Legal

Data Processing Addendum Overview

An overview of processing roles, safeguards, and enterprise DPA terms for cloud customers.

Effective July 20, 2026Last updated July 20, 2026Grabr, operated by an individual in Bangladesh

1. Status of this document

This Data Processing Addendum (“DPA”) overview describes the terms Grabr intends to apply when it processes Customer Personal Data on behalf of a cloud customer. It is a public overview/template. It becomes binding only when incorporated into a signed order, enterprise agreement, or written acceptance between the parties. It is not a signed DPA by itself.

2. Roles

Customer is the organization or individual that owns the Grabr workspace and determines the purposes of Customer Content processing.

Grabr / Provider (Grabr, operated by an individual in Bangladesh) processes Customer Personal Data to provide the cloud service.

Self-hosted deployments are outside this DPA unless separately agreed; the self-host operator is generally the controller for that instance.

3. Processing instructions

Grabr will process Customer Personal Data only to provide the service, on documented instructions from Customer (including configuration and connected integrations), and as required by law. If a legal requirement prevents following an instruction, Grabr will notify Customer unless legally prohibited.

4. Confidentiality and personnel

Grabr will ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate guidance for handling personal data.

5. Security

Grabr will implement appropriate technical and organizational measures as described in the Security Overview, including encryption of connected-account secrets at rest, access controls, and transport security for production traffic.

6. Subprocessors

Customer authorizes Grabr to engage subprocessors listed at /legal/subprocessors. Grabr remains responsible for subprocessors’ performance to the extent required by applicable law and any signed DPA.

7. International transfers

Customer acknowledges that processing may occur outside Bangladesh through subprocessors. The parties will cooperate in good faith on transfer safeguards required by applicable law for enterprise arrangements.

8. Assistance

Taking into account the nature of processing, Grabr will provide reasonable assistance with data-subject requests, security incidents affecting Customer Personal Data, and information needed for Customer’s compliance assessments, subject to confidentiality and reasonable cost recovery for disproportionate requests.

9. Security incidents

Grabr will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data in the cloud service, and will provide information reasonably available to help Customer meet legal obligations.

10. Return and deletion

Upon termination of cloud services, Customer may export available content through product features where offered. Grabr will delete or de-identify Customer Personal Data within a commercially reasonable period after a validated deletion request or account closure, except where retention is required by law or needed for secure backups, dispute resolution, or fraud prevention. Some deletions are currently handled manually rather than through a fully automated self-serve erasure flow.

11. Audits

Upon reasonable written request no more than once annually year (unless a breach or regulatory requirement justifies more), Grabr will provide available security information or summaries reasonably necessary to demonstrate compliance. On-site audits require mutual agreement on scope, timing, confidentiality, and cost.

12. Liability and contact

Liability under a signed DPA is subject to the limitations in the Terms unless a superseding enterprise agreement states otherwise.

To request an executable DPA package, email supportgrabber@gmail.com with your legal entity name and workspace details.

Related documents

  • Privacy PolicyHow Grabr collects, uses, stores, and shares personal data for cloud and self-hosted deployments.
  • Terms and ConditionsThe rules that govern your use of the Grabr website, cloud service, and related features.
  • SubprocessorsThird-party services that may process data to help operate the Grabr cloud service.
  • Security OverviewFactual security controls used by Grabr, customer responsibilities, and how to report issues.