Legal

Data Processing Addendum

Last updated August 2, 2026

This DPA forms part of our Terms of Service and applies where we process personal data on your behalf under data-protection laws such as the GDPR and UK GDPR.

1. Roles

For personal data processed through Axeible, you (the merchant) act as the controller and Grenz acts as the processor. Each party will comply with its obligations under applicable data-protection law.

2. Scope & purpose

We process data only to provide Axeible — scanning your store's themes, products, and pages for accessibility issues, helping remediate them, and producing reports — and on your documented instructions, including as set out in the Terms and Privacy Policy.

3. Categories of data

Axeible is designed to minimise personal data. The data involved is primarily your store's content and the account details of your staff who use the app. By design, Axeible does not require or collect your customers' personal data.

4. Our obligations

  • Process personal data only on your instructions.
  • Ensure people authorised to process it are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations.
  • Notify you without undue delay after becoming aware of a personal-data breach.
  • Delete or return personal data at the end of the service, subject to legal retention requirements.

5. Subprocessors

You authorise us to engage subprocessors to help provide the service — such as our hosting/infrastructure provider, our email provider, and our AI provider. We require each subprocessor to be bound by data-protection terms appropriate to the data they handle. To the maximum extent permitted by law, we are not responsible for the acts or omissions of our subprocessors, and our liability is limited as set out in our Terms of Service. We will inform you of material changes to our subprocessors on request.

6. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.

7. Audit

We will make available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audit requests, subject to confidentiality and security safeguards.

8. Contact

Data-protection questions and requests can be sent to hellogrenz@gmail.com.

Contact

Questions about this document can be sent to hellogrenz@gmail.com.