This page summarizes the Data Processing Addendum (“DPA”) that Grafty, Inc. enters into with enterprise customers. A countersigned DPA is available on request at info@grafty.ai(subject “[DPA Request]”).
Roles
Grafty runs on customer infrastructure. The customer is the controller (and, where applicable, the processor) of personal data processed inside their Grafty instance. Because that data never reaches Grafty, Inc., Grafty is not a processor of it.
Scope of Grafty’s processing
Grafty processes only the limited personal data submitted directly to Grafty, Inc. — for example, contact form entries, license registrations, and support requests. The DPA covers that scope.
Security measures
For data Grafty does process: TLS in transit, encryption of secrets at rest, least-privilege access, change management, vulnerability response, and audit logging on Grafty-operated systems.
Subprocessors
A current list of the subprocessors Grafty uses for its own website and operations is available on request. Updates are communicated to customers with the option to object.
Data subject requests
Grafty will assist customers in responding to data subject requests directed at Grafty-held data. Requests concerning data inside a customer’s instance are handled by the customer as controller.
International transfers
Standard Contractual Clauses are available where required.
Request a copy
Email info@grafty.aiwith the subject “[DPA Request]”.