⚔️GrimoirePrint
Convert Gallery Guide Contact

Data Processing Addendum

Last updated: 5 September 2026

This page is for customers who send us documents containing other people's personal data — typically a business or an agency using the API for its clients. It sets out the terms on which we process that data for you, and it lists every sub-processor involved. It forms part of our Terms of Service. If you are an individual using GrimoirePrint for your own documents, the Privacy Policy is the page you want; this one adds nothing for you.

This is our standard form, and it is under review by our solicitors. It applies as written to anyone using the service — you do not need to sign anything for it to apply. If your organisation needs a countersigned copy, or your own form, ask through [email protected], or the contact form, and we will work through it with you.

1. Who we are, and who is what

GrimoirePrint (grimoireprint.com) is operated by Commercial Maths Consulting Ltd (trading as GrimoirePrint), a company registered in England and Wales, company number 13451910, registered office Threeways, Sleepers Hill, Winchester SO22 4ND. For anything in this addendum, reach us at [email protected].

For the documents you send us, you are the controller and we are the processor: you decide whose data goes into a document and why, and we render it because you asked us to.

For your own account — your email address, your credit balance, your ledger — we are the controller, and the Privacy Policy governs it. Both are true at once, and they cover different data.

2. What we process, and for how long

Subject matter: converting a Markdown document into a PDF. Duration: the length of the conversion. Nature and purpose: rendering only — we do not read, index, analyse or learn from your documents. Types of data and categories of data subject: whatever you put in the document; we neither require nor inspect it.

In practice this is the shortest retention in the addendum: the document is written to a temporary file, read by the renderer, and deleted as soon as the conversion finishes. The PDF is held for five minutes so you can download it, then deleted. Neither is written to our database, included in our logs, or sent to any third party.

3. What we commit to

  • We process only on your instructions. Sending us a document is the instruction. If the law requires us to do something else, we will tell you first unless the law forbids us from telling you.
  • Confidentiality. Anyone who can access the systems that process your data is bound to keep it confidential.
  • Security. We keep appropriate technical and organisational measures. Section 10 of the Privacy Policy describes the ones that matter: TLS throughout, signed sessions, API keys stored only as a hash, and no passwords anywhere.
  • Sub-processors. Only the ones listed in section 5, on terms no less protective than these. If we add or replace one, we will publish it here and give at least 14 days' notice before it starts processing, so you can object; if you object on reasonable data-protection grounds and we cannot resolve it, you may stop using the service and we will refund your unused credits.
  • Helping you. We will help you respond to a data-subject request, and with data-protection impact assessments and consultations, so far as the help is something only we can give. In practice there is little to give: we hold your documents for seconds and keep no copy.
  • Breaches. If personal data we process for you is breached, we will tell you without undue delay after we become aware of it, with what we know and what we are doing about it.
  • Deletion. Your documents are deleted as part of every conversion, so there is nothing to return or delete when you stop using the service. Your account data is handled as the Privacy Policy says.
  • Demonstrating it. We will give you the information you reasonably need to satisfy yourself that we are meeting this addendum, and will contribute to an audit where the law requires one. Given the scale of what we process, we would expect to answer in writing rather than host an inspection, unless a regulator says otherwise.

4. International transfers

Some sub-processors are outside the UK, principally in the United States. Where that happens we rely on a mechanism recognised by UK law, confirmed provider by provider:

Provider What we rely on for transfers out of the UK
Railway (hosting) UK standard contractual clauses with the UK International Data Transfer Addendum. We have signed Railway's data processing addendum
Cloudflare EU standard contractual clauses (Module Two), amended by the UK Addendum for UK data, and the Data Privacy Framework
Resend (email) EU and UK standard contractual clauses, and the EU–US Data Privacy Framework with its UK Extension
Mixpanel (analytics) The EU–US Data Privacy Framework with its UK Extension, and standard contractual clauses Modules Two and Three. Analytics are ingested in the EU (api-eu.mixpanel.com) rather than the United States
GitHub (contact-form reports) EU standard contractual clauses with the Information Commissioner's International Data Transfer Addendum, and the EU–US Data Privacy Framework
Lemon Squeezy (payments) EU standard contractual clauses. Their terms do not name the UK Addendum, and we have raised it with them — see the note below

One exception is worth stating plainly. Lemon Squeezy's data processing terms rely on the EU standard contractual clauses and do not name the UK Addendum, and they are governed by the law of Utah. It is also the one relationship where their paperwork and ours describe different roles — their terms cast them as a processor, while as merchant of record they are an independent controller of the sale, which is how section 5 describes them.

5. Sub-processors

Everyone who touches data on our behalf, what they get, and why. Lemon Squeezy is listed for completeness even though it is not our sub-processor — it is the merchant of record and an independent controller of the sale, which is a different relationship and worth being clear about.

Provider What it processes Why Where
Railway (with its Cloudflare edge) Everything the service handles — the application, its database, its logs. Your documents pass through it during a conversion Hosting and delivery United States, with a global edge network
Resend The recipient's email address and the body of a sign-in or purchase email Transactional email. No mailing list, no marketing United States
Mixpanel A pseudonymous identifier, the page, referrer and UTM parameters, feature events, and — from our server — that a purchase or refund happened, with the pack, price and order references. Never your documents Product analytics. Browser analytics load only with the visitor's consent Ingested in the EU
GitHub What is sent through the contact form: the message, the subject, optionally a name and email, and the sender's markdown only if they tick the box Filed as an issue in our private repository so it can be worked on United States
Google / GitHub (sign-in) The sign-in request. We ask only for a verified email address and the provider's account identifier Signing in without a password Independent controllers for your account with them, not our sub-processors
Lemon Squeezy Your name, email, billing address and card details at checkout. Card details never reach us; we receive back only the paying email and the order and customer references Merchant of record — the seller of the transaction, and an independent controller of what it collects, under its own privacy policy United States

6. Precedence and changes

Where this addendum and the Terms of Service disagree about the processing of personal data you send us, this addendum wins. Everything else is governed by the terms, including the law that applies and where a dispute is heard.

We may update this page. The date at the top moves when we do, and a change of sub-processor carries the notice period in section 3.

Legal
Terms of Service Refunds & Cancellation Privacy Policy Data Processing