Platform

Solutions

Resources

More

Genesis platform logo

Platform

Solutions

Resources

More

Genesis platform logo

PRIVACY POLICY

PRIVACY POLICY

PRIVACY POLICY

Last Updated: March 30, 2026

Genesis Platform LLC (“Genesis”, “we”, “us”, or “our”) is committed to protecting personal data and handling it in a transparent, secure, and responsible manner. This Privacy Policy explains how we collect, use, store, disclose, transfer, and protect personal data when individuals interact with our website, platform, products, services, communications, and related business operations.

This Privacy Policy applies to visitors of genesisplatform.co, users of the Genesis Platform application, customer representatives, prospective customers, vendors, partners, event participants, and other individuals whose personal data may be processed in connection with our business.

By accessing or using our website, platform, or services, or by otherwise providing personal data to us, individuals acknowledge that their personal data may be processed as described in this Privacy Policy.

1. About Genesis and Scope of This Policy

Genesis Platform LLC provides software and related services designed to help organisations manage third-party risk, vendor assessments, compliance workflows, risk intelligence, and associated security and governance functions.

Data Controller

Genesis acts as a data controller for personal data collected from website visitors, business contacts, marketing subscribers, event attendees, prospective clients, and platform account administrators for its own business operations.

Data Processor

Genesis acts as a data processor or equivalent service provider on behalf of its customers when customers use the Genesis Platform to manage vendor records, questionnaire responses, compliance materials, contact information, risk data, or uploaded documents. In these cases, the customer remains the primary controller of that data, and Genesis processes it under the customer’s instructions and the applicable Data Processing Agreement (DPA).

Important: Where Genesis processes data solely on behalf of a customer, the customer’s privacy notice, internal policies, or contractual terms also apply. This Privacy Policy describes Genesis’s own privacy practices.

2. Categories of Personal Data We Collect

We collect and process personal data that is reasonably necessary for legitimate business operations, service delivery, security, compliance, support, product improvement, and to meet contractual and legal obligations.

Category Examples of Data Collected
Identity & ProfessionalFull name, job title, employer, department, business role, account identifiers
Contact InformationEmail address, phone number, business address, communication preferences
Account & AuthenticationUsername, login metadata, SSO identifiers, MFA status, role assignments
Technical & DeviceIP address, browser type, device ID, OS, session ID, timestamps, log files
Usage & ActivityPages viewed, features accessed, click behaviour, navigation patterns, workflow actions
Questionnaire & AssessmentVendor responses, compliance answers, uploaded files, audit materials, remediation notes
CommunicationSupport tickets, demo requests, email correspondence, helpdesk chats, webinar registrations
Marketing & CommercialLead source, interest areas, campaign engagement, subscription preferences
Payment & BillingBilling name, billing email, company address, payment status, invoice references
Public Risk IntelligencePublic breach mentions, exposed domain data, publicly reported incidents, vendor intelligence
AI-Derived & AnalyticalRisk scores, flags, summaries, contradictions, remediation suggestions, workflow recommendations

Note on AI-Derived Data: Derived outputs from Genesis’s AI features may in some cases relate to identifiable individuals, especially where users or vendor personnel are referenced in source materials. These outputs are generated to assist decision-making and are not intended to serve as the sole basis for decisions with significant individual consequences.

3. How We Collect Personal Data

  1. Direct interactions — forms, demo requests, account creation, email, phone, event registrations
  2. Platform usage — automatically collected technical and usage data as users interact with the platform
  3. From customers — customers may provide data about their employees, vendors, suppliers, or third parties
  4. From integrations — CRM systems, analytics providers, identity providers, support platforms, payment providers
  5. From public sources — open-source intelligence, regulatory publications, public breach or incident reporting
  6. Through cookies and similar technologies — as further described in Section 7

4. Purposes for Which We Use Personal Data

Purpose Lawful Basis Description
Deliver the PlatformContractAccount management, authentication, questionnaires, reports, dashboards, vendor risk workflows
Customer SupportContractResponding to inquiries, troubleshooting, implementation, customer success, service notifications
Security & Fraud PreventionLegitimate InterestDetecting suspicious behaviour, preventing unauthorised access, incident response, audit logs
Product ImprovementLegitimate InterestUsage analysis, interface improvements, defect resolution, feature development, performance
AI-Assisted FeaturesContract / Legitimate InterestSummarising data, detecting contradictions, classifying risks, improving AI model outputs
CommunicationsContract / ConsentProduct updates, security notices, billing, sales follow-ups, marketing where permitted
Legal & Regulatory ComplianceLegal ObligationMeeting applicable laws, responding to lawful requests, accounting, tax, legal claims
Business OperationsLegitimate InterestReporting, governance, corporate transactions, business continuity, disaster recovery
MarketingConsent / Legitimate InterestPromotional content, thought leadership, events — opt-in only or where lawful for B2B contacts
Demo & SalesLegitimate InterestResponding to demo requests, qualifying prospects, managing commercial pipeline

5. AI, Analytics, and Automated Processing

Genesis includes AI-powered capabilities that may analyse data, identify patterns, generate outputs, flag potential risks, prioritise actions, or assist users in reviewing vendor or assessment information. These functions may process personal data where it appears in source materials or usage patterns.

