Annex 1 · Data Processing Agreement
Annex to the Grant Mastermind Partner Framework Agreement, version 2.0 · draft of 07/10/2026 · subject to legal review before use.
Capitalised terms have the meaning given in the Framework Agreement.
A. Who is who
The Firm's client decides about its data. The Firm orders the work from us. We process the data only for that work.
| Who | Role |
|---|---|
| End Client | Controller |
| Firm | Processor for the End Client. If it processes the data for its own purposes, it is controller of that processing |
| ONE PERCENT NETWORK LLC (OPN) | Processor on behalf of the Firm or, where the Firm is its client's processor, sub-processor |
| Providers in section D | OPN's sub-processors |
A.1. This Annex is the processing contract required by Article 28(3) of Regulation (EU) 2016/679 (GDPR) for Firms in the European Union, by Article 28(3) of the UK GDPR for Firms in the United Kingdom and, for Firms in any other country, by the data protection law of that country, together with the module for that country in section F. Where the End Client is in a different country from the Firm, as stated in the Order Sheet, the module for the End Client's country also applies. This Annex is governed by the law of the Member State in which the Firm is established for Firms in the European Union, and by the laws of England and Wales for Firms in the United Kingdom. For all other Firms it is governed by the law that governs the Framework Agreement, except where the Firm's data protection law requires the processing contract to be governed by that law, and then only to the extent it requires. Where the Firm acts as controller and not as processor, references in this Annex to the End Client's instructions or authorisation are to the Firm's.
A.2. The Firm warrants that it holds each End Client's written authorisation to use OPN and the sub-processors in section D (Article 28(2) GDPR or equivalent rule), and that it does not take on stricter obligations towards its client than those in this Annex without first telling OPN.
B. Description of the processing
Which data, about whom, what for and for how long.
| Item | Content |
|---|---|
| Subject matter and purpose | 1) Selecting calls for the Firm's portfolio (bulletin). 2) Preparing grant Application Files. 3) Under Turnkey, filing them and obtaining the receipt. |
| Nature and operations | Receipt, consultation, storage, structuring, analysis with artificial intelligence tools, drafting, delivery to the Firm and, under Turnkey, filing on the Funder's portal. |
| Duration | While the Firm is a member and its orders last, plus the deletion periods in section I. |
| Data subjects | Members of governing bodies, staff, members and contact persons of the End Client and, where the call requires it, participants in or beneficiaries of its projects. Holder or representative named in a shared electronic certificate. |
| Types of data | Identification and contact data, position, professional and CV data, identity document number where the call requires it, project financial data and the data contained in a shared electronic certificate. Special categories and criminal-offence data only as set out in clause 13.6 of the Framework Agreement. |
C. OPN's obligations
The eight in Article 28(3) GDPR, applied outside the EU as well.
- Process data only on the Firm's documented instructions, which are those in the Framework Agreement, in each Order Sheet and any given in writing, including as regards international transfers. If an instruction appears to breach the applicable data protection law, OPN tells the Firm immediately.
- Ensure that persons authorised to process the data are bound by confidentiality.
- Apply the security measures in section E.
- Engage sub-processors only as set out in section D.
- Assist the Firm, as far as possible, in responding to data subject requests, forwarding any request received within 5 working days without answering it itself.
- Assist the Firm with Articles 32 to 36 GDPR or their equivalents, including breach notification under section H.
- At the end, delete or return the data under section I, at the Firm's choice.
- Make available to the Firm the information needed to demonstrate compliance and allow audits: first by questionnaire and documentation; on-site inspection with 30 days' notice, during business hours and at the requesting party's cost.
D. Sub-processors
We use these providers. If we change any, we give 30 days' notice and the Firm may object.
| Sub-processor | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting of the platform and website, database and file storage, online acceptance records | USA and Cloudflare's global network |
| Anthropic PBC | Artificial intelligence models via API | USA |
| Google LLC | Email and document storage (Google Workspace) | USA / EU |
| Plus Five Five, Inc. (Resend) | Delivery of service emails and notifications | USA |
OPN has a data processing agreement in force with each sub-processor listed, which includes the standard contractual clauses where they apply.
D.1. The Firm gives written general authorisation for the sub-processors listed. OPN gives 30 days' notice by email of any addition or replacement.
