GrantRT Privacy Policy
Effective Date: September 1, 2026 Version: 1.0 Operator: dakdan LLC, a Colorado limited liability company, doing business as GrantRT Contact: info@grantrt.com Jurisdiction of operation: Colorado, United States of America
1. Scope and Roles
1.1 What This Policy Covers
This Privacy Policy describes how dakdan LLC ("GrantRT," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the GrantRT platform at grantrt.com, its subdomains, application programming interfaces, automated grant registration and submission features, artificial intelligence drafting assistants, and all related services (collectively, the "Service").
This Policy applies to visitors to our websites, individuals who create accounts, and organizations that subscribe to the Service ("Customers"). It does not apply to the privacy practices of grant portals, funders, payment networks, or other third parties whose systems Customers access through or alongside the Service.
1.2 Controller and Processor Roles
GrantRT operates in two distinct capacities, and the distinction determines who is accountable for a given category of data.
GrantRT as controller. For account registration data, billing data, support communications, marketing communications, and website analytics, GrantRT determines the purposes and means of processing and acts as the controller (or "business" under United States state privacy law).
GrantRT as processor. For Customer Content, including grant application drafts, organizational financial records, donor and constituent records, beneficiary information, and any personal data a Customer uploads or generates within its workspace, the Customer is the controller and GrantRT is the processor (or "service provider"). GrantRT processes that data only on the Customer's documented instructions, which include the instructions embodied in the Terms of Service and in the Customer's configuration of the Service.
Customers subject to the General Data Protection Regulation or United Kingdom GDPR may request a Data Processing Addendum incorporating Standard Contractual Clauses by writing to info@grantrt.com with the subject line "DPA Request."
1.3 Not a Consumer-Facing Donor Platform
GrantRT is a business-to-business platform sold to nonprofit organizations, governmental subrecipients, educational institutions, and their advisors. Where a Customer imports donor or beneficiary records, those individuals are the Customer's data subjects. Requests from such individuals are routed to the Customer as described in Section 8.3.
2. Information We Collect
2.1 Account and Identity Information
Name, business email address, telephone number, job title, organization name, organization mailing address, password credentials in hashed form, multi-factor authentication settings, and user role and permission assignments within a Customer workspace.
2.2 Organizational and Eligibility Information
To support grant eligibility screening, registration, and application assembly, the Service collects and stores organizational records that may include:
- Employer Identification Number (EIN) and other taxpayer identification numbers
- Internal Revenue Service determination letters and tax-exempt status documentation
- IRS Form 990, 990-EZ, or 990-PF filings and attachments
- Unique Entity Identifier (UEI), SAM.gov registration data, CAGE codes, and NAICS or NTEE classifications
- Audited financial statements, budgets, indirect cost rate agreements, and Single Audit reports
- Board rosters, key personnel biographies, organizational charts, and conflict of interest disclosures
- State charitable solicitation registration numbers and filings
Taxpayer identification numbers are treated as sensitive information, are stored encrypted, are masked in the user interface except to authorized users of the owning workspace, and are excluded from analytics and product telemetry.
2.3 Grant Application Content
Narrative drafts, logic models, work plans, budgets and budget justifications, letters of support, attachments, funder correspondence, submission receipts and confirmation numbers, award notices, reporting deliverables, and the metadata associated with each of these.
2.4 Donor, Constituent, and Beneficiary Data
Where a Customer imports or connects donor management, customer relationship management, or program data, the Service may store names, contact details, giving history, engagement history, program participation records, and any demographic or outcome data the Customer chooses to include in an application or report. GrantRT does not solicit special category or sensitive personal data and instructs Customers not to upload health, biometric, genetic, precise geolocation, criminal history, or similar sensitive records except where a funder requires it in aggregate or de-identified form.
2.5 Grant Portal Credentials
To perform automated registration, retrieval, and submission, the Service stores credentials that a Customer supplies for third-party grant portals. Handling of these credentials is described in Section 5.
2.6 Payment and Billing Information
Subscription tier, billing contact, billing address, transaction history, invoice records, and tax status. Payment card numbers and bank account numbers are collected and processed directly by our payment processor and are not stored on GrantRT systems. GrantRT receives a payment token, the last four digits, card brand, and expiration date.
