1. Definitions
- “Affiliate” means an entity that directly or indirectly controls, is controlled by or is under common control with an entity, where ‘control’ means, for the purposes of this definition, an ownership, voting, or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question.
- “Agreement” means any standard terms, order forms, services agreements, platform terms, developer terms, our Terms of Use, our Privacy Policy, or other agreement by which Customer may receive services from Granola (“Agreement”).
- “Applicable AI Laws” means any applicable laws or regulations governing the development, deployment, provision or use of artificial intelligence systems, including, where applicable, Regulation (EU) 2024/1689 (“EU Artificial Intelligence Act” or “EU AI Act”), as amended from time to time.
- “Controller” means the natural or legal person, public authority, agency, or any other body which alone or jointly with others determines the purposes and means of Processing of Personal Data.
- “Customer Data” means any data provided or made available by or on behalf of Customer to Granola in connection with Customer’s use of the Services.
-
“Data Protection Laws” means all applicable laws and regulations, as amended, supplemented or replaced from time to time, in relevant jurisdictions relating to the Processing of Personal Data, including:
- “GDPR” meaning Regulation (EU) 2016/679 of the European Parliament and of the Council, known as the General Data Protection Regulation;
- “UK GDPR” meaning the GDPR as incorporated into UK law under section 3 of the European Union (Withdrawal) Act 2018, the UK Data Protection Act 2018, and the Data Protection, Privacy and Electronic Communications Regulations 2019 and 2020;
- “FADP” meaning the Swiss Federal Act on Data Protection;
- “CCPA” meaning the California Consumer Privacy Act of 2018, Cal. Civ. Code §1798.100 et seq. (“CCPA”), as amended by the California Privacy Rights Act of 2020 (“CPRA”).
- “Data Subject” means an identified or identifiable natural person to whom Personal Data relates and further includes the definitions of ‘Individual’ or ‘Consumer’ under applicable laws and regulations.
- “Granola” means Granola, Inc., Granola Labs Ltd., and their Affiliate companies subject to an intercompany agreement between such entities that may engage or assist in the performance of the Services and the Processing of Personal Data.
- “Personal Data” means (i) any data or information relating to an identified or identifiable living individual, including information that can be linked, directly or indirectly, with a particular Data Subject or (ii) is otherwise ‘personal information,’ ‘personally identifiable information,’ or similarly defined information under the applicable Data Protection Laws. As used herein, unless designated otherwise, it shall refer to the Personal Data provided by a Customer or an authorized User in relation to the Services.
- “Process,” “Processing,” or “Processed” means any operation or set of operations which is performed upon Customer Data, including Personal Data, whether or not by automated means, according to the definitions given to such terms in applicable Data Protection Laws.
- “Processor” means any natural or legal person, public authority, agency, or any other body which Processes Personal Data on behalf of a Controller or on the instruction of another Processor acting on behalf of a Controller.
- “Security Incident” means a reasonably suspected or actual compromise of Granola’s security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to Customer Data, including Personal Data, transmitted, stored or otherwise Processed by Granola under the Agreement.
- “Services” means all services provided by Granola in accordance with, and as defined in, the Agreement.
-
“Standard Contractual Clauses” means the Standard Contractual Clauses, as may be amended, superseded, or replaced, for the transfer of Personal Data to third countries pursuant to:
- Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”);
- The “International Data Transfer Addendum to the EU Commission Standard Contractual Clauses” issued by the Information Commissioner under §119.A(1) of the Data Protection Act 2018 (“UK Addendum”); and
- The applicable standard data protection clauses issued, approved or otherwise recognized under FADP (“Swiss SCCs”).
- “Subprocessor” means any subcontractor engaged in the Processing of Personal Data in connection with the Services.
- “Supervisory Authority” means any regulatory, supervisory, governmental, or other competent authority with jurisdiction or oversight over compliance with the Data Protection Laws.
- “Users” means all individuals using the Services as a Customer or as a user authorized by a Customer to use the Services.
