GRANSKA Terms, Privacy & Data Processing Terms
Version 1.0 · in force from
With effect from 18 September 2026, this Version 1.0 supersedes the GRANSKA Terms of Service Version 4, Data Processing Agreement Version 10, and Privacy Policy Version 11.
These Terms govern the use of GRANSKA, a service provided by MANI Dev AB, Swedish company registration number 559582-2338 ("MANI", "GRANSKA", "we", "us").
They contain our Terms of Service, Privacy Notice, and, where applicable, Data Processing Terms.
By using GRANSKA, you agree to the Terms of Service in this document. The Privacy Notice explains how MANI processes personal data and does not rely on your consent.
If you use GRANSKA on behalf of an organization, you confirm that you are authorized to bind that organization to these Terms, including the Data Processing Terms in Schedule 1.
1. The Service
GRANSKA is an AI-based decision-support tool for methodological and procedural review of documents and other material, ranging from non-sensitive policies and administrative documents to material containing highly sensitive personal information.
GRANSKA does not provide legal advice, make legal decisions, or replace independent professional assessment.
AI systems can make mistakes, including incorrect conclusions, inaccurate or invented references, contextual misunderstandings, and errors in legal or methodological interpretation.
Users must independently assess the output before relying on it in legal proceedings, dealings with public authorities, or other important matters.
2. Users and Customer Content
GRANSKA may be used by both Private Users and Organization Users, including companies, law firms, public authorities, and other professional organizations.
Private Users may use the Service with a personal account, and through some partner sites without one. Private Users are not required to purchase a subscription or make a payment.
"Customer Content" means documents, text, and other information submitted to GRANSKA, together with the analysis generated from that material.
Users may only submit material that they are legally permitted to process and provide to the Service.
MANI claims no ownership of Customer Content. Any rights remain with the user, customer organization, or other applicable rightsholder.
Customer Content is not used to train MANI's or Google's AI models.
3. Zero Data Retention
GRANSKA is designed around Zero Data Retention and read-and-burn architecture.
Customer Content is processed only for the requested review. It is not retained as a customer history, used for profiling, or used for machine learning.
The processing works as follows:
- Customer Content is transmitted over an encrypted connection to GRANSKA's cloud environment.
- Temporary storage, queues, or caching may be used only where technically necessary to perform and deliver the analysis.
- Uploaded documents are normally deleted when the analysis is completed. If that step does not complete, the automated deletion routine below removes them.
- A generated report is deleted when it is delivered to the user's browser. A report retrieved through the API is not deleted by being read, so that a dropped connection does not lose it; it is deleted when the customer's system requests deletion.
- An automated dead-man switch runs every 15 minutes to identify and delete abandoned or residual processing data.
- Whatever happens, all Customer Content relating to a review is deleted no later than 30 minutes after the review has been completed or aborted, whether or not anyone has fetched the report.
Customer Content is therefore normally present in the system only for the minutes required to perform and deliver the requested analysis. Apart from the two exceptions in the next paragraphs, no Customer Content is stored beyond the life of the review itself. GRANSKA does not create or maintain a persistent, searchable archive of Customer Content.
The first exception concerns usage receipts written before 25 August 2026. When a review failed before that date, the error description recorded on its receipt may quote text from the document that was being reviewed. Those receipts are currently kept without a set end date, and their statistics copy for 400 days (Section 5a); neither is deleted by the 30-minute bound above. Receipts written since that date contain no document text.
The second exception concerns Google Cloud's own logs for the Service. When a review failed before 25 August 2026, the error message written to those logs may quote text from the document that was being reviewed. Since that date the Service writes its own error codes there instead, but in a few remaining cases, such as a failed attempt that is handed back to be run again, an error message produced during the processing can still reach those logs, and it can quote a fragment of a document or its analysis. Those logs are kept for 30 days, so the last entries written before 25 August 2026 are deleted by 24 September 2026, and they are stored in Google Cloud Logging's global storage location, which is not limited to the EU. They are not deleted by the 30-minute bound above.
The operational event log contains no Customer Content. What the Service's logs do contain, where they are stored, and how long they are kept, is set out in Section 5a.
MANI personnel do not have routine access to Customer Content. Any internal access during active processing is technically and organizationally restricted and may occur only when necessary for purposes such as support, troubleshooting, security, or incident handling, by authorized personnel and to the minimum extent necessary.
