Data Processing Agreement
Version 1.1 · Effective 17 August 2026 (replaces version 1.0 of 11 August 2026; the processor is Viresta AS, a Norwegian company)
Who needs this. If you use GrantWise purely for your own proposal, you do not need this agreement — the Privacy Policy covers you and we are the controller.
This agreement applies when you use GrantWise in the course of your business on behalf of someone else — a consultant reviewing a client's proposal, an accelerator reviewing a portfolio company's application, a university office acting for a research group. In that case you are the controller of any personal data in the documents you upload, and GrantWise is your processor.
1. Parties
| Processor | Viresta AS, organization number 224 664 729, Lokaltunet 18, 1626 Manstad, Norway, trading as GrantWise ("GrantWise", "we"). Responsible person: Samina Shams. Contact: [email protected]. |
|---|---|
| Establishment and supervisory authority | Viresta AS is established in Norway, within the EEA, and is subject to the GDPR as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven). Its supervisory authority is Datatilsynet, the Norwegian Data Protection Authority. No representative under GDPR Article 27 is required. |
| Controller | The business customer that accepts these terms and uploads documents ("Customer", "you"). Where a signed copy is executed, the Customer's legal name and address are as stated on the signature page. |
This agreement supplements and forms part of the GrantWise Terms of Service (the "Principal Agreement"). Where they conflict on the processing of personal data, this agreement prevails. It takes effect when you first use the service in the capacity described above, whether or not a copy is signed.
2. Subject matter and duration
Subject matter. Automated pre-submission quality assessment of funding proposals, and delivery of the resulting report.
Duration. For the term of the Principal Agreement, and for each individual review only for as long as that review requires. Processing of an uploaded document ends when the review of it is complete.
3. Nature and purpose of processing
We receive a proposal document and supporting material, extract its text in memory, submit that text to a large language model for inference, generate a report, and deliver the report to the email address you supply. We process personal data only to provide that service, to secure it, to bill for it, and to meet legal obligations.
4. Categories of data subject
- Individuals named in the uploaded proposal or annexes — typically project team members, principal investigators, company officers and partner contacts.
- The individual submitting the review and receiving the report.
5. Types of personal data
- Names, job titles, professional affiliations, qualifications, biographies and CV content appearing in the uploaded documents.
- Professional contact details appearing in the uploaded documents.
- The submitting person's email address, chosen programme, optional project acronym, and optional organisation type and country.
- Technical data required to operate and secure the service, such as IP address and request timestamps.
Special category data. The service is not designed for and must not be used to process special categories of personal data under Article 9 GDPR, or personal data relating to criminal convictions. You must not upload documents containing such data. GrantWise does not knowingly process it.
6. Our obligations as processor
- Documented instructions. We process personal data only on your documented instructions. Your instruction is your use of the service: to run the review you request on the documents you upload. We will tell you if we believe an instruction infringes data protection law. If we are required by law to process beyond your instructions, we will inform you first unless the law forbids it.
- No training. We do not use your documents, their content, or the resulting reports to train, fine-tune or improve any machine learning model, and our AI provider is contractually bound not to do so with data submitted through the enterprise interface we use.
- Confidentiality. Every person authorised to process personal data under this agreement is bound by an obligation of confidentiality.
- Security. We implement the measures in Annex 2.
- Subprocessors. As set out in section 8.
- Assistance with data subject rights. If a data subject contacts us directly about data we process for you, we will not respond substantively; we will refer them to you and notify you without undue delay. Given that uploaded documents are not retained, our practical ability to assist is limited to confirming that no copy exists — which is usually a complete answer.
- Assistance with your obligations. Taking into account the nature of processing and the information available to us, we will assist you with data protection impact assessments, prior consultation and security obligations under Articles 32 to 36 GDPR.
- Breach notification. We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you, with the information available to us at that time and updates as investigation proceeds.
- Deletion or return. On termination, and at your choice, we delete or return personal data processed for you, and delete existing copies unless law requires retention. Because uploaded documents are not stored, this is limited in practice to generated reports and account correspondence.
- Audit. We make available the information necessary to demonstrate compliance with this agreement, and allow and contribute to audits, including inspections, by you or an auditor you mandate. Audits are on reasonable notice, no more than once in any twelve-month period unless a breach has occurred or a supervisory authority requires it, during business hours, subject to confidentiality, and at your cost. We may satisfy an audit request by providing our subprocessors' current certifications and reports where these address the request.
7. Your obligations as controller
- You warrant that you have a lawful basis for the processing you instruct, and that you have provided the required transparency information to the individuals whose personal data appears in the documents you upload.
- You warrant that you are entitled to disclose those documents to us, and that doing so does not breach any confidentiality obligation, consortium agreement, non-disclosure agreement or third-party right.
- You must not upload special category data, criminal-offence data, or personal data of children.
- You are responsible for the accuracy of the email address you supply. Reports are delivered to that address, and a wrong address is a disclosure we cannot recall.
