Last updated: 28/ Sep 2026
This policy explains how CyberSage Solutions Ltd ("we", "us") collects and uses personal data when you use GRC Sage, including the GRC Career Readiness Scorecard, the GRC Readiness Report, the founding cohort list, calls you book with us, and our courses.
CyberSage Solutions Ltd is the controller of your personal data.
Registered in Ireland,
Registered address: Drogheda Ireland
Contact for anything in this policy: [email protected]
When you take the scorecard
Your answers to the 20 questions
Your overall score and your score in each of the five domains
Your name and email address
Whether you ticked the box to receive GRC Sage updates
When you join the founding cohort list
Your name and email address
Your phone number and organisation, if you choose to give them
Your consent choices
When you book a call
The time you book, and your answers to the booking questions (your current field, the role you are aiming for, the hours you have available)
Your phone number, if you give it for reminders
When you enrol
Your name, email and billing details
Payment is handled by Stripe. We never see or store your full card number.
Automatically
Your time zone and basic technical details of the device and browser you use
Which of our pages and forms you visit
Whether you open our emails and which links you click
Our scorecard and forms can remember your name and email on the same device, so you do not have to type them again
What we do Legal basis Calculate your scores, show your results and email you the GRC Readiness Report You asked for it (steps taken at your request, GDPR Art. 6(1)(b)) Email you about the founding cohort after you join the list You asked for it (Art. 6(1)(b)) Send you wider GRC Sage updates, such as future cohorts and new content Your consent (Art. 6(1)(a)). You can withdraw it at any time Send SMS reminders for a call you booked Your consent (Art. 6(1)(a)) Run your course and provide what you paid for Our contract with you (Art. 6(1)(b)) Keep financial records Legal obligation under Irish tax law (Art. 6(1)(c)) Understand which emails and pages are useful, and improve them Our legitimate interest in running and improving the service (Art. 6(1)(f))
We do not share your scorecard answers or scores with employers or anyone else.
We do not sell your personal data.
We will never put you forward to an employer without asking you first. If we offer that in future, it will be a separate, clearly explained choice that you opt into, and you can withdraw at any time.
Your scores are calculated automatically from your answers. The result is guidance for you only. It has no legal or similarly significant effect on you.
We use a small number of service providers who process data on our instructions under written agreements.
Provider What they do Where HighLevel Inc. (with Mailgun for sending) Scorecard, forms, contact records, email and SMS United States Google (Google Workspace) Our email inbox EU and United States. Stripe Payments EU and United States [confirm] Vercel Hosting our website United States
Where data leaves the European Economic Area, we rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses.
Scorecard and list data: until you unsubscribe or ask us to delete it, or 24 months after your last contact with us, whichever comes first.
Call booking details: 12 months after the call, unless you enrol.
Student records: for the duration of your course and 2 years after it ends.
Financial records: 6 years, as Irish tax law requires.
You can ask us to:
give you a copy of your data
correct it
delete it
restrict or object to how we use it
move it to another provider
stop sending marketing, at any time (every email has an unsubscribe link)
Email [email protected]. We will reply within one month.
If you are unhappy with how we have handled your data, you can complain to the Data Protection Commission in Ireland at dataprotection.ie. If you live elsewhere, you can also contact your local regulator, for example the Nigeria Data Protection Commission under the Nigeria Data Protection Act 2023.
GRC Sage is for adults. Please do not use it if you are under 18.
We use providers with established security programmes, keep access to your data to the people who need it, and protect our accounts with multi-factor authentication.
If we change this policy in a way that matters, we will update the date at the top and tell you by email if you are on our list.