Data Processing Addendum (DPA)
Last updated: 20 August 2026
This Data Processing Addendum summarises how POSIMYTH Innovations (“we”, “us”, “our”), based in India and operating store.posimyth.com, processes personal data on behalf of business customers. It supplements our Terms & Conditions and Privacy Policy and reflects the EU/UK GDPR and India’s Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025. A signed copy is available on request at [email protected].
1. Roles
For personal data you provide as a customer, you are the controller / Data Fiduciary and we act as processor / Data Processor. For data we collect for our own purposes we are the controller. This DPA applies where we act as processor.
2. Subject matter, duration, nature and purpose
We process personal data to provide and support the WordPress products, licences and services you purchase, for the duration of your relationship with us and as required by law.
3. Types of data and data subjects
Typically contact and account details, order and licence data, and support communications, relating to you and your authorised users and customers.
4. Our obligations
We process personal data only on your documented instructions; keep authorised staff under confidentiality; apply appropriate technical and organisational security; assist you with data-subject / Data-Principal requests and with security, breach and impact-assessment duties; and make available information needed to demonstrate compliance.
5. Sub-processors
You authorise the sub-processors listed in our Privacy Policy (including Stripe, PayPal, Zoho TransMail (ZeptoMail), Elastic Email, Cloudflare, Hetzner, DigitalOcean, Google (Analytics 4, Tag Manager, Ads, Fonts and Sign-in), Meta (Facebook) Ads, Microsoft Clarity, Gist and WiserNotify). We impose data-protection terms on each and remain responsible for them.
6. International transfers
Personal data may be processed in India and other countries via our sub-processors under appropriate safeguards, such as standard contractual clauses where required.
7. Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data.
8. Return or deletion
On termination we will delete or return personal data processed on your behalf, except where retention is required by law.
9. Contact
To execute a signed DPA, contact POSIMYTH Innovations at [email protected]