GRACEPR

PRIVACY POLICY

Effective Date: Jan 1st, 2026     Last Updated: Jan 1st, 2026

 

1. Introduction

GRACEPR ("we", "our", "us") provides a change management and capability maturity services and systems platform ("the Platform"), including:


We respect your privacy and are committed to protecting personal data in accordance with global privacy laws, including GDPR (EU/UK), CCPA/CPRA (California), PIPEDA (Canada), Privacy Act (Australia/New Zealand), and other applicable regulations.

By using the Platform, you consent to the collection and use of information as described in this Privacy Policy.

2. Information We May Collect

A. Account and Profile Data

B. Transaction and Billing Data

  • Payment details, invoicing, and subscription history (processed via secure third-party providers).

C. Survey and Assessment Data

D. Platform Usage Data

E. Third-Party Integration Data

F. Communications Data

  • Support tickets, inquiries, feedback, and notifications.

3. How We Use Your Information

We use personal data to:

4. Legal Bases for Processing (GDPR/UK Users)

5. Data Storage and Transfers

Your data is securely stored in cloud infrastructure and associated analytics or reporting tools (e.g., Power BI).

International transfers are protected by safeguards like:

6. Data Sharing

We share data only with:

We do not sell any personal information.

7. Data Retention

8. Cookies and Tracking

We may use cookies and similar technologies for:

You can manage cookies via your browser, though disabling them may limit functionality.

9. Your Privacy Rights

Depending on your jurisdiction, you may:

California residents have additional rights under CCPA/CPRA. Requests can be submitted to us via email [contact us via www.gracepr.io]. Identity verification may be required.

10. Data Security

We implement:

While we use industry-standard protections, no system is completely secure.

11. Third-Party Services

We integrate with third-party tools for surveys and analytics.  Their privacy practices are governed by their own policies. GRACEPR is not responsible for third-party data handling.

12. Children's Privacy

The Platform is not intended for children under 16. We do not knowingly collect information from children.

13. Policy Updates

Changes will be posted on this page with a new "Last Updated" date. Significant changes may be communicated directly to users.

14. Contact

Email: see www.gracepr.io for latest email.

Address: New Zealand

Data Protection Officer: Not Applicable.



GRACEPR

GDPR Privacy Policy

Effective Date: Jan 1st, 2026   |    Last Updated: Jan 1st, 2026

 

1. Introduction

GRACEPR (“we,” “our,” “us”) operates the www. Gracepr.io website and SaaS platform known as GRACEPR (the “Platform”). Our services include online certification programs, readiness and capability surveys, and analytics dashboards for clients and practitioners.

We are committed to protecting the personal data of everyone who interacts with our system - whether you're a certified professional, a client administrator, a survey respondent, or a casual visitor. This policy explains how we collect, use, and protect that data, in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and related privacy laws.

 

2. Data Controller and Contact

For most processing activities, GRACEPR is the Data Controller. For survey and analytics data uploaded by clients, we act as a Data Processor on behalf of those clients.

 

GRACEPR

New Zealand

Email: See www.gracepr.io for latest email.



3. Data We Collect


We collect and process the following data depending on your relationship with the Platform:

a. For Certified Users and Course Participants

b. For Clients and Organizations

c. For Survey Respondents

d. Automatically Collected Data


4. Legal Basis for Processing


We process personal data under the following legal bases:


5. How We Use Data


We use your information to:

Survey data may be aggregated and anonymised to produce benchmarks or insights. No individual respondent is identifiable in aggregated outputs.


6. Data Roles



7. Data Sharing


We may share limited data with:

All vendors are bound by GDPR-compliant data processing agreements.

8. International Transfers


If data is transferred outside the European Economic Area (EEA), we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent protections.


9. Data Retention


We retain:

When retention periods expire, personal data is securely deleted or anonymised.


10. Your GDPR Rights


You have the right to:

To exercise your rights, contact us at www.gracepr.io. We will respond within the GDPR-required timeframes.


11. Data Security


We use encryption, role-based access, and network monitoring to protect all data in transit and at rest. Access to sensitive data is restricted to authorised personnel only. Regular backups and security audits are conducted to ensure integrity.

No digital system is perfectly secure, but we take every reasonable technical and organisational measure to minimise risk.


12. Cookies and Tracking


We use cookies and analytics tools for:

You can manage or withdraw cookie preferences through your browser or our consent banner.


13. Sub-Processors


A list of our approved sub-processors is available upon request and includes hosting, analytics, and payment service providers operating under GDPR-aligned contracts.


14. Updates to This Policy


We may revise this policy from time to time. The latest version will always be posted on our website, with an updated 'Effective Date.' Substantial changes may be communicated by email or in-app notice.


15. Contact


Data Protection Officer (DPO):

GRACEPR

Email: See www.gracepr.io for latest email.

If you are unsatisfied with our response, you have the right to contact your local Data Protection Authority (DPA).