D.2. The Firm may object on reasonable grounds within that period. If no solution is found, it may leave without penalty and OPN will not use the new sub-processor with its data.
D.3. OPN binds each sub-processor by contract to the same data protection obligations as this Annex, and remains fully liable to the Firm for what the sub-processor does (Article 28(4) GDPR).
D.4. Where the law of the End Client's country requires the controller's own written authorisation, general or specific, for each sub-processor (for example Chile from 1 December 2026, Argentina, Mexico and Peru), that authorisation is the one the End Client gives by naming each sub-processor in the engagement letter in Annex 3 or an equivalent document. The Firm obtains it before sending any data of that End Client and gives OPN a copy on request. For those End Clients, OPN does not use a new sub-processor with their data until the Firm confirms in writing that the End Client has authorised it. Until then OPN may continue with the sub-processors already authorised or, if it cannot provide the service without the new one, decline further Order Sheets for that End Client.
E. Security measures
Minimum access, encryption, separation by client and no model training.
- Access restricted to the OPN staff working on the Application File, with two-factor authentication.
- Encryption of documents in transit and at rest.
- Minimisation: before documents are sent to an artificial intelligence model, identity document numbers and data not needed for drafting are removed or replaced.
- Separation by Firm and by End Client: one party's data is never used for another.
- Data is not used to train or improve models or tools.
- Shared electronic certificates: stored encrypted and separately, with the password kept apart, access only for whoever handles the Application File, a log of each use, and deletion under clause 9.6 of the Framework Agreement.
- Logging of access and deliveries.
F. International transfers
Data goes to the USA. Each country has its own instrument, and the one for the Firm's country applies.
F.1. Firm in the European Union. The parties incorporate by reference the standard contractual clauses in Commission Implementing Decision (EU) 2021/914, Module Three (processor to processor), unmodified, with the Firm as data exporter and OPN as data importer, with these options: Clause 7 (docking clause) included; Clause 9, Option 2 (general authorisation, 30 days' notice); Clause 11, without the independent dispute resolution body option; Clause 13, the supervisory authority of the exporter's Member State; Clause 17, Option 2, the law of the Member State in which the data exporter is established or, where that law does not allow for third-party beneficiary rights, the law of Ireland; Clause 18, the courts of the Member State in which the data exporter is established. Sections B, E and D of this Annex serve as Annexes I.B, II and III of those clauses.
F.2. Firm in the United Kingdom. The clauses in F.1 apply together with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner (template B1.0, in force 21 March 2022, as revised under Section 18 of its Mandatory Clauses), whose Part 2 Mandatory Clauses are incorporated by reference. Tables 1 to 3 are completed with the information in F.1 and in sections B, D and E of this Annex. In Table 4, the Importer may end the Addendum. As that Addendum provides, it is governed by the laws of England and Wales and disputes under it go to the courts of England and Wales. The Firm, as exporter, carries out the transfer risk assessment; OPN gives it the information it reasonably needs about the law and practice of the USA and about OPN's own measures.
