Privacy Policy

Effective Date: 25-Mar-2026   |Last Updated: 25-Mar-2026

Pion Global Private Limited (“Pion Global”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal information you share with us.

This Privacy Policy explains how we collect, use, process, store, and protect personal data when you access or use the GRCNest product (https://www.grcnest.ai or https://www.grcnest.com) which is powered by our PIEDAP platform (https://www.grcnest.ai) or visit our company website https://www.pionglobal.com and other Pion Global websites.

As a proprietary digital platform offering Generative AI-powered enterprise services in quality engineering, assessments, test automation, and regulatory compliance, GRCNest is designed with data integrity, transparency, and security at its core. By accessing these websites, registering an account, or using the GRCNest services, you consent to the terms described in this Privacy Policy.

GRCNest, a compliance automation product developed under our PIEDAP (Pion Intelligent Enterprise Digital Assurance Platform) platform is a proprietary product owned and operated by Pion Global Private Limited, an Indian IT Products and Services company offering technology consulting, Product Engineering, digital transformation, Quality Engineering, DevOps, AI solutions, and platform-based services. This Privacy Policy applies specifically to data collected via the GRCNest product website and the PIEDAP platform website and related services.

Compliance Alignment

GRCNest is designed and operated in alignment with globally recognized compliance and security frameworks, including ISO/IEC 27001, SOC 2 Trust Services Criteria, the General Data Protection Regulation (GDPR), and the Digital Personal Data Protection Act, 2023 (India). Our data processing practices, security controls, and governance mechanisms are continuously evaluated and updated to meet evolving regulatory and industry standards. This ensures that Personal Data is handled with the highest levels of confidentiality, integrity, and availability, supporting enterprise-grade compliance, audit readiness, and trust.

Information We Collect

We collect several types of personal and technical information through the GRCNest product website and PIEDAP platform website, based on your interaction:

a. Information You Provide Voluntarily
• User and company details: Name, business email, phone number, organization name, designation
• Account credentials: Username, password (hashed/encrypted)
• Platform usage details: Inputs related to QA assessments, test cases, feedback, documents
• Support and communications: Emails, support tickets, feedback forms, webinar registrations

b. Information Collected Automatically
• Device and access information: IP address, browser type, operating system, session logs
• Behavioural data: Click patterns, feature usage, session duration, time on page
• Cookies and tracking: Analytics tools like Google Analytics or Hotjar may be used to collect user behaviour and performance insights

c. Third-Party or Public Sources
• If you access GRCNest product or PIEDAP platform through a partner or integrator, certain metadata or business identifiers may be shared with us under contractual obligations.

Purpose of Data Collection

We process the data we collect from you for the following purposes:

• To allow account registration, access, and secure login to the GRCNest product via PIEDAP platform
• To deliver GRCNest product and PIEDAP platform’s related AI-based services.
• To personalize platform features based on role, industry, and project needs
• To communicate with you regarding updates, service alerts, feature releases, or support
• To conduct platform analytics and performance monitoring
• To detect and prevent misuse, unauthorized access, or fraudulent activity
• To meet regulatory, contractual, and legal obligations

Contractual Obligation

GRCNest processes Personal Data where such processing is necessary for the performance of a contract with the user or customer, or in order to take steps at the request of the user prior to entering into a contract. This includes activities such as account creation, user authentication, onboarding, provisioning and delivery of platform services, processing transactions, providing customer support, and enabling integrations with third-party systems (e.g., cloud providers or enterprise tools). Without such processing, GRCNest would be unable to deliver its core functionalities, including compliance monitoring, control validation, and AI-driven risk analysis.

In fulfilling its contractual obligations, GRCNest ensures that Personal Data is processed strictly for defined service-related purposes and in accordance with applicable data protection laws, including GDPR and the Digital Personal Data Protection Act, 2023 (India). Where GRCNest acts as a data processor on behalf of enterprise customers, it processes data solely based on documented instructions provided by the customer and implements appropriate technical and organizational safeguards to protect such data. All processing activities under this legal basis are limited to what is necessary to deliver the agreed services and are subject to strict confidentiality, security, and access control measures.

