GRC FORGE - ISO 27001 Training Platform
Home
Foundation Academy Master ISO 27001 fundamentals
AI Audit Room Unique audit simulator
Quiz & Exams 600+ LI/LA questions
Pro Templates PRO 50+ ISMS documents
Risk Workshop PRO Risk analysis & treatment
🏆 Certification Track your progress to expert
Pricing Contact
Login Get Started
Home
Foundation Academy AI Audit Room Quiz & Exams Pro Templates Risk Workshop
Pricing Contact
Login Get Started Free
GDPR Compliant — EU 2016/679

Privacy Policy

Last updated: 14/03/2026 · GRC FORGE is committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable data protection law.

1. Data Controller

The data controller for your personal data is:

CompanyGRC FORGE
Emailcontact@grcforge.pro
DPO contactcontact@grcforge.pro
Websitehttps://grcforge.pro

2. Data Collected

CategoryDataLegal basis
AccountFirst name, last name, email, hashed password, role, planContract execution
ProgressionQuiz scores, completed modules, certificates, exam historyLegitimate interest
AI InteractionsQuestions asked to the AI, session identifiersContract execution
PaymentTransaction reference, plan, amount, currency (no card data stored)Legal obligation
TechnicalConnection logs, IP address, browser/OSLegitimate interest (security)
PreferencesInterface language, notification settingsLegitimate interest

3. Purposes of Processing

  • Account management: Authentication, profile, subscription access
  • Service delivery: Access to courses, quizzes, AI tools, certificates
  • Progression tracking: Storing scores, module completions, learning analytics
  • Billing: Payment processing, invoice management
  • Communications: Transactional emails, important service notifications
  • Security: Fraud detection, access logs, platform integrity
  • Product improvement: Anonymous usage analytics

GRC FORGE does not use your personal data for commercial prospecting without your explicit consent.

4. Data Retention

CategoryRetention period
Account dataFor the duration of the account, then 3 years after deletion request
Learning progressionDuration of account + 2 years
AI conversations12 months rolling (then anonymized)
Billing records10 years (legal obligation)
Connection logs12 months

5. Data Sharing

GRC FORGE does not sell your personal data. Data may be shared with the following categories of recipients:

  • Moneroo / Stripe: Payment processing (PCI-DSS compliant)
  • Anthropic: AI query processing (Claude API) — anonymized where possible
  • Hosting provider: Technical infrastructure
  • Email service: Transactional email delivery

All processors are subject to contractual obligations ensuring GDPR compliance. Data transfers outside the EU are governed by appropriate safeguards (Standard Contractual Clauses or adequacy decisions).

6. Your Rights

Under GDPR, you have the following rights regarding your personal data:

📋 Right of access Obtain a copy of all personal data held about you.
✏️ Right to rectification Request correction of inaccurate or incomplete data.
🗑️ Right to erasure Request deletion of your data ("right to be forgotten").
⏸️ Right to restriction Request temporary suspension of data processing.
📦 Right to portability Receive your data in a structured, machine-readable format.
🚫 Right to object Object to processing based on legitimate interest.

To exercise these rights, contact: contact@grcforge.pro

We will respond within 30 days of receiving your request. If you believe your rights have not been respected, you have the right to lodge a complaint with your national supervisory authority (e.g., CNIL in France).

7. Cookies and Trackers

CookiePurposeDuration
PHPSESSIDAuthentication sessionSession
grc_langLanguage preference1 year
csrf_tokenSecurity (CSRF protection)Session
AnalyticsAnonymous usage statisticsUp to 13 months

You can configure or disable cookies in your browser settings. Disabling essential cookies may prevent access to certain platform features.

8. Security

GRC FORGE implements technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure or destruction:

  • HTTPS encryption for all data in transit
  • Bcrypt hashing of passwords
  • CSRF protection on all sensitive forms
  • Regular security audits
  • Restricted access to personal data (need-to-know principle)

In the event of a personal data breach likely to result in a high risk for your rights, you will be notified without undue delay in accordance with GDPR Article 34.

9. Policy Updates

This Privacy Policy may be updated at any time. Any significant changes will be communicated by email or via a notice on the platform. We encourage you to review this policy periodically.

The date at the top of this page indicates when the policy was last revised.

10. Contact

For any questions regarding this Privacy Policy or to exercise your rights:

  • DPO email: contact@grcforge.pro
  • General contact: grcforge.pro/en/contact.php
GRC FORGE - ISO 27001 Training

The reference platform for ISO 27001 Lead Implementer & Lead Auditor certification. AI-powered training, real-world practice, verifiable certificates.

Platform

  • Quiz ISO 27001
  • Mock Exams LI/LA
  • Room IA (Carine)
  • Academy 5 Days
  • ISMS Templates

Resources

  • Pricing
  • The Team
  • Contact
  • Verify a certificate

Standards covered

  • ISO/IEC 27001:2022
  • ISO/IEC 27002:2022
  • ISO/IEC 27005:2018
  • ISO 19011:2018

Legal Disclaimer & Intellectual Property

GRC FORGE is an independent training platform. We are not affiliated with ISO, PECB, or IRCA. Our modules are original educational content designed to prepare learners for official exams through hands-on practice. GRC FORGE does not sell ISO standards: we teach implementation methods for ISO/IEC 27001:2022 and ISO/IEC 27002:2022.

© 2026 GRC FORGE. All rights reserved.

Legal notice Privacy policy Terms of service Refund policy
Français
🍪
Cookies & Privacy

We use cookies to measure audience and improve your experience. No data is sold to third parties. Privacy policy →