F.3. Firm in another country. In addition to this Annex, the module for its country applies:
| Country | Module |
|---|---|
| Canada | The Firm remains responsible for the data under PIPEDA (Schedule 1, principle 4.1.3), and this Annex is the contractual means by which OPN provides a comparable level of protection while it processes the data. The Firm informs the individuals concerned that their data may be processed in the USA and may be accessible to courts, law enforcement and national security authorities there. Quebec: before sending data to OPN, the Firm carries out the privacy impact assessment required by section 17 of the Act respecting the protection of personal information in the private sector. This Annex is the written agreement that section requires. OPN gives the Firm the information it needs for the assessment, and the parties agree in writing any additional measure the assessment identifies before data is sent. |
| Australia | OPN complies with the Australian Privacy Principles (except APP 1), handles complaints and reports any suspected breach without delay. |
| Mexico | Sending data to OPN is a communication to a processor and not a transfer (Federal Law on the Protection of Personal Data Held by Private Parties, published in the Official Gazette on 20 March 2025, Article 2, section XX), so it needs neither notice to the data subjects nor their consent. This Annex is the contractual instrument required by Articles 51 and 54 of the Regulations of that Law of 21 December 2011, which the parties apply insofar as they are consistent with the 2025 Law. The End Client authorises OPN and each sub-processor in section D in the document under D.4. |
| Chile | Until 30/11/2026, a written mandate (Law 19.628, Article 8). From 01/12/2026, the content of Article 15 bis as worded by Law 21.719, the End Client's specific written authorisation for each sub-processor in section D (D.4), and data subjects as third-party beneficiaries (Articles 27 and 28). |
| Colombia | Data transmission contract under Article 25 of Decree 1377/2013. |
| Peru | OPN takes on the same obligations as the sender (Regulation DS 016-2024-JUS, Article 20.1). The cross-border flow is notified to the DGTAIPD by the controller of the data bank, the End Client (Article 21.2); the Firm arranges it and OPN provides the information needed. |
| Argentina | The model contract for international transfers for the provision of services in Annex II of Provision 60-E/2016 applies without changes between the End Client, as data exporter and controller, as that model requires, and OPN, as data importer. Sections B, D and E of this Annex give the details for its Clause 2. Before sending data, the Firm has the End Client sign it, or signs it on the End Client's behalf under a written authority, and gives OPN a copy. Any contract that departs from that model needs the prior approval of the data protection authority (Article 2 of that Provision), and the Firm tells OPN before sending data. |
| USA and other countries | This Annex. If the Firm's law requires another instrument, the Firm says so before first sending data. |
F.4. OPN to Anthropic. This is an onward transfer within the USA. It is governed by Anthropic's data processing addendum, which includes the EU standard clauses (Modules Two and Three) and the UK Addendum. Anthropic PBC is not on the EU-US Data Privacy Framework list, so the transfer does not rely on it.
F.5. OPN gives the Firm its transfer impact assessment (Clause 14 of the standard clauses) on request. If a public authority asks for access to the data, OPN acts under Clause 15 and tells the Firm unless the law prohibits it.
G. Prohibited uses
A client's data serves only that client.
G.1. OPN does not use the data for its own purposes: not to train or improve models or tools, nor for anonymised examples or lessons learned, unless expressly agreed in writing with the Firm and with the End Client's authorisation.
G.2. OPN does not reuse text between End Clients applying to the same call.
G.3. OPN does not disclose the data to third parties, except to the sub-processors in section D, to the Funder when filing under Turnkey, or where a law requires it.
H. Personal data breaches
If something goes wrong, we tell you within 48 hours at most.
H.1. OPN notifies the Firm of any security breach affecting its data without undue delay and in any case within 48 hours of becoming aware of it, or sooner if the Firm's law requires, with the information available and the measures taken.
H.2. If it affects a shared electronic certificate, notice is given within 24 hours (clause 9.5 of the Framework Agreement).
I. Deletion
We keep each client's file so the next application is faster, in 12-month periods renewed automatically. You can ask us to delete it at any time.
I.1. Data for an Application File: on the Firm's instruction, given by accepting this Annex, OPN keeps the data of each End Client so that later Application Files for the same End Client can be prepared faster, for periods of 12 months renewed automatically at the end of each period. OPN deletes it within 30 days of the Firm's request at any time (for example, because the End Client is no longer its client), unless the Firm first asks for it to be returned.
I.2. Portfolio data for the bulletin: kept while the Firm is a member. The Firm may ask for its deletion at any time, and OPN deletes it within 30 days.
I.3. When the Firm leaves: OPN deletes all its data within 30 days.
I.4. Electronic certificates: kept and deleted under clause 9.6 of the Framework Agreement.
I.5. OPN provides a certificate of deletion on request. It keeps, in restricted form, only what a law requires it to keep (for example, invoices).
I.6. On the Firm's instruction, given by accepting this Annex, OPN keeps, for five years after each Application File ends, a record of the call, the date, the order reference and a SHA-256 hash of each text delivered, without the text. The purpose is to let OPN show the Firm and the End Client that it has complied with G.2 (Article 28(3)(h) GDPR). This record may be personal data in pseudonymised form. OPN keeps it apart from other data, uses it for no other purpose and deletes it at the end of that period.
J. Contact
J.1. Data protection and data subject requests: [email protected].
J.2. If this Annex conflicts with the Framework Agreement, this Annex prevails. If it conflicts with the standard clauses it incorporates, the standard clauses prevail.