1. Subject matter and duration
Granex processes personal data solely to provide the contracted service (management of cases, clients, documents, deadlines, communications and AI features). Processing lasts for the term of the subscription and until data is returned or deleted.
2. Nature and purpose of processing
Hosting, organisation, retrieval, structuring, backup and processing of the information entered by the firm, including AI-assisted processing.
3. Categories of data subjects and data
Data subjects: the firm's clients, counterparties, contacts and the firm's own staff. Data: identification, contact, documentary, immigration data (NIE, passport, nationality) and, where strictly necessary for the legal matter, special categories.
4. Processor obligations
- Process data only on documented instructions from the Controller.
- Ensure confidentiality of authorised personnel, bound by a duty of secrecy.
- Apply the technical and organisational measures of Article 32 GDPR (encryption, multi-tenant isolation, access control).
- Assist the Controller in responding to data-subject rights and with the obligations in Articles 32–36 GDPR.
- Make available the information needed to demonstrate compliance and allow audits.
5. Subprocessors
The Controller authorises the subprocessors listed below. Granex imposes the same data-protection obligations on them and will give reasonable prior notice of any addition or replacement, which the Controller may object to on justified grounds.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Supabase (Ireland) Ltd | Database, authentication and storage | EU (Ireland / Frankfurt) | Within the EU |
| Vercel Inc. | Application hosting and delivery | EU (eu-west region) | Within the EU / SCCs |
| Anthropic PBC | Legal AI features (Claude) | USA | Standard Contractual Clauses (SCCs) |
| Resend Inc. | Transactional email | EU | Within the EU / SCCs |
| Stripe Payments Europe Ltd | Payment processing | EU (Ireland) | Within the EU |
6. International transfers
As a rule, data is hosted in the EU. Transfers to Anthropic (USA) for AI features rely on Standard Contractual Clauses approved by the European Commission, with supplementary measures. Content sent to the AI is not used to train models.
7. Personal data breaches
Granex will notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware of a breach affecting its data, providing the information the Controller needs to comply with Articles 33 and 34 GDPR.
8. Return and deletion
On termination, at the Controller's choice, Granex will return or delete personal data and existing copies within 90 days, unless legally required to retain them.
9. Signature
Accepting the Terms and Conditions or creating an account constitutes acceptance of this DPA. Firms requiring a countersigned DPA on their own letterhead may request one at dpo@granex.es.