BACKGROUND
The Client and Grantify have entered into a services agreement (the Agreement) that may require Grantify to process Personal Data on behalf of the Client.
This Personal Data Processing Agreement (DPA) sets out the additional terms, requirements and conditions on which Grantify will process Personal Data when providing services under the Agreement. This DPA contains the mandatory clauses required by Article 28(3) of the UK GDPR and Article 28(3) of the EU GDPR for contracts between Controllers and Processors.
AGREED TERMS
Definitions and interpretation
The following definitions and rules of interpretation apply in this DPA.
Definitions:
Agreement: the agreement between the Client and Grantify comprising Grantify’s Terms of Business and the documents incorporated into it, as set out in the Terms of Business, and into which this DPA is incorporated.
Applicable Laws: as applicable, Domestic Law or EU Law.
Business Purposes: the services to be provided by Grantify to the Client as described in the Agreement and any other purpose specifically identified in Part 2 of Annex A.
Commissioner: the Information Commissioner (see Article 4(A3), UK GDPR and section 114, DPA 2018).
Controller, Processor, Data Subject, Personal Data, Personal Data Breach and processing: have the meanings given in the Data Protection Legislation.
Client: the organisation purchasing Grantify’s services and a party to the Agreement.
Client Personal Data: any Personal Data which Grantify processes in connection with this DPA in the capacity of a Processor, as set out in paragraph 1.2, Part 1 of Annex A.
Data Protection Legislation:
the Data Protection Act 2018 (DPA 2018);
the UK GDPR;
the EU GDPR; and
all other UK, EU and EEA member state laws relating to the processing of Personal Data and privacy.
Domestic Law: the law of the UK or a part of the UK.
EU GDPR: the General Data Protection Regulation ((EU) 2016/679).
EEA: the European Economic Area.
EU Law: the law of the European Union or any member state of the European Union or the EEA.
Records: has the meaning in clause 12.1.
Regulator: as applicable to the processing, the Commissioner, concerned EEA supervisory authorities and such other regulators with authority to enforce the Data Protection Legislation applicable to the processing.
Sub-Processor: has the meaning given to it in clause 8.1.
Grantify: GRANTIFY LIMITED incorporated and registered in England and Wales with the company number 12274128 and whose registered office is at Fora, 210 Euston Road, London, England, NW1 2DA.
Grantify Personal Data: any Personal Data which Grantify processes in connection with this DPA in the capacity of a Controller as set out in paragraph 1.1, Part 1 of Annex A.
Grantify Personnel: all directors, officers, employees, agents, consultants and contractors of Grantify engaged in the performance of its obligations under the Agreement or this DPA.
Grantify’s Privacy Policy: Grantify’s privacy policy, online linked to here or such other web address published by Grantify from time to time, as such privacy policy may be amended from time to time.
Term: this DPA's term as defined in clause 10.1.
UK GDPR: has the meaning given in section 3(10) (as supplemented by section 205(4)) of the DPA 2018.
This DPA is incorporated into the Agreement. Interpretations and defined terms set out in the Agreement apply to the interpretation of this DPA.
The Annexes form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.
In the case of conflict or ambiguity between:
any provision contained in the body of this DPA and any provision contained in the Annexes, the provision in the body of this DPA will prevail; and
any of the provisions of this DPA and the provisions of the Agreement, the provisions of this DPA will prevail in respect of the processing of Personal Data, and the provisions of the Agreement will prevail in all other respects.
Personal Data types and processing purposes
Both parties will comply with all applicable requirements of the Data Protection Legislation. This DPA is in addition to, and does not relieve, remove or replace, a party’s obligations or rights under the Data Protection Legislation.
The Client and Grantify agree and acknowledge that for the purpose of the Data Protection Legislation:
Grantify is the Controller of Grantify Personal Data;
the Client is the Controller and Grantify is the Processor of the Client Personal Data;
the Client retains control of the Client Personal Data and remains responsible for its compliance obligations under the applicable Data Protection Legislation, including providing any required notices and obtaining any required consents, and for the written processing instructions it gives to Grantify; and
in respect of the Client Personal Data, Part 2 of Annex A describes the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which Grantify may process the Client Personal Data to fulfil the Business Purposes.
