GDPR
This document describes the controller and processor roles, product controls, data-subject rights, and contract steps relevant to EU and UK GDPR deployments.
Contents and legal documents
Roles
For visitors to this website and users of our hosted console and sandbox, GrayPass is the data controller.
For end users of applications that integrate the GrayPass SDK and API, our customer is the controller and GrayPass acts as their processor under Article 28, processing behavioral timing data solely on the customer's documented instructions. Our data-processing agreement (Section VI) governs that relationship.
Lawful bases, per activity
- Behavioral enrollment and continuity assessment: the customer controller determines and documents the lawful basis and obtains any consent its jurisdiction requires. GrayPass requires notice and legally required consent before collection.
- Operating the website, console, and sandbox accounts: performance of a contract (Article 6(1)(b)).
- Security, abuse prevention, and service integrity: legitimate interests (Article 6(1)(f)), balanced against user rights and documented in our records of processing.
- Opt-in research data: separate explicit consent, revocable at any time.
- Legal compliance: Article 6(1)(c) where a law compels processing.
Minimization and protection by design
GDPR asks for data protection by design and by default (Article 25). The GrayPass pipeline is a literal implementation of it, described in the Data Privacy policy:
- Timings only: the SDK cannot read content, so content is never processed.
- Raw streams are reduced on the device and discarded; an encrypted, tenant-scoped template persists.
- Subject identifiers use a keyed hash per tenant and environment, so the same customer identifier is unrelated elsewhere.
- Templates can be revoked or deleted. A subject export never exposes the template vector.
- Decision logs carry reason codes so every automated decision is explainable to a human.
Data-subject rights
EU/EEA, UK, and Swiss users can exercise every GDPR right against us:
- Access and portability: a copy of your template metadata, decision history, and account data in a machine-readable format (Articles 15, 20).
- Rectification of account data (Article 16).
- Erasure: deletion of the Brainprint template, live sessions, and subject metadata, plus revocation of outstanding proofs (Article 17).
- Restriction and objection, including to any legitimate-interests processing (Articles 18, 21).
- Withdrawal of consent at any time, with effect going forward (Article 7(3)).
- Human review of any decision you believe was made solely by automated means with legal or similarly significant effect (Article 22). Reason codes make this review real rather than ceremonial.
Send requests to tools@graypass.org with the subject "GDPR request." We respond within thirty (30) days. If we act as processor for the application you use, we will route the request to the controller and support their response, as Article 28 requires.
International transfers
GrayPass operates from the United States. A customer must put an applicable transfer mechanism and data-processing agreement in place with GrayPass before enabling EU/EEA, UK, or Swiss populations. Technical measures include encryption in transit and at rest, tenant-scoped keyed identifiers, and the structural absence of raw behavioral streams.
The DPA and sub-processors
Data-processing and transfer terms are handled in the customer's written agreement. Contact tools@graypass.org before enabling a regulated population.
Amazon Web Services provides hosting, database, key management, and transactional email. Twilio processes SMS step-up verification only when enabled by a customer. Customers with an executed DPA receive notice of sub-processor changes as that agreement provides.
Breach notification
If a personal-data breach occurs, we notify affected controllers without undue delay after becoming aware, with enough detail to meet their Article 33 obligation to notify supervisory authorities within seventy-two (72) hours. Where we are the controller, we notify the competent authority and affected users directly on the same standard.
What a breach can expose is bounded by the stored records: encrypted tenant-scoped templates, assurance and decision traces, proof records, and operational logs. Raw behavioral streams never leave the device.
Complaints and contact
Privacy questions and rights requests: tools@graypass.org (subject "GDPR"). We would rather fix a concern directly, but you also have the right to lodge a complaint with your local supervisory authority: for EU residents, the authority of your member state; for UK residents, the Information Commissioner's Office.