Executive Summary of Terms & Privacy
This document establishes the binding terms governing your use of the TeamGRC Marketing Website (https://teamgrc.ai) and outlines how TeamGRC Inc. collects, processes, and protects personal data submitted through contact inquiries, demo requests, and website analytics in strict compliance with the European General Data Protection Regulation (GDPR / Dutch AVG) and global data privacy standards.
1. Acceptance of Terms & Scope of Agreement
These Terms of Website Use (“Terms”) constitute a legally binding agreement between you (“Visitor”, “User”, or “You”) and TeamGRC Inc., a corporation founded and operating in Amstelveen, The Netherlands, along with its corporate affiliates (“TeamGRC”, “we”, “us”, or “our”).
By accessing, browsing, interacting with, or submitting data through https://teamgrc.ai, its subdomains, landing pages, interactive compliance catalogs, ROI calculators, or contact channels (collectively, the “Marketing Site”), you expressly acknowledge that you have read, understood, and agreed to be legally bound by these Terms and our incorporated Privacy Policy.
If you do not agree to these Terms in their entirety, you must immediately cease accessing and using this Marketing Site.
2. Marketing Site vs. Enterprise SaaS Platform Distinction
It is critical to distinguish between the public Marketing Site and the proprietary TeamGRC Software-as-a-Service (“SaaS”) platform:
- Marketing Site: This public web portal is designed exclusively for informational, educational, and commercial evaluation purposes (e.g., product feature overviews, whitepapers, framework directories, ROI calculators, and demo scheduling).
- TeamGRC SaaS Platform: Access to the live, multi-tenant cloud SaaS platform, tenant-isolated risk databases, AI compliance orchestration agents, and API integrations is governed exclusively by a separate, negotiated Master Services Agreement (MSA), Service Level Agreement (SLA), and Data Processing Addendum (DPA) executed between TeamGRC and subscribing enterprise customers.
Browsing the Marketing Site, requesting a demo, or completing a contact form does not confer any license or entitlement to access the production TeamGRC SaaS platform.
3. No Formal Legal, Regulatory, or Audit Advice Disclaimer
Crucial Compliance & Legal Disclaimer
All content on this site—including framework crosswalks, ISO 27001/NIST/SOC 2 summaries, NIS2/DORA analyses, and ROI estimates—is published for general informational and marketing purposes only and does not constitute legal, regulatory, cybersecurity certification, or statutory audit advice.
While TeamGRC strives to maintain accurate and up-to-date information regarding global regulatory frameworks (such as ISO/IEC 27001, SOC 2 Type II, NIST CSF 2.0, EU NIS2 Directive, EU DORA, HIPAA Security Rule, and the EU Artificial Intelligence Act):
- The materials on this site do not substitute for formal legal counsel, licensed cybersecurity auditors, accredited third-party assessors, or accredited certification bodies.
- Your reliance upon any informational summary, regulatory matrix, or calculation obtained through the Marketing Site is done solely at your own risk.
- TeamGRC makes no representation or warranty that utilizing our methodology or platform guarantees audit clearance, statutory compliance, or immunity from regulatory penalties under any legal jurisdiction.
4. AI Demonstrations & Simulation Outputs
The Marketing Site may showcase illustrative AI-driven features, simulated risk matrices, automated control cross-mappings, or interactive chatbot demonstrations (“AI Demonstrations”).
You acknowledge that:
- AI Demonstrations utilize probabilistic language models and algorithmic synthesis intended to illustrate platform workflows.
- Sample outputs, automated compliance recommendations, and risk scores generated in public demos are illustrative simulations and should not be relied upon for production governance or risk decisions.
- TeamGRC does not ingest public marketing inquiries to train generalized foundation models without explicit enterprise contract terms.
5. Intellectual Property Rights & Limited License
The Marketing Site, its entire contents, features, and functionality (including but not limited to all software code, HTML/CSS layouts, UI design systems, brand assets, logos, graphics, text, framework cross-mapping taxonomies, methodology charts, audio/video media, and documentation) are the sole and exclusive intellectual property of TeamGRC Inc. and its licensors, protected under Dutch, European, United States, and international copyright, trademark, trade secret, and patent laws.
5.1 Limited Revocable License
Subject to your complete compliance with these Terms, TeamGRC grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access, view, and display the Marketing Site on your device solely for your internal evaluation of TeamGRC services.
5.2 Trademark Protection
“TeamGRC”, “TeamGRC.ai”, the TeamGRC emblem/logo, and all related names, logos, product and service names, designs, and slogans are proprietary trademarks of TeamGRC Inc. You are expressly prohibited from using such marks without the prior written authorization of TeamGRC. All other trademarks, trade names, or service marks appearing on the Site are the property of their respective owners.