Once Customer Content has been deleted under the Zero Data Retention process, no persistent copy remains in GRANSKA for later access, apart from what the receipts and log entries described above may quote. MANI personnel therefore cannot subsequently retrieve or review an uploaded document after it has been deleted.
4. Data Protection Roles
4.1 Organization Users
When GRANSKA is used on behalf of an organization, the organization determines why Customer Content is processed and normally acts as the Data Controller.
MANI acts as the Data Processor and processes Customer Content only on the organization's documented instructions.
The Data Processing Terms in Schedule 1 apply to this processing.
The organization remains responsible for establishing an appropriate legal basis for its processing, including any legal basis required for special categories of personal data or information relating to criminal offenses.
4.2 Private Users
Private Users use GRANSKA for their own purposes and do not act on behalf of a customer organization.
Where applicable data protection law applies to MANI's processing of Customer Content submitted by a Private User, MANI acts as the Data Controller for the temporary processing necessary to provide and secure the Service.
For users subject to the GDPR, Article 6(1)(b) may apply to the processing of the user's own personal data where necessary to provide the requested Service. Where Customer Content contains personal data relating to other individuals, processing may instead rely on Article 6(1)(f), where the applicable requirements for legitimate interests are met.
Special categories of personal data may only be processed where an applicable exception under Article 9(2) GDPR applies, including Article 9(2)(f) where processing is necessary for the establishment, exercise, or defense of legal claims. Personal data relating to criminal convictions and offenses may only be processed where permitted under Article 10 GDPR and applicable law.
Private Users must not submit personal data when doing so would be unlawful.
5. Privacy Notice – MANI's Own Processing
MANI processes only limited personal data for its own purposes, and not the content of what you upload, with the two exceptions described in Section 3: on usage receipts written before 25 August 2026, the error description may quote text from the document that was being reviewed, and an error message in Google Cloud's own logs, which are kept for 30 days, may quote text from a document or its analysis. This section describes that processing in general terms; Section 5a describes each category of data we hold, why we hold it, who can access it, where it is stored, and for how long.
For Organization Users, this includes the user's name, professional email address, organization, account role, and limited account and security information necessary to provide, administer, secure, and support the Service.
For Private Users with an account, this includes the email address and account identifier needed to provide the account. Private Users using a partner site without an account are not asked for account or contact information.
For all users, GRANSKA processes technical metadata necessary to operate, secure, and follow up the Service: for example timestamps, request duration, functions used, the AI resources and cost a review used, and technical status or error codes. This metadata does not contain Customer Content, except for the receipts and log entries described in Section 3. Where a user has an account, it is linked to the user's account identifier and organization, and it is then personal data.
MANI also uses this metadata for internal follow-up and statistics about how the Service is used: how many reviews are run, how long they take, what they cost, and how many shortcomings and strengths the review finds in each area of law it checks. The statistics contain counts only, never document text, quotes, or the wording of any finding; the copy of the receipts they are compiled from is described in Section 5a. Statistics about findings are compiled per organization and never per individual user within an organization, and a figure is only shown where it is based on at least five reviews.
Where MANI processes personal data relating to users, it does so where necessary to perform its agreement with the user or customer organization, comply with legal obligations, or pursue legitimate interests in administering, securing, and following up the Service. MANI does not use personal data for profiling or automated decision-making that produces legal or similarly significant effects.
The Zero Data Retention rules in Section 3 apply separately to Customer Content.
The account information requested from users is necessary to create and administer an account. Without this information, MANI may be unable to provide account access.
5a. What we hold about you
This section describes, by category, the personal data MANI keeps about a person who uses GRANSKA: what kind of data each category is, with representative examples, why we hold it and on what legal basis, who can access it, where it is stored, and for how long. The examples illustrate each category; they are not a list of every individual item of data. It does not cover the people described inside an uploaded document: about them, nothing is kept once the review is deleted under Section 3, except where the error description on a receipt written before 25 August 2026, or an error message in Google Cloud's own logs, quotes the document (Section 3). Receipts written since that date contain no document text, and the logs are kept for 30 days.
