Effective date: 27 September 2026
This Data Processing Addendum is between Wren Foundry and a business customer. Wren Foundry operates Tintstep. The ordinary sale is to an individual. An individual is not a controller appointing Wren Foundry as a processor. If you are that individual, the Privacy Policy applies and this addendum does not.
This addendum applies when a business and Wren Foundry both accept it, including by an electronic acceptance Wren Foundry records. On a point of data protection, this addendum controls over the Terms of Service. The liability limit in the Terms of Service applies to this addendum except where the Standard Contractual Clauses set a rule that cannot be varied.
1. Roles
The business customer is the controller. Wren Foundry is the processor. For the extension's on-device reading of page styles, Wren Foundry does not receive the page styles and is not a processor of them. This addendum covers account, billing, support, and site-log data that the controller's personnel submit to, or generate on, the Tintstep website.
2. Subject matter and details
Wren Foundry hosts accounts and subscriptions and answers support for the term of the controller's subscription, plus the retention periods in the Privacy Policy.
The processing is: storing account and subscription records, delivering account email, answering support, securing the site, and deleting or returning data as this addendum requires.
Personal data: business contact details, account credentials stored as hashes, device labels, subscription status, invoice references, and support messages. Card numbers entered on Stripe's pages are handled by Stripe under Stripe's terms and are not stored by Wren Foundry.
Data subjects: the controller's personnel who create accounts or write to support. Page content of the controller's own customers is not submitted to Wren Foundry.
The controller will not submit special-category data, government identifiers, or card numbers in a support message.
3. Instructions
Wren Foundry processes personal data only on the controller's documented instructions, which are this addendum, the Terms of Service, and the settings in the product, unless the law requires otherwise. Wren Foundry will tell the controller if an instruction appears to violate applicable data-protection law, unless the law forbids that notice.
4. Confidentiality
Wren Foundry limits access to people who need it to provide Tintstep and binds them to confidentiality.
5. Security
Wren Foundry maintains the measures in Annex II. The controller is responsible for deciding whether those measures fit the data it chooses to submit.
6. Subprocessors
Wren Foundry uses the companies listed at Subprocessors. That page is Annex III. Wren Foundry will email the account address at least 15 days before a new subprocessor starts handling the controller's personal data. The controller may object on a reasonable data-protection ground before that date. If Wren Foundry cannot reasonably accommodate the objection, the controller may cancel the subscription. Cancellation follows the Subscription Terms. Fees already due remain due.
Wren Foundry imposes data-protection terms on each subprocessor that are no less protective than this addendum for the processing that subprocessor performs. Wren Foundry remains liable to the controller for a subprocessor's performance of those obligations.
7. Assistance
Wren Foundry will assist the controller with data-subject requests, security inquiries, and data-protection impact assessments, taking into account the nature of the processing and the information available to Wren Foundry. Export and Delete in the product are the first means of access and deletion. Wren Foundry may charge a reasonable fee for a request that is repetitive or unfounded, where the law allows that fee.
8. Personal-data incidents
Wren Foundry will notify the controller without undue delay after becoming aware of a personal-data breach affecting the controller's personal data. The notice will include, as it becomes available, the information the controller reasonably needs to meet its own notice duties.
9. Deletion and return
At the end of the service, Wren Foundry deletes the controller's personal data on the schedule in the Privacy Policy, unless the law requires storage. Invoice records are kept for 7 years after the invoice date. On written request made before deletion, Wren Foundry will return a copy through the product's export function. A deleted record can remain in a backup until that backup expires and is not restored except to recover the service from an incident.
10. Audits
Once in any twelve-month period, the controller may ask for a written summary of the measures in Annex II. An on-site audit is available if a regulator requires it, on at least 30 days' notice, during business hours, under a confidentiality duty, and without access to another customer's data. The controller pays its own costs unless the audit finds a material breach of this addendum.
11. International transfers
Wren Foundry may process personal data in the United States, including through the subprocessors in Annex III.
Where GDPR applies to a transfer of the controller's personal data to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses, Module Two (controller to processor), annexed to Commission Implementing Decision (EU) 2021/914. The controller is the data exporter. Wren Foundry is the data importer.
The clauses are completed as follows. Clause 7 (docking) is not used. Clause 9(a), Option 2 applies: general written authorisation, with the notice period in section 6. Clause 11 (optional independent redress) is not used. For Clause 17, the governing law is the law of the EU member state where the controller is established. If the controller is not established in a member state, the governing law is the law of Ireland. For Clause 18, the courts are the courts of that same country. Annex I.A, I.B, and I.C are sections 1 and 2 of this addendum and this section 11. The competent supervisory authority is the authority of the controller's EU establishment, or the Irish Data Protection Commission if the controller is not established in the EU. Annex II is Annex II of this addendum. Annex III is the subprocessors page.
Where UK GDPR applies to the transfer, the parties also incorporate the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner and in force on 21 March 2022. The exporter and importer are the same parties. The approved EU SCCs are those selected in this section, including Module Two. Neither party may end the addendum under its Section 19.
The Standard Contractual Clauses control over this addendum where the clauses prohibit a change. They do not otherwise reduce a protection this addendum gives the controller.
12. Contact
Wren Foundry
[postal address]
Annex II. Technical and organisational measures
- TLS for data in transit to the website.
- Production data access limited to the service role and to staff accounts with a support or owner role.
- Row-level security on customer tables.
- Passwords stored as hashes by the authentication provider. Device refresh tokens stored as hashes.
- Payment-notification signatures checked before a payload is trusted.
- Logs that exclude email addresses, tokens, and message bodies.
- Provider backups. A deleted account may remain until the backup expires. A backup is not used to restore a deleted account except to recover the service from an incident.
- Dependency changes made through the source repository.
Wren Foundry does not describe these measures as a certification.