eGARC International

Privacy Policy

Last updated 17 September 2026

eGARC International is committed to protecting the information entrusted to our platform by organizations, users, auditors, risk professionals, compliance teams, and other authorized stakeholders. This Privacy Policy explains how we collect, use, protect, and manage information across the eGARC platform and related services.

eGARC may collect information provided by organizations and authorized users when they create an account, use our platform, request services, or communicate with us. This may include names, business email addresses, phone numbers, organization information, user roles, authentication information, audit records, risk and compliance data, governance information, supporting documents, activity logs, and other information necessary to provide the platform's services.

We use information to provide, maintain, secure, and improve the eGARC platform. This includes supporting audit management, risk management, compliance monitoring, fraud management, governance workflows, reporting, user administration, notifications, authentication, customer support, system security, and platform analytics. We use organizational information only for legitimate business and platform purposes and do not use customer data for unrelated advertising or profiling.

eGARC is designed to help organizations manage sensitive operational, audit, risk, compliance, governance, and fraud-related information. Organizations remain responsible for determining what information they enter into the platform and for ensuring that users have appropriate authorization to access that information. Access to organizational data is controlled through user accounts, roles, permissions, and other security mechanisms provided by the platform.

eGARC applies reasonable technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. Security measures may include encrypted connections, authentication controls, role-based access controls, permission management, secure session handling, audit trails, infrastructure security, and controlled access to platform systems. No internet-based system can guarantee absolute security, but we continuously work to protect the information entrusted to the platform.

eGARC may use cookies, session technologies, and similar mechanisms that are necessary to authenticate users, maintain secure sessions, remember preferences, and operate the platform. Authentication and session information is handled using security controls appropriate to the platform architecture. We do not use unnecessary third-party tracking technologies for unrelated advertising purposes.

eGARC does not sell customer or organizational data. Information may be processed or disclosed when necessary to provide platform services, operate infrastructure, maintain security, comply with applicable legal obligations, respond to lawful requests, or protect the rights and security of eGARC, its customers, users, or others. Where third-party service providers are used, they are expected to process information only for authorized purposes and subject to appropriate contractual or technical safeguards.

We retain information for as long as reasonably necessary to provide the eGARC services, maintain business and security records, satisfy contractual requirements, resolve disputes, comply with applicable legal obligations, and protect legitimate business interests. Retention periods may differ depending on the type of information, the organization's configuration, contractual requirements, and applicable legal or regulatory obligations.

Depending on applicable law and the relationship between eGARC and the organization using the platform, individuals may have rights relating to access, correction, deletion, restriction, or other processing of their personal information. Requests relating to organizational data may also need to be handled through the relevant customer organization or account administrator. We will review legitimate requests and take appropriate action in accordance with applicable requirements.

If you have a privacy question, security concern, data request, or question about how eGARC handles information, please contact our team through the official eGARC support or contact channel. When submitting a request, provide enough information for us to understand the nature of the request and, where necessary, verify your identity or authorization.

Have a privacy or data concern?

Contact the eGARC team through your organization's designated eGARC contact channel for privacy questions, security concerns, or data-related requests.