Grant Fund
Trust & legal

Data Processing Addendum

Last revised June 26, 2026Version 1.0

1. Introduction and scope

1.1. This Data Processing Addendum ("DPA") forms part of the agreement between Grant Fund LLC ("Grant Fund", "Processor") and the customer, Business User, grant consultant, accelerator, investor, company, or other entity using the Service ("Controller") where Grant Fund processes personal data on behalf of the Controller.

1.2. This DPA applies only to the extent that Grant Fund acts as processor or subprocessor under applicable data-protection law. It does not apply to processing for which Grant Fund acts as an independent controller, including account administration, billing, tax, compliance, KYC/KYB, fraud prevention, security, product analytics, communications, legal defence, and business operations.

1.3. This DPA is intended to satisfy Article 28 GDPR and equivalent processor-contract requirements under applicable law.

2. Definitions

2.1. "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach", "Subprocessor", and "Supervisory Authority" have the meanings given in GDPR unless applicable law provides otherwise.

2.2. "Customer Personal Data" means Personal Data submitted to the Service by or on behalf of the Controller and processed by Grant Fund on behalf of the Controller.

2.3. "Services" means the Grant Fund SaaS platform and related services governed by the Terms and applicable order or agreement.

3. Roles of the parties

3.1. The Controller determines the purposes and means of Processing Customer Personal Data.

3.2. Grant Fund processes Customer Personal Data as Processor only on documented instructions from the Controller, including the Terms, this DPA, any order form, support instructions, dashboard settings, and other written instructions accepted by Grant Fund.

3.3. If Grant Fund believes that an instruction infringes applicable data-protection law, Grant Fund will inform the Controller unless prohibited by law.

4. Subject matter, duration, nature, and purpose

4.1. Subject matter: Processing of Customer Personal Data in connection with Passport workflows, uploads, reports, grant eligibility screening, readiness analysis, AI-assisted classification, exports, support, compliance warnings, and related SaaS functionality.

4.2. Duration: For the term of the Services and thereafter only as required for deletion, return, backup, legal, tax, accounting, security, audit, dispute, compliance, anti-fraud, or legal-defence purposes.

4.3. Nature of Processing: Collection, recording, organisation, structuring, storage, hosting, adaptation, alteration, retrieval, consultation, analysis, enrichment, extraction, classification, summarisation, source matching, generation, transmission, disclosure to authorised subprocessors, restriction, deletion, and anonymisation.

4.4. Purpose: To provide, secure, support, maintain, improve, and operate the Services for the Controller in accordance with the agreement and documented instructions.

5. Categories of data subjects

5.1. Data subjects may include founders, directors, officers, employees, contractors, advisors, shareholders, beneficial owners, investors, board members, clients, portfolio company representatives, consortium partners, customer representatives, grant contacts, support contacts, and other individuals whose Personal Data is submitted to the Service by or for the Controller.

6. Categories of personal data

6.1. Categories may include names, business contact details, roles, titles, company affiliations, professional background, CV information, public business profiles, ownership information, UBO information, compliance information, sanctions or restricted-party indicators, communications, support content, uploaded files, Passport data, report data, grant-search data, usage data connected to Controller users, and other data submitted by or for the Controller.

7. Special-category and highly regulated data

7.1. The Services are not designed for special-category Personal Data, criminal-offence data, health data, biometric data, children's data, sensitive employee data, or highly regulated data.

7.2. The Controller must not submit such data unless expressly necessary for the permitted use of the Services, lawful under applicable law, authorised by the relevant data subject or rights holder where required, and covered by appropriate safeguards.

7.3. Grant Fund may reject, delete, quarantine, or restrict such data where it reasonably considers the data unnecessary, unlawful, excessive, risky, or inconsistent with the Services.

8. Processor obligations

8.1. Grant Fund will process Customer Personal Data only on documented instructions from the Controller unless required by Union, Member State, or other applicable law. If legally permitted, Grant Fund will inform the Controller of such legal requirement before Processing.

8.2. Grant Fund will ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations.

8.3. Grant Fund will implement appropriate technical and organisational measures taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of Processing, and risks to the rights and freedoms of natural persons.

8.4. Grant Fund will assist the Controller, taking into account the nature of Processing and information available to Grant Fund, with data-subject requests, security obligations, personal data breach notifications, data protection impact assessments, and prior consultations where required by applicable law.

8.5. Grant Fund will make available information necessary to demonstrate compliance with this DPA as described in Section 15.

9. Security measures

9.1. Grant Fund's security measures may include access controls, authentication controls, role-based permissions, encryption in transit where appropriate, hosting in the EU/EEA through Hetzner or other reputable EU/EEA infrastructure providers, logging, monitoring, backup procedures, least-privilege access, internal confidentiality obligations, vendor controls, incident response procedures, and security review of subprocessors.

9.2. Grant Fund may update security measures over time provided that such updates do not materially reduce the overall level of protection for Customer Personal Data.

9.3. The Controller remains responsible for secure user management, access permissions, credential security, lawful uploads, endpoint security, and internal access controls.

10. Subprocessors

10.1. The Controller authorises Grant Fund to engage subprocessors to provide hosting, storage, AI, infrastructure, payment, analytics, security, support, monitoring, compliance, communications, and other services necessary or useful for the Services.

10.2. Grant Fund will maintain a Subprocessor List identifying active, planned, or optional subprocessors and relevant service categories.

10.3. Grant Fund will impose data-protection obligations on subprocessors that are no less protective in substance than those required by Article 28 GDPR, taking into account the nature of the services provided.

