You do not need to sign this. This Addendum forms part of the Terms of Service and applies automatically from the moment you install Gridtiva, for as long as it stays installed. If your organisation requires a countersigned copy for its records, email support@gridtiva.com and we will provide one.

1. Roles, scope and order of precedence

This Addendum applies where, in providing Gridtiva, we process personal data on your behalf that is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, or Spanish Organic Law 3/2018 (LOPDGDD).

You are the controller. We are the processor. You determine why and how the metaobject content in your Shopify store is processed; we process it only to provide Gridtiva to you.

Where we process personal data about you as our customer — your name, your store’s contact details, correspondence with our support — we act as a controller for that limited set. That processing is described in our Privacy Policy and is outside this Addendum.

If this Addendum conflicts with the Terms of Service, this Addendum prevails for matters of personal data protection. Nothing here overrides your own agreement with Shopify.

2. Subject-matter, duration, nature and purpose

Subject-matter Reading, displaying and editing metaobject entries in your Shopify store, and keeping a verified, reversible record of the changes you apply.
Duration For as long as Gridtiva is installed on your store. Deletion on termination is set out in section 11.
Nature of processing Retrieval and display; editing on your instruction; writing to Shopify; verification of each write; durable storage of before-and-after values for 30 days; erasure.
Purpose Providing the service you installed, and nothing else. We do not use your data for our own purposes, for advertising, or to train machine-learning models.

3. Categories of data subjects and personal data

Gridtiva is not designed to process personal data, and normally does not. It requests only three Shopify scopes — read_metaobject_definitions, read_metaobjects and write_metaobjects — so it has no technical ability to reach customer records, orders, products or inventory.

Metaobjects are structured content: size guides, ingredient lists, store locators and so on. Whether any of it constitutes personal data is determined entirely by what you choose to put in your own metaobject fields.

Category Detail
Data subjects Any individual whose personal data you have chosen to store in a metaobject field — for example staff named in a store-locator entry, or an author named in a content entry. Determined by you, not by us.
Personal data The values held in the metaobject fields you edit, limited to the six field types Gridtiva can write: single-line text, multi-line text, integer, decimal, true/false and date.
Special category data Not permitted. You must not use Gridtiva to process data within Article 9 or Article 10 GDPR. See section 3.1 — this is a restriction on use, not a prediction about your content.
Frequency On demand, when you open the app and when you apply an update.

3.1 Restriction on special category and criminal offence data

You agree not to place data within Article 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify a person, health data, or data concerning sex life or sexual orientation — or within Article 10 GDPR (criminal convictions and offences) into metaobject fields you edit with Gridtiva.

We cannot enforce this technically, and we will not pretend otherwise. Gridtiva reads whatever a metaobject field contains and cannot inspect what it means. Nothing stops you typing a health condition into a text field.

It is therefore a contractual restriction, and the reason for it is plain: the measures in Annex II were designed for ordinary structured store content. Article 9 data would call for a level of protection we have neither assessed nor implemented.

If you place such data in scope anyway, you remain the controller, the processing falls outside the assumptions on which this Addendum and Annex II are built, and the obligation to carry out any further assessment and to apply any additional safeguards required by Articles 9, 32 and 35 GDPR is yours.

4. Processing on documented instructions

We process personal data only on your documented instructions, including for international transfers, unless required otherwise by EU or Member State law — in which case we will inform you before processing, unless that law prohibits it on important grounds of public interest.

Your instructions are: the Terms of Service, this Addendum, and the actions you take in the app. Selecting a definition instructs us to read it. Approving a preview instructs us to write exactly the cells shown in it, and nothing else.

We will immediately inform you if, in our opinion, an instruction infringes the GDPR or other data protection law, as required by Article 28(3) GDPR.

5. Confidentiality

Access to your data is limited to the operator named in section 15, who is bound by a duty of confidentiality. Gridtiva has no employees with routine access to merchant data, and no support process that requires us to read your metaobject values.

6. Security (Article 32)

We implement appropriate technical and organisational measures, described in Annex II. We keep them under review as the service changes.

