Data processing agreement

The Article 28 terms on which Matt Hillyer LLC processes personal data on your behalf. Last updated 28 August 2026.

Why this exists

You upload your quality documents to GrapeBeaver Intelligence — procedures, policies and plans that name their owners and approvers. That makes us a processor of personal data on your instructions, and Article 28 of the UK and EU GDPR requires the terms of that arrangement to be written down. This is those terms. It applies automatically to every customer and forms part of our terms of service — there is nothing to sign to bring it into effect, though we will sign a counterpart if your procurement process needs one. Write to privacy@grapebeaver.io.

1. Roles

You are the controller of the personal data contained in what you upload and in your product records. We are the processor of it.

We are separately the controller of your account and billing data, which is not covered by this agreement — our privacy notice covers that. The two roles are kept apart deliberately, because the obligations differ and a document that blurs them is one neither party can rely on.

2. Our instructions come from you

We process your data only on your documented instructions, which are: to provide the service described in the terms, and anything you subsequently ask us to do in writing. Using the product is itself an instruction to process what you put into it.

If the law requires us to process your data otherwise, we will tell you before doing so unless the law forbids us from telling you. If we think an instruction breaches data protection law, we will say so.

We will not use your data to train models, to build a product for anybody else, or for any purpose of our own.

3. Confidentiality

Everyone we allow to access your data is bound by a duty of confidence and has access only where it is necessary to operate the service or to answer a support request you have raised.

4. Security

We maintain the technical and organisational measures set out in Annex II, which satisfy Article 32. We will not materially weaken them during your subscription.

5. Sub-processors

You give general authorisation for the sub-processors in Annex III. Each is bound by written terms no less protective than these, and we remain fully liable to you for what they do.

We will give you at least 30 days' notice by email before adding or replacing one. If you reasonably object on data protection grounds within that period we will work with you to find an alternative, and if we cannot you may terminate the affected part of the service and receive a refund of fees paid for the unused remainder.

6. Helping you meet your own obligations

  • · Data subject requests. The product lets you find, export and delete your own content directly, which is usually the fastest route. Where it does not, we will help you respond within a timescale that lets you meet your one-month deadline. If a request reaches us directly we will not answer it ourselves — we will pass it to you, because the decision is yours.
  • · Impact assessments and prior consultation. We will give you the information about our processing that you reasonably need for a DPIA under Articles 35 and 36.
  • · Security and breach. See section 7.

7. Personal data breach

We will notify you without undue delay and within 72 hours of becoming aware of a personal data breach affecting your data, and sooner where we can. The notification will describe what happened, the categories and approximate number of records involved, the likely consequences, and what we are doing about it. Where we do not yet know something we will say so and follow up rather than delaying the first notification until the picture is complete.

Notifying your supervisory authority and your data subjects is your decision as controller. We will give you what you need to make it.

8. Return and deletion

You can export your data throughout your subscription and for 30 days after it ends. After that we delete it, including from backups on their ordinary expiry cycle rather than by selective extraction — backups are restored whole or not at all, and a promise to surgically remove one record from them is one no honest processor can keep. We will confirm deletion in writing on request.

9. Audit

We will make available the information needed to demonstrate our compliance with Article 28, and will answer a security questionnaire once in any twelve-month period. Where that is not sufficient for your regulator or your own quality system, we will agree an audit with reasonable notice, at your cost, during business hours, and without disrupting other customers or exposing their data.

10. International transfers

Processing takes place in the United States. Where you are in the UK or the EEA, the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this agreement by reference, with the UK Addendum issued under section 119A of the Data Protection Act 2018 where UK data is involved. Annex I, II and III below populate their annexes. In any conflict, the Clauses prevail over this agreement.

Governing law and jurisdiction for this agreement follow the terms of service: the laws of the State of Wisconsin, United States, without regard to its conflict of law provisions, with the state and federal courts located in Wisconsin having exclusive jurisdiction.

Annex I — the processing

  • · Subject matter. Providing GrapeBeaver Intelligence: regulatory intelligence matched against your products and the process documents you upload.
  • · Duration. For as long as your subscription runs, plus the deletion period in section 8.
  • · Nature and purpose. Storage, text extraction, indexing, automated analysis by large language model, and delivery by email of the results to the recipients you nominate.
  • · Categories of data subject. Your personnel — the named owners, authors, approvers and reviewers appearing in your documents, and the users you invite to the service.
  • · Categories of personal data. Names, job titles, business email addresses, and any personal data incidentally contained in documents you choose to upload. We do not require special category data, and the service is not designed to hold it.
  • · Frequency. Continuous for the duration of the subscription.

Annex II — technical and organisational measures

  • · Tenant isolation. Every record holding customer data carries an organization reference, and the data access layer refuses to execute a query that is not bound to a single organization — it raises rather than returning rows. Isolation is asserted at the data, view and API layers by an automated test suite that blocks a release on failure.
  • · Encryption. TLS enforced in transit with HSTS including subdomains. Encryption at rest for the database, backups and uploaded files.
  • · Access control. Role-based access within an organization. Argon2 password hashing. API keys stored only as SHA-256 hashes and displayed once. Administrative access limited to named operators and separated into two privilege levels.
  • · Application hardening. A restrictive content security policy permitting no third-party scripts, rate limiting on authentication endpoints applied in the application itself, and secure same-site session and CSRF cookies.
  • · File handling. Uploaded documents are served only through access-checked routes, never from a storage URL, and always as downloads rather than rendered in the browser.
  • · Resilience. Managed database with daily backups and point-in-time recovery.
  • · Logging. Every outbound call, email and model call is recorded with credentials redacted. Every publication records the reviewer and the timestamp.
  • · Secure development. Dependency vulnerability scanning and container image scanning on every change, alongside an automated test suite that must pass before a change is released.
  • · Model processing. Analysis shared with all subscribers is written from published regulatory material only and contains no customer data. Only per-organization output receives your content, and it is never used for model training.

Annex III — approved sub-processors

  • · Anthropic, PBC — Generates the written analysis. Receives the text of published regulatory material, and — for per-organization output only — your device and component names, your organization profile, and extracts of the documents you upload. (United States)
    The shared analysis of a regulatory item carries no customer data at all: it is written once and read by every subscriber, so one customer's information cannot appear in it.
  • · Stripe, Inc. — Payment processing and subscription billing. Receives your billing contact and payment details directly — card numbers are entered on Stripe's own hosted pages and never reach our servers. (United States)
  • · Render Services, Inc. — Hosting, application database and backups. Holds all account data and all customer content at rest. (United States (Oregon))
  • · Amazon Web Services, Inc. — Stores the documents you upload and the source files retrieved from publishers. (United States (Ohio, us-east-2))
    Objects are reachable only through views that check the organization. The bucket is private and carries no public ACL, so a stored document has no URL that works without a session.
  • · ActiveCampaign, LLC (Postmark) — Delivers digests, briefings, alerts, invitations and password resets. Receives recipient addresses and message content. (United States)