Third Party Index

Snapshot 30109

Document
Subprocessor list
URL
https://spumalabs.com/privacy.html#subprocessors
Fetched
HTTP status
200
Content type
text/html
Fetch mode
static
Size
25311 bytes
SHA-256 (raw)
7d42bc1018caf20eb4b0a187d5a49e3cd9b63db1fce6dd8121a274d4db5be0f2
SHA-256 (normalized text)
4233049031602018e08c53b69f580cb1629f280e5fb73513fb79c8163a6bafdd

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy & Data Governance Policy
Document Control: Active | Classification: Public | Last Reviewed: September 4, 2026 | Applies To: GRC Organizer by SPUMA Labs
1. Governance Commitment
At SPUMA Labs, we practice what we preach. GRC Organizer is designed with "Privacy by Design" principles. We practice strict data minimization: we process only the essential contact information required to secure your account and deliver critical alerts. We do not monetize your personal data.
2. Data Processing Inventory
The following matrix outlines the specific data elements processed within the GRC Organizer environment.
Data Element	Purpose of Collection	Legal Basis (GDPR/CCPA)	Storage & Retention
Business Email / Google Workspace Profile
Authentication: To create and verify your secure user account via SSO/Google IdP.
Compliance Verification: To verify Workspace account status for control evidence.
Alerts: To send in-app notifications and critical system updates.
Contractual Necessity
(To provide the service requested)	Encrypted (AES-256). Retained for duration of active subscription + 2 years for audit logs.
Usage Metadata	System Health: Monitoring uptime and error logs to ensure GRC Organizer stability.	Legitimate Interest
(Security & Performance)	Anonymized and aggregated. Retained for 12 months.
Financial Data	N/A	N/A	We do not store credit card data. All payments are processed via our PCI-DSS compliant payment provider.
3. Infrastructure & Sub-processors
To provide the GRC Organizer service, we partner with industry-leading infrastructure providers. We maintain a strict "Least Privilege" access policy with our vendors.
Sub-processor	Service Provided	Location (Data Residency)	Compliance Standards
Amazon Web Services (AWS)	Cloud Hosting & Database Storage	United States (US-East-1)	SOC 2 Type II, ISO 27001, GDPR Compliant
OpenAI (API)	AI Evidence Review: Automated analysis of control evidence screenshots.	United States	SOC 2 Type II, CCPA, GDPR Compliant
Google LLC (Google Cloud/Workspace)	Identity Provider (IdP): User authentication and email/domain verification.	Global / United States	SOC 2 Type II, ISO 27001, GDPR Compliant
Cloudflare	Zero Trust Authentication (IdP) & Edge Security	Global (Anycast Edge)	SOC 2 Type II, ISO 27001, PCI-DSS
AI Privacy Commitment
When using our AI-assisted evidence review, data is processed via OpenAI's API. We have strictly configured this integration so that your data is NOT used to train OpenAI’s models. Furthermore, use of AI features is entirely optional; users may choose to perform manual evidence reviews without triggering any data transmission to OpenAI.
Google API Limited Use Disclosure
GRC Organizer's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to serve advertisements or for the development/training of generalized AI models.
*Note: Data is encrypted at rest and in transit. Infrastructure providers do not have access to unencrypted data within GRC Organizer.*
4. Cookie Policy & Session Management
To maintain the integrity of your session, GRC Organizer utilizes cookies. We categorize these into "Strictly Necessary" (Active) and "Optional" (Inactive).
Cookie Category	Purpose	Status
Strictly Necessary
Identity & Access: Cloudflare and Google auth tokens to validate user identity.
Security: Enforces CSRF protection and WAF rules.
ACTIVE
(Cannot be disabled)
Marketing & Analytics
Performance: Tracking user journey to improve features.
Advertising: Retargeting and campaign measurement.
INACTIVE
(We do not currently deploy marketing pixels. Future deployment will require explicit opt-in.)
5. Incident Response & Breach Notification
SPUMA Labs maintains a robust Incident Response Plan aligned with TX-RAMP and GDPR standards. In the event of a confirmed security incident affecting the confidentiality, integrity, or availability of your data, we commit to the following notification timeline:
Rapid Notification (48-Hour Commitment): We will notify affected Account Administrators via email within 48 hours of discovery. This expedited timeline is designed to support our customers' compliance with Texas DIR reporting requirements (TX-RAMP) and other accelerated regulatory frameworks.
Transparency & Detail: Our notification will include the nature of the incident, the specific data potentially impacted, and the immediate mitigation steps taken by our security team.
Remediation: We will provide continuous updates until the incident is fully resolved.
6. User Rights & Controls
You maintain full control over your data in GRC Organizer. You may request an export of your data or deletion of your account at any time.
Right to Access: Request a copy of all personal data we hold.
Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your account and associated data.
Right to Rectification: Update or correct your business contact information.
7. Contacting Our Team
We welcome your questions regarding data governance and privacy rights.
Privacy Inquiries
Email: [email protected]
Purpose: GDPR/CCPA requests, policy questions.
Response: Within 30 days.
Security Incidents
Email: [email protected]
Purpose: Reporting vulnerabilities or events.
Response: Monitored 24/7.
8. Policy Change Log
We believe in transparency. Material changes to this policy will be logged here.
Version	Date	Description of Changes
v1.3	Sep 04, 2026	Added Disclaimer to footer. Disclaimer added to footer.
v1.2	Apr 06, 2026	Added Google IdP Integration. Included disclosures for Google Workspace email verification and Google API Limited Use compliance.
v1.1	Feb 07, 2026	Added OpenAI as Sub-processor. Introduced AI-powered evidence review features. Clarified "No Training" data policy and user opt-out controls for AI features.
v1.0	Jan 13, 2026	Initial Policy Release. Established for GRC Organizer launch. Validated AWS (US-East-1) as primary infrastructure. Integrated Cloudflare Zero Trust for authentication. Confirmed TX-RAMP alignment (48hr notification).