2. Roles of the Parties
- The Customer acts as the Controller of Customer Data, including Personal Data. The Customer is responsible for getting all required permissions and approvals to collect, use, share, store, and process Personal Data so Granola can provide the Services in accordance with the Agreement and Customer’s instructions.
- Granola acts as the Processor when Processing Personal Data as needed to provide the Services under the Agreement. Granola is a Processor unless it is acting as a limited Controller for the specific purposes listed in Section 3.
3. Data Processing
A. Customer Instructed Processing by Granola.- Where the Services include artificial intelligence or machine learning functionality, Granola may Process Customer Personal Data as necessary to provide, maintain, secure, support, and improve such functionality in accordance with Customer’s documented instructions, the Agreement, and this DPA.
- Granola will promptly notify Customer if, in Granola’s reasonable opinion, any instruction violates applicable Data Protection Laws or a supervisory authority’s direction.
- Granola may also Process Personal Data as required by applicable Data Protection Laws or a Supervisory Authority. Where legally permitted, Granola will notify Customer before carrying out any Processing required by law that is not based on Customer’s instructions.
- Granola will Process Personal Data for the duration of the Services. This DPA will terminate once Granola no longer Processes Personal Data on Customer’s behalf.
- Granola may Process System Data (as defined in the Agreement) as an independent controller, and not as a joint controller with Customer, to the extent permitted by applicable Data Protection Laws and the Agreement.
- Such Processing may include: (i) managing Granola’s relationship with Customer and authorized Users; (ii) operating Granola’s business, including accounting, audits, tax reporting, and compliance; (iii) monitoring, preventing, investigating, and detecting fraud, security incidents, misuse of the Services, and harm to Customers or Users; (iv) performing identity verification; (v) complying with legal or regulatory obligations applicable to Granola; and (vi) providing, maintaining, supporting, improving, and optimizing the Services.
- Granola’s Processing as an independent controller will be governed by its Privacy Policy available at https://go.granola.so/privacy.
- Customer is solely responsible for the legality, accuracy, and quality of the Personal Data it provides, the means by which such Personal Data is collected, and the instructions given to Granola regarding Processing.
- Customer represents and warrants that its instructions to Granola and its use of the Services will comply with applicable Data Protection Laws and not cause Granola to violate such laws.
- Any instructions outside of the Agreement or this DPA must be agreed to in writing by the parties and may be subject to additional fees.
- Granola is not responsible for determining what laws or regulations are applicable to Customer or their authorized Users.
- Granola will inform Customer if it knows or reasonably believes that any instructions violate the Agreement or any applicable law or regulation. Granola may refuse to comply with any instruction that in Granola’s discretion violates the Agreement or any applicable law or regulation.
-
Granola will not sell, disclose, provide, or share Personal Data except:
- As instructed by the Customer;
- In accordance with the Agreement, our Privacy Policy and this DPA; or
- As required by law.
- Granola will not retain, use, disclose, or combine Personal Data outside of its direct business relationship with Customer except as necessary to provide the Services, for legitimate business purposes on Customer’s behalf, as permitted by the Agreement, as permitted by our Privacy Policy, or as required by applicable Data Protection Laws.
- Granola may disclose Customer Data to the extent such data is required to be disclosed by law, by any government or regulatory authority, or by a valid and binding order of a law enforcement agency (such as a subpoena or court order), or other authority of competent jurisdiction.
- Granola will not disclose or provide access to any Customer Personal Data to any law enforcement agency, governmental entity, or regulatory authority unless required by law, by binding order of an enforcement agency, or compelled by legal process. Granola will attempt to redirect the law enforcement agency, government or regulatory authority directly to Customer.
- Where permitted, Granola will give Customer reasonable notice of demand for access or disclosure of Customer Data to allow Customer to seek a protective order or other appropriate remedy.
- Customer may, at its sole discretion, elect in the Services to permit third parties to access, view, share, download or otherwise act upon Customer Data.
- Granola may share Customer Data or make it available to third parties where permitted by the Agreement or as instructed by Customer or Users through the Services.
- Customer, including any authorized User, will not provide Personal Data that is inappropriate for the nature of the Services or that violates the Agreement and will indemnify Granola for any claims or losses arising from Customer’s sharing of data with third parties.