7. Sub-processors

You give a general authorisation for us to engage the sub-processors listed in Annex III. We impose data protection obligations on each of them that are no less protective than those in this Addendum, and we remain fully liable to you for their performance.

We will give you at least 30 days’ notice before adding or replacing a sub-processor, by updating Annex III on this page and, where we hold a contact address for you, by email. If you reasonably object on data protection grounds within that period, you may terminate by uninstalling Gridtiva without penalty. Because all billing runs through Shopify, cancelling your subscription in your Shopify admin is sufficient.

8. International transfers

Our platform sub-processor stores data in Canada and in the United States. Personal data you process through Gridtiva is therefore transferred outside the European Economic Area.

Transfers are made under the mechanisms in our agreement with that sub-processor: the European Commission’s adequacy decision for Canada, and for the United States the EU–US Data Privacy Framework adequacy decision and, where that is unavailable or does not cover a given recipient, the Standard Contractual Clauses adopted under Article 46(2)(c) GDPR together with a transfer impact assessment.

We will tell you, on request, which mechanism applies to a given transfer, and we will notify you if a mechanism we rely on ceases to be available.

9. Assisting you with data subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests under Chapter III GDPR.

In practice: because Gridtiva does not maintain its own copy of your metaobject content beyond the 30-day change history, a request for access, rectification or erasure is normally satisfied in Shopify itself, where the data lives. If a request requires action on our change history, contact support@gridtiva.com and we will act on it without undue delay.

If a data subject contacts us directly about your data, we will not respond substantively; we will refer them to you and inform you.

10. Assisting you with Articles 32 to 36, and breach notification

We will assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to us.

We will notify you of a personal data breach affecting your data without undue delay after becoming aware of it, and in any event in time to allow you to meet your own 72-hour obligation under Article 33(1). Our notification will describe, so far as known: the nature of the breach and the categories and approximate number of records concerned; the likely consequences; the measures taken or proposed; and a contact point.

We do not notify supervisory authorities or data subjects on your behalf. That is the controller’s decision and duty. We give you what you need to make it.

10.1 Data protection impact assessment — screening

Article 35(1) GDPR requires a DPIA where processing is likely to result in a high risk to individuals. That duty is yours as controller, not ours. What follows is the screening we have carried out on our own processing, so that you do not have to reconstruct it; providing it is part of the assistance section 10 promises.

Article 35(3) trigger Assessment
(a) systematic and extensive automated evaluation, including profiling, with legal or similarly significant effects Not met. Gridtiva makes no automated decisions and performs no profiling. It writes the values you reviewed, and nothing else.
(b) processing on a large scale of Article 9 or Article 10 data Not met. Such data is contractually excluded under section 3.1, and the service is not designed for it.
(c) systematic monitoring of a publicly accessible area on a large scale Not met. Gridtiva monitors nothing and observes no individual. It is opened deliberately, by a merchant, to edit their own content.

Against the nine criteria in the Article 29 Working Party DPIA guidelines (WP248 rev.01), endorsed by the European Data Protection Board, Gridtiva’s processing engages at most one, and only arguably: data processed on a large scale, in the limited sense that a store may hold many entries. That guidance treats two or more criteria as the point at which a DPIA is normally required.

Conclusion: no DPIA is required for Gridtiva’s processing as designed.

This screening covers our processing only. Your own use may reach a threshold ours does not — particularly if you place personal data in metaobject fields at scale — and that assessment remains yours to make. We will supply whatever information about Gridtiva you need in order to make it.

11. Deletion and return

At your choice, we delete or return personal data at the end of the service:

  • On uninstall, your change history, undo snapshots and sessions are deleted immediately and permanently. Your metaobject entries are untouched: they remain in your Shopify store, under your control.
  • Independently of uninstalling, change history and snapshots expire after 30 days and are permanently deleted by a scheduled job. The window is fixed in the software and is not configurable.
  • On Shopify’s shop/redact request, sent approximately 48 hours after uninstall provided you have not reinstalled, every stored field of your store record is erased.
  • Return is available on request before you uninstall, in a structured, commonly used, machine-readable format.

We retain no copy afterwards, except where EU or Member State law requires storage.

