Privacy Policy

28 June 2026
info@joingrasp.com
joingrasp.com

1. Who We Are

Traece B.V., operating as **Grasp** ("Grasp," "we," "our," "us"), respects your privacy and is committed to protecting the personal data of our customers, their users, and visitors to our website. This Privacy Policy explains how we collect, process, store, and protect personal data, and outlines your rights under the **EU General Data Protection Regulation (GDPR)**.

Grasp is a **B2B AI Governance platform** that helps organizations discover, govern, and manage AI tools and software — including shadow AI detection, continuous compliance monitoring against frameworks such as the EU AI Act, ISO 27001, and ISO 42001, and risk management across the full application landscape.

We act as a:

  • **Data Processor** — when processing customer data on behalf of our clients (who are the data controllers). This processing is governed by our DPA.
  • **Data Controller** — when collecting data from website visitors, trial signups, or marketing contacts.

For any privacy-related questions or requests, you can reach our privacy contact at **info@joingrasp.com**.

Our commitment is to **data protection, transparency, and security** at all times.

2. Types of Data We Collect

A. Customer & User Data (Processed on Behalf of Customers)

When providing our platform, we process personal data from several sources. The categories below summarise this processing; the authoritative description is set out in **Annex I of our DPA**.

**Identity Provider (SSO) Data**

Grasp connects to your organization's Identity Provider (Google Workspace or Microsoft Entra ID) to build a complete view of your application landscape. We process:

  • Directory data and organizational structure (departments, teams, roles, managers)
  • Connected applications and AI tool sign-in events visible in the SSO directory
  • Authentication and access metadata (SSO login activity, session metadata, MFA status, OAuth scopes; OAuth tokens are encrypted at rest)

**Desktop Agent Data**

Where deployed (distributed via your organization's MDM solution), Grasp's lightweight desktop agent detects the software and web applications in use across your environment, including shadow IT and shadow AI tools. The agent processes:

  • Device identifier and hardware metadata (device model, operating system, hostname)
  • Installed application inventory and versions
  • Application and process names, and bundle/package identifiers
  • Number of application sessions
  • **Visited domains** and browser extension identifiers

To protect employee privacy, the agent is configured to minimise its footprint:

  • It operates **only during configured working hours** (by default **09:00–17:00**). Administrators can adjust this window in Grasp's settings where needed.
  • It distinguishes business from personal browsing using the managed company browser profile.

The agent collects domain-level signals only. It does **NOT** collect: full URLs, page paths, or query strings (anything beyond the top-level domain); the content of web pages; screenshots or screen recordings; form inputs; keystrokes or keyboard input; file contents or file names on the device; passwords; or microphone, camera, or other sensor data.

The agent is designed to identify *which* applications and web services are in use — not to monitor *what* employees do inside those applications.

**Platform Activity Data**

  • Login and activity data within the Grasp platform itself
  • Role, permissions, and departmental information within Grasp
  • Governance decisions and their recorded reasons (approve, block, and dismiss actions are logged with user attribution for compliance and audit purposes)
  • Support tickets or correspondence with our support team

**Special categories of data.** The Services are not intended to process special categories of personal data (Article 9 GDPR), and customers are contractually required not to submit such data to the Services.

Customer and user data is never used to train AI models.

B. Website & Marketing Data

When interacting with our website, newsletter, or trial signup forms, we may collect:

  • Name, business email, company name, job title
  • IP address, browser type, device information
  • Cookies or similar technologies for marketing, analytics, and performance (subject to your consent via our cookie consent banner)

3. How We Use Personal Data

We only process personal data for legitimate and necessary purposes:

1. **Delivering Our Services** — Operate, maintain, and improve the Grasp platform; provide application discovery, shadow AI detection, compliance monitoring, governance dashboards, AI-powered insights, and agent recommendations.

2. **Security and Compliance** — Monitor access, detect anomalies, and prevent unauthorized activity; protect against fraud, abuse, or data breaches; support our customers' compliance obligations under frameworks including the EU AI Act, ISO 27001, ISO 42001, and SOC 2.

3. **Customer Support & Communication** — Respond to inquiries and provide technical support; communicate product updates, release notes, and relevant announcements.

4. **Legal & Regulatory Obligations** — Comply with applicable laws, regulations, or court orders.

**Note:** Personal data is not used for AI model training or sold to third parties.

4. Legal Basis for Processing

Under GDPR, Traece processes personal data on one or more legal grounds. Where Grasp acts as a **processor**, we process customer and user data on the **documented instructions of the customer (the controller)**, and the customer is responsible for establishing the legal basis for that processing. Where Grasp acts as a **controller** (website, marketing, and direct contacts), the legal bases below apply.