2.7 Usage, Device, and Technical Information
Internet protocol address, browser type and version, operating system, device identifiers, referring and exit pages, pages and features accessed, timestamps, session duration, feature interaction events, error and crash reports, and performance telemetry. Cookie and similar technology practices are described in the GrantRT Cookie Policy.
2.8 Communications
Support tickets, email correspondence, chat transcripts, onboarding and training session records, survey responses, and feedback submissions.
2.9 Information From Third Parties
Publicly available funder and opportunity data, federal and state registration databases, enrichment data from business information providers, authentication data from single sign-on providers a Customer elects to use, and referral information from partners.
3. How We Use Information
GrantRT uses information to:
- Provide, operate, maintain, and secure the Service
- Create and administer accounts, workspaces, and permissions
- Screen grant opportunities against a Customer's eligibility profile
- Assemble, format, and validate applications against funder requirements
- Register a Customer on grant portals and transmit completed applications at the Customer's direction under the limited agency described in the Terms of Service
- Retrieve submission confirmations, award notices, and funder correspondence
- Generate drafts, summaries, and suggestions through artificial intelligence features
- Process payments, issue invoices, and collect fees
- Provide customer support and respond to inquiries
- Send transactional, security, deadline, and service notices
- Send marketing communications, subject to applicable consent and opt-out rights
- Monitor, analyze, and improve performance, reliability, and usability
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our agreements
3.1 Artificial Intelligence Processing
The Service uses third-party large language model providers to power drafting, summarization, eligibility analysis, and review features. When a Customer uses an AI feature, the relevant Customer Content is transmitted to the applicable provider for inference.
GrantRT commits that:
- Customer Content is not used to train GrantRT's own models or any general-purpose model of our AI providers. We contract with AI providers on commercial or enterprise terms that exclude Customer inputs and outputs from provider model training.
- AI providers act as subprocessors under contractual confidentiality and security obligations.
- Customers may disable AI features at the workspace level. Disabling AI features materially reduces functionality.
- Aggregated, de-identified statistics that cannot reasonably be used to identify a Customer, an individual, or an application may be used to evaluate and improve the Service.
Artificial intelligence output may be inaccurate, incomplete, non-original, or unsuitable for submission. Section 9 of the Terms of Service governs the legal effect of AI output.
3.2 Legal Bases for Processing (EEA and United Kingdom)
Where GDPR applies and GrantRT acts as controller, we rely on: performance of a contract for account and service delivery; legitimate interests for security, product improvement, and business communications; consent for non-essential cookies and marketing where required; and legal obligation for tax, accounting, and compliance records. Where GrantRT acts as processor, the Customer is responsible for establishing a lawful basis for the data it uploads.
4. Disclosure of Information
4.1 We Do Not Sell Personal Information
GrantRT does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act and the Colorado Privacy Act.
4.2 Subprocessors and Service Providers
GrantRT discloses information to vendors that process data on our behalf under written contracts limiting use to the services we procure.
| Subprocessor | Function | Data Categories | Location |
|---|---|---|---|
| Vercel Inc. | Application hosting, edge delivery | Account, usage, technical | United States |
| Supabase Inc. | Database, authentication, object storage | Account, Customer Content, credentials vault | United States |
| Anthropic PBC | Large language model inference | Customer Content submitted to AI features | United States |
| OpenAI, L.L.C. | Large language model inference | Customer Content submitted to AI features | United States |
| Stripe, Inc. | Payment processing, subscription billing | Billing, transaction, tax | United States |
| Resend / SendGrid | Transactional and notification email | Account, communications | United States |
| Twilio Inc. | Short message service notifications | Account, telephone number | United States |
| PostHog Inc. | Product analytics | Usage, technical, pseudonymous identifiers | United States |
| Sentry (Functional Software, Inc.) | Error monitoring | Technical, diagnostic, limited context | United States |
| Cloudflare, Inc. | Content delivery, security, bot mitigation | Technical, network | United States and global edge |
A current subprocessor list is maintained at grantrt.com/legal/subprocessors. Customers may request notice of new subprocessors by writing to info@grantrt.com with the subject line "Subprocessor Notification."
