Skip to main content

Governance Pack

The Governance Pack is a pre-completed compliance brief that helps a security, privacy, procurement or governance reviewer understand how Navaid handles data.

It is available to every signed-in user under Settings → Governance and can be viewed in the browser or downloaded as a multi-page PDF.

Open the pack

  1. Select Settings in the navigation.
  2. Select the Governance tab.
  3. Review the organisation and requester shown on the cover.
  4. Read the current on-screen content before sharing it.

The cover is generated for the signed-in user and currently selected company and includes the document date.

What it covers

The pack is organised into ten sections:

  1. Product and processing summary
  2. Data collected and why
  3. Where data is held
  4. Security controls
  5. AI usage
  6. Sub-processors
  7. Data retention
  8. Legal basis and data-subject rights
  9. Incident response
  10. Security, privacy and general contacts

It also links the current privacy policy and terms.

Download PDF

  1. Select Download PDF.
  2. Wait while Navaid renders the on-screen document.
  3. Confirm the success message.
  4. Open the downloaded governance-pack-YYYY-MM-DD.pdf.
  5. Check pagination and the cover organisation before distributing it.

PDF generation occurs in the browser. Large browser zoom, extensions or memory pressure can affect rendering; retry at normal zoom if necessary.

How to use it in a review

Initial vendor questionnaire

Send the pack as background evidence, then answer organisation-specific questions separately. The pack describes Navaid’s product controls; it does not fill in your company’s risk acceptance, DPIA or procurement decision.

Security review

Ask the reviewer to pay particular attention to authentication, authorisation, encryption, secrets, application security and incident sections. Provide deployment-specific evidence through an approved channel when required.

Privacy review

Combine the pack with the current Privacy Policy and the company’s intended use. Consider what team members will enter into sessions or upload as company knowledge.

Periodic review

Download a fresh pack rather than relying on an old attachment. It is generated from the current application copy and dated at download.

What the pack is not

The Governance Pack is not:

  • a certification;
  • a penetration-test report;
  • legal advice;
  • a signed data-processing agreement;
  • a guarantee that every company workflow is appropriate;
  • a substitute for the live Privacy Policy or Terms;
  • evidence that a specific security control operated at a particular time.

Request additional evidence from the appropriate contact where required.

Data and sharing implications

The PDF includes the requesting user and selected organisation. Treat it as business documentation:

  • verify the company before downloading;
  • share only with intended reviewers;
  • avoid uploading it to public locations;
  • delete superseded copies under your retention policy;
  • do not modify it in a way that could imply Navaid made unsupported commitments.

Troubleshooting

The wrong organisation appears

Close the pack, switch companies, then reopen Settings → Governance.

Download fails

Keep the page open, return browser zoom to 100%, allow downloads for the site and retry once. If it persists, capture the visible error and browser/version.

The PDF layout looks different from the page

PDF pagination is generated from the browser-rendered document. Check all pages; retry in a current desktop browser if content is clipped.

A reviewer needs more detail

Use the contact information in section 10 and follow your organisation’s approved vendor-review process. Do not invent controls that are absent from the current pack.