Processing activity | Role | Purpose | Legal basis | Retention SSO / application landscape mapping | Processor | Application discovery and governance | Controller's instructions (controller determines basis) | Duration of contract; deleted per DPA §12 Desktop agent usage metadata | Processor | Shadow IT / AI detection, compliance reporting | Controller's instructions (controller determines basis) | Duration of contract; deleted per DPA §12 Platform activity & governance audit trail | Processor | Operate the platform; audit and compliance | Controller's instructions / contractual necessity | Duration of contract; deleted per DPA §12 Support correspondence | Controller / Processor | Provide technical support | Contractual necessity / legitimate interests | Duration of contract + 12 months Website & marketing data | Controller | Marketing, analytics, lead generation | Consent (marketing/analytics); legitimate interests (basic site operation and security) | Up to 36 months Security monitoring & fraud prevention | Controller | Protect the platform and its data | Legitimate interests | Per our security logging policy

Where we rely on legitimate interests, we conduct balancing tests to ensure our interests do not override the rights of data subjects. Where we rely on consent (e.g., marketing communications, cookie consent), it is requested explicitly and can be withdrawn at any time.

5. Automated Decision-Making

Grasp uses AI-powered features to assist our customers with governance decisions, including agent recommendations (e.g., suggesting whether to approve, block, or investigate an application) and risk scoring.

These features are **advisory only**. All governance decisions are made by authorized human users (typically CISOs or IT administrators) within the customer's organization. Grasp does not make automated decisions that produce legal or similarly significant effects on individuals without human review.

Confidence scores and recommendations are generated based on the customer's own precedent data and configurable rules — not on profiling of individual employees.

6. Sharing Personal Data

We **do not sell personal data**. We share personal data only where necessary to deliver our services, and only with the following **categories of recipients**:

  • Cloud infrastructure and hosting providers (EU/EEA)
  • AI / large language model API providers (used to classify and reason over AI-tool signals)
  • Web-research and enrichment providers (retrieval of publicly available vendor documentation; breach-exposure checks for email addresses)
  • Payment and billing providers
  • CRM and business-tooling providers
  • Transactional email providers
  • Marketing email and newsletter providers
  • Product analytics providers (anonymized usage data)
  • Security and content-delivery providers

A complete and up-to-date list of the sub-processors that process customer data on our customers' behalf — including each provider's name, purpose, and data location — is maintained in **Annex III of our DPA**, which forms part of our customer contracts. Providers used for our own website and marketing activities (where Grasp is the controller) fall under the categories above and this Privacy Policy. Customers are notified of any changes to our sub-processors, and may exercise any objection rights, in accordance with **Section 6 of the DPA**.

7. International Data Transfers

Most processing takes place within the EU/EEA. A limited number of sub-processors process specific data outside the EU/EEA — for example, AI and web-research providers (which receive domains, application names, and similar non-identifying signals), breach-exposure checks (which receive email addresses), and limited onward payment-processing transfers. Where this occurs:

  • All transfers comply with **Chapter V GDPR**.
  • We rely on an appropriate transfer mechanism — the **EU-US Data Privacy Framework** where the provider is certified, and/or **Standard Contractual Clauses (SCCs)** adopted by the European Commission — and apply supplementary measures (including encryption in transit, encryption at rest, and access controls).
  • Where applicable, we assess the data protection laws of the recipient country in line with EDPB guidance.

The specific transfer locations and mechanisms applicable to each sub-processor are set out in **Section 10 and Annex III of our DPA**.

8. Data Retention

Retention follows the schedule in **Section 12 of our DPA**, which is the authoritative source for customer data:

  • **Customer & User Data** — exportable through the Services during the contract term and during a **30-day post-termination grace period**. After the grace period, customer data is deleted within a further **30 days**, except for the limited categories below.
  • **Encrypted backups** (held by infrastructure sub-processors) — deleted in line with the sub-processor's standard backup cycle, and in any event within **90 days** of termination.
  • **Operational logs** (held by infrastructure sub-processors for security, observability, and abuse prevention) — retained in line with the relevant sub-processor's documented retention policies.
  • **Billing and transaction records** (held by Grasp and our payment provider) — retained for up to **7 years** to comply with Dutch tax and accounting law.
  • **Email delivery logs** (where transactional email is enabled) — retained in line with the email provider's documented retention policy.
  • **Website & Marketing Data** — retained for analytics and marketing purposes for up to **36 months**, unless otherwise required by law or withdrawn by consent.

