Data Processing Agreement

How Grail Analytics processes personal data contained in the Customer Data you submit.

Last updated: 7 August 2026

This Data Processing Agreement (DPA) supplements theTerms of Service between Grail Analytics (Processor, we) and the customer (Controller,you), and applies to the extent we process personal data on your behalf as part of Customer Data in delivering the Service. Capitalised terms not defined here have the meaning given in the Terms. If this DPA and the Terms conflict as to the processing of personal data, this DPA controls.

1. Scope and roles

You act as controller — or as processor on behalf of a controller — of any personal data included in the Customer Data you submit to the Service. For example, your ground-truth brand data may include named individuals, such as an executive’s biography used to check an AI Platform’s claims. We act as processor, or sub-processor, with respect to that personal data. Where you are a processor for your own customer, you confirm you are authorised to give us these instructions and to agree to this DPA on that controller’s behalf.

2. Subject matter, duration, nature and purpose

  • Subject matter: personal data contained within Customer Data submitted through the Service.
  • Duration: the term of your subscription, plus the post-termination retention period in Section 11.4 of the Terms.
  • Nature and purpose: storage, analysis and processing of Customer Data to provide the AI-visibility scoring, fact-checking and reporting features of the Service, as instructed by you through your use of the Service.
  • Categories of data subjects: typically limited to individuals named or referenced within your brand’s public-facing content — executives, spokespeople — to the extent you include them in ground-truth facts. Not typically consumer or employee personal data, unless you choose to submit it.
  • Categories of personal data: names, titles and similar business-context identifiers you choose to include in Customer Data. We do not request special categories of personal data and ask that you not submit them.

One processing fact worth stating precisely, because it is the whole product:delivering the Service means transmitting Customer Data to the AI model providers listed in Section 4. Your ground-truth facts are sent to a model both individually as evidence and as a whole corpus in order to adjudicate accuracy claims, and their text is sent to an embeddings API for matching. If you do not want a fact leaving our systems, do not submit it as ground truth. Uploaded source files are parsed and discarded at ingest — only the structured fact rows persist.

3. Our obligations

We will:

3.1 Process personal data only on your documented instructions, including as set out in the Terms and this DPA, unless required otherwise by law — in which case we will notify you first unless prohibited from doing so.

3.2 Ensure personnel authorised to process personal data are bound by confidentiality obligations.

3.3 Implement appropriate technical and organisational security measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, costs, and the nature and risk of the processing (Article 32 GDPR).

3.4 Notify you without undue delay after becoming aware of a personal data breach affecting your Customer Data, and provide reasonably available information to help you meet any notification obligations you may have.

3.5 Taking into account the nature of the processing, provide reasonable assistance to help you respond to data subject requests — access, correction, deletion, portability, objection — and to meet your obligations under Articles 32–36 GDPR, at your reasonable cost for anything beyond routine assistance. In practice, the self-service export and deletion tooling described in the Privacy Notice covers the common cases without our involvement.

3.6 At your choice, delete or return all personal data at the end of the relationship, except to the extent we are required to retain it by law, consistent with Section 11.4 of the Terms. Our operational timelines are the ones published in the Privacy Notice: live records removed within 30 days of a deletion request, and purged from backups within 90 days.

3.7 Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you designate — subject to reasonable notice, confidentiality, and no more than once per 12-month period absent a security incident or legal requirement. We may satisfy this through a summary of a recent third-party audit or certification where one exists, in lieu of an on-site audit.

[COUNSEL] — 3.7 commits us to an audit right we have no current process or third-party certification to satisfy. Either the operational commitment gets built before publication, or the clause is narrowed to what we can actually honour. A promised audit right we cannot service is worse than a narrower one.

4. Sub-processors

4.1 You authorise us to engage sub-processors to support delivery of the Service. As of the date above, our sub-processors are:

Sub-processorPurposeLocation
DigitalOceanApplication hosting, managed database, and object storage for reports and backupsUnited States
OpenAI, Anthropic, Google, PerplexityAI Platforms queried to generate the response data we analyse, and the models used for claim extraction, accuracy adjudication, embeddings, onboarding extraction and report proseUnited States
StripePayment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
Google (Analytics, Tag Manager)Site and product analytics, subject to consentUnited States
SentryError monitoringUnited States

[COUNSEL] — this list is verified against the codebase, not against signed contracts. Each vendor needs a data processing agreement in place with terms substantially similar to this one before publication, and the list must be confirmed against those executed contracts. The same marker appears in the Privacy Notice; they close together or not at all.

4.2 We will impose data protection obligations on sub-processors substantially similar to those in this DPA, and we remain responsible for their performance of those obligations. We will give you notice of any new sub-processor — by email or a notice on our site — and an opportunity to object on reasonable data-protection grounds within 14 days. If the objection is unresolved, you may terminate the affected part of the Service as your exclusive remedy.

[COUNSEL] — 4.2 commits us to advance notice of every new sub-processor. That is a standing operational obligation with no owner and no mechanism today; adding a model provider currently ships as a configuration change. Decide who owns the notice and where it is published before this is in force.

5. International transfers

Where personal data is transferred from the EEA, UK or Switzerland to the United States or another country not deemed to provide adequate protection, the transfer is made subject to the European Commission’s Standard Contractual Clauses (Module 2, controller-to-processor, or Module 3, processor-to-processor, as applicable), incorporated by reference, together with the UK International Data Transfer Addendum where relevant. To the extent a party’s details or annexes are needed to complete those clauses, the parties agree that the information in this DPA and the Terms serves that purpose, supplemented on request.

6. Liability

Each party’s liability under this DPA is subject to the limitations of liability in Section 8 of the Terms of Service, except to the extent applicable data protection law prohibits limiting liability for that type of claim.

7. Term

This DPA takes effect when the Terms take effect and continues for as long as we process personal data on your behalf under the Terms.

8. Contact

Questions about this DPA: hello@grailanalytics.ai.