10.4. Grant Fund remains responsible to the Controller for the performance of subprocessors' data-protection obligations to the extent required by GDPR.

11. Subprocessor change and objection mechanism

11.1. Grant Fund may add or replace subprocessors from time to time.

11.2. Grant Fund will provide notice of material subprocessor changes by website notice, dashboard notice, email, updated Subprocessor List, or other reasonable means. Unless a shorter period is required for security, compliance, emergency, or operational necessity, Grant Fund will aim to provide at least thirty (30) days' notice for material new subprocessors.

11.3. The Controller may object to a material new subprocessor on reasonable data-protection grounds by notifying Grant Fund within the notice period. The objection must describe the specific grounds.

11.4. Grant Fund may address the objection by providing additional information, implementing reasonable safeguards, using an alternative subprocessor where commercially reasonable, or allowing the Controller to terminate the affected Services in accordance with the Terms. Termination rights are limited to the affected Services and do not entitle the Controller to refunds except where required by the Terms or mandatory law.

12. International transfers

12.1. Grant Fund may transfer Customer Personal Data outside the EEA, United Kingdom, Switzerland, or other relevant jurisdiction where necessary for the Services, support, security, AI processing, payment, compliance, or other authorised Processing.

12.2. Where required, such transfers will rely on adequacy decisions, Standard Contractual Clauses, transfer-impact assessments, supplementary measures, derogations, or other lawful transfer mechanisms.

12.3. Where the EU Standard Contractual Clauses are required, the relevant modules will be deemed incorporated by reference as follows unless the parties execute them separately: Module Two for controller-to-processor transfers and Module Three for processor-to-subprocessor transfers, as applicable. The parties will complete Annexes with the information in this DPA, the Subprocessor List, and any applicable security documentation.

12.4. UK International Data Transfer Addendum and Swiss Addendum: [●]. Where required, the parties will execute or incorporate appropriate UK or Swiss transfer addenda.

13. Data-subject requests

13.1. Grant Fund will, taking into account the nature of Processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller's obligations to respond to data-subject requests.

13.2. If Grant Fund receives a data-subject request relating to Customer Personal Data, Grant Fund may redirect the request to the Controller or notify the Controller, unless prohibited by law.

13.3. Grant Fund is not responsible for responding directly to data-subject requests where the Controller is required to respond, except to the extent required by law or agreed in writing.

14. Personal data breach

14.1. Grant Fund will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

14.2. The notification will include information reasonably available to Grant Fund, which may include the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, measures taken or proposed, and contact point for further information.

14.3. Grant Fund's notification is not an acknowledgement of fault or liability.

14.4. The Controller remains responsible for determining whether regulatory or data-subject notification is required.

15. Audits and information

15.1. Grant Fund will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, certifications where available, third-party audit reports where available, subprocessors information, written responses, or other documentation.

15.2. Any audit must be reasonable, limited to what is required by GDPR, subject to confidentiality, and conducted in a way that does not compromise security, confidentiality, other customers' data, trade secrets, infrastructure integrity, or business operations.

15.3. On-site audits require prior written agreement, reasonable notice, scope limitations, appropriate confidentiality undertakings, and reimbursement of Grant Fund's reasonable costs unless prohibited by law.

15.4. The Controller may not conduct penetration tests, vulnerability scans, load tests, or security tests without Grant Fund's prior written consent.

16. Return and deletion

16.1. Upon termination or expiry of the Services, Grant Fund will return or delete Customer Personal Data in accordance with the Terms, Privacy Policy, Data Retention Summary, and this DPA.

16.2. Grant Fund may provide an archive downloadable for ninety (90) days where technically and legally possible.

16.3. After the archive period, Customer Personal Data will be deleted or anonymised unless longer retention is required or permitted for legal, tax, accounting, security, audit, dispute, compliance, anti-fraud, backup, legitimate business, or legal-defence reasons.

16.4. Backup copies may persist for a limited period in accordance with Grant Fund's backup and disaster-recovery procedures.

17. Controller obligations

17.1. The Controller represents and warrants that it has all rights, notices, consents, legal bases, authority, and instructions required for the lawful Processing of Customer Personal Data by Grant Fund.

17.2. The Controller must ensure that Customer Personal Data is accurate, current, relevant, not excessive, lawful, and suitable for Processing through the Services.

17.3. The Controller must not submit unlawful data, unauthorised third-party data, special-category data, export-controlled information, defence-related technical information, patent-critical disclosures, trade secrets, or confidential R&D materials unless lawful, authorised, necessary, and appropriately safeguarded.

18. Liability

18.1. Each party's liability under this DPA is subject to the limitations, exclusions, caps, and liability allocation in the Terms or other written agreement between the parties, except to the extent prohibited by applicable law.

18.2. This DPA does not expand Grant Fund's liability beyond the liability agreed in the Terms or applicable written agreement.

19. Order of precedence

19.1. In case of conflict between this DPA and the Terms, this DPA prevails only for processor-related data-processing terms to the extent required by applicable data-protection law.

19.2. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail to the extent of the conflict for the relevant transfer.

19.3. A signed written agreement between the parties prevails over this DPA only to the extent it expressly modifies this DPA and remains compliant with applicable data-protection law.

20. Contact

20.1. Data protection contact for Grant Fund: privacy@grant.fund.

Questions about your data?

For any privacy request or question, contact us at privacy@grant.fund.

Data Protection Officer / EU representative: Ivan Petrakov

Cookie preferences

We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies. You can change your choice anytime.