Trust Center
Our commitment to security, privacy, and transparent data practices.
1. How We Handle Your Data
At GRAP Solutions, trust is our core operating principle. We work under standard enterprise security requirements:
- NDA and DPA on every engagement: Signed before any project data changes hands, as standard practice, not an optional add-on.
- GDPR-aligned data handling: We implement strict data minimization, defined retention periods, and have a dedicated named process for access or deletion requests.
- Written security policy: Internal access controls, physical security, and PII-handling procedures are documented and available for review during vendor onboarding.
2. Compliance and Certification Status
We believe in absolute transparency about where we stand regarding formal certifications:
| Framework | Status | Notes |
|---|---|---|
| GDPR | Aligned | Data minimization, strict retention, and DPAs executed on all contracts. |
| HIPAA | Aligned Workflows | BAAs available on request for healthcare/medical data projects. |
| SOC 2 Type II | Audit In Progress | Formal audit cycle currently underway with external auditors. |
| ISO/IEC 27001 | Not Yet In Place | Processes and policies are aligned; formal audit planned. |
3. Authorized Subprocessors
To deliver our secure annotation, translation, and collection platforms, GRAP Solutions works with the following subprocessors:
| Entity Name | Service Description | Data Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting infrastructure, databases, and secure workspaces | US / EU / India (Configured per contract) |
| Google Cloud Platform | Auxiliary compute, backup hosting, and client deliverables transfer | US / EU / India (Configured per contract) |
| Formspree, Inc. | Contact form transmission and processing | United States |
4. Data Residency Options
Enterprise clients can specify geographic region restrictions for datasets under annotation. We support isolated data storage and workspace compute environments restricted to EU-only, US-only, or India-only availability zones, preventing egress across geographic boundaries.
5. Contact Security Group
For DPO inquiries, data access requests, or to review our complete written security policies, please contact our team at production@grap-solutions.com.