Legal and compliance

Our legal role, DPA, audit terms, policy program, and review process.

01

Who operates Graph One?

Our legal entity is Borg Collective GmbH, a German company.

Legal name
Borg Collective GmbH
Address
Scharnhorststraße 24, 10115 Berlin, Germany
Register
Local Court Berlin Charlottenburg, HRB 197356 B
VAT ID
DE319811966
Managing director
Maciej Laskus
02

Is Graph One a controller or a processor?

Our role depends on why we handle the data.

We act as a controller for our own account, website, product, billing, safety, and support needs.

We act as a processor for business customer data that we handle only on the customer's instructions. The DPA sets out that role.

03

Is a Data Processing Agreement available?

Yes. Email contact@graph.one and we will provide our DPA.

The DPA covers processor duties, security steps, service providers, transfers, help with data rights, audits, and return or deletion at the end of the service.

We do not post signed, customer-specific DPAs in public.

04

Which privacy-law terms does the DPA cover?

It includes GDPR and UK GDPR processor terms and CCPA service-provider terms.

For EEA transfers, the DPA uses the EU Standard Contractual Clauses where needed. It also includes the UK transfer addendum where that applies.

For other US state privacy laws, the DPA says we will agree any extra terms the law requires.

05

Can a business customer audit Graph One?

Yes. Our DPA gives customers information and audit rights on reasonable written request.

The standard DPA allows one audit each year unless law or a serious event calls for more. We first provide current documents and answers that may settle the review.

An audit must protect our confidential information and other customers' data, use reasonable notice, and avoid needless service disruption.

06

Do you help customers with DPIAs and privacy requests?

Yes. Our DPA requires reasonable help with privacy rights, security duties, DPIAs, and regulator contact.

The help depends on the processing and the information available to us. Send the request, deadline, and data or feature in scope to contact@graph.one.

07

Which security and privacy policies do you maintain?

We maintain written policies for access, encryption, data handling, incidents, recovery, changes, vulnerabilities, vendors, retention, and privacy.

We also keep an asset list, risk register, staff security rules, internal audit process, and corrective-action process.

These are internal working documents. Ask us for the policy summary or evidence needed for your review.

08

How do you review security risks and controls?

Our policies set regular risk, technical-control, document, and full security-program reviews.

The schedule calls for quarterly risk-register and policy document reviews, technical-control reviews twice a year, and a full internal security-program audit each year.

A schedule is not proof that a review happened. Ask us for the latest completed record if your assessment needs it.

09

What security rules apply to people who work at Graph One?

Staff and contractors must accept confidentiality and security duties before they receive system access.

Our policy requires identity and professional-background checks, security onboarding, annual policy and phishing awareness, and secure-development training for developers.

The Security topic explains the access and offboarding rules that apply once someone receives system access.

11

How can legal, privacy, or security teams reach you?

Email contact@graph.one.

Use the same address for a DPA, security evidence, a privacy request, a vendor review, or a security report. State your company and the document you need.