Traece B.V., operating as **Grasp** ("Grasp," "we," "our," "us"), respects your privacy and is committed to protecting the personal data of our customers, their users, and visitors to our website. This Privacy Policy explains how we collect, process, store, and protect personal data, and outlines your rights under the **EU General Data Protection Regulation (GDPR)**.
Grasp is a **B2B AI Governance platform** that helps organizations discover, govern, and manage AI tools and software — including shadow AI detection, continuous compliance monitoring against frameworks such as the EU AI Act, ISO 27001, and ISO 42001, and risk management across the full application landscape.
We act as a:
For any privacy-related questions or requests, you can reach our privacy contact at **info@joingrasp.com**.
Our commitment is to **data protection, transparency, and security** at all times.
When providing our platform, we process personal data from several sources. The categories below summarise this processing; the authoritative description is set out in **Annex I of our DPA**.
**Identity Provider (SSO) Data**
Grasp connects to your organization's Identity Provider (Google Workspace or Microsoft Entra ID) to build a complete view of your application landscape. We process:
**Desktop Agent Data**
Where deployed (distributed via your organization's MDM solution), Grasp's lightweight desktop agent detects the software and web applications in use across your environment, including shadow IT and shadow AI tools. The agent processes:
To protect employee privacy, the agent is configured to minimise its footprint:
The agent collects domain-level signals only. It does **NOT** collect: full URLs, page paths, or query strings (anything beyond the top-level domain); the content of web pages; screenshots or screen recordings; form inputs; keystrokes or keyboard input; file contents or file names on the device; passwords; or microphone, camera, or other sensor data.
The agent is designed to identify *which* applications and web services are in use — not to monitor *what* employees do inside those applications.
**Platform Activity Data**
**Special categories of data.** The Services are not intended to process special categories of personal data (Article 9 GDPR), and customers are contractually required not to submit such data to the Services.
Customer and user data is never used to train AI models.
When interacting with our website, newsletter, or trial signup forms, we may collect:
We only process personal data for legitimate and necessary purposes:
1. **Delivering Our Services** — Operate, maintain, and improve the Grasp platform; provide application discovery, shadow AI detection, compliance monitoring, governance dashboards, AI-powered insights, and agent recommendations.
2. **Security and Compliance** — Monitor access, detect anomalies, and prevent unauthorized activity; protect against fraud, abuse, or data breaches; support our customers' compliance obligations under frameworks including the EU AI Act, ISO 27001, ISO 42001, and SOC 2.
3. **Customer Support & Communication** — Respond to inquiries and provide technical support; communicate product updates, release notes, and relevant announcements.
4. **Legal & Regulatory Obligations** — Comply with applicable laws, regulations, or court orders.
**Note:** Personal data is not used for AI model training or sold to third parties.
Under GDPR, Traece processes personal data on one or more legal grounds. Where Grasp acts as a **processor**, we process customer and user data on the **documented instructions of the customer (the controller)**, and the customer is responsible for establishing the legal basis for that processing. Where Grasp acts as a **controller** (website, marketing, and direct contacts), the legal bases below apply.
Where we rely on legitimate interests, we conduct balancing tests to ensure our interests do not override the rights of data subjects. Where we rely on consent (e.g., marketing communications, cookie consent), it is requested explicitly and can be withdrawn at any time.
Grasp uses AI-powered features to assist our customers with governance decisions, including agent recommendations (e.g., suggesting whether to approve, block, or investigate an application) and risk scoring.
These features are **advisory only**. All governance decisions are made by authorized human users (typically CISOs or IT administrators) within the customer's organization. Grasp does not make automated decisions that produce legal or similarly significant effects on individuals without human review.
Confidence scores and recommendations are generated based on the customer's own precedent data and configurable rules — not on profiling of individual employees.
We **do not sell personal data**. We share personal data only where necessary to deliver our services, and only with the following **categories of recipients**:
A complete and up-to-date list of the sub-processors that process customer data on our customers' behalf — including each provider's name, purpose, and data location — is maintained in **Annex III of our DPA**, which forms part of our customer contracts. Providers used for our own website and marketing activities (where Grasp is the controller) fall under the categories above and this Privacy Policy. Customers are notified of any changes to our sub-processors, and may exercise any objection rights, in accordance with **Section 6 of the DPA**.
Most processing takes place within the EU/EEA. A limited number of sub-processors process specific data outside the EU/EEA — for example, AI and web-research providers (which receive domains, application names, and similar non-identifying signals), breach-exposure checks (which receive email addresses), and limited onward payment-processing transfers. Where this occurs:
The specific transfer locations and mechanisms applicable to each sub-processor are set out in **Section 10 and Annex III of our DPA**.
Retention follows the schedule in **Section 12 of our DPA**, which is the authoritative source for customer data:
Traece implements **technical and organizational measures** appropriate to the risk, in line with Article 32 GDPR. These are set out in full in **Annex II of our DPA** and include:
We conduct **Data Protection Impact Assessments (DPIAs)** for high-risk processing activities, including desktop agent deployment, in accordance with GDPR Article 35.
Data subjects have the following rights under GDPR:
1. **Access** — request a copy of your personal data
2. **Correction** — correct inaccurate or incomplete data
3. **Erasure** — request deletion of personal data (subject to contractual or legal limits)
4. **Restriction** — limit the processing of your personal data in specific contexts
5. **Objection** — object to processing based on legitimate interests
6. **Data Portability** — request a machine-readable copy of your data for transfer
7. **Withdraw Consent** — where processing is based on consent, you may withdraw it at any time
**For employees of Grasp customers:** your employer is the data controller. Please direct data subject requests to your organization's IT or privacy team in the first instance. We will assist your employer in fulfilling these requests in accordance with our DPA.
**For website visitors and direct contacts:** contact us directly at **info@joingrasp.com**.
We respond to all data subject requests within **30 days** as required by GDPR.
If a personal data breach occurs:
Grasp uses cookies and similar technologies on our website for analytics, performance, and marketing purposes.
Cookie data is **not sold** and is only shared with authorized sub-processors. For full details, see our [Cookie Policy](https://joingrasp.com/legal/cookies).
Grasp uses a large language model (provided via OpenAI's API) to **classify and reason over signals in your AI-tool catalog**. Inputs may include application names, process names, bundle identifiers, and domains derived from your environment. **No directly identifying personal data** of data subjects (such as names or email addresses) is transmitted to this provider.
**Greppy**, our AI agent, is part of the Grasp platform. It does not currently run on a third-party AI model. If and when a model provider is introduced for Greppy, the applicable provider terms — including the exclusion of customer data from model training — will apply and be available for review under NDA.
This section is consistent with **Section 14 and Annex III of our DPA**. We are committed to responsible AI use and monitor our own compliance with the EU AI Act as it applies to our platform.
We may update this Privacy Policy from time to time. Significant updates will be communicated through our platform, website, or email at least **30 days** before they take effect. The "Effective Date" at the top of this page reflects the most recent revision.
For questions, data subject requests, or GDPR inquiries:
**Traece B.V., operating as Grasp**
If you are unsatisfied with our response, you have the right to lodge a complaint with the **Autoriteit Persoonsgegevens** (Dutch Data Protection Authority) at [autoriteitpersoonsgegevens.nl](https://www.autoriteitpersoonsgegevens.nl).