4. Subprocessing
- Customer acknowledges that Granola may engage third-party Subprocessors, or may use its Affiliates as Subprocessors, to perform the Services. Customer hereby gives its authorization and consent to Granola to use the Subprocessors listed on the Subprocessor list (“List”) to Process Personal Data.
- Granola will enter into and maintain written agreements with each Subprocessor that include data protection obligations no less protective than those in this DPA. Granola remains responsible for the acts and omissions of its Subprocessors to the same extent as if Granola were directly performing the relevant Services.
- Granola’s List of current authorized Subprocessors is provided at trust.granola.ai/subprocessors. Granola may update the List from time to time to notify Customer of any addition, removal, modification, or replacement of a Subprocessor. Granola will provide Customer with at least ten (10) days’ prior notice before adding or replacing a Subprocessor by updating the List and may use additional reasonable methods, such as using the provided Customer contact information or via the Granola website or the Services, to provide notice of such changes to Customer.
- Customer may object to Granola’s use of a new Subprocessor by providing written notice of reasonable objection within thirty (30) days of the List publication (“Notice Period”). If Customer does not object within the Notice Period, the updated List is deemed accepted.
- If Customer objects within the Notice Period to a new Subprocessor, Customer must provide such objection in writing to Granola and include information regarding its reasonable data protection grounds for the objection. Granola will review the objection and use commercially reasonable efforts to address Customer’s concerns.
- Customer acknowledges that certain Subprocessors are necessary to provide the Services and that an objection may limit Granola’s ability to provide some or all features of the Services.
- If Granola is unable to provide a suitable replacement Subprocessor, Customer may terminate the Agreement with respect to the affected Services without penalty by providing written notice to Granola setting forth Customer’s reasonable grounds for objecting to the original Subprocessor and explaining why the proposed replacement Subprocessor is not suitable.
5. Data Subject Rights and Requests
- Customer is responsible for responding to Data Subject requests for the Customer Data that it controls. Granola will provide reasonable assistance, upon Customer’s reasonable request and to the extent required by applicable Data Protection Laws, to enable Customer to respond to Data Subject requests regarding Personal Data Processed under the Agreement.
- To the extent legally permitted, Granola will promptly notify Customer if it receives a request regarding the exercise of a Data Subject’s right of access, right to rectification, restriction of Processing, erasure (i.e., “right to be forgotten”), data portability, objection to Processing, or its right not to be subject to an automated individual decision making, or any other request to exercise rights granted by Data Protection Laws (with each such request being a “Data Subject Request”).
- If Granola receives a Data Subject Request in relation to Personal Data, Granola will advise the Data Subject to submit and/or also submit their request to Customer. Granola will not respond to a Data Subject Request except on Customer’s documented instructions or as required by law.
- To the extent legally permitted, Granola will assist Customer or its authorized User with the fulfillment of a valid Data Subject Request where Customer requires assistance from Granola in order to respond. Customer is responsible to the extent legally permitted for any costs and expenses incurred by Granola in providing such assistance.
6. Compliance with Laws
- Each Party will comply with the applicable Data Protection Laws and where relevant the Applicable AI Laws in connection with the Services.
- Customer is responsible for determining what laws apply to its business and whether the Services meet its legal requirements. Customer represents and warrants that it has complied and will continue to comply with applicable Data Protection Laws in its collection, use, storage, transfer and sharing of Customer Data, including Customer Personal Data, and that it has provided all required notices and obtained all necessary rights, permission, and consents for Granola to Process Personal Data as described in the Agreement and this DPA.
- Customer is solely responsible for the accuracy, quality, and legality of Personal Data it collects and provides to Granola, and the use of such in the Services, including any accounts or content created or managed through the Services.
- If required by applicable Data Protection Laws, Granola will provide reasonable information and assistance to help Customer complete data protection impact assessments or respond to Supervisory Authorities. Granola may satisfy this obligation by providing information in the Agreement and this DPA and may charge Customer for reasonable additional assistance if needed.