Genesis does not intend for AI-generated outputs alone to serve as the sole basis for decisions that produce legal effects or similarly significant individual consequences without appropriate human review. AI-generated outputs are intended to support decision-making, not replace accountable human judgment.

Safeguards Applied

  1. Access controls around data used in AI-enabled workflows
  2. Logging and monitoring of sensitive operations
  3. Data minimisation principles applied to AI processing
  4. Restrictions on internal staff access to customer data
  5. Contractual and security controls with relevant service providers

6. Disclosure of Personal Data

Genesis does not sell personal data. We disclose personal data only where necessary and appropriate:

Recipient Purpose Safeguards
Cloud Infrastructure ProviderHosting and data storageDPA, encryption, access controls
CRM PlatformCustomer relationship managementDPA, contractual confidentiality
Email Service ProviderTransactional and marketing emailsDPA, opt-in controls
Analytics ProviderProduct usage analyticsDPA, anonymisation where possible
Customer Support ToolHelpdesk and live supportDPA, access restrictions
Payment ProcessorSubscription billingDPA, PCI-DSS compliance
Security Monitoring ProviderThreat detection, loggingDPA, access controls
Professional AdvisersLegal, audit, accounting, insuranceConfidentiality obligations
Customers & Authorised UsersPlatform access — processor context onlyContract, platform permissions
Regulators / AuthoritiesLegal obligation or lawful requestOnly as required by law

Corporate Transactions: If Genesis undergoes a merger, acquisition, restructuring, or sale of assets, personal data may be disclosed as part of that transaction, subject to confidentiality protections and legal requirements.

7. Cookies and Similar Technologies

We use cookies and similar technologies on our website and, where applicable, in our platform to support operations, security, user experience, performance measurement, and communications.

Cookie Type Purpose Required?
EssentialSecurity, authentication, session handling, load balancingYes — cannot be disabled
FunctionalUser preferences, settings, experience personalisationOptional
AnalyticsUsage patterns, content and design improvement (e.g. Google Analytics)Optional
MarketingCampaign measurement, retargeting (e.g. LinkedIn Insight Tag)Optional — requires consent

Users can manage cookies through browser settings and, where implemented, through our cookie consent banner. Disabling some cookies may affect website or platform functionality.

8. International Data Transfers

Genesis Platform is incorporated in the UAE and our infrastructure may process data in the EU and US. When transferring personal data internationally, we implement appropriate safeguards:

  1. Standard Contractual Clauses (SCCs) approved by the European Commission
  2. Adequacy decisions where applicable
  3. Data Processing Agreements (DPAs) with all sub-processors
  4. Transfer risk assessments where appropriate
  5. Compliance with UAE Federal Decree-Law No. 45 of 2021 (Personal Data Protection Law — PDPL)
  6. Security and confidentiality controls enforced across all data transfer arrangements

9. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, to satisfy legal, accounting, tax, security, dispute resolution, or contractual requirements.

Data Type Retention Period Reason
Active account dataAccount duration + 90 days post-terminationService continuity, offboarding
Vendor assessment recordsCustomer contract duration + 1 yearAudit trail, contractual
Usage & analytics logs12 months rollingSecurity, product improvement
Marketing contact dataUntil consent withdrawn or 2 years inactivityGDPR / consent compliance
Financial & billing records7 yearsLegal / tax obligation
Support communications3 years from last interactionService quality, disputes
Security & audit logsUp to 12 months or as required by lawIncident investigation

When data is no longer required, Genesis will delete, anonymise, or securely dispose of it, unless continued retention is required or permitted by law.

10. Security of Personal Data

Genesis uses administrative, technical, and organisational measures designed to protect personal data against accidental, unlawful, or unauthorised destruction, loss, alteration, disclosure, access, or misuse.

Control Description
EncryptionData encrypted at rest (AES-256) and in transit (TLS 1.2+)
Access ControlRole-based access control (RBAC) across all systems and environments
Multi-Factor AuthenticationMFA required for all internal systems and privileged access
Vulnerability ManagementContinuous scanning and periodic penetration testing
Logging & MonitoringCentralised logging, security event monitoring, anomaly detection
Incident ResponseDocumented IR plan with defined escalation, containment, and notification procedures
Backup & RecoveryRegular encrypted backups and tested recovery processes
Staff GovernanceConfidentiality agreements, need-to-know access, security awareness training
ISO 27001Information security management system — certification in progress
SOC 2 Type IISecurity, availability, and confidentiality trust criteria — audit in progress

11. Personal Data Breaches

If Genesis becomes aware of a personal data breach involving personal data under its control, it will assess the incident promptly and take appropriate action to contain, investigate, remediate, and document the event.

