← graften.io
Who this applies to: This DPA applies automatically to all Graften subscribers. It becomes binding when you accept the Terms of Service. You do not need to sign a separate document — accepting the Terms incorporates this DPA. If your organisation requires a countersigned DPA for GDPR or contractual purposes, email legal@graften.io.
1. Definitions
- Controller — the party that determines the purposes and means of processing personal data
- Processor — the party that processes personal data on behalf of a controller
- Data Subject — an identified or identifiable natural person whose personal data is processed
- Personal Data — any information relating to an identified or identifiable natural person
- Processing — any operation performed on personal data
- Sub-processor — a third party engaged by the processor to carry out processing on behalf of the controller
- Applicable Data Protection Law — includes the Australian Privacy Act 1988, the Australian Privacy Principles, the UK GDPR, the New Zealand Privacy Act 2020, the Singapore PDPA, and any other applicable data protection legislation
2. Roles and relationship
The parties acknowledge that:
- The Subscriber is the Controller of personal data relating to their own staff, users, and operations
- Graften acts as Processor when processing that personal data to provide the platform services
- For MSP subscribers: the Subscriber is additionally a Controller (or Processor on behalf of their own clients) of their clients' data. Graften acts as Sub-processor for that client data.
- Each party remains an independent Controller of any personal data they process for their own internal business purposes
3. Graften's obligations as Processor
Graften will:
- Process personal data only on documented instructions from the Subscriber, including the purposes set out in the Terms of Service and this DPA
- Ensure that persons authorised to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures as described in Section 5
- Not engage sub-processors without the Subscriber's general authorisation (see Section 6) and notify the Subscriber of any intended changes to sub-processors
- Assist the Subscriber in responding to data subject rights requests where technically feasible
- Assist the Subscriber in meeting obligations under applicable data protection law regarding security, breach notification, impact assessments, and prior consultation
- Delete or return all personal data at the end of the service relationship, as described in Section 7
- Make available all information reasonably necessary to demonstrate compliance with this DPA
- Notify the Subscriber without undue delay (and within 48 hours where possible) upon becoming aware of a personal data breach
4. Subscriber's obligations as Controller
The Subscriber will:
- Ensure they have a lawful basis for providing personal data to Graften for processing
- Ensure data subjects have been informed about processing through appropriate privacy notices
- Respond to data subject requests in a timely manner and notify Graften of any requests that require Graften's assistance
- Ensure they have appropriate authorisation to audit and monitor any client systems processed through the platform
- Notify Graften of any changes to applicable data protection law that may affect this DPA
5. Security measures
Graften implements the following technical and organisational security measures:
Technical measures
- Per-subscriber AES-256-GCM encryption at rest using AWS KMS-managed Data Encryption Keys (DEKs) unique to each subscriber
- TLS 1.2 or higher for all data in transit; TLS 1.0 and 1.1 disabled
- Logical data isolation — all database queries are scoped to the authenticated subscriber's ID at the application layer
- Role-based access control within the platform
- MFA available and recommended for all user accounts
- Aurora PostgreSQL encrypted automated backups with 7-day retention
- VPC network isolation for database and internal services
- Comprehensive audit logging of all access and changes
Organisational measures
- Access to subscriber data by Graften staff is limited to what is necessary for support and platform operations
- Staff with access to production systems are subject to confidentiality obligations
- Security vulnerability disclosure program at security@graften.io
6. Sub-processors
The Subscriber provides general authorisation for Graften to engage the following categories of sub-processors. Graften will inform the Subscriber of any additions or replacements with reasonable notice.
| Sub-processor | Location | Purpose |
| Amazon Web Services | Australia (ap-southeast-2) | Cloud infrastructure, database, storage, KMS key management |
| Anthropic | United States | AI-assisted features (vCISO reports, chat). Zero data retention API. |
| Stripe | United States | Payment processing |
| Postmark (ActiveCampaign) | United States | Transactional email delivery |
| Have I Been Pwned | Australia | Dark web domain monitoring |
Business number validation calls are made to government registries (Australian Business Register, New Zealand Companies Office, Companies House UK, ACRA Singapore) which are government bodies, not sub-processors, and operate under their own statutory frameworks.
7. Data retention and deletion
- On account cancellation, Subscriber Data is retained in a paused state for 90 days to allow for reactivation or export
- After 90 days, Subscriber Data is permanently deleted from production systems
- Backup copies are deleted within 7 days of the main deletion (aligned with backup retention)
- Billing and financial records are retained for 7 years as required by Australian law regardless of account status
- The Subscriber may request immediate deletion by emailing privacy@graften.io. Immediate deletion will be completed within 30 days subject to legal retention requirements.
8. Data subject rights
Where a data subject makes a request to Graften directly relating to data processed on behalf of the Subscriber, Graften will promptly forward the request to the Subscriber. Graften will assist the Subscriber in fulfilling the request where technically feasible, including:
- Providing access to personal data held for that subscriber account
- Correcting inaccurate personal data
- Deleting personal data on instruction (subject to retention requirements)
- Exporting personal data in a structured, machine-readable format
9. Data breach notification
In the event of a personal data breach affecting Subscriber Data, Graften will:
- Notify the Subscriber without undue delay and within 48 hours of becoming aware of the breach where possible
- Provide the Subscriber with sufficient information to meet their own breach notification obligations under applicable law
- Cooperate fully with the Subscriber's investigation and remediation efforts
- Take all reasonable steps to contain the breach and prevent further unauthorised access
The Subscriber is responsible for any notifications to data protection authorities or affected data subjects required by applicable law.
10. Audits and inspections
Graften will, upon reasonable written notice (no less than 30 days) and at the Subscriber's expense, make available information necessary to demonstrate compliance with this DPA, and permit audits or inspections conducted by the Subscriber or a mandated third-party auditor, provided that:
- Audits are conducted during normal business hours and in a manner that minimises disruption
- The auditor is bound by confidentiality obligations no less protective than those in these Terms
- No more than one audit per 12-month period is permitted unless there is a specific basis to believe a breach has occurred
11. International transfers
Where personal data is transferred outside Australia or the EEA, such transfers are made on the basis of:
- AWS and Stripe: Standard Contractual Clauses and adequacy decisions where applicable
- Anthropic: Standard Contractual Clauses (zero data retention — data is not stored beyond the API call)
- Government registry lookups (ABR, NZBN, Companies House, ACRA): These are government bodies operating under their own statutory frameworks; only the business registration number is transmitted
12. Term and termination
This DPA remains in force for the duration of the Terms of Service. It terminates automatically when the Terms of Service terminate. Obligations relating to data deletion and confidentiality survive termination.
13. Order of precedence
In the event of conflict between this DPA and the Terms of Service, this DPA takes precedence with respect to data protection matters. The Terms of Service take precedence on all other matters.
14. Countersigned DPA
This DPA is incorporated into the Terms of Service by reference and is binding upon account creation. If your organisation requires a separately executed DPA (e.g. for GDPR compliance documentation or enterprise procurement purposes), contact legal@graften.io. We will provide a countersigned copy within 10 business days.