6. Acceptable Use & Prohibited Conduct
You agree to use the Marketing Site solely for lawful business evaluation purposes in accordance with these Terms. You specifically covenant and agree that you shall not:
- Scraping & Data Mining: Use any automated spider, crawler, scraper, robot, script, or systematic extraction tool to harvest data, text, framework crosswalks, or code from the Site, or circumvent any
robots.txtdirective. - AI Model Ingestion: Ingest, scrape, or extract any website content, documentation, or proprietary taxonomies to train, fine-tune, or benchmark external artificial intelligence or machine learning models without prior written consent.
- Security Violations: Probe, scan, penetration-test, or breach the vulnerability of the Marketing Site or its infrastructure without prior written authorization under a formal Responsible Disclosure Agreement.
- Malicious Payloads: Introduce viruses, Trojan horses, worms, logic bombs, ransomware, or other malicious, destructive, or technologically harmful code.
- Form Abuse & Denial of Service: Engage in form flooding, spamming honeypot fields, automated contact submissions, or launching Denial of Service (DoS/DDoS) attacks against our edge network.
- Reverse Engineering: Decompile, reverse engineer, disassemble, or attempt to derive the source code of any client-side or server-side scripts powering the Site.
- Misrepresentation: Impersonate TeamGRC, a TeamGRC executive or employee, another user, or submit falsified business contact details through demo booking forms.
7. Disclaimers of Warranties & Limitation of Liability
7.1 “As-Is” & “As-Available” Provision
THE MARKETING SITE, ITS CONTENT, AND ANY INFORMATION OR SERVICES OBTAINED THROUGH IT ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS, WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMISSIBLE UNDER APPLICABLE LAW, TEAMGRC INC. EXPRESSLY DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, TIMELINESS, OR UNINTERRUPTED AVAILABILITY.
7.2 Limitation of Damages
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL TEAMGRC INC., ITS DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES (INCLUDING LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF GOODWILL, LOSS OF DATA, WORK STOPPAGE, OR BUSINESS INTERRUPTION) ARISING OUT OF OR IN CONNECTION WITH YOUR ACCESS TO, USE OF, OR INABILITY TO USE THE MARKETING SITE, REGARDLESS OF THE THEORY OF LIABILITY (CONTRACT, TORT, STRICT LIABILITY, OR NEGLIGENCE), EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
7.3 Aggregate Liability Cap
TO THE EXTENT PERMITTED BY APPLICABLE LAW, TEAMGRC'S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATING TO THE PUBLIC MARKETING SITE SHALL IN NO EVENT EXCEED ONE HUNDRED EUROS (€100.00 EUR) OR ONE HUNDRED US DOLLARS (\$100.00 USD).
8. Privacy Notice & Data Controller Identification
TeamGRC is committed to protecting your privacy, safeguarding personal data, and maintaining strict compliance with the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), the Dutch GDPR Implementation Act (Uitvoeringswet AVG), the UK GDPR, and applicable US state privacy laws (including the California Consumer Privacy Act / CCPA / CPRA).
For the purposes of European data protection laws, the Data Controller responsible for the processing of personal data collected via the Marketing Site is:
Corporate Operations & European Cloud Hosting: European Union
Privacy & Data Protection Officer Contact: privacy@teamgrc.ai
9. Categories of Personal Data Collected
When you interact with our Marketing Site, we collect only the minimal personal data necessary to facilitate business inquiries, schedule product demonstrations, and maintain secure site operations:
| Category of Data | Source / Collection Channel | Specific Data Fields | Primary Purpose |
|---|---|---|---|
| Business Contact Data | Contact Form & Demo Request Form | First Name, Last Name, Corporate/Work Email, Phone Number, Company Name, Job Title/Role. | Direct B2B sales outreach, scheduling live platform demonstrations, and responding to inquiries. |
| Inquiry Context Data | Form Message & Notes fields | Compliance frameworks of interest (e.g. ISO 27001, NIS2), organizational security challenges, inquiry message. | Tailoring the demonstration walkthrough to your organization's specific GRC requirements. |
| Technical & Telemetry Data | Automated HTTP logs | IP address, browser type/version, device category, operating system, referrer URL, timestamp of request. | Network security, DDoS mitigation, rate-limiting, and diagnosing server communication faults. |
| Client-Side Preferences | Browser LocalStorage | Visual theme toggle state (teamgrc-theme: light | dark). | Preserving your visual dark/light mode preference across page navigations (Zero tracking). |
Special Categories of Data: TeamGRC does not collect, solicit, or process any special category personal data (e.g., health, racial/ethnic origin, biometric data, religious beliefs, or trade union membership) through the Marketing Site.