Account and organization data
What identifies you and your place in the Service. For example: your email address, account identifier, organization, role, and language choice. How you sign in: if you sign in with Google, the link to your Google account and the name and profile picture it provides; if you sign in with email and password, your password, which is stored only in a hashed form that cannot be read back, and whether your email address has been verified. When the account was created and last signed in. If you signed up through a link that marked you as a business or a public authority, that marking is recorded with your account; it decides nothing about what your account can do.
- Why
- To let you sign in, to administer your access, and to know which links brought users to the Service
- Legal basis
- Art. 6(1)(b); for Organization Users, Art. 6(1)(f)
- Who can access it
- You can see your own account details, including how you arrived. The administrators of your organization can see its members and their roles. Authorized MANI personnel.
- Where it is stored
- Your account, organization, role, email address and language choice: within the EU, in Google Cloud's europe-west1 region (Belgium). Your sign-in details, which are your email address, your hashed password or the link to your Google account with the name and picture it provides, whether your address has been verified, and when you signed up and last signed in: Firebase Authentication, a Google service that processes this data only in the United States (Section 7).
- How long
- For as long as the account exists. To close it, contact support (Section 6). When an account is deleted, Google removes its sign-in details from its backup systems within 180 days. The marking of how you arrived through a link is currently kept without a set end date.
Invitation data
What is needed to invite someone to an organization and to deliver the invitation. For example: the invited email address, the inviting organization, the role offered, and the account identifier of the person who sent it; the invitation's identifier, which is the code in the invitation link, the kind of invitation, and the language of the letter; when it was created and when it expires, whether and when the letter was sent, and the email provider's message identifier. The invitation email itself carries the recipient's email address and the content of the letter, which names the inviting organization, sometimes the person who sent the invitation, and carries the invitation link.
- Why
- To deliver an invitation to join an organization
- Legal basis
- Art. 6(1)(f)
- Who can access it
- The administrators of the inviting organization. Anyone who holds an invitation link can see the invitation it belongs to. Authorized MANI personnel. Resend, for the invitation email.
- Where it is stored
- The invitation record: within the EU, in Google Cloud's europe-west1 region (Belgium). The invitation email: sent to Resend, which processes and holds it in the United States (Section 7).
- How long
- The invitation record: until the invitation is accepted, withdrawn or replaced. An invitation nobody accepts is deleted shortly after it expires. The invitation email: retained by Resend in accordance with its standard retention for sent emails, which does not end when the invitation record is deleted.
Usage receipts
A technical receipt for each review, for each failed attempt, and for other AI requests you make in the Service. For example: identifiers for your account, your organization and the review; when it ran and for how long; its status and outcome, including an error category if it failed and whether it was refused, retried or resumed from an earlier attempt; the review profile, document type and size of the uploaded file; the AI model and region, how the request was routed and whether cached material was reused; which parts of the review ran; the AI resources used and the cost; technical measurements of how the uploaded file was read; and counts of shortcomings and strengths found per area of law. When MANI personnel test an organization's set-up, the receipt names that organization. Never document content, with one exception: on receipts written before 25 August 2026, the error description may quote text from the document that was being reviewed.
- Why
- Quotas, cost allocation, security, and follow-up of the Service
- Legal basis
- Art. 6(1)(f)
- Who can access it
- The administrators of your organization can see its receipts. Authorized MANI personnel.
- Where it is stored
- Within the EU, in Google Cloud's europe-west1 region (Belgium)
- How long
- Currently kept without a set end date. A retention period is being decided and will be stated here.
Statistics copy of the receipts
The same data as the receipts, copied daily to a separate store used for internal statistics. For receipts written before 25 August 2026 this includes the error description, which may quote the document (Section 3).
- Why
- Follow-up of use, cost, and quality
- Legal basis
- Art. 6(1)(f)
- Who can access it
- Authorized MANI personnel.
- Where it is stored
- Within the EU, in Google Cloud's europe-west1 region (Belgium)
- How long
- 400 days
Organization statistics
Monthly totals per organization. A figure is only shown where it is based on at least five reviews. For an Organization User, it contains no data about individual users. For a Private User with an account, the organization is that user's own account, so its totals concern that user.
- Why
- Follow-up of use, cost, and quality
- Legal basis
- Art. 6(1)(f)
- Who can access it
- Authorized MANI personnel.