Should the determination in clause 2.2 change, then the parties shall work together in good faith to make any change which is necessary to this DPA.
Grantify’s obligations
Grantify will only process the Client Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes in accordance with the Client's written instructions, unless Grantify is required by any Applicable Laws to otherwise process that Client Personal Data. Where Grantify is relying on any Applicable Laws as the basis for processing Client Personal Data, Grantify shall notify the Client of this before performing the processing required by any Applicable Laws unless those Applicable Laws prohibit Grantify from so notifying the Client on important grounds of public interest.
Grantify will not process the Client Personal Data for any other purpose or in a way that does not comply with this DPA or the Data Protection Legislation. Grantify shall inform the Client if, in the opinion of Grantify, the instructions of the Client infringe the Data Protection Legislation.
Grantify must comply promptly with any Client written instructions requiring Grantify to amend, transfer, delete or otherwise process the Client Personal Data, or to stop, mitigate or remedy any unauthorised processing.
Grantify will maintain the confidentiality of the Client Personal Data and will not disclose the Client Personal Data to third parties unless the Client or this DPA specifically authorises the disclosure, or as required by any Applicable Laws, a UK or EU/EEA member state court or the Regulator. If any Applicable Laws, an UK or EU/EEA member state court or the Regulator requires Grantify to process or disclose the Client Personal Data to a third party, Grantify must first inform the Client of such legal or regulatory requirement and give the Client an opportunity to object or challenge the requirement, unless any Applicable Laws prohibit the giving of such notice.
Grantify will reasonably assist the Client with meeting the Client's compliance obligations under the Data Protection Legislation, taking into account the nature of Grantify’s processing and the information available to Grantify, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with the Regulator under the Data Protection Legislation.
Grantify Personnel
Grantify will ensure that all of Grantify Personnel:
are informed of the confidential nature of the Client Personal Data and are bound by confidentiality obligations and use restrictions in respect of the Client Personal Data;
have undertaken training on the Data Protection Legislation relating to handling Client Personal Data and how it applies to their particular duties; and
are aware both of Grantify’s duties and their personal duties and obligations under the Data Protection Legislation and this DPA.
Security
Grantify must at all times implement appropriate technical and organisational measures against accidental, unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of the Client Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of the Client Personal Data, including the measures set out in Annex B.
Grantify must implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:
the pseudonymisation and encryption of Client Personal Data;
the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
the ability to restore the availability of and access to the Client Personal Data in a timely manner in the event of a physical or technical incident; and
a process for regularly testing, assessing and evaluating the effectiveness of the security measures.
Personal Data Breach
Grantify will promptly, and in any event within 48 hours, notify the Client if it becomes aware of:
the loss, unintended destruction or damage, corruption, or unusability of part or all of the Client Personal Data. Grantify will restore such Client Personal Data at its own expense as soon as possible;
any accidental, unauthorised or unlawful processing of the Client Personal Data; or
any Personal Data Breach.
As soon as practicable after giving any notice pursuant to clause 6.1, where Grantify becomes aware of (a), (b) and/or (c) above, it shall, without undue delay, also provide the Client with the following information:
a description of the nature of (a), (b) and/or (c), including the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned;
the likely consequences; and
a description of the measures taken or proposed to be taken to address (a), (b) and/or (c), including measures to mitigate its possible adverse effects.
Immediately after the Client has been notified pursuant to clause 6.1, following any accidental, unauthorised or unlawful Client Personal Data processing or Personal Data Breach, the parties will co-ordinate with each other to investigate the matter. Further, Grantify will reasonably co-operate with the Client in the Client's handling of the matter, including:
assisting with any investigation;
facilitating interviews with Grantify Personnel and former Grantify Personnel involved in the matter, including its officers and directors;
making available all relevant records, logs, files, data reporting and other materials required to comply with all Data Protection Legislation or as otherwise reasonably required by the Client; and
taking reasonable and prompt steps to mitigate the effects and to minimise any damage resulting from the Personal Data Breach or accidental, unauthorised or unlawful Personal Data processing.
Grantify will not inform any third party of any accidental, unauthorised or unlawful processing of all or part of the Client Personal Data and/or a Personal Data Breach without first obtaining the Client's written consent, except when required to do so by any Applicable Laws.
