Legal · Customer DPA

    Data Processing Agreement

    This DPA describes how Mavenly processes personal data on behalf of customer organizations using the platform. It supplements our Terms of Service and Privacy Policy.

    Last updated July 31, 2026

    01

    Scope and roles

    This Data Processing Agreement ("DPA") forms part of the Mavenly Terms of Service between Mavenly Inc. ("Mavenly", "Processor") and the customer organization ("Customer", "Controller") and governs Mavenly's processing of Personal Data on Customer's behalf.

    Customer is the Controller of Personal Data it submits to the Service. Mavenly is the Processor and processes Personal Data only on documented instructions from Customer, including as set out in this DPA and the Terms of Service.

    02

    Subject matter and duration

    The subject matter is the provision of the Mavenly grant management platform. Processing continues for the term of Customer's subscription and any post-termination retention period described in clause 9.

    03

    Nature and purpose of processing

    • Hosting and operating Customer's workspace, pipeline, proposals, and reports.
    • Generating grant matches, proposal drafts, critiques, compliance checks, and funder updates using AI models.
    • Sending service, deadline, and account notifications to authorized users.
    • Providing support, security monitoring, backups, and platform reliability.
    04

    Categories of data subjects and Personal Data

    Data subjects: Customer's employees and authorized users, funder and program-officer contacts logged by Customer, and any individuals referenced in Customer content.

    Personal Data: names, business email addresses, job titles, organization affiliation, authentication metadata, interaction logs, and any personal information contained in documents Customer uploads or drafts.

    Customer must not submit special categories of data (health, biometric, criminal, or similar) or data relating to children through the Service unless expressly agreed in writing with Mavenly.

    05

    Mavenly's obligations

    • Process Personal Data only on Customer's documented instructions, unless required by law.
    • Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
    • Implement the technical and organizational measures described in clause 6.
    • Assist Customer, taking into account the nature of processing, with data subject requests and with data protection impact assessments.
    • Make available information necessary to demonstrate compliance and allow for audits as described in clause 10.
    06

    Security measures

    • Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256).
    • Row-level authorization on every tenant table so workspace data is isolated by organization.
    • Role-based access control, least-privilege administrative access, and audit logging of privileged actions.
    • Managed, encrypted backups with tested restore procedures.
    • Vulnerability management, dependency scanning, and periodic access reviews.
    • Secrets stored in a managed secret store; no production credentials in source code.
    07

    Sub-processors

    Customer provides general authorization for Mavenly to engage sub-processors. Our current sub-processors, their purpose, and their data locations are listed at mavenly.ai/subprocessors.

    Mavenly will give at least 30 days' notice before adding or replacing a sub-processor. Customer may object on reasonable data protection grounds, in which case the parties will work in good faith toward a resolution; if none is reached, Customer may terminate the affected Service without penalty.

    Mavenly remains liable for its sub-processors' performance of their data protection obligations.

    08

    AI processing

    Content that Customer submits to AI features is transmitted to Mavenly's model providers solely to generate the requested output. Mavenly contracts for zero data retention and no training on Customer content with its model providers. AI output is generated for Customer's review and is not a substitute for professional judgment.

    09

    Retention, return, and deletion

    On termination, Customer may export its data from the Service. Mavenly deletes or returns Personal Data within 30 days of termination, except where retention is required by law. Encrypted backups age out on a rolling 35-day schedule.

    10

    Audits

    On written request no more than once per twelve months, Mavenly will provide its then-current security documentation and respond to a reasonable security questionnaire. On-site or third-party audits may be arranged where required by applicable law, at Customer's expense and subject to reasonable confidentiality terms.

    11

    Personal data breach

    Mavenly will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data breach affecting Customer data, and will provide the information reasonably available to assist Customer's own notification obligations.

    12

    International transfers

    Where Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module Two, Controller to Processor) and the UK International Data Transfer Addendum by reference, with Customer as data exporter and Mavenly as data importer.

    13

    Order of precedence and signature

    In the event of a conflict, this DPA prevails over the Terms of Service with respect to the processing of Personal Data. This DPA takes effect on Customer's acceptance of the Terms of Service. Customers who require a counter-signed copy or a negotiated version may request one at privacy@mavenly.ai.

    Need a signed copy?

    Email privacy@mavenly.ai with your organization's legal name and we'll return a counter-signed DPA, plus our security overview and sub-processor list.