- Where it is stored
- Within the EU, in Google Cloud's europe-west1 region (Belgium)
- How long
- Kept without a set end date
Operational and platform logs
Technical records of how the Service runs. The operational event log records, for each review and each AI and API call, for example the time, duration, AI model and region, resources used, status and error codes, and account and organization identifiers; it holds no document content and no IP address. Google Cloud's own request, error and access logs for the Service record, for example, the time, the function called and its result, account identifiers, IP address, browser type, and error messages. Error messages written there when a review failed before 25 August 2026 may quote text from the document that was being reviewed, and in a few remaining cases an error message can still quote a fragment of a document or its analysis (Section 3).
- Why
- Operation, security, troubleshooting, and follow-up
- Legal basis
- Art. 6(1)(f)
- Who can access it
- Authorized MANI personnel.
- Where it is stored
- The operational event log: within the EU, in Google Cloud's europe-west1 region (Belgium). Google Cloud's own logs: Google Cloud Logging's global storage location, which is not limited to the EU.
- How long
- The operational event log 90 days. Google Cloud's own logs 30 days.
Administrative and configuration records
Records of who did what to an organization's configuration and account. For example: which account created or last changed a configuration or an API key; when a configuration is copied between organizations, who copied it, from and to which organization, what was copied, and when; and for each action MANI personnel take on an organization's account through the platform API, who took it and with which credential and client, what was acted on, which may include the account identifier of the user it concerns, the stated reason, a fingerprint of the request rather than its content, the outcome, how long it took, and when.
- Why
- Security, accountability, and support
- Legal basis
- Art. 6(1)(f)
- Who can access it
- The administrators of your organization can see which account created or last changed its configurations and API keys. Authorized MANI personnel.
- Where it is stored
- Within the EU, in Google Cloud's europe-west1 region (Belgium)
- How long
- Records of copied configurations 24 months. The others are currently kept without a set end date.
Idempotency records for organization set-up
When MANI personnel create an organization through the platform API, a record that lets a repeated request be answered without creating the organization twice. It holds: an identifier derived from the account identifier of the person who made the request and the request's own key, that account identifier, which request it was, a fingerprint of the request rather than its text, whether the request is still running or has finished, when it was made and when the record expires, and the answer the request was given, which is that the request succeeded, the new organization's identifier, the invitation link, when the invitation expires, the language of the invitation letter, whether the letter was sent, and a place for the email provider's own message that is always left empty. It never holds the invited email address, and never the email provider's own message when a letter could not be sent.
- Why
- To make sure a repeated request does not create a second organization, and to give a repeated request the answer the first one received
- Legal basis
- Art. 6(1)(f)
- Who can access it
- Only the Service's servers read it, to answer a repeated request. No user can read it through the Service, and authorized MANI personnel can reach it.
- Where it is stored
- Within the EU, in Google Cloud's europe-west1 region (Belgium)
- How long
- 24 hours
Feedback you send
The text you write in the feedback box, what kind of feedback it is and where in the Service you sent it, with your account identifier and role, when you sent it, and whether MANI has marked it as resolved. Anything you write there, including any text you paste from a document, is kept with your feedback. So that it is read, a notice is also placed in the GRANSKA team's Feedback app (feedback.granska.cloud), which is built with Lovable and stores its data with Supabase. The notice holds the identifier of your feedback, what kind of feedback it is, your role, where in the Service you sent it, which installation of the Service it came from, and how long your message is. It never holds the text you wrote or your email address, but its identifier leads back to your feedback and your account.
- Why
- To read and answer your feedback
- Legal basis
- Art. 6(1)(f)
- Who can access it
- Authorized MANI personnel.
- Where it is stored
- Your feedback: within the EU, in Google Cloud's europe-west1 region (Belgium). The notice in the Feedback app: with Supabase, in a region that has not yet been confirmed and will be stated here.
- How long
- Currently kept without a set end date
Browser security and preference data
What the website keeps in your own browser. Your sign-in session, your language choice, the last workspace you used, the account type you arrived with through a link, and a short note of a running review (its random identifier, start time and the review profile it was started with, stored under your own account identifier). The review running in the current tab is also noted there. Administrators who use the API tester keep their last 20 test requests and responses in that tab. Security data kept for Firebase App Check, described below.