Legal Basis for Processing

For users in regions governed by data protection laws such as the GDPR or CCPA, we process personal data based on the following lawful grounds:

• Consent: For marketing emails, analytics cookies, or newsletters
• Contractual necessity: To deliver the core features and services of GRCNest product and PIEDAP platform.
• Legitimate interest: To enhance platform performance, perform usage analytics, and support user engagement
• Legal obligation: To comply with tax, regulatory, and law enforcement obligations

Cookies and Tracking Technologies

The GRCNest product and PIEDAP platform websites uses cookies and similar tracking technologies to ensure the proper functioning of the platform, enhance user experience, analyze usage patterns, and maintain security. These may include essential cookies for authentication and session management, performance and analytics cookies to understand system usage, and security-related cookies to detect and prevent unauthorized access. Where required by applicable laws, such as GDPR and DPDP, GRCNest obtains user consent for non-essential cookies and provides users with the ability to manage or disable cookies through browser settings or cookie preference controls; however, disabling certain cookies may impact the functionality of the platform. You may manage your cookie preferences using the cookie banner on our website or adjust settings in your browser.

Sub-Processor Transparency

GRCNest may engage trusted third-party sub-processors to support the delivery of its services, including cloud infrastructure, data storage, analytics, and security operations. All sub-processors are carefully evaluated and contractually bound to meet stringent data protection, confidentiality, and security requirements consistent with applicable laws such as GDPR and DPDP, as well as industry standards like ISO/IEC 27001 and SOC 2. GRCNest maintains an up-to-date list of sub-processors and, where required, provides customers with prior notice of material changes, enabling them to review or raise objections in accordance with applicable agreements.

Data Sharing and Disclosure

Pion Global does not sell your personal data. However, we may share data under the following strictly controlled conditions:

• With authorized third-party processors: For hosting, storage, analytics, email delivery, and support services (e.g., AWS, SendGrid, HubSpot)
• With Pion Global subsidiaries or internal teams: For operational continuity and service delivery
• With regulators or authorities: If mandated by law, legal proceedings, or government requests
• In mergers, acquisitions, or transfers: Subject to confidentiality agreements and safeguards

All vendors and partners with access to data are contractually bound to adhere to confidentiality, data protection, and cybersecurity standards.

Data Storage and Security

We implement strong security protocols to ensure the protection and confidentiality of user data:

• Data encryption: Both in transit (TLS/SSL) and at rest (AES-256)
• Access control: Role-based access, audit logging, and identity management
• Hosting infrastructure: Secure cloud environments (e.g., AWS, Azure)
• Monitoring: Intrusion detection, vulnerability scans, and routine assessments
• Data minimization: We collect only the minimum data needed to fulfil our services

Pion Global Private Limited takes security of data seriously. GRCNest uses industry-standard technical and organizational measures to protect Information from loss, misuse, and unauthorized access or disclosure. These steps take into account the sensitivity of the personal information GRCNest collects, processes, and stores, and the current state of technology. Given the nature of communications and information processing technology, GRCNest cannot guarantee that Information in our care will be absolutely safe from intrusion by others during transmission through the Internet or while stored on our systems or otherwise. When you click a link to a third-party site, you will be leaving our site and GRCNest doesn’t control or endorse what is on third-party sites.

Data Retention

We retain personal and business data only for as long as necessary for the purposes described in this Privacy Policy. This may include

• Provide the services you have subscribed to
• Pursue legitimate business interest
• Conduct audit and meet contractual or legal obligations, resolve disputes and enforce our agreements
• Support analysis, reporting, and client communication

After the data retention period expires, data will be deleted, anonymized, or securely archived.

International Transfers

The GRCNest product and PIEDAP platform and services may involve cross-border data transfers. Where applicable, we ensure:

• Adequate data protection through Standard Contractual Clauses (SCCs) or equivalent mechanisms
• Compliance with applicable laws in jurisdictions such as the EU, UK, and US

Trust & Compliance Commitment

GRCNest is designed as a Self-Governing Trust & Compliance Product, enabling organizations to continuously monitor, validate, and strengthen their compliance posture. Through AI-driven insights and automated controls validation, GRCNest ensures real-time assurance aligned with global standards, helping enterprises proactively manage risk, maintain data integrity, and build lasting trust.

AI & Automated Decision-Making

GRCNest leverages artificial intelligence and automated processing to support functionalities such as control validation, risk analysis, anomaly detection, and generation of compliance insights. These AI-driven processes are designed to

assist Controls validation, Risk prediction, Evidence analysis, decision-making and improve efficiency; however, GRCNest does not rely solely on fully automated decisions that produce legal or similarly significant effects on individuals without appropriate human oversight. We implement measures to ensure transparency, fairness, and accuracy in AI outputs, and users may review and request additional information or clarification regarding AI-driven outcomes, in accordance with applicable data protection regulations including GDPR and DPDP.