7. Data Transfers
A.- Customer appoints Granola to transfer Customer Personal Data to the United States or any other country in which Granola, or its Subprocessors, operate, store, and process Customer Personal Data to provide the Services in accordance with the provisions of this DPA.
- Granola may transfer and process Customer Personal Data to and within the United States, to and within the European Union, as constituted pursuant to the Treaty on European Union, as amended from time to time (“EU”), the European Economic Area pursuant to the Agreement on the European Economic Area, as amended from time to time (“EEA”), the United Kingdom (“UK”), and Switzerland, as well as to third-party countries and to Subprocessors, Affiliates, or our professional advisors. Granola will ensure that such transfers are made in compliance with applicable Data Protection Laws and this DPA.
- Any transfer of Customer Personal Data subject to this DPA from member states of the EU, EEA, the UK or Switzerland, to any countries where the relevant authorities have not decided that the third country or more specified sectors within that third country ensures an adequate level of protection, will be made through the relevant Standard Contractual Clauses (“SCCs”).
-
Controller to Processor/Controller to Controller Transfers. The EU SCCs in the Appendices will apply to Personal Data that is protected by the GDPR and processed in accordance with Section 3.A. of this DPA, completed as follows:
- Module One (Controller to (Limited) Controller) or Module Two (Controller to Processor) will apply (as applicable);
- in Clause 7, the optional docking clause will apply;
- in Clause 9, Option 2 will apply, and the time period for prior notice of Subprocessor changes shall be as set out in Section 4 of this DPA;
- in Clause 11, the optional language will not apply;
- in Clause 17, Option 1 will apply, and the EU SCCs will be governed by the law of Ireland; and
- in Clause 18(b), disputes shall be resolved before the courts of Ireland.
-
Controller to Controller Transfers. The EU SCCs in the Appendices will apply to Personal Data that is protected by the GDPR and processed in accordance with Section 3.B. of this DPA, completed as follows:
- Module One will apply;
- in Clause 7, the optional docking clause will apply;
- in Clause 11, the optional language will not apply;
- in Clause 17, Option 1 will apply, and the new EU SCCs will be governed by the law of Ireland; and,
- in Clause 18(b), disputes shall be resolved before the courts of Ireland.
-
Transfers from the UK. When Personal Data is protected by the UK GDPR, the UK Addendum in the Appendices will apply, completed as follows:
-
The SCCs will also apply to transfers of such Personal Data, subject to the following:
- Tables 1 to 3 of the UK Addendum will be completed with relevant information from the SCCs as provided in Section 7.B. of this DPA;
- the option “neither party” will be deemed checked in Table 4; and
- The start date of the UK Addendum (as set out in Table 1) will be the effective date of this DPA.
-
The SCCs will also apply to transfers of such Personal Data, subject to the following:
-
Transfers from Switzerland. When Personal Data is protected by the Swiss DPA, the EU SCCs will apply in accordance with Section 7.B. with the following modifications:
- any references in the EU SCCs to EU data protection laws will be interpreted as references to the FADP;
- references to “EU”, “Union”, “Member State” and “Member State law” shall be interpreted as references to Switzerland and Swiss law, as applicable; and,
- references to the “competent supervisory authority” and “competent courts” shall be interpreted as references to the Federal Data Protection and Information Commissioner (“FDPIC”) and competent courts in Switzerland.
8. Data Access, Return, and Destruction
- Granola will update, correct, or delete Customer Data at Customer’s authorized and verified request.
- Upon the termination or expiration of the Agreement, at the written direction of Customer, Granola will return or delete Customer Data, unless further storage of such Customer Data is required or authorized by applicable law, the terms of the Agreement or this DPA, or if such Customer Data is archived on back-up systems. If return or destruction is impracticable or prohibited, Granola will take measures to block such Customer Data from any further Processing (except to the extent necessary for its continued hosting or as required by law, rule or regulation) and will continue to appropriately protect Customer Data remaining in its possession, custody, or control.
- Any costs incurred by Granola arising from Customer’s specific requests that are different from the above will be paid by Customer with Granola to provide an estimate and the Parties agree to such costs in writing.
