GrindzeroSuomeksi

Data Processing Agreement

Effective from: 25 August 2026

Grindzero Oy (Business ID 3411998-2), Mukulakuja 4 A9, 04300 Tuusula, Finland ("Grindzero")

This is Grindzero's standard data processing agreement. It takes effect without a separate signature when a Business User uses the Service. If customer-specific terms are required, the parties may execute a signed processing agreement that prevails over this document.

Effectiveness and application

This agreement is incorporated by reference into Grindzero's Terms of Service and becomes part of the contract between the customer ("Controller") and Grindzero when the Controller accepts the Terms, creates an organisation account, or starts using Grindzero's public API. A counterpart signature is not required. The current version is at https://www.grindzero.app/en/legal/dpa. Prior versions are recorded in the change log.

If the Controller and Grindzero have separately signed a processing agreement that replaces or supplements this one, that signed agreement prevails.

Parties and roles

Processor: Grindzero Oy (as above).

Controller: the Business User that has accepted the Terms of Service, as identified on the Grindzero organisation account.

Role split: Grindzero is the processor of personal data of the Controller's own end users (for example drivers, site managers, and other authorised users) when that data is processed through the Service. Grindzero is the controller of its own customer accounts, billing, and marketing (for example the Controller's own sales or billing contacts). This agreement does not apply to that processing; it is covered by Grindzero's Privacy Policy.

1. Subject matter and duration

This agreement covers processing of personal data that occurs when using the Grindzero Service (mobile app, admin app, public API). It remains in force for as long as the service relationship continues, and thereafter to the extent clause 8 requires.

2. Nature and purpose of processing

Grindzero processes personal data on behalf of the Controller for:

  • identifying and authenticating users (SMS one-time codes, email/password, Google sign-in, multi-factor authentication)
  • coordinating worksites, transports, and surplus concrete logistics
  • providing the Controller's own data via the public API (reporting, integrations)
  • securing and operating the Service

Processing is automated and manual, and continues for the term of the service relationship. Scope is further described in Annex A.

3. Categories of data and data subjects

Data categories (see also the Privacy Policy):

CategoryExamples
Identity dataphone number, email, name, company, role
Technical account datauser identifiers, login logs, IP address
Location datadriver GPS (foreground and background when sharing is enabled for a truck)
Uploaded documents and imageswaybills, receiving-point photos — may contain personal data
Message contentsupport requests and other contacts

Data subjects: users authorised by the Controller (for example employees, drivers, site managers) who use the Service on the Controller's behalf.

Special categories (GDPR Art. 9): the Service is not designed to collect special-category data. Waybills and receiving-point photos may incidentally include identifiable people. That is treated as ordinary personal data, not Art. 9 data, because the purpose of capture is not to reveal health, origin, or other special-category information.

4. Legal basis

The Controller is responsible for having a GDPR Art. 6 legal basis for processing its users' personal data (typically contract or legitimate interest — see the Terms of Service). Grindzero processes data only on the Controller's documented instructions and under this agreement.

5. Processor obligations

Grindzero will:

5.1. process personal data only on the Controller's documented instructions (Terms of Service + this agreement), unless EU or national law requires otherwise — in which case Grindzero will notify the Controller before processing, unless the law forbids notice;

5.2. ensure that persons authorised to process the data are bound by confidentiality;

5.3. implement appropriate technical and organisational measures under GDPR Art. 32 (clause 7);

5.4. comply with the sub-processor terms in clause 6 and Annex B;

5.5. assist the Controller, by appropriate measures, with data-subject rights (GDPR Chapter III). Account deletion and access to one's own data are available as self-service in the Service (see the Privacy Policy). Grindzero will respond to other requests within 10 business days;

5.6. assist the Controller with Arts. 32–36 obligations to the extent reasonably possible given the nature of the processing and the information available to Grindzero;

5.7. delete or return personal data after the service relationship ends, as set out in clause 8;

5.8. make available the information needed to demonstrate compliance with this agreement and allow audits under clause 9.

6. Sub-processors

The Controller authorises Grindzero's use of sub-processors as listed in Annex B.

Grindzero will give at least 30 days' notice before a new sub-processor starts processing the Controller's personal data, by email or in the Service. The Controller may object on reasoned data-protection grounds within 15 days of notice.

Platform sub-processors (Supabase, Vercel, Cloudflare, Upstash) are necessary to operate the Service. A reasoned objection to those means the Controller may terminate the service relationship. Grindzero cannot continue to provide the Service without transferring data to them.

Other sub-processors (for example Sentry, Resend, SMS providers, optional Google sign-in): if the parties do not resolve an objection within 30 days, the Controller may terminate the service relationship to the extent it concerns data processed by that sub-processor. Until resolved, Grindzero will not move the Controller's data to the objected new sub-processor.

Grindzero is responsible for ensuring that each Art. 28 sub-processor is bound by data-protection obligations at least as protective as this agreement. Google Maps Platform and Google sign-in are listed in Annex B for transparency; they may act in part as independent controllers (see Annex B).

7. Security (GDPR Art. 32)

Grindzero implements appropriate technical and organisational measures for the risk of the processing, including:

  • role-based access control (Row Level Security, Supabase Auth) — a user sees only their organisation's data
  • encryption in transit (TLS) and at rest (Supabase/AWS standard)
  • login and change logs for critical operations
  • multi-factor authentication required for admin roles in production
  • access limited to people who need it for their work
  • automatic daily backups (Supabase Pro). Point-in-time recovery is available as an add-on, not by default

8. Deletion or return at the end of the agreement

When the service relationship ends, Grindzero will:

8.1. make the Controller's own data available in machine-readable form (API responses / CSV export) within 30 days of termination;

8.2. delete or anonymise personal data as the Controller chooses, unless law requires retention (for example accounting law) — following the same model as account deletion (default 30 days, the organisation may extend up to 365 days; see the Privacy Policy).