8. Subprocessors
You give general written authorisation for us to engage the subprocessors listed below. We impose data protection obligations on each subprocessor that are no less protective than those in this agreement, and we remain fully liable to you for their performance.
| Subprocessor | Purpose | Processing location |
|---|---|---|
| Google Cloud / Vertex AI (Google Ireland Ltd / Google LLC) | AI inference; temporary report storage in Firestore | EU (europe-west1 and EU multi-region) |
| Cloudflare, Inc. | Website delivery, DNS, security and DDoS protection | Global edge network |
| Resend (Plus Five Five, Inc.) | Transactional email delivery of reports and reminders | United States |
| Stripe, Inc. / Stripe Payments Europe Ltd | Payment processing. Stripe acts as an independent controller for payment data; we never receive card details. | EU and United States |
Not a subprocessor: website analytics. We use PostHog (PostHog Cloud EU, Frankfurt) for analytics on grantwise360.com, loaded only for visitors who accept analytics in our cookie banner. PostHog is not a subprocessor under this agreement, because it never receives Customer Data: no uploaded document, no document content, no report, no file name and no proposal-derived personal data is sent to it. It processes website visitor data for which GrantWise is the controller in its own right, described in section 6 of our Privacy Policy. It is named here so that the boundary is explicit rather than assumed. If that ever changes, it becomes a subprocessor and the notice period below applies.
Changes. We will give you at least 30 days' notice before adding or replacing a subprocessor, by email to the address associated with your use of the service and by updating this page. If you reasonably object on data protection grounds within that period, you may terminate the Principal Agreement without penalty and receive a pro-rata refund of any prepaid amount for services not yet delivered. To receive notice by email, subscribe at [email protected].
9. International transfers
Viresta AS is established in Norway, within the EEA. Our own processing takes place in Norway, and AI inference and temporary report storage take place in EU regions. Where you are established in the EEA, your disclosure of personal data to us is therefore not a transfer to a third country and needs no transfer mechanism.
Onward transfers do occur at the subprocessor layer: email delivery and parts of payment processing involve transfer to the United States. For those transfers we act as exporter and rely on one or more of: an adequacy decision; the EU–US Data Privacy Framework where the recipient is certified; or the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914, which apply in Norway through the EEA Agreement.
Where the Standard Contractual Clauses nonetheless apply between you and us — for example where you are established outside the EEA and the Clauses are the agreed mechanism — Module Two (controller to processor) is incorporated into this agreement by reference and completed as follows: clause 7 (docking) applies; clause 9 option 2 (general written authorisation) applies with the 30-day notice period in section 8; clause 11 does not include the optional independent dispute resolution body; clause 17 selects the law of Ireland; clause 18(b) selects the courts of Ireland. Ireland is selected because clause 17 requires the law of an EU Member State and Norway, as an EEA state, does not qualify; this choice governs the Clauses only and does not displace the Norwegian governing law in section 11. Annexes I, II and III of the Clauses are populated by sections 2 to 5, Annex 2 and section 8 of this agreement respectively.
We carry out transfer impact assessments where required and will inform you if we become unable to comply with the Clauses.
10. Liability and term
Each party's liability under this agreement is subject to the limitations and exclusions in the Principal Agreement, except where a limitation is not permitted by applicable data protection law. This agreement terminates automatically when the Principal Agreement ends, save for provisions that by their nature survive.
11. Governing law
This agreement is governed by Norwegian law, in line with the Principal Agreement, and the agreed venue is Søndre Østfold tingrett. Where the Standard Contractual Clauses apply, the law specified in section 9 governs those Clauses instead, and nothing in this agreement limits the rights of data subjects under them or under the GDPR as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven).
Annex 1 — Processing summary
| Subject matter | Automated pre-submission assessment of funding proposals |
|---|---|
| Duration | Term of the Principal Agreement; per document, only for the duration of the review |
| Nature and purpose | Text extraction, AI inference, report generation, report delivery |
| Personal data | As listed in section 5 |
| Data subjects | As listed in section 4 |
| Retention | Uploaded documents: not stored. Generated report and delivery email: up to 7 days. Version registry: scores, non-reversible fingerprints and short finding summaries, containing no proposal text. Payment records: as required by law. |
Annex 2 — Technical and organisational measures
- Data minimisation by architecture. Uploaded documents are held in memory for the duration of the review and are never written to a document database or object store. This is the primary security control: data that is not stored cannot be breached, exfiltrated or wrongly retained.
- Encryption. TLS for all data in transit. Encryption at rest for the temporary report store and all subprocessor storage.
- Access control. Least-privilege service accounts per service. Credentials held in a managed secret store, never in source code or configuration files. Administrative endpoints require a separate access token.
- Regional processing. AI inference and temporary report storage are configured to EU regions.
- Retention limits enforced in code. Generated reports carry an expiry timestamp and are deleted automatically; retention is not left to manual housekeeping.
- Content-redacted logging. Operational logs record timing, status, error category and cost. Proposal text, report text, evidence quotations and prompt bodies are excluded from logs by design.
- Input validation. File type and size validation before extraction; limits on decompressed size and parse time to resist archive-bomb and resource-exhaustion attacks.
- Rate limiting and abuse controls on public endpoints.
- Segregation. Analytics and benchmark records are irreversibly separated from identity and contain no proposal or report text.
- Change control. Continuous integration runs the full test suite, including a booted-server smoke test, on every change before deployment.
- Resilience. Managed, replicated cloud infrastructure with provider-level redundancy. Because customer documents are not retained, there is no customer-document backup to restore or to leak.
- Personnel. Access limited to personnel who need it, each under a confidentiality obligation.
Signature
This agreement is effective without signature when you use the service in the capacity described above. If your procurement process requires a signed copy, download the PDF, complete and sign the controller block, and send it to [email protected]. We will return a countersigned copy.
Questions: [email protected] · Terms of Service · Privacy Policy · Legal Notice