12. Audits and information

We make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance, please write to support@gridtiva.com. Given the scale of the service, we expect most requests to be satisfied by written answers and by the documentation of our platform sub-processor. An on-site inspection may be conducted on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, at your cost, and subject to confidentiality.

13. Liability

Liability under this Addendum is subject to the limitations in section 9 of the Terms of Service, except that nothing limits liability which cannot lawfully be limited — including liability arising from wilful misconduct (dolo) under Article 1102 of the Spanish Civil Code, and any liability of a controller or processor under Article 82 GDPR.

14. Term

This Addendum takes effect when you install Gridtiva and continues until the later of uninstalling and our deletion of all personal data under section 11. Sections 5, 11, 12 and 13 survive termination.

15. Contact

Franzsheskoli Carlos Cabrera Toribio
Carrer de l'Avellaner 57, Matadepera 08230
Tax identification: 60549467N
support@gridtiva.com

We are established in Spain, within the European Union. No representative under Article 27 GDPR is required. We have not appointed a Data Protection Officer, because none of the conditions in Article 37(1) GDPR applies to this service; the contact address above is the point of contact for all data protection matters.

Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), www.aepd.es.

Annex I — Details of processing

The subject-matter, duration, nature and purpose are set out in section 2. The categories of data subjects and personal data are set out in section 3. The controller is you; the processor is the operator named in section 15.

Annex II — Technical and organisational measures

These are the measures Gridtiva implements. Measures at the infrastructure layer are those of our platform sub-processor, whose own documentation governs them.

Measure Implementation
Tenant isolation Every stored record is scoped to a single store. The software checks store identity on every read and every write and refuses any request whose store identity does not match.
Identity resolution The browser never supplies the store identity. It is resolved server-side from the authenticated Shopify session and validated against a durable record before use.
Authentication Shopify session tokens. Gridtiva has no login, no password and no credential of its own to be stolen.
Access minimisation Three Shopify scopes, all metaobject-only. No customer, order, product or inventory scope is requested, so none can be exercised.
Secret handling Access tokens and secrets are held by the platform, and are never written to logs, never returned to the browser and never included in error messages.
Log minimisation Application logs are written to contain identifiers, phase codes, timings and counts — not merchant field values.
Integrity of writes Every write is preceded by a fresh read and followed by an explicit verification. A write that cannot be verified is reported as unconfirmed rather than as a success, and a value changed by someone else since you reviewed it is refused rather than overwritten.
Reversibility Each verified change is stored with the value it replaced, and can be undone for 30 days.
Storage limitation A 30-day expiry is written onto every stored row and enforced by a scheduled job that runs hourly and deletes permanently.
Deletion Immediate and permanent deletion on uninstall; full erasure of the store record on Shopify’s shop/redact request.
Encryption in transit All traffic between your browser, Gridtiva and Shopify uses HTTPS/TLS.
Infrastructure measures Physical security, storage-level encryption, network security, backup and availability are provided and documented by our platform sub-processor. We do not restate them here; we can supply that provider’s current security documentation on request.

Annex III — Authorised sub-processors

Sub-processor Processing carried out Location
Gadget Inc. Application hosting, database, background job execution and logging for Gridtiva. Gadget publishes its own sub-processors in its privacy policy. Canada and the United States
Cloudflare, Inc. Authoritative DNS for gridtiva.com, and hosting, delivery and TLS termination for this website. Website visitors only; no merchant data reaches it, and it is not used by the Gridtiva application, which runs inside your Shopify admin. Global anycast network — no single region. See the note below.

Why no region is stated for Cloudflare. Cloudflare serves this website from whichever of its edge locations is closest to the visitor, so there is no single country or region in which the website is hosted, and naming one would be inventing a fact. Cloudflare’s own data protection terms and its published sub-processor list govern that processing.

This affects website visitors only. No merchant metaobject data passes through Cloudflare: the Gridtiva application runs inside the Shopify admin and talks to Gadget and Shopify directly.

Shopify is not our sub-processor. We do not engage Shopify to process data on your behalf — you already have your own relationship with Shopify, and Shopify is the source and the destination of the data Gridtiva reads and writes. Shopify’s processing of your store data is governed by your agreement with Shopify, not by this Addendum.