Groundcraft legal
Data Processing Addendum
For customers whose sites collect personal data from visitors.
In force 12 August 2026 · Version 1.0
Parties. Mind Hack, Inc., 651 N Broad St Ste 104, Middletown, DE 19709-6401, United States (“Groundcraft,” the processor) and the customer named on the account (the controller).
Effective date: 12 August 2026. Version: 1.0.
How this is executed. This addendum is automatically part of the Terms of Service for every customer — there is nothing to sign, request, or countersign. It applies whenever a customer’s hosted sites collect personal data from their visitors: contact forms, lead capture, bookings, comments, and similar. If your procurement process needs a countersigned copy, email us and we will sign this document as written; we will not negotiate a bespoke variant, because a document we cannot honor uniformly across the estate is worse than no document.
1. Roles, stated plainly
For the personal data of your site visitors, you decide why and how it is collected — you are the controller. Groundcraft stores and processes it only to run your sites and the platform features you enable — we are your processor. (For your own account data — your name, email, billing — we are the controller; that is covered by the Privacy Policy, not this DPA.)
2. Subject matter and instructions
- What we process: the content of your hosted sites, including personal data your sites collect from visitors (typically: names, email addresses, phone numbers, message content in form submissions; whatever your forms ask for).
- Categories of data subject: your site visitors, your customers, and anyone else who submits data to a site we host for you.
- What we do with it: host, store, back up, transmit, and display it; route lead notifications; and run the platform features you have turned on. Nothing else.
- Your instructions: these terms, your configuration of your sites and features, and any lawful written instructions you give us. We will not process visitor data for our own purposes, and we do not use it to train AI models.
- If we believe an instruction violates data-protection law, we will tell you before proceeding.
3. Duration
For as long as you have an active subscription, plus the deletion window in §8.
4. Confidentiality
People who can access customer site data (our operations staff) are bound by confidentiality obligations and access production systems only as needed to run and support the service.
5. Security
Measures as described in the Privacy Policy §10: key-based access to production, card data isolated to Stripe, regular backups (nightly; hourly on higher plans), monitored infrastructure. We will maintain measures appropriate to the risk under GDPR Art. 32 and will not materially reduce the overall security of the service during your subscription.
6. Subprocessors
- You give general authorization for the subprocessors listed in the Privacy Policy §5 — currently Stripe/WooCommerce Payments, Google Cloud/Firebase, Contabo GmbH, and, where you enable the relevant features, Google APIs and DataForSEO. Mailee is not a subprocessor: it is our own email platform, operated by Mind Hack, Inc.
- We will give 30 days’ notice before adding or replacing a subprocessor that touches visitor data. If you object on reasonable data-protection grounds and we cannot accommodate you, you may cancel under the normal terms with a refund of any prepaid, unused period — that is the honest remedy a provider our size can offer, and we would rather state it than pretend to a veto we could not survive.
- We remain responsible to you for our subprocessors’ performance, and we bind them to obligations materially equivalent to this DPA.
7. Assisting you
Taking into account what a hosting processor can actually see and do:
- Visitor rights requests (access, deletion, correction): your site’s own admin tools handle most of these directly. Where they cannot — e.g., purging a visitor’s data from backups — we will assist on request.
- Security and DPIAs: we will provide reasonable information about our processing and measures to support your compliance obligations (Art. 32–36).
- Audits: we will answer reasonable written security questionnaires and provide available evidence — this DPA, the Privacy Policy, summaries of our measures, and the audit reports our infrastructure providers publish. We do not offer on-site audits, and we would rather say so than accept a clause we could not honor at our size.
8. Deletion and return on termination
When your subscription ends, the Terms of Service §11 window applies — 30 days. During it you can export your sites in full: content, databases, and the visitor data they contain. When the window closes, we delete site content and backups, including visitor personal data, from our systems, except where law requires retention. On written request we will confirm deletion.
9. Breach notice
If we confirm a personal-data breach affecting your visitor data, we will notify you without undue delay, and in any case within 72 hours of confirming it, with what we know: nature of the breach, data and sites affected, measures taken, and a contact for follow-up. We will not notify your visitors ourselves — that is the controller’s call — but we will support your notification obligations.
10. International transfers
Visitor data is stored on servers in Germany (Contabo); platform operations and backups involve transfer to the United States (Google Cloud — see Privacy Policy §6).
For customers subject to GDPR or UK GDPR, transfers from the EEA/UK to Mind Hack, Inc. in the United States are governed by the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), Module Two (controller → processor), and Module Three (processor → processor) where you act as a processor for your own clients, incorporated into this DPA by reference with the following elections:
- Clause 7 (docking): included.
- Clause 9 (subprocessors): Option 2, general written authorization, with the 30-day notice period in §6.
- Clause 11 (redress): the optional independent-dispute-resolution paragraph is not included.
- Clause 17 (governing law): the law of Ireland.
- Clause 18(b) (forum): the courts of Ireland.
- UK transfers: the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, with Tables 1–4 completed from this DPA; the “Importer” may end the Addendum under Section 19.
- Annex I (parties, description of processing): §§1–3 of this DPA.
- Annex II (technical and organisational measures): §5 of this DPA and Privacy Policy §10.
- Annex III (subprocessors): §6 of this DPA and Privacy Policy §5.
Where the SCCs conflict with the rest of this DPA on an EEA/UK transfer, the SCCs prevail.
11. Precedence
If this DPA conflicts with the Terms of Service on the processing of visitor personal data, this DPA wins.
12. Contact
Mind Hack, Inc. 651 N Broad St Ste 104, Middletown, DE 19709-6401, United States hello@groundcraft.dev · (240) 573-1425