Data processing agreement
Last updated: 22 August 2026
This data processing agreement (“DPA”) forms part of the agreement between Grunda (“Processor”) and the customer (“Controller”) for the Grunda service, and reflects the parties' obligations under the EU General Data Protection Regulation (GDPR). For a countersigned copy, or to attach this DPA to a signed order form, contact us through the contact page.
1. Roles and scope
The Controller decides which systems to connect and what to approve; Grunda processes personal data contained in that customer data only as a processor, on the Controller's documented instructions. Grunda acts as an independent controller only for its own marketing site and sales process, as described in the privacy policy.
2. Subject matter and duration
Processing covers the personal data contained in the CRM and business systems the Controller connects or uploads, for the duration of the service agreement plus the deletion period in section 9.
3. Nature and purpose of processing
- Mirroring connected systems to detect data quality issues.
- Proposing and — after the Controller's approval — executing fixes (merges, normalizations, enrichment, archival).
- Serving the governed read API and notifications the Controller configures.
4. Categories of data and data subjects
Typically business contact data: names, business email addresses and phone numbers, employers, job titles, and CRM activity metadata relating to the Controller's customers, prospects, and their employees. The Controller is responsible for not connecting special categories of data; the Service is not designed for them.
5. Confidentiality and personnel
Persons authorized to process the data are bound by confidentiality and access the data only as needed to operate and support the Service.
6. Security measures
- Encryption in transit (TLS) for all traffic.
- Encryption at rest for stored data; credentials such as CRM tokens and API keys are additionally encrypted at the application layer (AES-256-GCM).
- Role-based access control in the product; every entry point authorizes itself and every CRM write requires an explicit approval.
- Hosting in the EU (see subprocessors); logical separation per customer, with optional dedicated data-plane hosting.
- Audit logging of data-changing operations, with provenance recorded on changed values.
7. Subprocessors
The Controller authorizes the following subprocessors. We will give at least 30 days' notice before adding or replacing one, during which the Controller may object on reasonable grounds.
- Vercel Inc. — application hosting and content delivery.
- Supabase (on AWS, eu-west-1) — database hosting and authentication.
- Resend — transactional email (invitations, notifications).
- Optional, per configuration: enrichment providers and AI model providers the Controller enables, and Slack or Microsoft when the Controller connects a workspace. Each receives only the data needed for the enabled feature.
8. International transfers
Customer data is hosted in the EU. Where a subprocessor processes personal data outside the EEA, transfers rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.
9. Deletion and return
On termination, we return the mirrored customer data in a machine-readable format on request made within 30 days, then delete it from production systems within 30 days and from backups on their rotation schedule (at most 90 days). Disconnecting a system during the term stops further mirroring immediately, and the Controller can request deletion of that mirror at any time.
10. Assistance and notification
- We notify the Controller without undue delay after becoming aware of a personal data breach affecting customer data, with the information needed for the Controller's own obligations.
- We assist, taking into account the nature of processing, with data subject requests and with the Controller's security, DPIA, and consultation obligations.
11. Audits
We make available the information reasonably necessary to demonstrate compliance with this DPA, and allow audits — normally satisfied by documentation and third-party attestations, with on-site audits on reasonable notice, at most once per year unless a breach or supervisory authority requires otherwise.
12. Precedence
If this DPA conflicts with the terms of service or another agreement between the parties regarding the processing of personal data, this DPA prevails to the extent of the conflict.