4.3 Grant Portals and Funders
At a Customer's direction, GrantRT transmits registration data, organizational records, and application content to grant portals and funding agencies designated by the Customer. Once transmitted, that information is governed by the receiving portal's or funder's privacy practices and applicable public records law. Federal and state grant records may be subject to disclosure under the Freedom of Information Act or state equivalents.
4.4 Legal and Protective Disclosure
We may disclose information where we reasonably believe it is necessary to comply with law, regulation, legal process, or governmental request; to enforce our agreements; to investigate suspected fraud, security incidents, or violations; or to protect the rights, property, or safety of GrantRT, our Customers, or the public. Where legally permitted, we will notify the affected Customer before disclosing Customer Content in response to legal process.
4.5 Corporate Transactions
If GrantRT is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to continued protection under this Policy or a successor policy providing comparable protection. Customers will receive notice of any change in control that materially affects the handling of Customer Content.
4.6 With Consent or at Customer Direction
We disclose information to third parties where the Customer or user directs us to do so, including through integrations, exports, and shared workspace access.
5. Grant Portal Credential Handling
Automated portal registration and submission require GrantRT to store and use credentials issued to the Customer by third-party portals. Because these credentials carry elevated risk, GrantRT applies the following specific controls.
- Encryption. Portal credentials are encrypted at rest using authenticated encryption with keys managed separately from the application database, and encrypted in transit using TLS 1.2 or higher.
- Non-display. Stored credentials are never rendered in the user interface after entry and cannot be retrieved in plaintext by Customer users or by GrantRT support personnel through the application.
- Non-logging. Credentials are excluded from application logs, error reports, analytics events, and support tooling.
- Use limitation. Credentials are decrypted only in memory, only for the duration of an automated session initiated at the Customer's direction, and only for registration, retrieval, upload, and submission on the portals the Customer designates.
- Access control. Access to the credential subsystem is restricted to named engineering personnel under least privilege, is logged, and is reviewed.
- Deletion. Credentials are deleted within thirty (30) days of Customer removal, workspace deletion, or account termination, subject to encrypted backup expiration described in Section 7.
Customer obligations. The Customer is responsible for confirming that each portal's terms of use permit third-party automated access and credential storage, for using dedicated service accounts rather than shared personal credentials where the portal permits, for rotating credentials on personnel change, and for removing credentials from the Service when access is no longer authorized. Several major federal, state, and private grantmaker portals restrict or prohibit automated access. GrantRT does not warrant that any portal permits automation.
6. Security
GrantRT maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption in transit and at rest, role-based access control, least privilege provisioning, multi-factor authentication for administrative access, network segmentation, dependency and vulnerability scanning, centralized logging and alerting, environment separation, background-checked personnel with confidentiality obligations, security awareness training, and a documented incident response plan.
No system is perfectly secure. Customers are responsible for maintaining the confidentiality of their credentials, configuring workspace permissions appropriately, promptly deprovisioning departed personnel, and notifying us at info@grantrt.com with the subject line "Security Incident" upon discovery of any suspected compromise.
Breach notification. GrantRT will notify affected Customers without undue delay and, where GrantRT acts as processor, within seventy-two (72) hours of confirming a personal data breach affecting Customer Content, providing the information reasonably available to support the Customer's own notification obligations.
7. Data Retention and Export
| Data Category | Retention Period |
|---|---|
| Account records | Duration of the account, plus 90 days after termination |
| Customer Content, including applications and organizational records | Duration of the subscription, plus 30 days for self-service export, then deletion |
| Portal credentials | Until Customer removal or 30 days after termination, whichever is earlier |
| Financial and tax records | 7 years, as required by tax and accounting obligations |
| Application and security logs | 12 months operational, up to 24 months for security investigation records |
| Product analytics | 24 months in identifiable form, then aggregation or deletion |
| Support communications | 3 years from resolution |
| Encrypted system backups | 35-day rolling window, after which backups expire automatically |
| Marketing contact records | Until opt-out, plus suppression list retention necessary to honor the opt-out |
Deletion requests are executed against production systems promptly and propagate through backup expiration within the 35-day rolling window. GrantRT may retain information where required by law, to resolve disputes, or to enforce agreements.
