grydor Trust center

Data Processing Addendum

Controller and processor terms for personal data handled through Grydor.

This Data Processing Addendum forms part of the agreement between the customer as controller and the Grydor contracting entity as processor when Grydor processes Customer Personal Data on the customer’s behalf.

1. Scope and instructions

Grydor processes Customer Personal Data only to provide, secure, maintain, and support the service, comply with documented customer instructions, and meet applicable law. The agreement, administrator configuration, signed API requests, and support instructions are documented instructions. Grydor will notify the customer if an instruction appears to violate applicable data-protection law unless prohibited from doing so.

2. Processing details

  • Subject matter: unified endpoint enrollment, inventory, policy, software, query, support, audit, and related administration.
  • Duration: the subscription term plus the return, deletion, backup, and legally required retention periods.
  • Data subjects: customer administrators, personnel, contractors, device users, directory contacts, support contacts, and other people represented in customer-configured data.
  • Data: identity and organization records, device and software inventory, network identifiers, management and security state, task and policy evidence, customer-selected query results, audit events, and support material.
  • Purpose: operating the contracted service and executing the customer’s authorized device-management instructions.
  • Sensitive data: not required by default. Customers must not intentionally submit special-category data, highly sensitive government identifiers, health data, payment-card data, private communications, or unrestricted file contents unless a signed Order Form expressly authorizes the category and safeguards.

3. Confidentiality and personnel

Grydor limits access to personnel and contractors who need it to perform assigned duties, binds them to confidentiality, provides security training appropriate to their role, and removes access when no longer required.

4. Security

Grydor maintains risk-appropriate technical and organizational measures, including tenant isolation, least-privilege authorization, strong administrator authentication, signed device requests, encryption in transit, protected secret storage, audit evidence, secure development controls, backup and recovery procedures, vulnerability handling, and incident response. Current details are in Security and incident response. Grydor may update controls without materially reducing overall protection.

5. Subprocessors

The customer gives general authorization to use the providers listed on the Subprocessors page. Grydor contractually requires each subprocessor to protect Customer Personal Data consistently with this DPA. Grydor remains responsible for its processor obligations. Material new subprocessors receive at least 30 days’ notice where required. A customer may object on reasonable data-protection grounds during that period; the parties will seek a practical alternative, and either party may terminate the affected service if none is available.

6. Data-subject requests

Taking account of the nature of processing, Grydor provides reasonable assistance for access, correction, deletion, restriction, portability, objection, and consent-withdrawal requests. If Grydor receives a request concerning Customer Personal Data, it will direct the requester to the customer unless legally prohibited. The customer remains responsible for the response and lawful decision.

7. Security incidents

Grydor will notify the customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. The initial notice will describe known scope, affected data and people, likely consequences, containment, and a contact point, with supplemental information as investigation continues. Grydor will preserve appropriate evidence, mitigate harm, and reasonably assist the customer’s legal notifications. Grydor does not notify affected people on the customer’s behalf unless instructed or legally required.

8. DPIAs, regulators, and audits

Grydor supplies information reasonably necessary for the customer’s data-protection impact assessment and regulatory consultation concerning the service. Once per year, and additionally after a material incident or regulator request, the customer may request current independent reports or a scoped audit. Audits require reasonable notice, confidentiality, non-disruption, qualified auditors, and avoidance of access to another customer’s data. The customer bears costs unless the audit identifies a material Grydor breach.

9. Return and deletion

During the subscription, the customer may export supported data using documented service functions. On termination or written instruction, Grydor returns or deletes Customer Personal Data unless law requires retention. Live-system deletion is targeted within 30 days and backup expiry within 90 days. Grydor may retain isolated evidence required for security, billing disputes, or legal claims and will protect it from ordinary use.

10. International transfers

The service region and data locations are recorded in the Order Form and subprocessor list. If a restricted transfer requires safeguards, the parties incorporate the applicable European Commission Standard Contractual Clauses or another valid mechanism, complete the required annexes, and document supplementary measures. The signed transfer terms control over inconsistent public language.

11. Customer duties

The customer provides lawful instructions, limits collection to what is necessary, gives required notices, manages authorization, configures retention, evaluates high-risk monitoring, and ensures that use of scripts, queries, directory data, and device controls complies with applicable law. The customer must not instruct Grydor to weaken tenant isolation, audit integrity, or secret protection.

12. Priority and execution

This DPA controls over conflicting service terms for Customer Personal Data. The parties, contact details, competent authority, governing terms, transfer module, security annex, and any sector-specific requirements must be completed in the signed Order Form or DPA signature page. Publishing this reference text alone does not execute a DPA for an unidentified party.

On this page