Last updated 4 October 2026

Data Processing Agreement

This agreement (“DPA”) is part of the Terms of Service between Massive Dynamic Limited (“Processor”) and the customer (“Controller”). It applies when we process personal data on the Controller’s behalf in providing Grounded. If it conflicts with the Terms on data protection, this DPA prevails.

It takes effect when you accept the Terms. To receive a signed copy, write to the address at the end of this page.

1. Scope of the processing

  • Subject matter and duration: providing the Service, for as long as the Controller has an account, plus the deletion period in section 9.
  • Nature and purpose: storing documents, building a search index, retrieving passages and generating answers with language models, recording conversations and ratings, and showing analytics to the Controller.
  • Data subjects: the Controller’s users; visitors who use the Controller’s widget or MCP endpoint; people named in the Controller’s documents.
  • Personal data: whatever the Controller’s documents and its visitors’ questions contain; the website a widget is used on; ratings and handoff clicks; a salted hash of the visitor’s IP address for rate limiting. The Controller must not submit special categories of data (Terms, section 4).

2. Instructions

We process personal data only on the Controller’s documented instructions — the Terms, this DPA and the Controller’s use of the Service’s settings — unless the law requires otherwise, in which case we will tell the Controller first unless the law forbids it. We will tell the Controller if we believe an instruction breaks data protection law.

3. Confidentiality

Everyone we authorise to process personal data is bound by confidentiality. Customer data is never used to train models, by us or by the model providers we route to.

4. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit (TLS) to and between our services;
  • tenant isolation enforced by row-level security in the database, deny-by-default;
  • widget access limited to the websites the Controller allows, with per-visitor rate limits and per-plan quotas;
  • language-model requests restricted to zero-data-retention endpoints, so prompts and outputs are not stored by the provider;
  • production access limited to named personnel, by key-based authentication, with the database not exposed to the internet;
  • regular backups, and validation of every input at trust boundaries.

5. Sub-processors

The Controller authorises the sub-processors below. We impose data protection terms on each that are no less protective than this DPA, and remain responsible for their performance. We will announce a new sub-processor by updating this page and notifying the Controller by email at least 14 days before it starts processing; the Controller may object on reasonable data protection grounds, and if we cannot address the objection, may terminate the affected service and receive a refund of prepaid fees for it.

Sub-processorPurposeDataLocation
Hostinger International LtdDatabase and file storage (virtual server)All customer content, conversations, account dataGermany (Frankfurt)
Vercel Inc.Application hostingRequests in transit, server logsEU (Frankfurt region); United States company
OpenRouter, Inc.Routing requests to language and embedding models, zero data retention onlyQuestions, retrieved passages, document text being indexedUnited States
Google LLC (Google Cloud / Vertex AI)Embeddings and the default answer model, zero data retentionQuestions, retrieved passages, document text being indexedUnited States / EU
Fireworks AI, Inc.Reranking search results (Business plan), zero data retentionQuestions and candidate passagesUnited States
Amazon Web Services, Inc. (Bedrock)Claude models, when a customer selects one, zero data retentionQuestions and retrieved passagesUnited States / EU
Microsoft Corporation (Azure OpenAI)OpenAI models, when a customer selects one, zero data retentionQuestions and retrieved passagesUnited States / EU
Stripe, Inc. / Stripe Payments Europe, Ltd.Payments, invoicing, tax calculationBilling contact, payment details, billing addressUnited States / Ireland

6. International transfers

Where personal data is transferred outside the European Economic Area to a country without an adequacy decision, the transfer is covered by the EU–US Data Privacy Framework (where the recipient is certified) or the European Commission’s Standard Contractual Clauses (Module 2 or 3), which are incorporated by reference.

7. Assistance

Taking into account the nature of the processing, we will reasonably help the Controller respond to data subject requests, carry out data protection impact assessments and consult supervisory authorities. Requests we receive directly from a Controller’s data subjects will be forwarded to the Controller.

8. Personal data breaches

We will notify the Controller without undue delay after becoming aware of a personal data breach affecting its data, with the information reasonably available to us, and will keep the Controller informed as we learn more.

9. Deletion and return

The Controller can delete documents, bots and their conversations at any time in the Service. When the account ends, we delete the Controller’s personal data within 30 days, and from backups as they rotate, unless the law requires us to keep it.

10. Audits

We will make available the information reasonably needed to demonstrate compliance with this DPA, primarily through written answers and documentation. On-site audits may take place once a year, with 30 days’ notice, during business hours, at the Controller’s cost, by an auditor bound by confidentiality, and without access to other customers’ data.

11. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent permitted by law.

12. Contact

Massive Dynamic Limited, Hong Kong company registration no. 78076051. Unit 1603, 16/F, The L. Plaza, 367–375 Queen’s Road Central, Sheung Wan, Hong Kong. Email: support@mdhk.ltd.