Data Processing Agreement
Effective from: 25 August 2026
Grindzero Oy (Business ID 3411998-2), Mukulakuja 4 A9, 04300 Tuusula, Finland ("Grindzero")
This is Grindzero's standard data processing agreement. It takes effect without a separate signature when a Business User uses the Service. If customer-specific terms are required, the parties may execute a signed processing agreement that prevails over this document.
Effectiveness and application
This agreement is incorporated by reference into Grindzero's Terms of Service and becomes part of the contract between the customer ("Controller") and Grindzero when the Controller accepts the Terms, creates an organisation account, or starts using Grindzero's public API. A counterpart signature is not required. The current version is at https://www.grindzero.app/en/legal/dpa. Prior versions are recorded in the change log.
If the Controller and Grindzero have separately signed a processing agreement that replaces or supplements this one, that signed agreement prevails.
Parties and roles
Processor: Grindzero Oy (as above).
Controller: the Business User that has accepted the Terms of Service, as identified on the Grindzero organisation account.
Role split: Grindzero is the processor of personal data of the Controller's own end users (for example drivers, site managers, and other authorised users) when that data is processed through the Service. Grindzero is the controller of its own customer accounts, billing, and marketing (for example the Controller's own sales or billing contacts). This agreement does not apply to that processing; it is covered by Grindzero's Privacy Policy.
1. Subject matter and duration
This agreement covers processing of personal data that occurs when using the Grindzero Service (mobile app, admin app, public API). It remains in force for as long as the service relationship continues, and thereafter to the extent clause 8 requires.
2. Nature and purpose of processing
Grindzero processes personal data on behalf of the Controller for:
- identifying and authenticating users (SMS one-time codes, email/password, Google sign-in, multi-factor authentication)
- coordinating worksites, transports, and surplus concrete logistics
- providing the Controller's own data via the public API (reporting, integrations)
- securing and operating the Service
Processing is automated and manual, and continues for the term of the service relationship. Scope is further described in Annex A.
3. Categories of data and data subjects
Data categories (see also the Privacy Policy):
| Category | Examples |
|---|---|
| Identity data | phone number, email, name, company, role |
| Technical account data | user identifiers, login logs, IP address |
| Location data | driver GPS (foreground and background when sharing is enabled for a truck) |
| Uploaded documents and images | waybills, receiving-point photos — may contain personal data |
| Message content | support requests and other contacts |
Data subjects: users authorised by the Controller (for example employees, drivers, site managers) who use the Service on the Controller's behalf.
Special categories (GDPR Art. 9): the Service is not designed to collect special-category data. Waybills and receiving-point photos may incidentally include identifiable people. That is treated as ordinary personal data, not Art. 9 data, because the purpose of capture is not to reveal health, origin, or other special-category information.
4. Legal basis
The Controller is responsible for having a GDPR Art. 6 legal basis for processing its users' personal data (typically contract or legitimate interest — see the Terms of Service). Grindzero processes data only on the Controller's documented instructions and under this agreement.
5. Processor obligations
Grindzero will:
5.1. process personal data only on the Controller's documented instructions (Terms of Service + this agreement), unless EU or national law requires otherwise — in which case Grindzero will notify the Controller before processing, unless the law forbids notice;
5.2. ensure that persons authorised to process the data are bound by confidentiality;
5.3. implement appropriate technical and organisational measures under GDPR Art. 32 (clause 7);
5.4. comply with the sub-processor terms in clause 6 and Annex B;
5.5. assist the Controller, by appropriate measures, with data-subject rights (GDPR Chapter III). Account deletion and access to one's own data are available as self-service in the Service (see the Privacy Policy). Grindzero will respond to other requests within 10 business days;
5.6. assist the Controller with Arts. 32–36 obligations to the extent reasonably possible given the nature of the processing and the information available to Grindzero;
5.7. delete or return personal data after the service relationship ends, as set out in clause 8;
5.8. make available the information needed to demonstrate compliance with this agreement and allow audits under clause 9.
6. Sub-processors
The Controller authorises Grindzero's use of sub-processors as listed in Annex B.
Grindzero will give at least 30 days' notice before a new sub-processor starts processing the Controller's personal data, by email or in the Service. The Controller may object on reasoned data-protection grounds within 15 days of notice.
Platform sub-processors (Supabase, Vercel, Cloudflare, Upstash) are necessary to operate the Service. A reasoned objection to those means the Controller may terminate the service relationship. Grindzero cannot continue to provide the Service without transferring data to them.
Other sub-processors (for example Sentry, Resend, SMS providers, optional Google sign-in): if the parties do not resolve an objection within 30 days, the Controller may terminate the service relationship to the extent it concerns data processed by that sub-processor. Until resolved, Grindzero will not move the Controller's data to the objected new sub-processor.
Grindzero is responsible for ensuring that each Art. 28 sub-processor is bound by data-protection obligations at least as protective as this agreement. Google Maps Platform and Google sign-in are listed in Annex B for transparency; they may act in part as independent controllers (see Annex B).
7. Security (GDPR Art. 32)
Grindzero implements appropriate technical and organisational measures for the risk of the processing, including:
- role-based access control (Row Level Security, Supabase Auth) — a user sees only their organisation's data
- encryption in transit (TLS) and at rest (Supabase/AWS standard)
- login and change logs for critical operations
- multi-factor authentication required for admin roles in production
- access limited to people who need it for their work
- automatic daily backups (Supabase Pro). Point-in-time recovery is available as an add-on, not by default
8. Deletion or return at the end of the agreement
When the service relationship ends, Grindzero will:
8.1. make the Controller's own data available in machine-readable form (API responses / CSV export) within 30 days of termination;
8.2. delete or anonymise personal data as the Controller chooses, unless law requires retention (for example accounting law) — following the same model as account deletion (default 30 days, the organisation may extend up to 365 days; see the Privacy Policy).
