IntelliGRC Privacy Policy

Version 1.3 (September 14, 2021)

At IntelliGRC, Inc. (“IntelliGRC”, “we” or “us”), we place the highest importance on respecting and protecting the privacy of our customers. Our most important asset is our relationship with you. We want you to feel comfortable and confident when using our Web site and our service. We would like to share with you the following principles that govern our information practices and other privacy aspects of our Web site and our service. Throughout this policy, we refer to information that personally identifies you as "Personally Identifiable Information" or “PII”.

Changes to this Privacy Policy

We will update this privacy policy when necessary to reflect customer feedback and changes in our services as well as applicable laws, rules and regulations. When we post changes to this policy, we will revise the "last updated" date at the top of the policy and post the updated policy at http://www.intelligrc.com/privacy. If there are material changes to the statement or in how Tiber Creek will use your personal data, we will notify you either by prominently posting a notice of such changes before they take effect or by directly sending you a notification. We encourage you to periodically review this privacy policy to learn how IntelliGRC is protecting your information. Using IntelliGRC websites or services after a notice of changes has been sent to you or published on our website shall constitute consent to the changed terms and practices. Unless stated otherwise, our current privacy policy applies to all information that IntelliGRC has about you and your account.

To Contact Us

If you have privacy-related questions that are not addressed here, please contact the Privacy Team by email privacy@intelligrc.com, or write us at: Tiber Creek Consulting, Inc. - IntelliGRC , 12015 Lee Jackson Hwy Suite 600, Fairfax VA 22033.

Personal Information

Personal Information We Collect

By using this website or registering for our service, you voluntarily and willingly provide us with certain information, including personally identifiable information, which we collect in order to provide the IntelliGRC website and service. Personal Information refers to information about you that can be used to contact or identify you, and information on your use of and activities at our site and through the IntelliGRC service that may be connected with you. Personal information that we collect may include, but is not limited to, your name, phone number, billing information, email address and postal addresses.

Personal Information may also include information you supply to us concerning your preferences and interests expressed in the course of use of our site and the IntelliGRC service. If you are unsure whether you would like to provide information to us and/or having your information used as permitted in this Privacy Policy, you should not register for our service or, if you are already a user of our service, you should close your account. We maintain these account identifiers as long as necessary for our internal business purposes. For the sake of clarity this account identifier information is not inclusive of data you may upload and store within IntelliGRC apps. Please see https://www.intelliGRC.com/terms for IntelliGRC's process for purging app data at termination of contract.

How We Use Personal Information

By submitting your information, you are expressly and voluntarily accepting the terms and conditions of this privacy policy. You have the right to withdraw your consent to our collection and use of your information by changing your account settings or closing your account, but your withdrawal of consent will not be retroactive. We may use the information you provide to (i) provide our site and services to you and administer your use of our site and services, (ii) to communicate with you and fulfill requests you may make, (iii) to provide you with information and announcements with respect to our service, and (iv) to provide you with further information and offers from us or third parties that we believe you may find useful or interesting, including newsletters, marketing or promotional materials and other information on services and products offered by us or third parties.

We may use your Personal Information to communicate with you through email and text messages and notices posted at our website or on your account and to provide you with customer support. If you decide at any time that you no longer wish to receive any such communications, please follow the “unsubscribe” instructions provided in any of the communications sent to you, or update your “account settings” information.

We may also use the information provided by you or obtained through your use of our site or service to improve our site, services, features and content, to customize your user experience, and to better understand your needs and interests. We use information we obtain by technical means (such as the automatic recording performed by our servers or through the use of cookies) for the above purposes as well as to monitor, measure and analyze use of the site and our services, to generate and derive useful data and information concerning the interests, characteristics and website use behavior of our users, and to verify that visitors to the site meet the criteria required to process their requests.

We may use sources outside of IntelliGRC to supplement the information you give us. For example, we may validate your address using other sources. We use this data to help us maintain accuracy and provide you with better service.

How We Share Personal Information

We do not sell or rent your personal information to anyone.

Third Party Service Providers. We have limited relationships with third parties to assist us in providing the IntelliGRC service to you, for example, by fulfilling customer orders or providing customer service. These service providers are contractually required to maintain the confidentiality of the information we provide them. The contracts outline the appropriate use and handling of your information and prohibit third parties from using any of your personal information for purposes unrelated to the product or service for which they’ve been contracted. Vendors are required to maintain the confidentiality of the information we provide to them.

Legal Disclosures. We may disclose or report personal information in limited circumstances where we believe in good faith that disclosure is required to comply with applicable laws, rules or regulations, to enforce or apply our Terms of Service, available at http://www.intelligrc.com/terms and other agreements, or to protect the rights, property, or safety of IntelliGRC, users of our service, or others. For example, we may be required to disclose personal information to cooperate with regulators or law enforcement authorities, to comply with a legal process such as a court order, subpoena, search warrant, or a law enforcement request.

Business Partners. We have business partners that provide services, some of which are co-branded. Partner services and sites are clearly identified. When you request any of these products or services, you are permitting us to provide your personal information to the partner to fulfill your request. This Web site may provide links to third-party sites, such as those of our business partners and online advertisers. Because IntelliGRC does not control the information policies or practices of these third parties, you should review their privacy policies to learn more about how they collect and use personal information.

