Grinfi OÜ — Grinfi and Telegrin
Last updated: September 2, 2026 · Version 1.0
Why this document exists
When you use Grinfi or Telegrin to find, store and contact people, you decide whose data is processed and why. Under the GDPR that makes you the controller and us your processor, and Article 28 requires the two of us to have this agreement in writing.
This DPA is part of the Terms of Use and applies automatically from the moment you start using the Service. You do not need to sign anything; if your own compliance process needs a countersigned copy, write to [email protected] and we will provide one.
Where this DPA and the Terms disagree about personal data, this DPA wins.
1. Definitions
"GDPR" means Regulation (EU) 2016/679. "Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR.
"Customer Personal Data" means personal data that we process on your behalf through the Service — principally the data of the prospects your campaigns find and the people you message.
"You" is the customer named in the workspace; "we" is Grinfi OÜ.
2. Roles
- You are the controller of Customer Personal Data. You decide which channels are monitored, which keywords are used, which people become leads and who is contacted.
- We are the processor. We process Customer Personal Data only to provide the Service, and only on your documented instructions.
- Separately, we are the controller of your own account data — your name, email, billing and how you use the app. That is not covered by this DPA; it is described in the Privacy Policy.
3. What is processed
| Subject matter | Providing the Service: monitoring public channels, AI qualification of messages, storing leads, preparing and delivering replies |
| Duration | For as long as your workspace is active, plus the retention periods in section 9 |
| Nature and purpose | Collection, storage, organisation, analysis by AI, retrieval, transmission to destinations you configure, and deletion |
| Types of personal data | Public display name or handle; link to a public profile; the text of public messages; channel, date and time; AI relevance score; subsequent conversation content; any personal data you upload or type into campaigns |
| Categories of data subjects | Authors of public messages your campaigns match; your prospects, leads and contacts; the members of your own team you invite |
| Special categories | None. You must not use the Service to process special categories of personal data (Article 9) or data relating to criminal convictions |
4. Your instructions
Your configuration of the Service — campaigns, keywords, channels, agents, delivery destinations — together with the Terms and this DPA, are your complete documented instructions to us. We will not process Customer Personal Data for any other purpose.
We will tell you if, in our opinion, an instruction infringes the GDPR. We may suspend processing of that instruction until it is resolved.
Your responsibilities as controller. You confirm that you have a lawful basis for the monitoring and the contact you carry out, that you have carried out any balancing assessment your legitimate interest requires, that you will honour data subjects' objections, and that you will not use the Service to process special categories of data.
5. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality obligations, and gets access only to what their role requires.
6. Security
We implement appropriate technical and organisational measures, including: encryption in transit (TLS) and at rest for sensitive fields; bcrypt password hashing; role-based access control within a workspace and least-privilege access for our staff; separated production and development environments with separate credentials and data; daily automated backups with a weekly automated restore test; automated stripping of credentials and secrets from logs and error reports; and monitoring and alerting on service health.
We keep these measures under review as risks and the state of the art change. A current description is available on request.
7. Sub-processors
You give us general authorisation to engage sub-processors. The categories we use are described in section 7 of the Privacy Policy; a current list naming each one is available on request — write to [email protected] and we will send it, under a confidentiality undertaking if you prefer.
We engage each sub-processor under a contract requiring it to process personal data only on our instructions and under confidentiality and security obligations, and we remain fully liable to you for their performance.
Changes. Before a new or replacement sub-processor starts processing Customer Personal Data in a way that materially affects you, we will tell you by email. If you have a reasonable data-protection objection, tell us within 30 days and we will work with you on an alternative; if none is workable, you may stop using the affected part of the Service.
8. International transfers
Application servers and the database are located in the European Economic Area. Some sub-processors — notably the AI providers — process data in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), module 3 (processor to processor), which are incorporated into this DPA by reference, together with supplementary technical measures and, where applicable, the recipient's certification under the EU–US Data Privacy Framework.
For the purposes of the SCCs: you are the data exporter, we are the data importer, Annex I is section 3 of this DPA, Annex II is section 6, and Annex III is the sub-processor list referred to in section 7. The governing law is Estonian and the forum is Estonia.
9. Data subject requests
If a data subject contacts us directly about data we hold on your behalf, we will not respond substantively; we will identify you as the controller and pass the request to you without undue delay.
We will help you meet your own obligations, taking into account the nature of the processing:
- the Service lets you search, edit and delete any lead or conversation yourself;
- it lets you export the whole workspace as a single JSON file;
- for anything those do not cover, write to [email protected] and we will assist.
We do not charge for reasonable assistance.
10. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay, with the information you need for your own notification: what happened, which categories and approximate numbers of data subjects and records are involved, the likely consequences, and the measures we have taken.
Notifying the supervisory authority and affected data subjects is your responsibility as controller; we will give you the information and assistance you need to do it.
11. Assistance with assessments
On request we will give you the information reasonably needed for a data protection impact assessment or a prior consultation with a supervisory authority, in so far as it relates to our processing.
12. Audits
On reasonable written request, and no more than once a year unless a supervisory authority requires otherwise, we will make available the information necessary to demonstrate our compliance with this DPA, and answer your reasonable questions in writing. Where an on-site audit is genuinely required, we will agree scope, timing and confidentiality with you in advance; each party bears its own costs.
13. Deletion and return
On termination of your use of the Service, we delete Customer Personal Data in line with the Privacy Policy: the workspace is deleted, with a 30-day window in which you can cancel the deletion, after which it becomes permanent. Export what you need before you delete — the Service provides a one-click export.
Backups are overwritten within 30 days. We may retain data where EU or Estonian law requires it (for example accounting records), for the period that law requires and for no other purpose.
Ongoing retention is yours to set. We run no automatic purge: Customer Personal Data stays until you delete it, ask us to delete it, or close the workspace. As controller you decide how long it is kept, and must not keep it longer than your purpose requires. We action deletion requests without undue delay.
14. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms of Use. This DPA applies for as long as we process Customer Personal Data on your behalf, and its provisions on confidentiality, deletion and liability survive.
15. Contact
Grinfi OÜ, registry code 16546847 Vesivärava tn 50-201, Kesklinna linnaosa, Tallinn, Harju maakond, 10152, Estonia [email protected]