Grantify agrees that the Client has the sole right to determine whether to provide notice of the accidental, unauthorised or unlawful processing and/or the Personal Data Breach to any Data Subjects, the Regulator, law enforcement agencies or others, as required by law or regulation or in the Client's discretion, including the contents and delivery method of the notice. The Client shall not offer any remedy to affected Data Subjects without the prior written approval of Grantify, such approval not to be unreasonably withheld or delayed.
The Client will cover all reasonable expenses associated with the performance of the obligations under 6.1 to 6.3 unless the matter arose from Grantify’s negligence, wilful default or breach of this DPA, in which case Grantify will cover all of its expenses and time costs.
Grantify will also reimburse the Client for actual reasonable expenses that the Client incurs when responding to an incident of accidental, unauthorised or unlawful processing and/or a Personal Data Breach to the extent that Grantify caused such incident and/or Personal Data Breach, including all costs of notice and any remedy as set out in clause 6.5.
Transfers of Personal Data
Grantify (and any Sub-Processor) may transfer or otherwise process the Client Personal Data outside of the UK or the EEA provided that Grantify shall ensure that all such transfers are effected in accordance with the Data Protection Legislation.
Sub-Processors
The Client provides its prior, general authorisation for Grantify to appoint any third party or subcontractor (Sub-Processor) to process the Client Personal Data if:
the Sub-Processor is listed in Part 3 of Annex A or the Client is provided with an opportunity to object to the appointment of each new Sub-Processor, at least 14 days prior to the appointment of any new Sub-Processor;
Grantify enters into a written contract with the Sub-Processor that contains terms substantially the same as those set out in this DPA, in particular, in relation to requiring appropriate technical and organisational data security measures, and, upon the Client's written request, provides the Client with copies of the relevant excerpts from such contracts;
Grantify maintains control over all of the Client Personal Data it entrusts to the Sub-Processor; and
Grantify remains responsible for the acts or omissions of any Sub-Processor as if they were the acts or omissions of Grantify.
The parties agree that Grantify will be deemed by them to control legally any Client Personal Data controlled practically by or in the possession of its Sub-Processors.
Where the Client objects to the appointment of any Sub-Processor pursuant to clause 8.1(a), Grantify may terminate the Agreement with immediate effect by giving written notice to the Client.
Complaints, Data Subject requests and third-party rights
Grantify must take such technical and organisational measures as may be appropriate, and promptly provide such information to the Client as the Client may reasonably require, to enable the Client to comply with:
the rights of Data Subjects under the Data Protection Legislation, including subject access rights, the rights to rectify, port and erase Personal Data, object to the processing and automated processing of Personal Data, and restrict the processing of Personal Data; and
information or assessment notices served on the Client by the Regulator under the Data Protection Legislation.
Grantify must:
notify the Client as soon as possible in writing if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Client Personal Data or to either party's compliance with the Data Protection Legislation;
notify the Client as soon as possible if it receives a request from a Data Subject for access to their Client Personal Data or to exercise any of their other rights under the Data Protection Legislation;
give the Client, at the Client’s cost, its full co-operation and assistance in responding to any complaint, notice, communication or Data Subject request; and
not disclose the Client Personal Data to any Data Subject or to a third party other than in accordance with the Client's written instructions, or as required by any Applicable Laws.
Term and termination
This DPA will remain in full force and effect so long as:
the Agreement remains in effect; or
Grantify retains any of the Personal Data related to the Agreement in its possession or control (Term).
Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect the Client Personal Data will remain in full force and effect.
Data return and destruction
At the Client's request, Grantify will give the Client, or a third party nominated in writing by the Client, a copy of or access to all or part of the Client Personal Data in its possession or control.
On termination of the Agreement for any reason or expiry of its term, Grantify will securely delete or destroy or, if directed in writing by the Client, return and not retain, all or any of the Client Personal Data related to this DPA in its possession or control.
If any law, regulation, or government or regulatory body requires Grantify to retain any documents, materials or Client Personal Data that Grantify would otherwise be required to return or destroy, it will notify the Client in writing of that retention requirement, giving details of the documents, materials or Client Personal Data that it must retain, the legal basis for such retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends.
