ILegal framework
Data processing under Art. 28 GDPR.
When we operate Grantifex for you, we process personal data on your behalf.
When foundations, public authorities or other organisations run their grant portal as a Grantifex instance hosted by us, we process personal data — for example of applicants and reviewers — exclusively on their behalf. The organisation remains the controller within the meaning of the GDPR; we act as the processor.
Art. 28 GDPR requires a data processing agreement (DPA) for this. It bindingly defines the subject matter, duration, nature and purpose of the processing as well as the obligations of both parties. For productive use of Grantifex, our customers conclude such a DPA with us.
IIKey terms
What our DPA covers.
The essential commitments in brief.
- Documented instructions — we process data exclusively on the customer's documented instructions.
- Technical and organisational measures (TOMs) — encryption, access control, tenant separation and backups, documented as an annex to the agreement.
- Sub-processors — listed by name; changes are announced in advance, with a right to object.
- Deletion concept — defined periods for the deletion and return of all data at the end of the contract.
- Audit rights — customers may verify compliance themselves or have it verified.
We provide the complete data processing agreement on request: [email protected].
IIIDemo instances
Demos run on test data.
A simple rule applies to demo instances: no real personal data.
Demo instances are for evaluation and process test data only. Please do not enter any real personal data into a demo — neither of applicants nor of staff. Demo instances are deleted completely after 14 days; a data processing agreement is only concluded when moving to productive operation.
IVSub-processors
Our current list of sub-processors.
These service providers are used to operate hosted Grantifex instances.
- netcup GmbH, Daimlerstrasse 25, 76185 Karlsruhe, Germany — server infrastructure and hosting of the instances (data centre in Germany).
- IONOS SE, Elgendorfer Strasse 57, 56410 Montabaur, Germany — sending and receiving e-mail (transactional and notification mails).
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA — DNS, content delivery, DDoS/bot protection and web application firewall. Transfers based on the EU-US Data Privacy Framework and the EU standard contractual clauses.
Backups are stored encrypted on infrastructure operated by us in Germany; no further service provider is involved. We announce changes to this list to DPA customers in advance — with a right to object.
As of: 13 June 2026.