10. Legal Bases for Processing (GDPR Article 6)
In accordance with Article 6 of the GDPR and the Dutch AVG, TeamGRC processes your personal data strictly under the following recognized legal bases:
- Pre-Contractual Measures & Contract Negotiation (Art. 6(1)(b) GDPR): Processing is necessary at the request of the data subject prior to entering into a contract when you submit a demo request, request platform pricing, or ask for product specifications.
- Legitimate Business Interests (Art. 6(1)(f) GDPR): Processing is necessary for our legitimate B2B commercial interests in responding to corporate inquiries, safeguarding our web application from malicious bot attacks, analyzing aggregate site performance, and conducting targeted B2B commercial outreach, provided such interests are not overridden by your fundamental rights and freedoms.
- Consent for Marketing & Newsletters (Art. 6(1)(a) GDPR): Where you subscribe, submit an inquiry, or opt in, we process your contact details to send TeamGRC newsletters, product release updates, regulatory threat advisories, and marketing emails. You retain the absolute right to withdraw your consent and unsubscribe at any time.
- Consent for Third-Party Partner Data Sharing (Art. 6(1)(a) GDPR): Where you submit an inquiry, request a demonstration, or provide consent, you authorize and consent to TeamGRC passing the details you have entered (such as your name, corporate email, phone number, company name, and inquiry notes) to third-party partner companies that TeamGRC collaborates with (including authorized resellers, GRC implementation consultancies, and joint solution providers) for relevant follow-up, consultation, and commercial outreach.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Processing necessary to comply with European, Dutch, or international legal, accounting, tax, or law enforcement mandates.
11. Hosting, Marketing Communications & Third-Party Partner Sharing
11.1 Cloud Infrastructure & Technical Sub-processors
TeamGRC maintains a strict commitment to European data sovereignty and enterprise-grade cloud security:
- Primary Cloud Infrastructure: The Marketing Site, API execution, and contact databases reside strictly within the European Union.
- Content Delivery & Edge Security: Static assets are distributed with strict TLS 1.3 encryption and DDoS mitigation.
- Technical Sub-processors: We engage only trusted, ISO 27001 / SOC 2 certified third-party service providers (e.g., enterprise transactional email relays, calendar scheduling tools) bound by strict Data Processing Addenda (DPAs).
- International Data Transfers: Any transfer of personal data outside the European Economic Area (EEA) is conducted pursuant to valid adequacy decisions under GDPR Article 45, or executed under standard European Commission Standard Contractual Clauses (SCCs) with supplementary technical safeguards.
11.2 Consent for Newsletters & Marketing Communications
By submitting your contact information through our contact or demo forms, subscribing to our mailing list, or providing consent on the Marketing Site, you consent to receive marketing communications and informational newsletters from TeamGRC, which may include:
- Periodic newsletters detailing regulatory compliance updates (e.g., NIS2, DORA, ISO 27001, EU AI Act, NIST CSF);
- Product release announcements, platform feature updates, and technical whitepapers;
- Invitations to educational webinars, live demonstrations, and cybersecurity executive briefings;
- Commercial offers, promotional materials, and tailored platform evaluation opportunities.
Withdrawal of Marketing Consent / Unsubscribe: You may withdraw your marketing consent at any time without charge. Every promotional email transmitted by TeamGRC incorporates an automated, single-click “Unsubscribe” link. Alternatively, you may submit an opt-out request at any time to privacy@teamgrc.ai.
11.3 Consent to Pass Details to Third-Party Partner Companies
To deliver comprehensive Governance, Risk, and Compliance solutions, localized sales assistance, and specialized technical implementation services, TeamGRC works in collaboration with select third-party partner companies (“Authorized Partners”), including:
- Channel Partners & Resellers: Regional technology providers authorized to distribute, license, and support TeamGRC solutions;
- Implementation & Consulting Partners: Cybersecurity consulting firms, certified auditors, and GRC advisory partners who assist organizations with compliance assessments and solution deployment;
- Technology & Integration Partners: Companies that collaborate with TeamGRC to deliver joint product integrations, combined demonstrations, or co-branded offerings.
Scope of Partner Data Sharing Consent: By submitting your details on this website (including through contact forms, demo requests, or inquiry submissions) or by consenting to partner collaboration, you expressly consent and agree that TeamGRC may pass the details you have entered—including your name, corporate email address, telephone number, company name, job title, and specific inquiry or interest notes—to third-party partner companies that TeamGRC works with.
Permitted Purpose & Partner Obligations: Authorized Partners are permitted to use your shared details solely for the purposes of following up on your inquiry, providing relevant technical or commercial information, conducting joint demonstrations, assessing compliance requirements, or offering related consulting and implementation services. All Authorized Partners are contractually required to maintain the confidentiality and security of your personal data in accordance with applicable data protection laws.
Revoking Partner Sharing: You retain the right at any time to object to or revoke consent for the sharing of your personal data with third-party partners by contacting privacy@teamgrc.ai with the subject line “Partner Sharing Opt-Out”.
