Data Processing Terms
Processor terms applying where customer data contains personal data.
- Version
- 1.0
- Effective date
- 17 August 2026
- Last updated
- 17 August 2026
- Document owner
- the Groundmaster project, with responsibility assigned to its legal and compliance function
- Applicable jurisdiction
- Portugal, European Union
- Permanent URL
- https://www.groundmaster.pt/legal/dpa
1.Roles
The Customer is the controller for personal data contained in its Organisation workspace and determines the purposes and means of that processing. the Groundmaster project is the processor and processes such data only on the Customer's documented instructions, which include the configuration choices made in the Platform and the use of its features.
2.Subject matter, duration and nature of processing
| Element | Description |
|---|---|
| Subject matter | Provision of the Platform as described in the Terms of Use and Documentation |
| Duration | The term of the Subscription, plus any export and deletion periods set out in the Data Retention & Deletion Policy |
| Nature and purpose | Hosting, storage, retrieval, structuring, transmission, display, backup, security monitoring, support and AI-assisted analysis initiated by Users |
| Types of personal data | Identity and contact data, credentials and authentication metadata, role and permission data, personnel and qualification documents, activity and audit data, records containing personnel identifiers, and AI interaction data |
| Categories of data subjects | Authorised Users and administrators, personnel of the Customer and its contractors, and individuals named in operational or technical records |
3.Processor obligations
- process personal data only on documented instructions and not for our own purposes;
- ensure personnel with access are bound by confidentiality and act on a need-to-know basis;
- implement and maintain appropriate technical and organisational measures;
- assist the Customer with data subject requests, impact assessments and consultations with supervisory authorities;
- notify the Customer without undue delay after becoming aware of a personal data breach affecting its data;
- make available information reasonably necessary to demonstrate compliance;
- delete or return personal data at the end of processing, subject to legal retention requirements.
4.Controller obligations
- ensure a lawful basis exists for the data it places in the Platform and for the instructions it gives;
- provide the required transparency information to its own personnel and other data subjects;
- configure roles, permissions, page-level access, retention settings and sharing appropriately;
- keep access lists current, and suspend or remove access when no longer required;
- avoid submitting special categories of personal data unless a lawful basis and safeguards are in place.
5.Security measures
We maintain measures including encryption in transit and at rest, row-level access enforcement, role-based and page-level authorisation, logical tenancy separation, least-privilege administrative access, secret management, audit logging, monitoring and alerting, secure development practices, dependency review, backup and restoration testing, and defined incident response. The Security Overview describes these controls; measures may be updated provided the level of protection is not reduced.
6.Subprocessing
The Customer authorises the use of subprocessors for hosting, storage, authentication, email delivery, model inference, monitoring and similar functions, by category as described in the Subprocessors document. Each subprocessor is bound by written terms imposing protection obligations no less protective than these terms. We remain responsible for their performance and will give notice of intended changes so that the Customer may object on reasonable data protection grounds.
7.International transfers
Transfers outside the European Economic Area rely on an adequacy decision or on appropriate safeguards such as standard contractual clauses, together with a transfer risk assessment and supplementary measures where required. Primary hosting and processing regions are the European Economic Area (EEA), where technically available; any processing by third-party subprocessors outside the EEA is subject to appropriate GDPR safeguards, including Standard Contractual Clauses where applicable.
8.AI processing
Where a User invokes an AI-assisted feature, the prompt and the context required to answer it are transmitted to a model provider acting as subprocessor, solely to return a response. Providers are contractually prohibited from using that content to train their models. AI output is generated for the requesting Organisation only.
9.Audits and assistance
On reasonable written request and subject to confidentiality, we will provide information about our processing and security measures, and will cooperate with audits that are proportionate, scheduled in advance, and limited to what is necessary to verify compliance.
10.Return and deletion
At the end of processing, personal data is deleted or returned in accordance with the Data Retention & Deletion Policy and the Data Export & Portability Policy, except where retention is required by law. Backup copies are removed on their normal expiry cycle.
11.Liability and precedence
Liability under these terms is subject to the limitations in the Terms of Use, except where applicable data protection law provides otherwise. In case of conflict, these terms prevail for personal data processing.
Change history
| Version | Date | Change |
|---|---|---|
| 1.0 | 17 August 2026 | Initial processor terms covering scope, security, subprocessing, transfers and assistance. |
Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.