- Why
- Strictly necessary to provide and protect the Service you asked for
- Legal basis
- Art. 6(1)(b) / strictly necessary
- Who can access it
- It stays in your browser. What App Check sends to Google is described below.
- Where it is stored
- Your browser
- How long
- Your sign-in session: until you sign out.
- Your language choice: until you close the browser.
- The last workspace you used: until you use another workspace or clear your browser's stored data. Signing out does not remove it.
- The account type you arrived with through a link: kept without a set end date, until you clear your browser's stored data.
- The note of a running review: removed when the report is fetched and not used after 45 minutes. A note that is never removed that way stays until you start another review or clear your browser's stored data.
- The review running in the current tab, and the API tester's requests and responses: until the tab is closed.
- The App Check security data: until it is replaced, which happens automatically while you use the website, or until you clear your browser's stored data.
Apart from what is kept in your browser and the four exceptions below, the data described above is stored within the EU, in Google Cloud's europe-west1 region (Belgium). Your sign-in details are held by Firebase Authentication, which processes them only in the United States. Google Cloud's own logs are stored in Google Cloud Logging's global storage location, which is not limited to the EU. To deliver the invitation email, the recipient's email address and the content of the letter are sent to Resend, which processes and holds them in the United States (Section 7), and Resend retains its copy in accordance with its standard retention for sent emails. The notice of your feedback is held in the Feedback app, with Supabase, in a region that has not yet been confirmed.
The website uses Firebase App Check with reCAPTCHA Enterprise, services provided by Google, to protect the Service against automated abuse. To do so, it stores strictly necessary security data in your browser and sends technical signals about your browser and device to Google for risk assessment. This is done solely for security, fraud and abuse prevention, and never for analytics or advertising.
6. Data Protection Rights
Where MANI acts as Data Controller, individuals may have rights under applicable data protection law, including rights to access, correct, delete, restrict, or object to certain processing and, where applicable, receive their personal data in a portable format.
Requests may be sent to support@utredningsgranskaren.se. They are handled manually, and answered within one month.
Where a request concerns Customer Content processed for an Organization User, that organization is normally the Data Controller. MANI will assist the organization as required under applicable law.
Because Customer Content is deleted through the Zero Data Retention architecture, MANI will normally no longer hold the relevant Customer Content when a request is received. The data described in Section 5a is held, and is covered by these rights.
Individuals may also lodge a complaint with the competent data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
7. Cloud Infrastructure and Subprocessors
GRANSKA uses Google Cloud and Google Gemini for cloud infrastructure and AI processing.
The relevant Google Cloud contracting entity is Google Cloud EMEA Limited.
The Service is configured so that Customer Content is processed within Europe/EU/EEA, apart from the log entries described in Section 3, and AI processing takes place through Google's EU multi-region on a Google Cloud endpoint with data residency restricted to EU Member States.
Customer Content submitted to the AI service is not used to train Google's or MANI's AI models.
Sign-in details are handled by Firebase Authentication, a Google service that processes them only in the United States (Section 5a).
Email that the Service sends, such as invitations to join an organization, is delivered by Plus Five Five, Inc. (trading as Resend). Resend receives the recipient's email address and the content of the message, never Customer Content. Resend processes data in the United States; the transfer is covered by the EU Commission's standard contractual clauses.
MANI may use other subprocessors where necessary to provide the Service. Subprocessors that process Customer Content must be subject to appropriate confidentiality, security, and data protection obligations.
Where personal data is transferred internationally, MANI uses the safeguards required by applicable data protection law.
Additional rules for Organization Users are set out in Schedule 1.
8. User Obligations
Users must not:
- use GRANSKA unlawfully;
- submit material they are not legally permitted to process;
- attempt to gain unauthorized access to the Service or its systems;
- interfere with the security or operation of GRANSKA;
- systematically extract or reproduce the Service or its underlying architecture for the purpose of developing a competing service; or
- present GRANSKA output as an authoritative legal or professional determination without appropriate independent assessment.
Users are responsible for the material they choose to submit and for how they use the resulting analysis.
9. Intellectual Property
MANI owns or licenses the intellectual property rights in GRANSKA, including its software, interface, prompt architecture, methods, design, and trademarks.
Users receive a limited, non-exclusive, non-transferable, and revocable right to use the Service for its intended purpose and in accordance with these Terms.
MANI acquires no ownership rights in Customer Content.
Subject to any third-party rights in the underlying material, users and customer organizations may use reports generated for them for their own purposes.
10. Changes, Availability, and Suspension
MANI may update GRANSKA and these Terms when necessary for legal, security, technical, or operational reasons.
Material changes will be communicated in an appropriate manner before they take effect where required by applicable law.
MANI may suspend or restrict access where reasonably necessary to protect the Service, prevent misuse, address security risks, or comply with law.
Nothing in this Section limits rights that cannot lawfully be excluded.
11. Liability
GRANSKA is a decision-support tool, and its output may contain errors. Users must independently assess output before relying on it.
To the maximum extent permitted by applicable law, MANI is not liable for indirect or consequential loss, loss of profit or business, litigation costs, or other losses resulting from reliance on AI-generated output without appropriate independent assessment.
MANI is not responsible for the outcome of legal, administrative, professional, or other proceedings in which GRANSKA output is used.
Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited.
12. Private Users and Consumer Rights
Private Users may access GRANSKA without a subscription or payment.
If a Private User qualifies as a consumer under applicable law, any mandatory consumer rights remain unaffected by these Terms.
Nothing in these Terms excludes, restricts, or replaces a consumer right that cannot legally be excluded, restricted, or replaced.
13. Governing Law and Disputes
These Terms are governed by Swedish law.
For Organization Users, disputes that cannot be resolved amicably shall be determined by a competent Swedish court.
For consumers, the choice of Swedish law does not deprive the consumer of mandatory protections available under the law that would otherwise apply to the consumer.
Any mandatory rules concerning where a consumer may bring or be subject to legal proceedings also remain unaffected.
14. Contact
The Service is provided by:
MANI Dev AB, Swedish company registration number 559582-2338, trading as GRANSKA. Email: support@utredningsgranskaren.se
Schedule 1 – Data Processing Terms
These Data Processing Terms apply whenever MANI processes personal data on behalf of an Organization User acting as Data Controller.
They form part of the agreement between MANI and the organization and are intended to satisfy the requirements applicable to processor agreements under Article 28 GDPR and corresponding requirements under other applicable data protection laws.
If these Data Processing Terms conflict with another provision of the Terms regarding MANI's processing of Customer Content on behalf of an organization, this Schedule prevails.
1. Subject Matter and Instructions
MANI processes Customer Content solely to provide the document review requested by the Controller.
The Controller's use of GRANSKA, selections made within the Service, and other documented instructions constitute the Controller's instructions to MANI.
MANI shall process personal data only on documented instructions from the Controller unless required to do otherwise by applicable law. Where legally permitted, MANI shall inform the Controller before carrying out processing required by law.
If MANI considers an instruction to violate applicable data protection law, MANI shall inform the Controller without undue delay.
2. Nature, Purpose, and Duration
Processing may include receiving, extracting, transmitting, temporarily storing, analyzing, and deleting Customer Content for the purpose of generating and delivering the requested review.
The processing relationship continues for as long as the organization uses GRANSKA.
Individual Customer Content is processed only temporarily and is deleted in accordance with the Zero Data Retention rules in Section 3 of the Terms, and in any event no later than 30 minutes after the review has been completed or aborted.
Two exceptions described in Section 3 of the Terms are not covered by that bound: the error description on a usage receipt written before 25 August 2026, which may quote text from the document that was being reviewed and which is currently kept without a set end date on the receipt and for 400 days in its statistics copy (Section 5a), and an error message in Google Cloud's own logs, which may quote text from a document or its analysis and is deleted after 30 days.
3. Personal Data and Data Subjects
Customer Content may include:
- names and contact information;
- personal identity numbers and other identifiers;
- family, employment, financial, and social information;
- health information and other special categories of personal data;
- information concerning alleged or actual criminal offenses or proceedings; and
- any other personal data contained in material submitted by the Controller.
Data subjects may include:
- customers, clients, employees, and applicants;
- children, parents, guardians, and family members;
- parties to legal or administrative proceedings;
- witnesses and other third parties;
- public officials and case workers; and
- lawyers and other professionals.
The Controller determines which Customer Content is submitted to GRANSKA.
