Data Processing Addendum
Version 1.1 — last updated 2026-08-27. Template text requiring legal review before it is offered to business customers.
1. Scope and roles
This addendum forms part of the Terms of Service and applies where Merkel Digital Ltd. processes personal data on behalf of a customer in connection with HEIC Convert Free. The customer is the controller and we are the processor for that data. For our own account administration, billing and security purposes we act as an independent controller, as described in the Privacy Policy. Terms such as "personal data", "processing", "controller", "processor" and "data subject" have the meaning given in the UK/EU GDPR.
2. Image contents are not transferred to us
Conversion is performed entirely within the end user's browser. Image files and their contents are not transmitted to, received by, or stored by us, and there is no server-side conversion fallback. We are therefore not a processor of the image data itself.
3. Subject matter, duration, nature and purpose
- Subject matter: provision of a browser-based image conversion service and the accounts that access it.
- Duration: the term of the customer's subscription, plus the retention periods in section 9.
- Nature and purpose: authentication, subscription management, billing, support and security.
- Categories of data subject: the customer's authorised users.
- Categories of personal data: email addresses, account identifiers, subscription and billing metadata, support correspondence, IP addresses and technical logs.
- Special category data: none is requested or required.
4. Our obligations
- Process personal data only on the customer's documented instructions, including for transfers, unless required by law — in which case we notify the customer unless the law prohibits it.
- Ensure personnel authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures in section 6.
- Not sell personal data or use it for our own advertising or model training.
- Immediately inform the customer if an instruction appears to infringe data protection law.
5. Subprocessors
The customer gives general authorisation for the subprocessors listed on the Subprocessors page. We impose data protection obligations no less protective than this addendum on each of them and remain fully liable for their performance. We will give at least 30 days' notice before adding or replacing a subprocessor, and the customer may object on reasonable data protection grounds; if the objection cannot be resolved, the customer may terminate the affected subscription without penalty for the unused period.
6. Security measures
- Encryption in transit (TLS) for all traffic; encryption at rest at the database provider.
- Row-level authorisation on customer records, default deny, scoped to the signed-in user.
- Administrative roles held in a dedicated table and verified server-side only.
- Secrets held server-side and never shipped to the browser.
- Least-privilege administrative access with audit logging of administrative actions.
- Rate limiting on authentication, support and billing endpoints.
- Dependency scanning and prompt patching.
- Backups managed by the database provider, restorable point-in-time.
7. Assistance and data subject requests
Taking into account the nature of the processing, we assist the customer with data subject requests, data protection impact assessments and prior consultations. If a data subject contacts us directly about customer data, we refer them to the customer rather than responding substantively, unless legally required.
8. Breach notification
We notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting their data, with the information reasonably available: nature of the breach, categories and approximate numbers affected, likely consequences and measures taken or proposed.
9. Return and deletion
On termination, and at the customer's choice, we delete or return personal data and delete existing copies within 30 days, except where retention is required by law — for example billing and tax records — in which case the data remains subject to this addendum for as long as it is retained.
10. Audits
We make available the information necessary to demonstrate compliance and allow for audits by the customer or an independent auditor, on reasonable notice, no more than once per year unless a breach or regulator requires otherwise, during business hours, subject to confidentiality, and without disrupting other customers. Where available, provider documentation and our Security page satisfy the request in the first instance.
11. International transfers
Where personal data is transferred out of the UK, EEA or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor) apply and are incorporated by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. Docking, audit and governing-law options follow the parties' agreement; the customer is the data exporter and we are the data importer.
12. Liability
Each party's liability under this addendum is subject to the limitations and exclusions in the Terms of Service, except where applicable data protection law prohibits that limitation.
13. No certification claims
We do not claim SOC 2, ISO 27001, HIPAA, PCI DSS or any other certification, and no third-party audit has been performed. Statements in this addendum describe measures actually implemented.
14. Precedence and contact
In case of conflict, this addendum prevails over the Terms of Service for matters of personal data processing. To execute a countersigned copy, contact info@heicconvertfree.com.