9. Data Security Measures

Traece implements **technical and organizational measures** appropriate to the risk, in line with Article 32 GDPR. These are set out in full in **Annex II of our DPA** and include:

  • Encryption at rest (AES-256 where provided by the relevant hosting or database provider) and in transit (TLS 1.2 or higher, or equivalent secure transport)
  • Multi-factor authentication (MFA) for all personnel accessing production systems
  • Role-based access control on a least-privilege basis, with logical tenant segregation
  • Backups and durable storage protected by the relevant providers' encryption and resilience controls
  • Security monitoring, logging, and a documented incident response procedure
  • Vulnerability scanning of dependencies and infrastructure
  • Employee confidentiality obligations and security awareness training

We conduct **Data Protection Impact Assessments (DPIAs)** for high-risk processing activities, including desktop agent deployment, in accordance with GDPR Article 35.

10. Data Subject Rights (GDPR)

Data subjects have the following rights under GDPR:

1. **Access** — request a copy of your personal data

2. **Correction** — correct inaccurate or incomplete data

3. **Erasure** — request deletion of personal data (subject to contractual or legal limits)

4. **Restriction** — limit the processing of your personal data in specific contexts

5. **Objection** — object to processing based on legitimate interests

6. **Data Portability** — request a machine-readable copy of your data for transfer

7. **Withdraw Consent** — where processing is based on consent, you may withdraw it at any time

**For employees of Grasp customers:** your employer is the data controller. Please direct data subject requests to your organization's IT or privacy team in the first instance. We will assist your employer in fulfilling these requests in accordance with our DPA.

**For website visitors and direct contacts:** contact us directly at **info@joingrasp.com**.

We respond to all data subject requests within **30 days** as required by GDPR.

11. Data Breach Notification

If a personal data breach occurs:

  • We will notify affected customers (controllers) **without undue delay** and no later than **72 hours** after becoming aware of the breach, in accordance with GDPR Article 33 and **Section 8 of our DPA**.
  • We will provide all information necessary for customers to assess the impact and fulfill their own notification obligations.
  • We will provide assistance to mitigate potential harm and document all breaches in our internal breach register.

12. Cookies and Tracking

Grasp uses cookies and similar technologies on our website for analytics, performance, and marketing purposes.

  • **Strictly necessary cookies** are used without consent (session management, security).
  • **Analytics and marketing cookies** are only placed after you provide consent via our cookie consent banner.
  • You can manage or withdraw cookie consent at any time via the cookie settings on our website.

Cookie data is **not sold** and is only shared with authorized sub-processors. For full details, see our [Cookie Policy](https://joingrasp.com/legal/cookies).

13. Our Own Use of AI

Grasp uses a large language model (provided via OpenAI's API) to **classify and reason over signals in your AI-tool catalog**. Inputs may include application names, process names, bundle identifiers, and domains derived from your environment. **No directly identifying personal data** of data subjects (such as names or email addresses) is transmitted to this provider.

  • We use **API-only access**. Customer data is not used to train, fine-tune, or improve third-party AI models, and our AI sub-processors are engaged under terms that prohibit or default-disable such use.
  • AI outputs within Grasp (recommendations, risk scores) are advisory and always subject to human decision-making by the customer's authorized users.

**Greppy**, our AI agent, is part of the Grasp platform. It does not currently run on a third-party AI model. If and when a model provider is introduced for Greppy, the applicable provider terms — including the exclusion of customer data from model training — will apply and be available for review under NDA.

This section is consistent with **Section 14 and Annex III of our DPA**. We are committed to responsible AI use and monitor our own compliance with the EU AI Act as it applies to our platform.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Significant updates will be communicated through our platform, website, or email at least **30 days** before they take effect. The "Effective Date" at the top of this page reflects the most recent revision.

15. Contact Us

For questions, data subject requests, or GDPR inquiries:

**Traece B.V., operating as Grasp**

  • General inquiries: info@joingrasp.com
  • Website: joingrasp.com
  • Registered office: Vrije Heerlijkheid 39, 1566 MH Assendelft (gemeente Zaanstad), the Netherlands
  • KVK (Chamber of Commerce) number: 98464604

If you are unsatisfied with our response, you have the right to lodge a complaint with the **Autoriteit Persoonsgegevens** (Dutch Data Protection Authority) at [autoriteitpersoonsgegevens.nl](https://www.autoriteitpersoonsgegevens.nl).