9. Audits and information

On request, Grindzero will provide reasonable information to demonstrate compliance (for example the sub-processor list, a security description, Annex B). Audits are once per year, primarily remote (documentation and questionnaires). On-site audits are agreed separately. The Controller bears the cost of an audit unless findings show a material breach of this agreement, in which case Grindzero bears the cost.

10. Personal data breaches

Grindzero will notify the Controller without undue delay of a personal data breach affecting the Controller's data, aiming to notify within 72 hours of becoming aware of it. The notice will include available information on the nature of the breach, likely consequences, and measures taken or planned. Channel: the technical contact recorded in the Service, and info@grindzero.io.

The 72-hour period in GDPR Art. 33 is Grindzero's deadline to the supervisory authority, not the customer-notice standard in this clause.

11. International transfers

Some sub-processors process data outside the European Economic Area. Each such transfer is covered by EU Standard Contractual Clauses and/or EU–U.S. Data Privacy Framework certification, depending on the vendor — see Annex B. Some sub-processors (Supabase, Sentry EU region, GatewayAPI EU account, Tavoittaja.fi) process data in the EU/EEA.

12. Liability

The following applies to personal data processing under this agreement and prevails over the general limitation of liability in the Terms of Service to the extent of a breach of this agreement:

Grindzero's aggregate liability for damage arising under this agreement is capped at the fees the Controller paid Grindzero during the preceding twelve (12) months. The cap does not apply to damage caused by wilful misconduct, gross negligence, breach of confidentiality, or an administrative fine imposed on the Controller by a supervisory authority insofar as the fine is demonstrably based on Grindzero's breach of this agreement.

Other use of the Service remains subject to clause 12 of the Terms of Service.

13. Term and governing law

This agreement is governed by Finnish law. Disputes shall first be addressed by negotiation; otherwise they shall be resolved in the competent district court at Grindzero's domicile (Finland).

A customer-specific signed processing agreement is available by contacting info@grindzero.io.


Annex A — Scope of processing

This standard annex covers the Controller's use of the Grindzero Service (mobile app, admin app, and public API) limited to the Controller's own organisation.

The public API is at https://api.grindzero.app/api/v1 and is described at https://api.grindzero.app/docs. Processing is limited to data the Controller's API key is scoped to access (for example read:orgs, write:orgs:self, read:data, write:data, or *). Current scopes are shown in the admin app on the API key.

GPS tracking in the mobile app is in scope for the Controller's own users when location sharing is enabled. The public API does not expose live GPS unless a documented endpoint exists.

This annex does not cover: (a) other organisations' data; (b) an integration governed by a separately signed processing agreement.

When documented public API routes or scopes are added, they fall under this annex to the extent the Controller enables them. Changes are described in the API documentation.


Annex B — Sub-processors and transfers (GDPR Chapter V)

VendorPersonal data seenRegionTransfer mechanismVendor terms
Supabase Inc.All data categoriesEU (AWS eu-north-1, Stockholm)No Chapter V transfer—
Vercel Inc.IP, request logs; API traffic transits the platformUnited States (vendor's primary processing facilities)EU SCCs (module 2). No DPF certificationvercel.com/legal/dpa
Upstash Inc.API key, request rate (no content)United States / globalSCCs (module 2) and EU–U.S. DPFupstash.com/trust/dpa.pdf
Cloudflare Inc.IP addresses, request URLs (DNS and edge)Global edge networkSCCs (module 2) and EU–U.S. DPFcloudflare.com/cloudflare-customer-dpa
Google LLC (Maps Platform)Location data for maps and geocodingGlobal Google infrastructureSCCs and/or DPF. Google may act in part as an independent controller; listed for transparencycloud.google.com/terms/data-processing-addendum
Google LLC (sign-in)Identity data only for users who choose Google sign-inGlobalThe user authenticates directly with Google; Google typically acts as an independent controller for that event, not as Grindzero's Art. 28 sub-processorpolicies.google.com/privacy/frameworks
OnlineCity ApS (GatewayAPI, EU account)Phone number, verification codeEU (gatewayapi.eu). Sub-processors: Hetzner (Germany and Finland), HeySender (Denmark)No Chapter V transfer in practice. EU DPA accepted for the account on 24 April 2026 (gatewayapi.eu, Agreements)onlinecity.io/legal-documents/gatewayapi/dpa-eu
Resend Inc. (Plus Five Five, Inc.)Email, message content, metadataUnited StatesSCCs (module 2) and EU–U.S. DPFresend.com/legal/subprocessors
Functional Software Inc. (Sentry)Technical logs, possibly identifiers in error contextEU (Frankfurt, de.sentry.io)No Chapter V transferSentry DPA
Prospectum Oy (Tavoittaja.fi)Phone number, verification codeFinland / EUNo Chapter V transfer—

Change log

  • 2026-08-25: First published standard DPA. Effective by incorporation into the Terms of Service. GatewayAPI EU DPA confirmed accepted on the account (app.gatewayapi.eu, 24 April 2026).
Terms of Service·Privacy Policy·info@grindzero.io
← Back to home