9. Artificial Intelligence
A. AI Functionality. Granola uses artificial intelligence to deliver the Services, including for the purpose of enabling features that process Customer Data in accordance with Customer’s documented instructions. B. Model Training. Unless opted out through Granola’s Product, Granola may use information provided by the User to Granola for the development and improvement of its Services and applicable artificial intelligence functionalities, where such information has been aggregated and de-identified. Such aggregated and de-identified information does not identify specific individuals and does not constitute Personal Data. Granola will not attempt to re-identify such aggregated and de-identified information. C. Product Improvement. Granola does not use your Personal Data to train or improve our AI models. Where Users choose to opt in through the Services, Granola may use aggregated, de-identified data for AI model training. D. Customer Responsibility. Customer is responsible for determining whether AI-generated outputs are appropriate for Customer’s intended use and for applying appropriate human review before relying upon such outputs. E. AI Compliance Cooperation. Each Party is responsible for complying with the obligations imposed on it under Applicable AI Laws in connection with the Services. Upon Customer’s reasonable written request, Granola will provide information reasonably requested by Customer to assist Customer in complying with Applicable AI Laws, subject to confidentiality, security, and legal restrictions.10. Security Measures
- Security Program. Granola will maintain appropriate technical and organizational measures designed to protect the security, confidentiality, and integrity of Customer Data, including Personal Data, as described in Granola’s Trust Center at trust.granola.ai and as otherwise set forth in the Agreement or this DPA.
- Updates. Granola may update its security measures from time to time to reflect technological changes and industry standards, provided such updates do not materially reduce the overall security of Customer Data or violate applicable law.
- Access Controls. Granola will implement reasonable access controls to prevent unauthorized access to Customer Data and will ensure that access is limited to authorized personnel subject to confidentiality obligations and appropriate security training.
- Data Use Limitations. Granola will limit copying and use of Customer Data to what is necessary to provide the Services, comply with applicable law, or as otherwise permitted under the Agreement or this DPA. Granola maintains reasonable technical and organizational measures designed to reduce the risk of unauthorized access to Customer prompts, inputs, outputs, and Personal Data processed through AI functionality or features.
- Customer Responsibilities. Customer is responsible for its secure use of the Services, including safeguarding account and application programming interface (“API”) credentials, implementing internal access controls, and protecting Customer Data during transmission to and from the Services.
- Security Information. In addition to the security disclosures on our Trust Center, trust.granola.ai, upon reasonable written request, Granola will make available information reasonably necessary to demonstrate compliance with its security obligations, including applicable third-party audit reports or certifications (such as SOC-2 or equivalent) and standardized security questionnaires.
- Audits. If the information provided is insufficient to demonstrate compliance with this Section, Customer may conduct an audit with regard to the subject matter of this Section through an independent third-party auditor that is not a Granola competitor, subject to reasonable confidentiality controls, reasonable prior notice, no more than once per calendar year, during normal business hours, limited to systems relevant to Customer Data and within the scope of this Section. Customer will bear all audit costs and provide Granola with a copy of the audit results. Audits required under the SCCs will be conducted within the scope of and in accordance with, this Section.
11. Security Incidents
- If either Party becomes aware of a Security Incident directly relating to Customer Data, such discovering Party will notify the other Party without undue delay (typically within 72 hours) and will take reasonable steps to investigate, contain, and mitigate the effects of the Security Incident.
- If a Security Incident results in unauthorized access to Personal Data, each Party will provide reasonable cooperation and assistance to the other Party to support compliance with applicable laws regarding notification and communication obligations, including by providing reasonably available information to the other Party regarding: (i) the nature of the Security Incident and the categories and approximate number of affected records; (ii) the likely consequences of the incident; and (iii) the measures taken or planned to address and mitigate the incident.
- For clarity, Granola’s obligations under this Section to report, respond or notify of a Security Incident do not constitute an admission of fault or liability by Granola with respect to the Security Incident.