9. Audits and information
On request, Grindzero will provide reasonable information to demonstrate compliance (for example the sub-processor list, a security description, Annex B). Audits are once per year, primarily remote (documentation and questionnaires). On-site audits are agreed separately. The Controller bears the cost of an audit unless findings show a material breach of this agreement, in which case Grindzero bears the cost.
10. Personal data breaches
Grindzero will notify the Controller without undue delay of a personal data breach affecting the Controller's data, aiming to notify within 72 hours of becoming aware of it. The notice will include available information on the nature of the breach, likely consequences, and measures taken or planned. Channel: the technical contact recorded in the Service, and info@grindzero.io.
The 72-hour period in GDPR Art. 33 is Grindzero's deadline to the supervisory authority, not the customer-notice standard in this clause.
11. International transfers
Some sub-processors process data outside the European Economic Area. Each such transfer is covered by EU Standard Contractual Clauses and/or EU–U.S. Data Privacy Framework certification, depending on the vendor — see Annex B. Some sub-processors (Supabase, Sentry EU region, GatewayAPI EU account, Tavoittaja.fi) process data in the EU/EEA.
12. Liability
The following applies to personal data processing under this agreement and prevails over the general limitation of liability in the Terms of Service to the extent of a breach of this agreement:
Grindzero's aggregate liability for damage arising under this agreement is capped at the fees the Controller paid Grindzero during the preceding twelve (12) months. The cap does not apply to damage caused by wilful misconduct, gross negligence, breach of confidentiality, or an administrative fine imposed on the Controller by a supervisory authority insofar as the fine is demonstrably based on Grindzero's breach of this agreement.
Other use of the Service remains subject to clause 12 of the Terms of Service.
13. Term and governing law
This agreement is governed by Finnish law. Disputes shall first be addressed by negotiation; otherwise they shall be resolved in the competent district court at Grindzero's domicile (Finland).
A customer-specific signed processing agreement is available by contacting info@grindzero.io.
Annex A — Scope of processing
This standard annex covers the Controller's use of the Grindzero Service (mobile app, admin app, and public API) limited to the Controller's own organisation.
The public API is at https://api.grindzero.app/api/v1 and is described at https://api.grindzero.app/docs. Processing is limited to data the Controller's API key is scoped to access (for example read:orgs, write:orgs:self, read:data, write:data, or *). Current scopes are shown in the admin app on the API key.
GPS tracking in the mobile app is in scope for the Controller's own users when location sharing is enabled. The public API does not expose live GPS unless a documented endpoint exists.
This annex does not cover: (a) other organisations' data; (b) an integration governed by a separately signed processing agreement.
When documented public API routes or scopes are added, they fall under this annex to the extent the Controller enables them. Changes are described in the API documentation.
Annex B — Sub-processors and transfers (GDPR Chapter V)
| Vendor | Personal data seen | Region | Transfer mechanism | Vendor terms |
|---|---|---|---|---|
| Supabase Inc. | All data categories | EU (AWS eu-north-1, Stockholm) | No Chapter V transfer | — |
| Vercel Inc. | IP, request logs; API traffic transits the platform | United States (vendor's primary processing facilities) | EU SCCs (module 2). No DPF certification | vercel.com/legal/dpa |
| Upstash Inc. | API key, request rate (no content) | United States / global | SCCs (module 2) and EU–U.S. DPF | upstash.com/trust/dpa.pdf |
| Cloudflare Inc. | IP addresses, request URLs (DNS and edge) | Global edge network | SCCs (module 2) and EU–U.S. DPF | cloudflare.com/cloudflare-customer-dpa |
| Google LLC (Maps Platform) | Location data for maps and geocoding | Global Google infrastructure | SCCs and/or DPF. Google may act in part as an independent controller; listed for transparency | cloud.google.com/terms/data-processing-addendum |
| Google LLC (sign-in) | Identity data only for users who choose Google sign-in | Global | The user authenticates directly with Google; Google typically acts as an independent controller for that event, not as Grindzero's Art. 28 sub-processor | policies.google.com/privacy/frameworks |
| OnlineCity ApS (GatewayAPI, EU account) | Phone number, verification code | EU (gatewayapi.eu). Sub-processors: Hetzner (Germany and Finland), HeySender (Denmark) | No Chapter V transfer in practice. EU DPA accepted for the account on 24 April 2026 (gatewayapi.eu, Agreements) | onlinecity.io/legal-documents/gatewayapi/dpa-eu |
| Resend Inc. (Plus Five Five, Inc.) | Email, message content, metadata | United States | SCCs (module 2) and EU–U.S. DPF | resend.com/legal/subprocessors |
| Functional Software Inc. (Sentry) | Technical logs, possibly identifiers in error context | EU (Frankfurt, de.sentry.io) | No Chapter V transfer | Sentry DPA |
| Prospectum Oy (Tavoittaja.fi) | Phone number, verification code | Finland / EU | No Chapter V transfer | — |
Change log
- 2026-08-25: First published standard DPA. Effective by incorporation into the Terms of Service. GatewayAPI EU DPA confirmed accepted on the account (app.gatewayapi.eu, 24 April 2026).