Legal document

Data Processing Agreement (DPA)

Last updated: July 2026

This Data Processing Agreement (DPA) forms part of the Terms and Conditions and governs the processing of personal data that Granex carries out on behalf of the firm, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). The firm acts as Controller and Granex as Processor.

01

1. Subject matter and duration

Granex processes personal data solely to provide the contracted service (management of cases, clients, documents, deadlines, communications and AI features). Processing lasts for the term of the subscription and until data is returned or deleted.

02

2. Nature and purpose of processing

Hosting, organisation, retrieval, structuring, backup and processing of the information entered by the firm, including AI-assisted processing.

03

3. Categories of data subjects and data

Data subjects: the firm's clients, counterparties, contacts and the firm's own staff. Data: identification, contact, documentary, immigration data (NIE, passport, nationality) and, where strictly necessary for the legal matter, special categories.

04

4. Processor obligations

  • Process data only on documented instructions from the Controller.
  • Ensure confidentiality of authorised personnel, bound by a duty of secrecy.
  • Apply the technical and organisational measures of Article 32 GDPR (encryption, multi-tenant isolation, access control).
  • Assist the Controller in responding to data-subject rights and with the obligations in Articles 32–36 GDPR.
  • Make available the information needed to demonstrate compliance and allow audits.
05

5. Subprocessors

The Controller authorises the subprocessors listed below. Granex imposes the same data-protection obligations on them and will give reasonable prior notice of any addition or replacement, which the Controller may object to on justified grounds.

SubprocessorPurposeLocationTransfer safeguard
Supabase (Ireland) LtdDatabase, authentication and storageEU (Ireland / Frankfurt)Within the EU
Vercel Inc.Application hosting and deliveryEU (eu-west region)Within the EU / SCCs
Anthropic PBCLegal AI features (Claude)USAStandard Contractual Clauses (SCCs)
Resend Inc.Transactional emailEUWithin the EU / SCCs
Stripe Payments Europe LtdPayment processingEU (Ireland)Within the EU
06

6. International transfers

As a rule, data is hosted in the EU. Transfers to Anthropic (USA) for AI features rely on Standard Contractual Clauses approved by the European Commission, with supplementary measures. Content sent to the AI is not used to train models.

07

7. Personal data breaches

Granex will notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware of a breach affecting its data, providing the information the Controller needs to comply with Articles 33 and 34 GDPR.

08

8. Return and deletion

On termination, at the Controller's choice, Granex will return or delete personal data and existing copies within 90 days, unless legally required to retain them.

09

9. Signature

Accepting the Terms and Conditions or creating an account constitutes acceptance of this DPA. Firms requiring a countersigned DPA on their own letterhead may request one at dpo@granex.es.

Data Processing Agreement (DPA) | Granex