GRCDog

Data Processing Agreement

Last updated: July 19, 2026

Who this is for

If your organization is subject to the EU/UK GDPR, or a similar law that requires a written data processing agreement between you (the controller) and GRCDog (the processor for your tenant compliance content, see below) before you can use a tool like this on personal data, request one below. Most customers using GRCDog in Solo mode, where data never leaves the browser, will not need one; it applies to Connectedmode, where your organization’s data is stored on our servers. See our Privacy Policy for the difference between the two modes.

Controller vs. processor: what applies when

Whether GRCDog is a controller or a processor depends on the category of data, not on a single label for the whole relationship. We are a controller for some data and a processor for other data, at the same time, for the same customer.

We are the controller (we decide the purpose and means of processing) for: account and authentication data (your name, email address, and password hash, or the basic profile info Google or GitHub share when you sign in that way); billing data handled through Stripe; support requests and messages sent to our support inbox; and marketing-site data such as cookies and referral tracking, described in our Privacy Policy.

We are the processor (we act only on your documented instructions) for: the tenant compliance content your organization enters in Connected mode, meaning the projects, controls, evidence, audit findings, and other ISMS/GRC records your team creates in the product. This is the data our DPA exists to cover.

What a GRCDog DPA covers

Once signed, our DPA sets out, at minimum: the categories of personal data GRCDog processes on your behalf (account details, and whatever compliance content your team enters); the purpose and duration of that processing (delivering the product to you, for as long as your account is active); your instructions as controller and our obligation to act only on them for tenant compliance content; confidentiality commitments for anyone with access to your data; the security measures we apply (see the Privacy Policy); our sub-processors, listed in full below; and the terms under which we assist you with data subject requests and notify you of a personal data breach.

Sub-processors

We use the following sub-processors to run GRCDog. This schedule reflects our current understanding of our own infrastructure. We will update this schedule as our infrastructure changes, and a signed DPA entitles you to advance notice before we add a new sub-processor that will process your tenant compliance content.

Sub-processorRoleRegion
HetznerHosting: application servers and databaseGermany (EU)
Hetzner Storage BoxOffsite backup storageGermany (EU)
CloudflareContent delivery, network proxy, and DNSGlobal edge network
StripePayment processing and billingUnited States
ResendTransactional email delivery (verification, password reset, invites, notices)United States
SentryError monitoring and application diagnosticsUnited States
GoogleSign in with Google (OAuth)United States / global
GitHubSign in with GitHub (OAuth)United States / global

Data location and international transfers

GRCDog’s application servers and database are hosted on Hetzner infrastructure in Germany. Cloudflare, our content delivery and proxy provider, operates a global network, so requests to GRCDog may pass through Cloudflare points of presence outside Germany or the EU on their way to our servers.

Several of our sub-processors, Stripe, Resend, Sentry, Google, and GitHub, are based in or process data in the United States. Where using GRCDog involves transferring personal data from the EU/UK to one of these providers, we rely on the transfer safeguards each provider describes in its own data processing terms, for example Standard Contractual Clauses or, where a provider participates in it, the EU-U.S. Data Privacy Framework. We have not independently verified every provider’s current transfer mechanism; tell us in your request if you need the specifics documented for your organization’s DPA.

Where GRCDog is run from

GRCDog is operated by BestBusinessBrands, based in Illinois, United States. That is the contracting entity for your DPA; see Data location and international transfers above for where the infrastructure that processes your data actually runs. If your organization needs Standard Contractual Clauses or an equivalent international transfer mechanism alongside the DPA, tell us that in your request and we will include them.

How to request one

Email [email protected] with your organization’s legal name and the account email you signed up with. We will send you the current DPA template for signature and follow up on any questions before you sign.

Related documents

See also our Terms of Service and Privacy Policy, which apply alongside any signed DPA.