Trust, security and compliance
Everything procurement, security and legal teams usually ask before working with us, in one place: company facts, data protection, information security, how we use AI, and where we stand on the EU AI Act and accessibility.
Items marked To be confirmed are being verified with our legal and security teams. We only list certifications, partnerships and commitments we can document.
Company facts
The details vendor registration forms ask for.
- Legal name
- GrapefruitTo be confirmed
- Registration number (CUI) and trade register
- To be confirmed
- Founded
- 1999To be confirmed
- Group
- Part of RCI Holding
- Offices
- Bucharest, 15 Dacia Blvd · Iasi, 6 Vasile Pogor St
- Team locations
- Bucharest, Iasi, Cluj-Napoca, Timisoara, Brasov
- Headcount
- To be confirmed
- Annual turnover band
- To be confirmed
- Professional liability insurance
- To be confirmed
- Invoicing
- To be confirmed
- Contact for procurement
- office@grapefruit.ro
GDPR and data protection
We process personal data only as needed to deliver the work you contract, under a written agreement.
- Data processing agreement (DPA) available on request, or we review yours.
- Subprocessor list shared with the DPA. To be confirmed
- Data residency: client data hosted in the EU by default. To be confirmed
- Data protection contact for data subject requests and incidents. To be confirmed
- Retention: project data kept only as long as the contract requires. To be confirmed
- How we handle data on this website is described in the privacy policy.
Information security
The practices below describe how our delivery teams work. Details and evidence are in the security pack.
- Access control: least-privilege access to client systems, individual accounts, access removed at project end. To be confirmed
- Secure development: code review, dependency updates and security testing before release. To be confirmed
- Incident response: defined process and client notification. To be confirmed
- Penetration testing: on client request or as part of launch readiness. To be confirmed
- Confidentiality: mutual NDA before sensitive documents are shared.
- Certifications: none listed until verified. To be confirmed
How we use AI in delivery
We use AI to work faster and to build AI systems for clients, with rules that protect your data and your customers.
- Client data is never used for training public AI models. We use providers under business terms that exclude training on customer data.
- Human review: people check AI output before it reaches clients or end users. In the UNTOLD project, the AI drafts and a copywriter edits.
- Vetted tools: only approved AI tools are used on client work. To be confirmed
- Model choice per use case: we are not tied to one AI provider, and you own what we build for you.
- Measured quality: accuracy is defined and tested before launch. See how we work.
- Written AI usage policy for our teams, available in the security pack. To be confirmed
EU AI Act readiness
The EU AI Act applies in stages. These are the dates that matter for most of the projects we deliver.
Now
AI literacy (Article 4)
Companies using AI must make sure their staff have sufficient AI literacy. AI literacy training for your teams can be part of a project.
2 August 2026
Transparency (Article 50)
People must be told when they interact with an AI system, and AI-generated content must be identifiable. We design this in.
2 December 2027
High-risk systems (Annex III)
Obligations for high-risk AI systems apply from this date, as moved by the Digital Omnibus, Regulation (EU) 2026/1744.
In every AI project we classify the use case by risk level at the start, document data flows and human oversight, and hand over the documentation you need. The AI Opportunity Scan includes a risk classification per use case. This is not legal advice; we work alongside your legal counsel.
Accessibility
The European Accessibility Act has applied to many consumer-facing digital products and services since June 2025.
- WCAG 2.2 AA as our delivery target for new websites and apps. To be confirmed
- Accessibility audits of existing products, with a prioritised fix list. Accessibility audit
Public procurement and tenders
We take part in private RFPs and public tenders, alone or in consortia.
- SEAP/SICAP: registered for Romanian public procurement. To be confirmed
- EU-funded and education projects: for example the INGENIUM European University Alliance digital platform.
- Commercial models: fixed scope, time and materials, dedicated teams and framework agreements. To be confirmed
- Tender documents: send them through our RFP fast lane and we confirm participation quickly.
“The migration of the website was both a challenging and complex project and the support provided by the Grapefruit team was very good, and they were hands-on through the entire technical process. Also, the fact that there was an Agile project management approach in place from start to the end, made the entire way of working efficient and clear from one iteration to the other and I really appreciated the collaboration with them.”
Request the security pack
Choose the documents your due diligence needs. We send them by email, after a mutual NDA where needed.
Running a tender? Invite us to your RFP
Questions security and procurement teams ask
Will our data be used to train AI models?
No. Client data is never used to train public AI models. We use AI providers under business terms that exclude training on customer data, deploy in your cloud or an agreed EU region where needed, and cover processing with a data processing agreement.
How do you deal with AI mistakes and hallucinations?
We agree how accuracy will be measured before we build, test on your own examples, and add guardrails and human review wherever an error would be costly. After launch we keep measuring, so problems show up in numbers rather than in front of customers.
Will we be locked into one vendor or AI model?
No. We work with several model providers and choose per use case. You own what we build for you, and we hand over code, prompts, evaluation sets and documentation so you can switch models or partners.
Are you ready for the EU AI Act?
We classify each AI use case by risk level at the start of a project, design in transparency and human oversight, and prepare the documentation you will need. Transparency duties under Article 50 have applied since 2 August 2026. We do not give legal advice and can work alongside your legal counsel.
Is Grapefruit stable enough for a multi-year contract?
Grapefruit has delivered digital products since 1999 and is part of RCI Holding. Company registration details, references and financial information for vendor registration are available on request.
How long does vendor due diligence take with you?
Request the security pack on this page and we send it within 1 business day. We can complete your vendor security questionnaire and sign a mutual NDA before sharing sensitive documents.
Ready when your procurement process is
Invite us to your RFP, or start with a conversation about what you need.
We reply within 1 business day, usually the same day. Not ready to talk? Take the free AI assessment.