Granola

Last Reviewed: 03 Jun 2026

Data Use Review

At a Glance

Granola's DPA covers the required processor obligations in respect of customer provided personal data. Granola's DPA explicitly reserves the right to act as an independent controller over Business Contact Data and Usage Data for account management, fraud detection, compliance and other business purposes. Granola also retains aggregated data for AI model training after account termination. We recommend this contract is manually reviewed to ensure the data use terms are acceptable to you.

Company & Product Details

HQ

United States

Products

AI Meeting Notepad

Product description

Transcribes and summarises meetings using AI.

What data is being processed?

Business Contact Data, Usage Data, Customer Data (including audio or transcript captured using the Services)

Document Details

Date of DPA

02 Jul 2025

Additional date information

DPA last updated 2nd July 2025, as stated in the document header. This DPA supplements Granola's standard Terms of Use and any related Enterprise Order Form (preamble).

What jurisdictions are covered?

EU GDPR (Regulation (EU) 2016/679), UK GDPR (as retained in UK law via the European Union (Withdrawal) Act 2018), UK Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003, Swiss Federal Act on Data Protection (FADP), and applicable US state privacy laws including the CCPA/CPRA. The EU–US Data Privacy Framework, UK Extension, and Swiss–US Data Privacy Framework are also referenced (clause 1.2, sections 6.2, 6.3, 6.4).

Is the DPA incorporated into service or customer agreements?

Yes
The DPA supplements Granola's standard Terms of Use and any related Enterprise Order Form. In the event of conflict, the order of precedence is: (1) applicable Standard Contractual Clauses; (2) this DPA; (3) the Agreement; (4) Granola's privacy policy. All claims arising from this DPA are subject to the terms and limitations of the Agreement (preamble, section 12).

Location & Transfers

Where is data held or processed?

United States Granola's primary processing operations take place in the United States. Transfers of Personal Data to the US are necessary for the provision of the Services. Transfers outside the EEA, UK, and Switzerland are addressed through the Data Privacy Framework or Standard Contractual Clauses where the Framework does not apply or ceases to be available (section 6.1).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
EU SCCs (Commission Decision 2021/914, 4 June 2021) are incorporated as a fallback for ex-EEA transfers where the Data Privacy Framework does not apply, with Modules 1 (C2C), 2 (C2P), or 3 (P2SP) applied as relevant; governed by Irish law with disputes before Irish courts. UK Addendum (ICO, s119A Data Protection Act 2018) incorporated as a fallback for ex-UK transfers. Swiss transfers handled via EU SCCs with FADP-specific modifications, including the FDPIC as the competent supervisory authority (sections 6.2, 6.3, 6.4).

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Granola commits to maintaining appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing Personal Data. The specific measures are described on Granola's Trust Center at trust.granola.ai, which is incorporated as the Annex II security information for the EU SCCs (section 5, Exhibit B).

Non Processor Data Use

Does the company process data solely as a processor?

No
The DPA explicitly states that the parties acknowledge and agree that Granola may process Business Contact Data and Usage Data as an independent controller (not a joint controller with Customer). Granola processes these categories as controller for the following purposes: (i) to manage its relationship with Customer; (ii) core business operations (accounting, audits, tax, compliance); (iii) monitoring, investigating, and detecting fraud, security incidents and misuse; (iv) identity verification; (v) compliance with legal or regulatory obligations; and (vi) as otherwise permitted under Privacy Laws. Additionally, Granola retains aggregated, de-identified, or anonymised data to train its machine learning or artificial intelligence models and to improve Granola's products and services, including after termination of the account or Services. (DPA, independent controller section and aggregated data provisions)

Subprocessing

General authorization

General
General written authorisation is granted by this DPA for Granola to engage its Affiliates and the Authorised Subprocessors listed in Exhibit B, and to engage additional third parties as needed for the Services. A current list of subprocessors is published at trust.granola.ai/subprocessors. Granola provides at least 10 days' prior notice before enabling any new subprocessor. Customer may object within 10 days on data protection grounds; if Granola cannot offer a commercially reasonable alternative, Customer may discontinue the affected service. Failure to object within 10 days constitutes deemed approval (sections 4.1, 4.2, 4.3, 4.4).

Do all the DPA terms flow down to sub-processors?

Yes
Granola enters into written agreements with Authorised Subprocessors imposing data protection obligations comparable to those in this DPA. Granola remains liable to Customer for any failure by a subprocessor to fulfil its data protection obligations. Where SCCs apply, the subprocessor authorisation constitutes Customer's prior written consent under Clause 9(c) of the EU SCCs (section 4.5).

Is data only processed on the instruction of the controller?

Yes
Granola processes Personal Data only: (i) for purposes set out in the Agreement; (ii) in a manner consistent with Customer's documented instructions, which include the Agreement and this DPA; and (iii) as required by Privacy Laws or a supervisory authority, with prior notice to Customer where legally permitted. Granola must immediately notify Customer if an instruction is believed to infringe Privacy Laws (sections 2.2, 2.4).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
Upon receipt of a Data Subject Request, Granola notifies Customer and advises the Data Subject to submit their request directly to Customer. At Customer's request, and where Customer cannot respond independently, Granola applies appropriate technical and organisational measures to assist with responding to Data Subject Requests. Customer bears costs of any such assistance (sections 7.1, 7.2, 7.3).

Does the contract include staff confidentiality clauses?

Yes
Granola ensures that any person authorised to process Personal Data has agreed to protect that data in accordance with Granola's confidentiality obligations in the Agreement. Granola may also disclose Personal Data to advisers, auditors, or third parties as reasonably required in connection with its obligations under the DPA, Agreement, or provision of Services (sections 3.1, 3.2).

Are there audit rights for the data?

Structured
Upon Customer's written request at reasonable intervals and subject to confidentiality controls, Granola either: (i) provides copies of certifications or compliance reports demonstrating adherence to prevailing data security standards; or (ii) if reports are insufficient under Privacy Laws, allows Customer's independent third-party representative to conduct an audit of Granola's data security infrastructure. Audit conditions: reasonable prior written notice required; business hours only; maximum once per calendar year; restricted to Customer-relevant data; Customer bears all costs. Audit rights are linked to EU SCCs Clause 8.9 (section 8.3).

Is there assistance with DPIA requests?

Yes
Granola provides reasonable cooperation and assistance for Customer to conduct Data Protection Impact Assessments (DPIAs) and/or to demonstrate compliance with Privacy Laws, where Customer does not already have access to the relevant information. Granola also assists with Customer's prior consultation with Supervisory Authorities or regulatory agencies where required by Privacy Laws. Customer bears costs of such assistance (sections 8.1, 8.2).

How much notice is provided for data breaches?

Without undue delay upon becoming aware of a Personal Data Breach, Granola informs Customer and takes steps deemed necessary and reasonable to remediate the breach. Granola provides reasonable cooperation to assist Customer in notifying the relevant Supervisory Authority and affected Data Subjects. Notification obligations do not apply where the breach results from Customer's own actions or omissions (sections 9.1, 9.2, 9.3).

What happens to the data on termination?

Upon termination or expiration of the Agreement, Granola returns or deletes Personal Data at Customer's choice, unless further storage is required or authorised by applicable law. If return or deletion is impracticable or prohibited by law, Granola blocks the Personal Data from any further processing (other than as required by law) and continues to protect it appropriately. Certification of deletion is provided by Granola to Customer only upon Customer's request (section 10).