Privacy notice
How GrapeBeaver Intelligence handles personal data, who receives it, and what you can ask us to do about it. Last updated 28 August 2026.
Two different roles, and the difference matters
We hold personal data in two capacities and your rights differ between them.
For account and billing data — who you are, which plan you are on, what you have read — we decide why it is held, so we are the controller and this notice is the full account of what we do. Write to us directly.
For what your organization uploads — your quality documents, your product records, your profile — we hold it on your instructions and for no purpose of our own, so we are a processor and your employer is the controller. If you are an employee of a customer asking about a document your company uploaded, ask your own organization first; we will help them answer, but the decision is theirs. The terms of that arrangement are in our data processing agreement.
Who we are
Matt Hillyer LLC, operating GrapeBeaver Intelligence. Write to us at the addresses below — they are the contact route for everything in this notice, including any right you wish to exercise.
Privacy enquiries and requests: privacy@grapebeaver.io. Security reports: security@grapebeaver.io.
What we hold as controller, and why we are allowed to
- · Account. Email address, name, job title, time zone and display preference, password (stored only as an Argon2 hash), the date you joined and when you were last seen.
- · Organization. Organization name, plan tier, seat allocations, team membership and role, and invitations you send or receive.
- · Billing. Plan, subscription status and the Stripe customer reference. Card details are held by Stripe and never by us.
- · Usage. Which advisories you have read, the decisions your organization records against them, and a log of outbound email and model calls made on your behalf.
- · Support. Anything you send us through the feedback form or by email.
The lawful basis is performance of a contract for everything needed to give you the service you signed up for — an account, a subscription, the digests you asked to receive. It is our legitimate interest in running and securing the service for the operational logs, rate-limiting records and the audit trail of who approved what, balanced against the fact that these are records of professional activity rather than private life. Where we ask for consent — marketing that is not about a service you hold — you can withdraw it without affecting the service.
What we hold as processor
- · Documents you upload. Typically published standards, your own policies, and the product documentation you would give your own customers — plus any personal data those happen to carry, a named owner or approver most commonly. Reference copies for the agents to read against: the platform reads them, never edits them, and is not the system your teams work from.
- · Product records. Your device portfolio, software bill of materials, and the component inventory derived from it.
- · Organization profile. What you tell us about your markets, standards, operating functions and risk framework so that analysis can be written for you.
We never use it to train a model, we never use it to build a product for anybody else, and we do not read it except where it is necessary to run the service or you have asked us for support. Your documents are yours; the platform comments on them and never edits them.
What we do not hold
GrapeBeaver Intelligence does not process protected health information or patient data, and no part of the product requires it. We do not collect special category data under Article 9. We have no advertising, no analytics, and no third-party tracking of any kind — the content security policy the site is served under does not permit a third-party script to run, so there is nothing to opt out of.
Nothing on our pages is fetched from anybody else's server. Typefaces, stylesheets and images are all served from our own, so loading a page sends your IP address to us and to nobody else. That is deliberate: a font hosted elsewhere sets no cookie and still discloses every visitor to a third party, which is the kind of transfer a cookie banner would not have covered.
Cookies
Two, both strictly necessary and neither used to track you: a session cookie that keeps you signed in, and a CSRF token that prevents another site submitting a form as you. Both are secure and same-site. There is no analytics cookie and no advertising cookie, which is why this site shows you no cookie banner.
Who else receives it
We do not sell personal data and we do not share it for anybody else's marketing. These are the sub-processors that make the service work:
-
· Anthropic, PBC — Generates the written analysis. Receives the text of published regulatory material, and — for per-organization output only — your device and component names, your organization profile, and extracts of the documents you upload.
(United States)
The shared analysis of a regulatory item carries no customer data at all: it is written once and read by every subscriber, so one customer's information cannot appear in it. - · Stripe, Inc. — Payment processing and subscription billing. Receives your billing contact and payment details directly — card numbers are entered on Stripe's own hosted pages and never reach our servers. (United States)
- · Render Services, Inc. — Hosting, application database and backups. Holds all account data and all customer content at rest. (United States (Oregon))
-
· Amazon Web Services, Inc. — Stores the documents you upload and the source files retrieved from publishers.
(United States (Ohio, us-east-2))
Objects are reachable only through views that check the organization. The bucket is private and carries no public ACL, so a stored document has no URL that works without a session. - · ActiveCampaign, LLC (Postmark) — Delivers digests, briefings, alerts, invitations and password resets. Receives recipient addresses and message content. (United States)
We may also disclose data where the law requires it. If we are ever compelled to hand over customer content, we will tell the customer unless we are legally prohibited from doing so.
Where it goes
The service is hosted in the United States, and every sub-processor above operates there. If you are in the United Kingdom or the European Economic Area, your data is therefore transferred outside it. Those transfers rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where UK data is involved), together with the technical measures described in our security posture — encryption in transit and at rest, and access limited to the people who operate the service.
How long we keep it
- · Account data — while your account is open, and for up to 90 days after it closes so it can be restored if the closure was a mistake.
- · Uploaded documents and product records — until you delete them, or until 30 days after your organization closes its account.
- · Retrieved source documents — a rolling two years, after which the file is deleted and only the record of what was retrieved and where to find the publisher's current version remains.
- · Billing records — as long as tax and accounting law requires, which is longer than the account itself.
- · Operational logs — a rolling window sufficient to investigate an incident, and no longer.
Automated analysis, and what it is not
GrapeBeaver Intelligence uses large language models to summarise regulatory material and to write about how it may bear on your products and documents. That output is decision support: it is reviewed by a person before publication, it recommends that somebody consider something, and it never makes a determination about you or about a product. There is no automated decision-making producing legal or similarly significant effects within the meaning of Article 22, and no profiling of individuals — the analysis is about regulatory documents and products, not about people.
Your rights
Where we are the controller you can ask us to give you a copy of your data, correct it, delete it, restrict or object to what we do with it, or send it to somebody else in a portable form. Write to privacy@grapebeaver.io. We will answer within one month, and we will not charge you or make the service worse because you asked.
You can also complain to a supervisory authority — in the UK the Information Commissioner's Office, in the EEA the authority for the country you live or work in. We would rather you came to us first, but that is your right and not our permission to give.
Changes
If we change this notice we will update the date at the top. If a change materially affects what we do with your data we will tell account holders by email before it takes effect, rather than relying on you to re-read this page.