Griffinity

Legal

Data Processing Agreement

Draft terms for personal data Griffinity processes under a separately contracted organisational workshop or consulting engagement.

Last updated: 28 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Griffinity (“Processor”) and the organisational customer identified in a signed order form or statement of work (“Controller”), where Griffinity processes Personal Data on the Controller’s documented instructions for a separately contracted workshop or consulting engagement.

If you use Griffinity only as an individual learner registering yourself, Griffinity generally acts as an independent controller and this DPA does not apply—see the Privacy Policy instead.

1. Definitions

  • “Applicable Data Protection Law” means GDPR, UK GDPR, and any other privacy law that applies to the processing
  • “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings in Applicable Data Protection Law
  • “Services” means the separately contracted workshop, consulting, or related support described in the main agreement
  • “Sub-processor” means a third party engaged by Griffinity to process Personal Data on behalf of the Controller

2. Roles and scope

Controller determines the purposes and essential means of processing attendee, contact, and staff Personal Data it supplies. Processor processes such Personal Data only to administer and deliver the separately contracted Services and related support agreed in writing.

Annex-style details (subject matter, duration, nature, types of data, categories of data subjects) are deemed included as follows unless a custom schedule is attached:

  • Subject matter — delivery of the contracted AI governance, privacy workshop, consulting, or related support services
  • Duration — term of the Services plus deletion/return period in Section 10
  • Nature — collection, storage, communication, administration, and support needed to deliver the contracted engagement
  • Types of Personal Data — name, work email, organisation, role, attendance or engagement records, and support correspondence where provided; special-category data is not required and should not be submitted
  • Data subjects — Controller’s staff, contractors, workshop attendees, or business contacts included in the contracted engagement

3. Controller instructions

Processor will process Personal Data only on documented instructions from Controller (including via configuration of the Services and this DPA), unless required by law. If Processor believes an instruction infringes Applicable Data Protection Law, it will inform Controller without undue delay.

4. Confidentiality

Processor ensures persons authorised to process Personal Data are bound by confidentiality obligations and receive appropriate privacy/security awareness.

5. Security

Taking into account the state of the art, costs, and risk, Processor implements appropriate technical and organisational measures as summarised in /legal/security, including access control, encryption in transit, environment segregation where applicable, and logging. Controller is responsible for supplying accurate contact details and promptly correcting or withdrawing information it has provided.

6. Sub-processors

Controller authorises Processor to engage Sub-processors necessary to deliver the Services (hosting, auth, email, payments, media delivery). Processor will impose data-protection obligations no less protective than this DPA. A current illustrative list includes managed cloud database/auth hosts, email providers, payment processors, and media/CMS hosts. Processor will provide an updated list on written request and will give reasonable notice of material Sub-processor changes where required by law, allowing Controller to object on reasonable data-protection grounds.

7. International transfers

Where Personal Data is transferred internationally, Processor will ensure an appropriate transfer mechanism under Applicable Data Protection Law (e.g. adequacy, SCCs / UK IDTA) is in place with relevant Sub-processors.

8. Assistance to Controller

Taking into account the nature of processing, Processor will assist Controller by appropriate technical and organisational measures, insofar as possible, for:

  • Responding to Data Subject requests
  • Security and DPIA-related information reasonably available to Processor
  • Breach notification as set out below
  • Demonstrating compliance with this DPA via reasonable information and, where agreed, audits

Audits: Controller may request information necessary to demonstrate compliance. On-site or invasive audits require reasonable notice, are limited to once per 12 months unless a Breach or regulatory demand requires more, and must not compromise other customers’ security. Processor may satisfy audit rights via reputable third-party reports (e.g. SOC 2 / ISO summaries from infrastructure providers) where available.

9. Personal Data Breaches

Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data, and will provide information reasonably available to help Controller meet its own notification duties. Processor’s notification is not an admission of fault.

10. Return and deletion

Upon termination of the Services or on Controller’s written request, Processor will delete or return Personal Data (at Controller’s choice, where technically feasible), except where retention is required by law or needed for dispute resolution, security logs, or backups that expire on a rolling schedule. Certificate verification records may be retained in minimised form if needed to prevent fraud.

11. Liability

Liability under this DPA is subject to the limitations and exclusions in the main Terms or SOW, except where Applicable Data Protection Law prohibits such limitation.

12. Order of precedence

If this DPA conflicts with the Terms regarding data protection for Processor activities, this DPA prevails. Custom schedules signed by both parties prevail over this standard DPA.

13. Contact

Privacy / DPA contact: hello@griffinity.com