Breach Notification: Where required by applicable law, Genesis will notify affected parties and/or competent supervisory authorities within 72 hours of becoming aware of a reportable breach, in line with GDPR Article 33 and applicable UAE regulations.

12. Your Rights

Depending on your location and applicable law, you may have the following rights over your personal data. To exercise any right, contact us at privacy@genesisplatform.co. We will respond within 30 days, or within any shorter period required by applicable law.

Right Description
AccessRequest a copy of the personal data we hold about you
RectificationAsk us to correct inaccurate or incomplete data
ErasureRequest deletion of your personal data (“right to be forgotten”)
PortabilityReceive your data in a structured, machine-readable format
ObjectObject to processing based on legitimate interest or for direct marketing
RestrictRequest that we limit how we process your data in certain circumstances
Withdraw ConsentWithdraw consent for marketing or non-essential processing at any time
ComplaintLodge a complaint with your local data protection supervisory authority

Processor Context: Where Genesis acts as a processor on behalf of a customer, requests relating to customer-controlled data may need to be directed to the relevant customer. Genesis will assist the customer as required by applicable contracts or law.

13. Marketing Communications

Where permitted by law, Genesis may send business-related marketing or promotional communications about products, updates, events, thought leadership, or related services. Where consent is required, we will seek it before sending.

Individuals may opt out of non-essential marketing communications at any time by using unsubscribe links or by contacting us directly. Transactional, service, billing, support, and security communications may still be sent where necessary.

14. Third-Party Links and External Services

Our website or platform may contain links to third-party websites, services, or resources. Genesis is not responsible for the privacy, security, or content practices of external sites not controlled by us. We recommend reviewing the privacy notices of any third parties before providing personal data.

15. Children’s Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact privacy@genesisplatform.co immediately and we will delete it without undue delay.

16. Regional Privacy Notes

Genesis aims to align its practices with applicable privacy requirements across the jurisdictions in which it operates and serves customers, including GDPR-aligned principles and UAE PDPL compliance commitments.

Where specific regional laws apply, Genesis may provide additional disclosures, contractual commitments, or request handling processes appropriate to those laws. Nothing in this Privacy Policy is intended to limit any rights individuals may have under applicable law.

17. Changes to This Privacy Policy

Genesis may update this Privacy Policy to reflect changes in law, regulation, technology, business operations, or privacy practices. When we make material changes, we will:

  1. Update the Effective Date and Last Updated date at the top of this document
  2. Notify active users via email at least 14 days before changes take effect
  3. Maintain a version history of this document available upon request

Continued use of our website, platform, or services after an updated Privacy Policy becomes effective constitutes acceptance of the revised policy to the extent permitted by law.

18. Contact Us

Privacy Emailinfo@genesisplatform.co
General Contactinfo@genesisplatform.co
CompanyGenesis Platform LLC
Registered AddressDubai Founders HQ, Dubai, UAE
Response TimeWithin 30 days of receipt
Contact Formgenesisplatform.co/contact-us

19. Important Notice

Disclaimer: This Privacy Policy is intended to provide general information about Genesis’s data handling practices. It does not constitute legal advice. Because privacy obligations may vary based on jurisdiction, customer implementation, integrations, and platform use cases, Genesis recommends that organisations seek qualified legal counsel when assessing specific compliance obligations or preparing supporting legal documentation.

Book a demo with Genesis

See yourself how Genesis Platform Eliminated manual TPRM with AI

Genesis Platform Logo

Genesis assists businesses in identifying and reducing their attack surface while also managing and collaborating with third parties.

Dubai, UAE

Genesis platform location marker

© Copyright Genesis Platform 2026, All Rights Reserved

Genesis Platform Logo

Genesis assists businesses in identifying and reducing their attack surface while also managing and collaborating with third parties.

Dubai, UAE

Genesis platform location marker

© Copyright Genesis Platform 2026, All Rights Reserved

Genesis assists businesses in identifying and reducing their attack surface while also managing and collaborating with third parties.

Registered Office Address: Hamdan

Innovation Incubator, Dubai, UAE

Product

Resources

Whitepapers

© Copyright Genesis Platform 2024, All Rights Reserved

© Copyright Genesis Platform 2026, All Rights Reserved

Genesis assists businesses in identifying and reducing their attack surface while also managing and collaborating with third parties.

Registered Office Address: Hamdan

Innovation Incubator, Dubai, UAE

Product

Resources

Whitepapers

© Copyright Genesis Platform 2024, All Rights Reserved

© Copyright Genesis Platform 2026, All Rights Reserved

Get a Free Vendor Security Report

Start your PoC in 24 hours and see vendor risks instantly