Legal
Data Processing Agreement
Last updated: July 10, 2026
Contents
Definitions
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Sub-processor” have the meanings given in the EU General Data Protection Regulation (GDPR) and, where applicable, comparable US state privacy laws.
“Customer Personal Data” means personal data submitted to, stored in, or processed by GrydBase on behalf of a workspace — including contact, client, and lead records entered into the CRM, and content processed through GrydBase’s email, website, and AI features.
Roles of the parties
For Customer Personal Data, the workspace (Customer) is the data controller and Caleb Media Studio, LLC, operating GrydBase (“we,” “us”), is the data processor. We process Customer Personal Data only on Customer’s documented instructions, as given through use of the Service and this DPA, except where otherwise required by law.
If Customer has enabled white-label/reseller functionality, Customer may itself act as controller or processor for its own end customers, as described in Section 10 of the Privacy Policy.
Details of processing
- Subject matter: Provision of the GrydBase business management platform (CRM, email, websites, domains, billing, and AI assistance).
- Duration: For as long as Customer maintains an active workspace, plus any post-termination retention described in Section 10.
- Nature and purpose: Storage, retrieval, transmission, and display of Customer Personal Data to operate the Service as configured by Customer.
- Categories of data subjects: Customer's own personnel, clients, leads, and other contacts entered into the workspace.
- Categories of personal data: Name, email, phone, address, and other contact or business details Customer chooses to store; payment metadata (not raw card numbers, which we never receive); technical data such as IP address and session identifiers.
Confidentiality
We ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations, whether contractual or statutory.
Security measures
We implement the technical and organizational measures described in Section 12 of the Privacy Policy (encryption in transit, encrypted storage of sensitive values, row-level tenant isolation, session token rotation, and least-privilege access to service credentials), appropriate to the risk of the processing.
Sub-processors
Customer authorizes our use of the sub-processor categories listed in Section 5 of the Privacy Policy (database hosting and authentication, application hosting, payment processing, email delivery, AI inference, and domain registration/DNS). We impose data protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We will notify Customer of any new sub-processor category by email or workspace notification before it begins processing Customer Personal Data, and Customer may object on reasonable data protection grounds by contacting support@grydbase.com.
Data subject rights
Taking into account the nature of the processing, we will assist Customer, through the features of the Service and reasonable support requests, in responding to requests from data subjects to exercise their rights (access, correction, deletion, portability) under applicable law. Customer is responsible for responding to its own end customers’ requests; we provide the tools and support to make that possible.
Breach notification
We will notify Customer without undue delay after becoming aware of a breach affecting Customer Personal Data, and will provide the information reasonably available to us to help Customer meet its own notification obligations, consistent with Section 12 of the Privacy Policy.
International transfers
Our infrastructure providers may process data in the United States and other countries. Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, such transfers rely on Standard Contractual Clauses or an equivalent safeguard provided by the relevant sub-processor. Customers with specific cross-border transfer requirements should contact support@grydbase.com to discuss additional safeguards.
Return or deletion of data
On termination of the underlying agreement, we delete or anonymize Customer Personal Data in line with Sections 7 (retention) and 9 (deletion) of the Privacy Policy, except for records we are required by law to retain (e.g., billing records retained for tax purposes).
Audit rights
We will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including relevant sections of our sub-processors’ compliance documentation (e.g., SOC 2 reports) where we are permitted to share them. For anything beyond that, contact support@grydbase.com to discuss a mutually reasonable audit process.
Liability and term
This DPA is subject to the limitation of liability and governing law provisions in Sections 15 and 16 of the Terms of Service. It remains in effect for as long as we process Customer Personal Data on Customer’s behalf.
How this DPA applies to you
This DPA takes effect automatically alongside the Terms of Service for any workspace processing personal data through GrydBase — no separate signature is required for it to apply. If your organization needs a signed or countersigned copy for your own vendor-compliance records, email support@grydbase.com with your company details and we will send one for signature.