6 years, as Irish tax law requires.

Your rights

You can ask us to:

  • give you a copy of your data

  • correct it

  • delete it

  • restrict or object to how we use it

  • move it to another provider

  • stop sending marketing, at any time (every email has an unsubscribe link)

Email [email protected]. We will reply within one month.

If you are unhappy with how we have handled your data, you can complain to the Data Protection Commission in Ireland at dataprotection.ie. If you live elsewhere, you can also contact your local regulator, for example the Nigeria Data Protection Commission under the Nigeria Data Protection Act 2023.

Age

GRC Sage is for adults. Please do not use it if you are under 18.

Security

We use providers with established security programmes, keep access to your data to the people who need it, and protect our accounts with multi-factor authentication.

Changes

If we change this policy in a way that matters, we will update the date at the top and tell you by email if you are on our list.