← graften.io
LEGAL

Data Processing Agreement

Effective date: 10 July 2026  ·  Version 1.0

Who this applies to: This DPA applies automatically to all Graften subscribers. It becomes binding when you accept the Terms of Service. You do not need to sign a separate document — accepting the Terms incorporates this DPA. If your organisation requires a countersigned DPA for GDPR or contractual purposes, email legal@graften.io.

1. Definitions

2. Roles and relationship

The parties acknowledge that:

3. Graften's obligations as Processor

Graften will:

4. Subscriber's obligations as Controller

The Subscriber will:

5. Security measures

Graften implements the following technical and organisational security measures:

Technical measures

Organisational measures

6. Sub-processors

The Subscriber provides general authorisation for Graften to engage the following categories of sub-processors. Graften will inform the Subscriber of any additions or replacements with reasonable notice.

Sub-processorLocationPurpose
Amazon Web ServicesAustralia (ap-southeast-2)Cloud infrastructure, database, storage, KMS key management
AnthropicUnited StatesAI-assisted features (vCISO reports, chat). Zero data retention API.
StripeUnited StatesPayment processing
Postmark (ActiveCampaign)United StatesTransactional email delivery
Have I Been PwnedAustraliaDark web domain monitoring

Business number validation calls are made to government registries (Australian Business Register, New Zealand Companies Office, Companies House UK, ACRA Singapore) which are government bodies, not sub-processors, and operate under their own statutory frameworks.

7. Data retention and deletion

8. Data subject rights

Where a data subject makes a request to Graften directly relating to data processed on behalf of the Subscriber, Graften will promptly forward the request to the Subscriber. Graften will assist the Subscriber in fulfilling the request where technically feasible, including:

9. Data breach notification

In the event of a personal data breach affecting Subscriber Data, Graften will:

The Subscriber is responsible for any notifications to data protection authorities or affected data subjects required by applicable law.

10. Audits and inspections

Graften will, upon reasonable written notice (no less than 30 days) and at the Subscriber's expense, make available information necessary to demonstrate compliance with this DPA, and permit audits or inspections conducted by the Subscriber or a mandated third-party auditor, provided that:

11. International transfers

Where personal data is transferred outside Australia or the EEA, such transfers are made on the basis of:

12. Term and termination

This DPA remains in force for the duration of the Terms of Service. It terminates automatically when the Terms of Service terminate. Obligations relating to data deletion and confidentiality survive termination.

13. Order of precedence

In the event of conflict between this DPA and the Terms of Service, this DPA takes precedence with respect to data protection matters. The Terms of Service take precedence on all other matters.

14. Countersigned DPA

This DPA is incorporated into the Terms of Service by reference and is binding upon account creation. If your organisation requires a separately executed DPA (e.g. for GDPR compliance documentation or enterprise procurement purposes), contact legal@graften.io. We will provide a countersigned copy within 10 business days.