Legal
Data Processing Addendum
How we process the personal data inside your code, error reports and app data on your behalf. It forms part of the Terms of Service; there is nothing to sign.
Last updated September 24, 2026 · Beyond the Brackets USA LLC
01What this addendum is
This Data Processing Addendum (“DPA”) forms part of our Terms of Service between you and Beyond the Brackets USA LLC, a Delaware limited liability company, 8 The Green, STE R, Dover, DE 19901, USA (“we”, “us”). It applies whenever the code, error reports, app data or messages you give Grace (“Your Content”) contain personal data protected by Data Protection Laws: the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act.
For that personal data (“Customer Personal Data”), you are the controller and we are your processor. If you are an agency working on your clients' apps, you act as their processor and we are your subprocessor, and you confirm that your clients have authorized it. On data protection matters, this DPA prevails over the Terms.
Personal data we handle for our own purposes, such as your account and billing details, is covered by our Privacy Policy instead.
02Processing on your instructions
We process Customer Personal Data only on your documented instructions. Those are the Terms, this DPA, the way you configure and use Grace, and any other instruction you give us in writing that we accept. We tell you if we believe an instruction breaks Data Protection Laws, and if the law requires us to process data otherwise, we tell you first unless the law forbids it.
Under US state privacy laws we act as your service provider. We do not sell or share Customer Personal Data, and we do not retain, use or disclose it outside our direct business relationship with you or for any purpose other than providing Grace, nor combine it with personal data from other sources except as those laws allow.
03Details of the processing (Annex I)
| Item | Detail |
|---|---|
| Subject matter | Providing Grace to you under the Terms |
| Duration | For as long as the Terms are in force, then until deletion as set out below |
| Nature and purpose | Hosting, copying, indexing and analyzing Your Content with automated tools and AI models; running your app in isolated environments; producing reports, findings and fixes; support and the engineering work in your plan |
| Data subjects | Whoever appears in Your Content: typically your users and customers, your staff and contractors, and your clients' users |
| Categories of data | Whatever Your Content contains. In practice: names, email addresses, user identifiers, IP addresses and similar data found in code, test fixtures, seed files, logs, error reports and stack traces |
| Special categories | Not intended. Please keep health, biometric and other special category data out of what you connect |
04Our people
Only people who need Customer Personal Data to provide Grace, support you or keep it secure can access it, and each of them is bound by confidentiality.
05Security (Annex II)
We keep appropriate technical and organizational measures in place for the risk involved, taking into account the state of the art and the cost of putting them in place. Today they are:
- Encryption in transit (HTTPS) for every connection to the site, the app and its interfaces.
- Isolation between accounts, enforced at a single access layer that every request to an app goes through.
- The app, its database and the copies of your code hosted in France, with the database and cache reachable only from the server itself.
- Access tokens for the code and error-tracking services you connect encrypted at rest (AES-256-GCM), with key rotation.
- Passwords stored as Argon2id hashes; editor keys and invitations stored only as hashes.
- Your app run in isolated containers, and previews reached only through signed links that expire after an hour.
- Secrets detected and blocked before they are committed, where the Grace Guardian checks are installed.
- Access by our staff limited to the needs described above.
- Copies of your code deleted when you delete the app, and GitHub copies deleted automatically after 30 days without an audit.
We may change these measures, provided the overall level of protection does not decrease.
06Subprocessors (Annex III)
You authorize us to use the subprocessors below. Each is bound by written terms that protect Customer Personal Data at least as well as this DPA, and we remain responsible for them.
| Subprocessor | What they do | Where |
|---|---|---|
| Scaleway | Hosts the Grace app, its database, and the copies of the code you connect | France (Paris) |
| Vercel | Hosts this website, and runs the AI Gateway that routes each AI request to the model provider in use | United States |
| Provides the default AI model (Gemini), and sign-in with Google | United States | |
| OpenAI | Provides the embedding model that indexes code, and its chat models when selected | United States |
| Other model providers on the AI Gateway (for example Anthropic) | Receive data only when one of their models is selected for a task, by you or in our configuration | United States |
| Resend | Sends account, report and booking emails | United States |
Before a new subprocessor starts processing Customer Personal Data, we update this list and email account owners at least 30 days ahead. You can object on reasonable data protection grounds within that period. If we cannot address the objection, you may end the affected service and we refund the fees you prepaid for the period after it ends.
07Helping you meet your obligations
- If one of your data subjects contacts us, we pass the request to you and don't answer it ourselves unless you ask us to. You can delete apps, and the data they hold, from the app; for anything else, we help you respond.
- We give you reasonable help with data protection impact assessments and consultations with supervisory authorities about Grace.
- You can reach us about any of this at hello@agent-grace.com.
08Personal data breaches
If we become aware of a breach of security affecting Customer Personal Data, we notify you without undue delay, and in any case within 48 hours. We tell you what we know (what happened, the data and people likely to be affected, the likely consequences, what we are doing about it and who to contact) and send the rest as we learn it. We take reasonable steps to contain the breach and limit its effects. Notifying you is not an admission of fault.
09International transfers
We are established in the United States, and some of our subprocessors are too. When Customer Personal Data from the EEA is transferred to us or to a subprocessor in a country without an adequacy decision, the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 apply and are incorporated into this DPA by reference: Module Two where you are a controller, Module Three where you are a processor. For those clauses:
- the optional docking clause (Clause 7) applies;
- under Clause 9, option 2 (general written authorization) applies, with the 30-day notice described above;
- the optional redress wording in Clause 11 does not apply;
- under Clauses 17 and 18, the clauses are governed by French law, and the courts of Paris, France have jurisdiction;
- Annexes I, II and III are the sections of this DPA with those names.
For data from the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies alongside the clauses. For data from Switzerland, the clauses apply with the adjustments the Federal Data Protection and Information Commissioner requires, and references to the GDPR are read as references to the Swiss Federal Act on Data Protection. If the clauses and this DPA ever conflict, the clauses prevail.
10Deletion and return
While the Terms are in force, deleting an app deletes its Customer Personal Data as the Privacy Policy describes. When the Terms end, download the reports you want to keep; we then delete the remaining Customer Personal Data within 30 days, unless the law requires us to keep some of it, in which case we keep it protected and use it for nothing else.
11Audits
We make available the information you reasonably need to verify that we meet this DPA, including written answers to a security questionnaire once a year.
On-site audits
Where that information is not enough, or a supervisory authority requires it, you may audit us, through an independent auditor bound by confidentiality, with 30 days' notice, during business hours, no more than once a year unless a breach calls for it, and at your cost.
12Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms, to the extent Data Protection Laws allow. Where documents conflict, the Standard Contractual Clauses prevail, then this DPA, then the Terms. This DPA lasts as long as we hold Customer Personal Data.