Grievance Redressal

GRCNest is committed to addressing any concerns or complaints regarding the processing of Personal Data in a timely and transparent manner. In accordance with applicable laws, including the Digital Personal Data Protection Act, 2023 (India), users may raise grievances or exercise their rights by contacting the designated Grievance Officer at [email protected]. Upon receipt of a complaint, GRCNest will acknowledge and resolve the issue within the timelines prescribed under applicable law, ensuring fair review, appropriate action, and communication of the outcome to the concerned individual.

Your Rights and Choices

Depending on your jurisdiction, you have the right to:

• Access a copy of your personal data
• Request correction or deletion of your data
• Restrict or object to data processing in certain scenarios
• Withdraw consent at any time (without affecting prior processing)
• Request a copy of your data in a portable format (Data Portability)
• Lodge a complaint with a Data Protection Authority

To exercise these rights, email us at [email protected].

Children’s Privacy

GRCNest, a compliance automation product that is powered by PIEDAP platform is a business product/platform intended for adult professionals. We do not knowingly collect personal data from individuals under 16 years of age. If we become aware of such data, we will delete it promptly.

Third-Party Integrations and Links

GRCNest may integrate or offer integrations with third-party platforms and services, including but not limited to cloud providers (e.g., AWS, Azure), enterprise systems (e.g., ServiceNow), and analytics or security tools, to enable core platform functionality and enhance service delivery. Any data shared with such third-party integrations is processed strictly based on customer configuration and instructions, and only to the extent necessary to provide the requested services. GRCNest ensures that all third-party service providers are subject to appropriate contractual, security, and data protection obligations; however, the use of such integrations may also be governed by the respective third party’s privacy policies, and GRCNest is not responsible for the independent practices of these external services. This Privacy Policy does not govern third-party practices. We encourage users to read the privacy policies of those external platforms before interacting with them.

Data Breach Notification

In the event of any actual or reasonably suspected unauthorized access, disclosure, alteration, loss, or destruction of Personal Data or Customer Data (“Data Breach”), GRCNest shall promptly initiate its incident response procedures aligned with industry standards, including ISO/IEC 27001 and SOC 2. Upon becoming aware of a Data Breach that is likely to result in a risk to the rights and freedoms of individuals, GRCNest will notify affected customers without undue delay and, where applicable, within seventy-two (72) hours, in accordance with applicable data protection laws including the General Data Protection Regulation (GDPR) and the Digital Personal Data Protection Act, 2023 (India).

Such notification will include, to the extent reasonably available, details regarding the nature and scope of the breach, the categories of data affected, the potential impact, and the measures taken or proposed to mitigate the incident. GRCNest will also provide guidance on any recommended actions that customers or users should take to protect themselves, where applicable.

GRCNest shall take all reasonable steps to contain, investigate, and remediate the breach, including conducting root cause analysis and implementing corrective measures to prevent recurrence. Where required by law, GRCNest will cooperate with relevant regulatory authorities and fulfill applicable reporting obligations. All breach-related communications and investigations will be handled with appropriate confidentiality, except where disclosure is required for legal or regulatory purposes.

Governing Law

This Privacy Policy and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of India, without regard to its conflict of law principles. Subject to any applicable arbitration provisions, the courts located in Bangalore, Karnataka, India shall have exclusive jurisdiction over all matters arising from or relating to this Privacy Policy.

Dispute Resolution Framework

In alignment with GRCNest’s commitment to trust, governance, and compliance, any disputes arising in connection with this Privacy Policy shall be resolved through a structured dispute resolution mechanism:

• Good Faith Negotiation: Parties shall first attempt to resolve disputes through mutual discussions within 30 days.
• Binding Arbitration: If unresolved, the dispute shall be referred to binding arbitration under the Arbitration and Conciliation Act, 1996.
• Jurisdiction & Seat: Bangalore, India shall be the exclusive seat and venue.
• Finality: The arbitral award shall be final and binding on all parties.

This approach ensures efficient, confidential, and enforceable resolution, aligned with enterprise governance practices.

Changes to the Privacy Policy

Pion Global may update this Privacy Policy from time to time to reflect changes in:

• Laws and regulatory requirements
• Platform features and architecture
• Internal practices or third-party services

Any significant changes will be communicated via email or prominently on the GRCNest or PIEDAP website. Your continued use of the product and platform indicates your acceptance of the revised policy.

Contact Us

📩 For any queries, concerns, or requests related to Privacy Policy, you may contact us at [email protected]

Thank you for choosing Pion Global - Your trust is our priority