Trust
EU-native, GDPR by design.
Grinexura is built in Paris for institutions that must justify every selection decision to applicants, donors and regulators.
EU hosting
Application data is stored and processed on infrastructure located in the European Union. No transfer outside the EEA is required to operate the service.
Lawful basis
Processing rests on the contract with the awarding institution (data controller). Grinexura acts as processor under Article 28 GDPR, governed by a written DPA.
Data minimisation
Forms collect only fields the programme defines. Special-category data is optional, clearly labelled and never used by automated scoring.
No automated decisions
No applicant is rejected or selected by an algorithm. Article 22 GDPR safeguards are met by design: every decision is taken by a named human with a reason code.
Access control
Role-based permissions, conflict-of-interest exclusion, field-level anonymisation and full access logging.
Retention
Retention periods are configured per programme; records are deleted or anonymised at the end of the agreed period.
Rights handling
Tooling for access, rectification, erasure, restriction and portability requests, with controller approval workflow.
Breach process
Documented incident response with controller notification within 72 hours, per Article 33 GDPR.
