What we may do with your customers’ data, what we must do to protect it, who else we let near it, and what happens when you leave. It forms part of your Terms and needs no separate signature — though we will sign a copy if your process requires one.
You are the controller: you decide why and how your customers’ personal data is used. Graymat (Private) Limited is your processor: we act on your instructions and for no other purpose.
Data about you and your team — account, billing, support — is different: there we are the controller, and /privacy governs it. This agreement is only about your customers.
Only what is needed to provide the service, and only as your Terms, your configuration and your written instructions require. Using it to improve our own product, to train a model, to build a marketing audience or to enrich anything of ours is outside the permission you are giving here.
If we believe an instruction of yours breaks the law, we will tell you and may pause it rather than carry it out.
Subject matter: operating your commerce business inside Graymat. Duration: while your account is open, plus the deletion windows in clause viii. Data subjects: your customers, people who abandoned a cart, visitors to your store if you install the pixel, and your own staff.
Written from the live schema rather than a template: 66 tables hold personal data across 112 columns. No special-category data is intended or required — there is no field for health, religion, ethnicity, biometrics, government identity numbers or card numbers. A free-text note could be misused to record one; that is outside the intended use, and we ask you not to.
You give general authorisation for us to use sub-processors. The current list is at /subprocessors, which describes each sub-processor by function and location. The named list is provided to you on request and forms part of this agreement.
30 days’ email notice before we add or replace one. Object on data-protection grounds within those 30 days and we will find another way — and if there is none, you may terminate the affected service without penalty, pro rata refunded. Every sub-processor is bound to terms no weaker than these, and we remain fully responsible to you for what they do.
Export any time while the account is open. On termination your data stays available for 30 days; after that we delete it from live systems and it ages out of backups within a further 90 days. We confirm in writing when it is gone, if you ask.
We keep only what the law requires — invoices, tax records, and a minimal access log. None of it contains your customers’ contact details.
Once a year, or after a breach affecting you, ask us to demonstrate compliance. We will answer a reasonable security questionnaire and walk your team through how isolation and access control actually work — including showing the automated checks run.
An on-site inspection or third-party audit is at your cost, on 30 days’ notice, no more than once a year, and must not disturb another merchant’s data.
Liability here is subject to the cap in your Terms. Where this agreement and the Terms conflict on the handling of personal data, this agreement wins.