Data processing agreement
Last updated: October 4, 2026
This agreement applies when an organization (the controller) uses a Granite workspace and Granite processes personal data on its behalf (the processor), as required by Article 28 GDPR. It is part of the terms of service.
Subject and duration
Granite processes the content members put into the workspace and the members' account data, for as long as the workspace exists and until it is purged after deletion.
Granite's commitments
- Process the data only on the controller's documented instructions, which are the terms and the controller's use of the service.
- Ensure staff with access are bound by confidentiality.
- Apply the security measures described on the security page: encryption in transit and at rest with a key per workspace, access control, audit logging, and encrypted backups.
- Use only the sub-processors listed, under equivalent obligations, and give 30 days' notice of new ones so the controller can object.
- Help the controller answer data subject requests, using the workspace's admin tools (members, SCIM, export, deletion) or on request.
- Notify the controller of a personal data breach without undue delay, and within 48 hours of becoming aware of it.
- Delete the data when the workspace is deleted: it is purged after a 30-day recovery window, its key is destroyed, and backups expire within 35 days.
- Make available the information needed to demonstrate compliance, and allow reasonable audits.
Transfers
Where data leaves the European Economic Area, the European Commission's standard contractual clauses apply.