Privacy Policy
Last updated 8 July 2026
We built GRC Solo on one rule — observe reality, don't assert it — and we hold our own data practices to it. This policy says exactly what we collect, why, and what we don't. The short version: we collect the email you give us, we don't track you, and your operational security data never reaches us at all.
Who this covers
This policy applies to the GRC Solo marketing website (this site). GRC Solo is operated by Unusual SA Ventures LLC, a Wyoming limited liability company (registered agent: Northwest Registered Agent Service Inc, 30 N Gould St Ste N, Sheridan, WY 82801). The GRC Solo product is delivered as a federated install and is governed separately — your operational security data stays on your infrastructure and is never routed through us.
What we collect
Email you submit. When you request access or join the waitlist, we store the email address you enter. That is the only personal data we ask for.
Server logs. Our hosting provider processes standard request metadata (including your IP address, transiently) to serve and secure the site. See subprocessors.
Analytics. We use Vercel Web Analytics, a privacy-first, cookieless tool that sets no cookies, stores nothing on your device, and does not track you across sites. That is why you see no cookie wall here — we don't need one.
What we deliberately don't do
No advertising cookies, no cross-site tracking, no data brokers, no sale or rent of your data. We do not receive, store, or process the security evidence, secrets, or operational data of GRC Solo customers — the product's federated architecture means that data never enters our systems, so we cannot lose, leak, or be compelled to hand it over.
Why we process it, and our legal basis
We use your email solely to respond to your request and to contact you about the private preview. Under the GDPR our basis is your consent (which you can withdraw at any time) and our legitimate interest in responding to an inbound request. We do not use it for automated decision-making or profiling.
How long we keep it
We keep your email while the private preview is active and you remain interested. Ask us to delete it and we will, promptly. If you never convert, we periodically purge stale access-request records.
Who else processes data for us (subprocessors)
We use a small, deliberately short list of vendors to run the site. We keep that list current and observed — it reflects what our code actually uses, not a boilerplate. See the live list: /subprocessors.
Your rights
Wherever you are, you can ask us to access, correct, export, or delete your email, and to stop contacting you. If you are in the EU/UK (GDPR) you also have the right to object, to restrict processing, to data portability, to withdraw consent, and to complain to your supervisory authority. If you are in California (CCPA/CPRA) you have the right to know, delete, correct, and opt out of sale/sharing — note that we do not sell or share your data. To exercise any of these, email privacy@grcsolo.com.
International transfers
We are based in the United States and process the limited data described above there. GRC Solo currently offers its services to US-based businesses and does not target or market to data subjects in the EU/EEA or UK. If and when we offer services there, we will appoint and publish a GDPR Article 27 (and UK) representative before doing so.
Children
This site and product are for business use and not directed to anyone under 16. We do not knowingly collect data from children.
Changes
If we change this policy we update the date above. Material changes for the private preview will be communicated to people on the list.
Contact
Privacy questions or requests: privacy@grcsolo.com. Security issues: see /security.