For the purposes of this clause 11, Grantify shall be deemed to have deleted or destroyed the Client Personal Data when such Client Personal Data has been, to the extent technically and legally possible, put beyond further use of Grantify.
Records
Grantify will keep detailed, accurate and up-to-date written records regarding any processing of the Client Personal Data, including but not limited to, the access, control and security of the Client Personal Data, Sub-Processors, the processing purposes, categories of processing, and a general description of the technical and organisational security measures referred to in clause 5.1 (Records).
Grantify will ensure that the Records are sufficient to enable the Client to verify Grantify’s compliance with its obligations under this DPA and the Data Protection Legislation and Grantify will provide the Client with copies of the Records upon request.
The Client and Grantify must review the information listed in the Annexes to this DPA whenever requested by the Client to confirm its current accuracy and update it when required to reflect current practices.
Audit
Grantify will permit the Client and its third-party representatives to audit Grantify’s compliance with its DPA obligations during the Term, on reasonable written notice at a frequency of not more than once per year.
The frequency restrictions set out in clause 13.1 shall not apply where the Client is directly required by the Regulator to audit Grantify’s compliance with its obligations under this DPA or if there has been, or the Client reasonably suspects that there has been, a Personal Data Breach and/or a breach of Grantify’s obligations under this DPA and/or the Data Protection Legislation.
Warranties
Grantify warrants that:
Grantify Personnel are reliable and trustworthy and have received the required training on the Data Protection Legislation; and
it has no reason to believe that the Data Protection Legislation prevents it from providing any of the Agreement's contracted services.
The Client warrants that Grantify’s expected use of the Client Personal Data for the Business Purposes and as specifically instructed by the Client will comply with the Data Protection Legislation.
This DPA is entered into on the Effective Date, as defined in the Terms of Business.
Annex A — Personal Data processing purposes and details
Part 1 – Role of the parties
1.1 Where Grantify acts as a Controller:
(a) when processing Personal Data contained within correspondence between the Client’s staff, Grantify Personnel, and/or documents relating to the establishment, management, audit, operation, and communication (on which Grantify may wish to rely on to establish its rights and liabilities under the Agreement) in respect of the Agreement for the provision of the contracted services;
(b) when processing Personal Data of the Client’s staff for marketing purposes; and
(c) when processing Personal Data of Data Subjects whose Personal Data is otherwise provided to or obtained by Grantify in connection with the Agreement for Grantify’s business purposes (for example, the enhancement or development of its products and/or services), as further described in Grantify’s Privacy Policy.
1.2 Where Grantify acts as a Processor:
Save as set out in paragraph 1.1 of this Annex A, when processing the Personal Data of Data Subjects whose Personal Data is collected and/or processed through the services provisioned under the Agreement, where Grantify processes such Personal Data on behalf of the Client.
Part 2 – Particulars of processing
2.1 Subject matter of processing
The performance of Grantify’s duties under the Agreement.
2.2 Duration of processing
For the term of the Agreement and for such time afterwards as required for the parties to exercise their rights and obligations under clause 11.
2.3 Nature of processing
(a) Hosting and operating the platform and making the Grantify’s services available to the Client;
(b) Enabling authorised users to access and use the Grantify’s services;
(c) Storing and processing Client content submitted for the purpose of grant applications;
(d) Generating and reviewing grant application content;
(e) Providing support services, user administration, and usage reporting.
2.4 Business Purposes
To enable Grantify to perform its duties under the Agreement.
2.5 Personal Data categories
(a) account and contact details of authorised users (name, email address, telephone number, job title, employer, and login credentials); and
(b) system and usage data; and
(c) any personal data contained in Client content uploaded to or generated within Grantify’s platform or provided as part of the services, for grant applications, which may include the names, roles, biographical, financial and identification details of the Client’s personnel and connected individuals,
together with any other types of categories of Personal Data that may be applicable to the circumstances.
2.6 Data Subject types
(a) The Client’s authorised users; and
(b) The Client’s founders, directors, officers, employees, and other individuals whose Personal Data is included in Client content submitted for grant applications.