12. Data Retention Schedules
We retain personal data only for as long as necessary to fulfill the commercial and legal purposes for which it was originally collected:
- Demo Requests & Sales Inquiries: Retained for the duration of the active B2B sales cycle plus twenty-four (24) months following the last meaningful business contact, unless an earlier request for erasure is submitted.
- General Support & Contact Inquiries: Retained for twelve (12) months from resolution of the query.
- Server Access & Security Logs: Retained on an automated rolling schedule of ninety (90) days for forensic anomaly detection and cybersecurity mitigation, after which logs are permanently overwritten or purged.
13. Your Data Protection Rights Under GDPR & EU Law
If you are located within the European Economic Area (EEA), the United Kingdom, or Switzerland, you possess extensive statutory rights under Chapter III of the GDPR:
| GDPR Article | Statutory Right | Description of Entitlement |
|---|---|---|
| Article 15 | Right of Access | Obtain confirmation as to whether we process your data and receive a copy of such personal data. |
| Article 16 | Right to Rectification | Request the immediate correction of inaccurate or incomplete personal data. |
| Article 17 | Right to Erasure (“To Be Forgotten”) | Request deletion of your personal data where retention is no longer legally justified. |
| Article 18 | Right to Restriction of Processing | Request temporary suspension of data processing during verification or dispute resolution. |
| Article 20 | Right to Data Portability | Receive your provided data in a structured, commonly used, machine-readable format (JSON/CSV). |
| Article 21 | Right to Object | Object at any time to data processing based on legitimate interests or direct B2B marketing. |
Exercising Your Rights: To exercise any statutory right, please submit a written request to privacy@teamgrc.ai. We will respond within thirty (30) calendar days without charge.
Supervisory Authority Complaint: You also have the right to lodge a formal complaint with a competent supervisory authority, in particular the Dutch Data Protection Authority:
Bezuidenhoutseweg 30, 2594 AV Den Haag, The Netherlands
Website: autoriteitpersoonsgegevens.nl
14. United States State Privacy Disclosures (CCPA / CPRA)
This section applies solely to residents of California, Virginia, Colorado, Utah, Connecticut, and other US states with comprehensive privacy legislation:
- No Sale or Sharing of Personal Information: TeamGRC has not sold, shared, or rented personal information to third parties for monetary or cross-context behavioral advertising in the preceding twelve (12) months.
- Right to Know & Delete: US residents have the right to request disclosure of categories of personal information collected, sources, business purposes, and to request deletion of such data.
- Non-Discrimination: We will never discriminate against you (by denying services or altering terms) for exercising your statutory privacy rights.
To submit a California Consumer Privacy Act request, email privacy@teamgrc.ai with the subject line “CCPA/CPRA Privacy Request”.
16. Technical & Organizational Security Measures (TOMs)
As a Governance, Risk, and Compliance software provider, TeamGRC applies rigorous Technical and Organizational Measures (TOMs) pursuant to Article 32 of the GDPR:
- Transport Layer Security: Enforced HTTPS with TLS 1.3 cryptography for all inbound and outbound web sessions.
- Encryption at Rest: AES-256 bit encryption applied across all backend databases, object stores, and backup archives.
- Access Control & Least Privilege: Strict role-based access control (RBAC), multi-factor authentication (MFA), and zero-trust administrative boundaries across cloud infrastructure.
- Continuous Vulnerability Management: Automated static application security testing (SAST), dependency scanning, and active cloud posture monitoring.
17. Governing Law, Dispute Resolution & Jurisdiction
These Terms, the Privacy Policy, and any dispute, controversy, or claim arising out of or relating to your use of the Marketing Site shall be governed by, construed, and enforced in accordance with the laws of The Netherlands, without regard to conflict of law principles.
Any legal dispute or proceeding arising out of or in connection with these Terms that cannot be resolved amicably shall be submitted to the exclusive jurisdiction of the competent district court in Amsterdam, The Netherlands, without prejudice to any mandatory statutory consumer venue rights applicable under local European Union regulations.
18. Amendments, Severability & Contact Inquiries
18.1 Modifications to Terms
TeamGRC reserves the right to revise and update these Terms and Privacy Policy periodically to reflect evolving legal mandates, regulatory guidance, or website enhancements. When amendments are enacted, we will update the “Effective Date” at the top of this document. Your continued browsing of the Site following the posting of revised terms constitutes your binding acceptance.
18.2 Severability
If any provision of these Terms is determined by a court of competent jurisdiction to be unlawful, invalid, or unenforceable, that provision shall be enforced to the maximum extent permissible, and the remaining provisions shall continue in full force and effect.
18.3 Corporate Contact Channels
For inquiries, feedback, or legal notices concerning these Terms or our data protection practices, please contact us through the appropriate department: