Granola
Last Reviewed: 03 Jun 2026
At a Glance
Granola's DPA covers the required processor obligations in respect of customer provided personal data. Granola's DPA explicitly reserves the right to act as an independent controller over Business Contact Data and Usage Data for account management, fraud detection, compliance and other business purposes. Granola also retains aggregated data for AI model training after account termination. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.
Company & Product Details
HQ
United States
Products
AI Meeting Notepad
Product description
Transcribes and summarises meetings using AI.
What data is being processed?
Business Contact Data, Usage Data, Customer Data (including audio or transcript captured using the Services)
Document Details
Date of DPA
02 Jul 2025
Additional date information
DPA last updated 2nd July 2025, as stated in the document header. This DPA supplements Granola's standard Terms of Use and any related Enterprise Order Form (preamble).
What jurisdictions are covered?
EU GDPR (Regulation (EU) 2016/679), UK GDPR (as retained in UK law via the European Union (Withdrawal) Act 2018), UK Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003, Swiss Federal Act on Data Protection (FADP), and applicable US state privacy laws including the CCPA/CPRA. The EU–US Data Privacy Framework, UK Extension, and Swiss–US Data Privacy Framework are also referenced (clause 1.2, sections 6.2, 6.3, 6.4).
Is the DPA incorporated into service or customer agreements?
Link
https://docs.granola.ai/help-center/policies/data-processing-addendum
Location & Transfers
Where is data held or processed?
United States Granola's primary processing operations take place in the United States. Transfers of Personal Data to the US are necessary for the provision of the Services. Transfers outside the EEA, UK, and Switzerland are addressed through the Data Privacy Framework or Standard Contractual Clauses where the Framework does not apply or ceases to be available (section 6.1).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Granola commits to maintaining appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing Personal Data. The specific measures are described on Granola's Trust Center at trust.granola.ai, which is incorporated as the Annex II security information for the EU SCCs (section 5, Exhibit B).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Without undue delay upon becoming aware of a Personal Data Breach, Granola informs Customer and takes steps deemed necessary and reasonable to remediate the breach. Granola provides reasonable cooperation to assist Customer in notifying the relevant Supervisory Authority and affected Data Subjects. Notification obligations do not apply where the breach results from Customer's own actions or omissions (sections 9.1, 9.2, 9.3).
What happens to the data on termination?
Upon termination or expiration of the Agreement, Granola returns or deletes Personal Data at Customer's choice, unless further storage is required or authorised by applicable law. If return or deletion is impracticable or prohibited by law, Granola blocks the Personal Data from any further processing (other than as required by law) and continues to protect it appropriately. Certification of deletion is provided by Granola to Customer only upon Customer's request (section 10).