LAST UPDATED · August 21, 2026
How Grit Board processes customer-controlled personal data on behalf of customers — incorporated into the Terms of Service automatically, with countersigned copies available on request.
This Data Processing Addendum ("DPA") supplements the Grit Board Terms of Service or other written agreement between Grit Board LLC ("Grit Board," "we," "us," or "our") and the customer that uses Grit Board ("Customer," "you," or "your"). It is incorporated into the Terms of Service and applies automatically — you do not need to sign anything separately. If your procurement team needs a countersigned copy, email hello@gritboard.io and we will sign one.
This DPA applies when Grit Board processes personal data on behalf of Customer in connection with the service, including customer-uploaded or synced sales-rep roster, activity, pipeline, quota, scoring, board, and season data.
If there is a conflict between this DPA and the Terms of Service about personal data processing, this DPA controls for that issue.
For customer-controlled sales-rep data, Customer is the controller or business, and Grit Board is the processor or service provider acting on Customer's instructions.
For account, billing, website, support, and service-administration data that Grit Board determines how to process, Grit Board may act as an independent controller or business as described in the Privacy Policy.
Grit Board processes personal data to provide, secure, support, maintain, and improve the service; operate boards, games, imports, integrations, scoring, exports, and season history; authenticate users; troubleshoot issues; prevent abuse; and comply with law.
We do not sell customer data, do not share it for cross-context behavioral advertising, do not use it to train machine-learning or AI models, do not retain, use, or disclose it for any purpose other than providing the service under this DPA, and do not combine it with data from other sources or other customers. It runs your boards, and that is it.
The categories of data subjects may include Customer users, administrators, managers, sales representatives, employees, contractors, prospects, and other individuals whose data Customer provides to the service.
Grit Board will process customer-controlled personal data only on documented Customer instructions, including instructions in the Terms, this DPA, product settings, imports, integrations, support requests, and other written directions.
Customer is responsible for ensuring that its instructions comply with applicable law. If Grit Board believes an instruction violates applicable data protection law, Grit Board may notify Customer and suspend the affected processing where appropriate.
Customer is responsible for having a lawful basis to collect, upload, sync, and process personal data through Grit Board. Customer is also responsible for providing any required privacy notices, employment notices, workplace monitoring disclosures, consents, or internal approvals.
Customer is responsible for configuring access controls, managing authorized users, reviewing outputs before using them for employment or compensation decisions, and ensuring that Grit Board is used in a lawful and non-discriminatory manner.
Grit Board will ensure that personnel authorized to process customer-controlled personal data are subject to appropriate confidentiality obligations or professional duties of confidentiality.
Grit Board will implement and maintain appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Today those measures include:
Customer authorizes Grit Board to use the subprocessors listed at gritboard.io/subprocessors, which names every provider, its purpose, and its processing location. Grit Board will impose data protection obligations on subprocessors appropriate for the services they provide, and remains responsible for their performance to the extent required by applicable law.
We will update the subprocessor list at least 30 days before a new subprocessor starts processing customer data, and email the account owner of every customer on a paid plan. If Customer objects on reasonable data-protection grounds within those 30 days, Grit Board will either accommodate the objection or allow Customer to cancel without penalty for the remainder of its term.
Grit Board is based in the United States and processes personal data in the United States. Customer authorizes Grit Board and its subprocessors to make international transfers as needed to provide the service, subject to the safeguards below.
Grit Board LLC is not certified under the EU-US Data Privacy Framework. Where a transfer from the EEA, the UK, or Switzerland requires a safeguard, we will enter into the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two, controller-to-processor), with the UK Addendum where applicable — email hello@gritboard.io and we will get them signed. For transfers of Brazilian personal data, we will execute the ANPD's standard contractual clauses (Resolução CD/ANPD nº 19/2024) with Customer on request.
Taking into account the nature of the processing and the information available to Grit Board, Grit Board will provide reasonable assistance to Customer for data subject requests, security obligations, data protection impact assessments, prior consultations, and compliance inquiries where required by applicable law.
If Grit Board receives a request from a data subject about customer-controlled personal data, Grit Board may direct the requester to Customer or notify Customer where appropriate, unless legally prohibited.
Grit Board will notify Customer without undue delay after becoming aware of a personal data breach affecting customer-controlled personal data, as required by applicable law.
The notice will include available information reasonably needed for Customer to meet its own breach-notification obligations. Grit Board's notice of an incident is not an admission of fault or liability.
You can export everything we hold for your organization at any time from the account page — a single JSON file, generated on demand, no request to us needed.
Deleting your account removes your organization's data from our live systems, disconnects any CRM connection and revokes the stored credential, cancels any active subscription, and deletes the associated logins. Backup copies may retain data for a short period before they age out, and we may keep the minimum records the law requires — billing records among them. Anything retained stays covered by this DPA until it is gone.
Grit Board will make available information reasonably necessary to demonstrate compliance with this DPA, taking into account the nature of the service, Customer's plan, confidentiality, security, and the protection of other customers.
In practice we satisfy this with documentation: our Security page, this DPA, the subprocessor list, and written answers to a reasonable security questionnaire, once per year. If applicable law requires more, or following a confirmed security incident affecting Customer's data, the parties will agree on a proportionate audit — with at least 30 days' written notice, during business hours, under NDA, at Customer's cost, and scoped so it never exposes another customer's data.
For Mexican customers, this DPA is intended to document the encargado relationship under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (2025): Customer is the responsable for sales-rep data, and Grit Board processes it only on Customer's documented instructions. Sharing data with Grit Board under this DPA is a remisión to an encargado, not a transfer requiring data-subject consent.
Customer is responsible for providing the required privacy notices to its reps before uploading or syncing their data, and for handling ARCO rights requests, with Grit Board's reasonable assistance as described in this DPA.
For Brazilian customers, this DPA is intended to work as an operator agreement under the LGPD (Lei nº 13.709/2018): Customer is the controller (controlador) of sales-rep data and Grit Board is the operator (operador), processing only on Customer's instructions.
Customer is responsible for the legal basis for processing employee data and for giving reps whatever notice Brazilian law requires before uploading or syncing their data. Grit Board will give reasonable assistance with data-subject requests under Article 18 — including Article 20 requests to review automated scoring — and with any ANPD inquiry. hello@gritboard.io is our data-subject communication channel for LGPD purposes.
For Colombian customers, this DPA is intended to serve as the written transmission contract required by Decreto 1377 de 2013 for sending personal data to Grit Board as processing agent (encargado): Grit Board processes only under Customer's instructions and treatment policy, safeguards the security of the data, and keeps it confidential. Customer remains responsible for the authorizations Colombian law requires from its reps.
For customers subject to GDPR-style laws, the parties intend this DPA to satisfy processor-contract requirements for customer-controlled personal data, including documented instructions, confidentiality, security, subprocessors, assistance, breach notice, deletion or return, and audit information. Transfer safeguards are covered in the International Transfers section above.
Questions about this DPA can be sent to hello@gritboard.io.
Notices may be sent to Grit Board LLC, 6378 W 9890 N, Highland, UT 84003, United States.