12. Liability; Limitations
The liability of each Party arising out of or relating to this DPA (including any applicable SCCs) is subject, to the maximum extent permitted by applicable laws, to the exclusions and limitations of liability set forth in the Agreement. For the avoidance of doubt, each Party’s liability under this DPA is limited to the extent such liability is caused by that Party’s own acts or omissions.13. Notices
Granola may provide notices to Customer and Users as directed in the Agreement, using the provided Customer contact information, or via the Granola website or the Services. Customer may provide notices to Granola by contacting Granola at privacy@granola.so.Appendix A – Details of Processing
Nature and Purpose of Processing: Granola will Process Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Customer’s instructions as set forth in this DPA. The nature of Processing includes, without limitation:- Receiving data, including collection, accessing, retrieval, recording, and data entry
- Holding data, including storage, organization and structuring
- Using data, including analysis, consultation, testing
- Updating data, including correcting, adaptation, alteration, alignment and combination
- Protecting data, including restricting, encrypting, and security testing
- Sharing data, including disclosure, dissemination, allowing access or otherwise making available
- Returning data to Customer or data subject
- Erasing data, including destruction and deletion
- Processing Customer Data through artificial intelligence and machine learning functionality to generate meeting summaries, notes, action items, and other Customer-requested outputs.
Appendix B – Information required for the EU Standard Contractual Clauses (SCCs)
For the purposes of EU SCCs, the Parties agree to the following:The optional docking clause is selected. | |
This DPA and the Agreement are Customer’s complete and final documented instructions at the time of signature of the Agreement to Granola for the Processing of Personal Data. Any additional or alternate instructions must be consistent with the terms of this DPA and the Agreement. For the purposes of clause 8.1(a), the instructions by Customer to Process Personal Data are set out in this DPA and include onward transfers to a third party located outside the EU / EEA for the purpose of the performance of the Services. | |
The Parties agree that the certification of deletion of Personal Data that is described in clause 8.5 and 16(d) of the EU Standard Contractual Clauses shall be provided by Granola to Customer only upon written request. | |
The Parties agree that the audits described in clause 8.9 of the EU Standard Contractual Clauses shall be carried out in accordance with the audit provisions as agreed in the Agreement and this DPA. | |
Option 2 under clause 9 shall apply. For the purposes of clause 9(a), Granola has Customer’s general authorization to engage Subprocessors in accordance with this DPA. Granola shall make available to Customer the current list of Subprocessors in accordance with this DPA. Pursuant to clause 9(a), Customer acknowledges and expressly agrees that Granola may engage new Subprocessors as described in this DPA. Granola shall inform Customer of any changes to Subprocessors following the procedure provided in this DPA. | |
This optional redress clause is not selected. | |
Clause 13 shall apply as follows:
| |
For the purposes of clause 15(1)(a), Granola shall notify Customer only and not the Data Subjects in case of government access requests. Customer shall be solely responsible for promptly notifying the Data Subjects as necessary. | |
Option 1 is selected. The governing law for the purposes of clause 17 shall be the law that is designated in the Governing Law section of the Agreement. If the Agreement is not governed by an EU Member State law, the EU Standard Contractual Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third party beneficiary rights. The Parties agree that this shall be the law of Ireland. | |
The courts under clause 18 shall be those designated in the venue section of the Agreement. If the Agreement does not designate an EU Member State court as having exclusive jurisdiction to resolve any dispute or lawsuit arising out of or in connection with this Agreement, the Parties agree that the courts of Ireland shall have exclusive jurisdiction to resolve any dispute arising from the EU Standard Contractual Clauses. | |
The Appendix shall be completed as follows:
|
For the Purposes of Annex I of the EU SCCs
Controller to Controller (Limited) (“Module One”):For the Purposes of Annex II of the EU SCCs - Technical and Organizational Measures
Granola provides the following summary of its Technical and Organizational Measures in accordance with Annex II of the EU SCCs. Granola implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk in providing the Services, including:- Logical access controls and role-based access restrictions
- Encryption of Personal Data in transit and at rest, where appropriate
- Secure authentication and account access mechanisms
- Monitoring, logging, and incident response procedures
- Regular security reviews and employee security training

