Data Processing Addendum
Last updated: 9 October 2026
This addendum applies when we process personal data on your behalf under the EU or UK GDPR, the Swiss Federal Act on Data Protection, or a law that requires a similar agreement. It is part of the Terms of Service.
| Term | What we agree |
|---|---|
| Roles | You are the controller of personal data contained in your websites and code ("Your Data"); Misimi Corp is the processor. |
| Subject matter and duration | Providing the Service, for as long as you have an account. |
| Nature and purpose | Automated accessibility and website quality checks, storing results and the evidence record, showing the public record you choose to publish, and writing code fixes with AI. |
| Data and data subjects | Personal data that appears on the pages we check or in the code of a repository you connect; your users and any other people named there. |
| Instructions | We process Your Data only on your documented instructions, which include the Terms of Service and what you ask the Service to do, unless the law requires otherwise, in which case we tell you where that is lawful. |
| Confidentiality | Everyone with access is bound by confidentiality. |
| Security | The measures in section 10 of the Privacy Policy, appropriate to the risk (GDPR Art. 32). |
| Sub-processors | You authorise those listed in section 6 of the Privacy Policy: Cloudflare, Clerk, Creem, Anthropic and GitHub. We give notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve it, you may end the agreement. We place equivalent obligations on each sub-processor. |
| Assistance | Taking into account the nature of the processing, we help you respond to requests from individuals and meet your duties on security, breach notification and impact assessments. |
| Breach notice | We tell you without undue delay after becoming aware of a personal data breach affecting Your Data. |
| Deletion | Code read by Website Mechanic is not kept by us after the job finishes. Everything else is deleted when you delete the site or your account, unless the law requires us to keep it. |
| Audits | We make available the information needed to show we meet GDPR Art. 28 and allow reasonable audits on 30 days' notice, at your cost, once a year. |
| Transfers | The EU Standard Contractual Clauses (module two or three, as applicable), the UK Addendum to them, and the Swiss amendments are incorporated by reference where they are required. |
Where this addendum and the Terms of Service disagree about personal data, this addendum applies.