Export. For thirty (30) days following termination, Customers may export Customer Content through the in-product export function in machine-readable format. After that window, Customer Content is deleted and is not recoverable.
8. Your Privacy Rights
8.1 United States State Privacy Rights
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws may have the right to:
- Confirm whether we process personal information about them and access that information
- Obtain a portable copy of personal information they provided
- Correct inaccurate personal information
- Delete personal information, subject to legal exceptions
- Opt out of sale, sharing for targeted advertising, and profiling with legal or similarly significant effects
- Limit use and disclosure of sensitive personal information
- Not receive discriminatory treatment for exercising these rights
- Appeal a denial of a rights request
GrantRT does not sell personal information, does not share it for targeted advertising, and does not engage in profiling producing legal or similarly significant effects.
8.2 EEA, United Kingdom, and Swiss Rights
Individuals in these jurisdictions may have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent, and may lodge a complaint with their supervisory authority.
8.3 How to Exercise Rights
Submit requests to info@grantrt.com with the subject line "Privacy Rights Request." Include the right you are exercising, your name, the email address associated with the Service, and, if applicable, the organization involved. We will verify identity using reasonable measures proportionate to the sensitivity of the request. Authorized agents must provide written authorization.
We respond within forty-five (45) days, extendable once by an additional forty-five (45) days with notice, and within one (1) month for GDPR requests, extendable by two (2) months for complex requests. Appeals may be submitted with the subject line "Privacy Rights Appeal" and are decided within forty-five (45) days.
Requests concerning Customer Content. Where an individual's data was uploaded by a Customer, that Customer is the controller. GrantRT will refer the request to the Customer and assist the Customer in responding. Donors, constituents, and beneficiaries of a nonprofit should direct requests to that organization.
8.4 Communications Preferences
Marketing emails include an unsubscribe link. Transactional, security, billing, deadline, and legal notices are not optional while an account remains active.
9. Global Privacy Control and Opt-Out Signals
GrantRT honors the Global Privacy Control signal and other recognized universal opt-out mechanisms as required by the Colorado Privacy Act and comparable laws. When such a signal is received from a browser, we treat it as a request to opt out of sale and sharing and to disable non-essential analytics cookies for that browser.
10. International Transfers
GrantRT is operated from the United States and processes data on infrastructure located primarily in the United States. Where personal data is transferred from the EEA, United Kingdom, or Switzerland to the United States, transfers are made under Standard Contractual Clauses or another approved transfer mechanism, supplemented by the technical and organizational measures described in Section 6. A copy of the relevant transfer terms is available on request.
11. Children's Privacy
The Service is intended for use by adults acting in a professional capacity and is not directed to children under sixteen (16). We do not knowingly collect personal information from children. Customers whose programs serve minors are responsible for their own compliance with the Children's Online Privacy Protection Act, the Family Educational Rights and Privacy Act, and applicable state law before uploading any records concerning minors.
12. Third-Party Sites and Integrations
The Service links to and integrates with third-party sites, portals, and applications. Their privacy practices are governed by their own policies. GrantRT is not responsible for the content, security, or privacy practices of third parties.
13. Changes to This Policy
We may update this Policy. Material changes take effect thirty (30) days after we provide notice by email to account administrators and by in-product notice. Non-material changes take effect on posting. The Effective Date and Version above reflect the current revision. Prior versions are available on request to info@grantrt.com with the subject line "Prior Policy Version."
14. Contact
dakdan LLC d/b/a GrantRT Colorado, United States of America Email: info@grantrt.com
Use these subject lines for routing:
| Subject Line | Purpose |
|---|---|
| Privacy Rights Request | Access, deletion, correction, portability, opt-out |
| Privacy Rights Appeal | Appeal of a denied request |
| DPA Request | Data Processing Addendum for EEA, UK, or Swiss customers |
| Subprocessor Notification | Subscribe to subprocessor change notices |
| Security Incident | Report a suspected compromise |
| Prior Policy Version | Request an archived version of this Policy |
This Policy is provided for informational purposes and does not constitute legal advice to any Customer regarding that Customer's own privacy obligations.