4. Controller Obligations
The Controller is responsible for:
- ensuring that its processing and instructions are lawful;
- establishing the required legal basis for processing;
- providing required information to data subjects;
- complying with applicable requirements for special-category and criminal-offense data; and
- ensuring that its authorized users use GRANSKA in accordance with applicable law and these Terms.
5. MANI's Obligations as Processor
MANI shall:
- process personal data only on documented instructions from the Controller;
- ensure that persons authorized to process personal data are subject to confidentiality obligations;
- implement appropriate technical and organizational security measures;
- assist the Controller, considering the nature of the processing, with requests from data subjects;
- assist the Controller as reasonably required with security obligations, personal data breaches, data protection impact assessments, and prior consultations;
- notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Content;
- make available information necessary to demonstrate compliance with applicable processor obligations; and
- allow and reasonably contribute to audits and inspections required under applicable data protection law.
MANI recognizes that Customer Content may contain highly confidential information, including information protected by legal professional privilege, professional secrecy, or statutory confidentiality.
6. Security
MANI maintains technical and organizational measures appropriate to the nature and risks of the processing.
These include, where applicable:
- encryption in transit;
- encrypted temporary storage;
- isolated processing environments;
- access controls;
- restricted personnel access;
- automated deletion mechanisms;
- content-masked operational logging; and
- procedures for security incidents and system changes.
The Zero Data Retention architecture described in Section 3 is a central security and data minimization measure.
7. Subprocessors
The Controller gives MANI general authorization to engage subprocessors necessary to provide GRANSKA.
The principal subprocessor for cloud infrastructure and AI processing is Google Cloud EMEA Limited, including the use of Google Cloud and Google Gemini.
Plus Five Five, Inc. (trading as Resend) delivers email sent by the Service, such as invitations to the Controller's users. It receives recipient email addresses and message content, never Customer Content, and processes them in the United States under the EU Commission's standard contractual clauses.
MANI shall:
- impose on subprocessors the same data protection obligations applicable to MANI under these Data Processing Terms;
- remain responsible to the Controller for the performance of its processor obligations; and
- inform the Controller of intended additions or replacements of subprocessors, giving the Controller a reasonable opportunity to object on legitimate data protection grounds.
8. International Transfers
MANI shall ensure that transfers of personal data subject to transfer restrictions comply with applicable data protection law.
Where required, MANI will rely on an adequacy decision, approved standard contractual clauses, or another legally recognized transfer mechanism.
The core GRANSKA processing environment is configured for EU-based Customer Content storage, application logic, and AI computation as described in Section 7 of the Terms. The log entries described in Section 3 of the Terms are stored in Google Cloud Logging's global storage location, which is not limited to the EU.
9. Deletion and Return
The parties agree that the Controller's standing instruction is for Customer Content to be deleted in accordance with GRANSKA's Zero Data Retention architecture.
Apart from the receipts and log entries described in paragraph 2 of this Schedule, which may quote parts of it, MANI does not maintain a persistent copy of Customer Content, and none that can be returned. The Controller is therefore responsible for retaining its own original documents and any generated reports it wishes to keep.
Upon termination of the processing relationship, MANI shall delete any remaining personal data processed on behalf of the Controller unless applicable law requires continued retention.
10. Audit and Compliance Information
MANI shall make available information reasonably necessary to demonstrate compliance with its obligations as a processor.
The Controller, or an independent auditor acting on its behalf, may conduct audits or inspections where reasonably necessary to verify compliance with applicable data protection law.
Audits shall, where possible, be conducted in a manner that minimizes disruption to MANI's operations and does not compromise the security or confidentiality of other customers or systems.
11. Order of Precedence
If this Schedule conflicts with another provision of these Terms concerning MANI's processing of personal data on behalf of a Controller, this Schedule prevails.
12. Aggregated Statistics
The Controller agrees that MANI may derive aggregated statistics from its provision of the Service: the number of reviews, their duration, the AI resources and cost they used, and the number of shortcomings and strengths found per area of law. Such statistics never include Customer Content, document text, quotes, or the wording of any finding, and are compiled per organization and never per individual user. Once aggregated in this way they are not Customer Content; MANI processes them as Data Controller for the purposes described in Section 5 of the Terms.