Part 3 – Approved Sub-Processors:
| Sub-processor | Location of processing | Purpose of processing |
|---|---|---|
| Amazon Web Services | United States | Cloud hosting and infrastructure |
| AssemblyAI Inc. | United States | Transcription of client audio content |
| Box.com (UK) Ltd | United Kingdom | Storage of client documents |
| Bubble Group, Inc. | United States | Cloud hosting and customer portal used to deliver the Services |
| Calendly LLC | United States | Scheduling of client meetings |
| Cloudflare, Inc. | United States | Content delivery and security layer |
| Docmosis Pty Ltd | Australia | Automated generation of documents from client data |
| Gong.io Inc. | United States | Recording and transcription of client calls |
| Google Cloud Platform & Firebase (Google Cloud EMEA Limited) | Ireland | Application backend and database services |
| Google Meet (Google Cloud EMEA Limited) | Ireland | Recorded client meetings |
| Google Workspace (Google Cloud EMEA Limited) | Ireland | Email and communications used in delivering the Services |
| HubSpot Ireland Ltd | Ireland | Client relationship management (CRM) tool |
| Langfuse GmbH | Germany | LLM observability. Logging of production prompts and outputs |
| Mixpanel, Inc. | United States | Product usage analytics of Authorised Users |
| monday.com Ltd. | Israel | Work management. Grant delivery workflows containing client data |
| OpenAI, LLC | United States | AI vendor. Generation and review of grant application content |
| Perplexity AI, Inc. | United States | AI vendor. Retrieval, analysis, and summarisation of publicly available information |
| Pinecone Systems, Inc. | United States | Vector database. Embeddings of client content for AI retrieval |
| PostHog, Inc. | United States | Product usage analytics of Authorised Users |
| SerpApi, LLC | United States | Retrieval of publicly available web search results to support application features |
| Slack Technologies Limited | Ireland | Communications relating to the Services, which may include Authorised User contact details |
| Twilio Ireland Limited | Ireland | Transactional email |
| TYPEFORM SL | Spain | Client-facing forms and data collection |
| Zapier, Inc. | United States | Workflow automation involving client data |
| Zendesk UK Ltd | United Kingdom | Client support |
| Zoom Communications, Inc. | United States | Recorded client meetings |
Annex B — Security measures
Grantify maintains the technical and organisational measures set out below to protect Client Personal Data against accidental, unauthorised, or unlawful processing, access, loss, destruction, alteration, disclosure, or damage.
The Services are delivered on infrastructure operated by third-party cloud and platform providers, including the providers listed in Part 3 of Annex A. Where a measure below is implemented by such a provider, Grantify’s obligation is to select providers that maintain appropriate security measures, to configure the Services securely, and to keep that selection under review.
These are the measures in place at the date of this DPA. Grantify may update them from time to time to reflect changes in technology, its services, or the threat landscape, provided that no update materially reduces the overall level of protection for Client Personal Data.
Access control. Access to systems containing Client Personal Data is granted on a role-based, least-privilege basis. Access is revoked promptly when personnel leave or change roles.
Encryption. Client Personal Data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest in databases, file storage and backups.
Hosting and infrastructure. Grantify does not operate its own servers. Administrative interfaces are not publicly exposed, and a web application firewall and denial-of-service protection sit in front of the application.
Secure development. Changes are peer-reviewed before release to production, and development, staging and production environments are separated. Dependencies are scanned for known vulnerabilities, and credentials are held in a secrets manager rather than in source code.
Segregation. Client Personal Data is logically separated, with access controls designed to prevent one client accessing another client’s data.
Logging and monitoring. Access to production systems and Client Personal Data is logged and retained, with alerting on failed authentication attempts and other unusual activity.
Backups. Backups are taken automatically at least daily, are encrypted, and are stored separately from production systems.
Incident response. Grantify maintains a documented incident response procedure with a named owner and an escalation path enabling notification to affected clients within the timeframes set out in this DPA. Incidents are subject to a written review.
Sub-processors. New sub-processors are subject to a security review before onboarding, are engaged under written data protection terms, and are recorded in Part 3 of Annex A.
Grantify reviews these measures at least annually and following any material change to the Services or any Personal Data Breach.
.png)