Business Transfers. Should we sell, merge or transfer any part of our business, part of the sale may include your personal information and you agree that any such third party will have the right to continue to use your Personal Information and other information that you provide to us or which we obtain through your use of the service.

We also may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

If you use an email address provided by your organization, such as your employer or school, to sign into the IntellIGRC service, the owner of the domain associated with your email address may: (i) control and administer your account and (ii) access and process data you share with IntelliGRC. If your organization is administering your use of the IntellIGRC Service, please direct your privacy inquiries to your administrator.

We will provide an individual opt-out or opt-in choice before we share their data with third parties other than our agents, or before we use it for a purpose other than which it was originally collected or subsequently authorized. To limit the use and disclosure of your personal information, you can submit a written request to Privacy@IntelliGRC.com.

Cookies, Web Beacons and other Web Technologies

We use a variety of technologies on our Web site. Among these are cookies, which are pieces of information that our Web sites provide to your browser. Cookies allow us to customize your visit to our Web site by recognizing you when you return. You can choose to decline cookies while at our Web site, however, this may limit your ability to access certain areas of the Web site. Most browsers accept and maintain cookies by default. Check the "Help" menu of your browser to learn how to change your cookie preference.

When we track activity on our Web site, we collect information such as your IP address, browser type and version, and pages you view. We also keep track of how you got to our site and any links you click on to leave our site. Once you leave our site, we do not track you. We use your Web site activity to assist us in offering you a personalized Web experience, assist you with technical support and to tailor our offerings to you.

We may access and set cookies using Web beacons, also known as single-pixel GIFs which are invisible graphical images. These Web beacons tell us useful information regarding our site such as which pages users access. When we send you e-mails, we may include a single-pixel GIF to determine the number of people who open our e-mails. When you click on a link in an e-mail, we record this individual response to allow us to customize our offerings to you.

Your Right to Access and Control Your Personal Information

You may access, review, revise, correct, or delete the personal information provided in your registration or account profile by changing your preferences in “My Preferences.” If you update any of your information, we may keep a copy of the information that you originally provided to us in our archives for uses documented in this policy.

Security of Personal Information

We protect the confidentiality and security of your personal information by using industry-recognized security safeguards such as encryption, multi factor authentication and firewalls among others, coupled with carefully developed security procedures to protect your information from loss, misuse or unauthorized alteration. Whenever we ask for sensitive information we encrypt it as it is transmitted to us. Our employees are trained and required to safeguard your information and, using physical, electronic and procedural safeguards, we restrict access to personal information to those employees and agents for business purposes only. Additionally, we use internal and external resources to review the adequacy of our security procedures.

Although IntelliGRC uses industry standard security measures, the Internet is not a 100% secure environment and IntelliGRC cannot, and does not, ensure or warrant the security of any information you transmit or store using the IntelliGRC service. There is no guarantee that your information may not be accessed, disclosed, altered or destroyed by breach of any of IntelliGRC physical, technical or managerial safeguards and we are not responsible for third party circumvention of your privacy settings or IntelliGRC’s security measures. You are responsible for maintaining the secrecy of your unique password and account information and for controlling access to your IntelliGRC account.

Our Retention of Personal Data

We retain personal data only for as long as necessary to provide the services and fulfill the transactions you have requested, or for other essential purposes such as complying with our legal obligations, resolving disputes, and enforcing our agreements.

Other Places Where We Collect Personal Information

IntelliGRC Blog

If you use our blog on this Web site, you should be aware that any personally identifiable information you submit there can be read, collected, or used by other users of these forums, and could be used to send you unsolicited messages. We are not responsible for the personally identifiable information you choose to submit in this forum.

IntelliGRC Billing

When you subscribe to a level of IntelliGRC service requiring a fee, we require that you provide your billing address and your credit card information, including credit card number and expiration date. Credit card information is used solely for the purpose of billing you for IntelliGRC service. Credit card transactions are processed by a third party. IntelliGRC does not ever see your credit card information, nor do we store any part of the number, CVV code, or other tokens.

Your IntelliGRC service is billed to an account. IntelliGRC recognizes the account in which your data lives as the owner of your data. The account is responsible for payment and can transfer ownership of your data. Account owners and administrators should keep in mind that if they grant another individual full administrative rights to their account, that person will have access to the account's billing information.

IntelliGRC Partner Program

If you apply for the IntelliGRC Partner Program, you are required to provide your company's address, contact information, and other demographic information in order for IntelliGRC to contact you regarding the IntelliGRC Developer program.

Organization Information:
Tiber Creek Consulting Inc., Attn: IntelliGRC
12015 Lee Jackson Hwy Suite 600, Fairfax VA 22033

IntelliGRC

IntelliGRC is the intelligent Governance, Risk Management, and Compliance platform. Using automation, IntelliGRC provides a holistic approach to information security.

Privacy Policy

IntelliGRC® is a registered trademark of Tiber Creek Consulting, Inc.

© 2021 Tiber Creek Consulting, Inc.