Legal

Data Processing Addendum

Last updated 11 August 2026

This Addendum forms part of the Anookz Terms of Service and describes how ANOOKZ LIMITED (“Anookz”) processes personal data belonging to your customers. Where this Addendum and the Terms conflict on the handling of personal data, this Addendum applies.

Roles

You are the controller of your customers’ personal data. Anookz is the processor, acting on your instructions — in practice, the features you switch on and the integrations you connect.

What we process

We process the minimum needed to run the features you use. From connected sales channels:

  • Customer id and name — stored, so a point-of-sale sale can show who it belongs to.
  • Email and phone — read when you search for a customer to attach to a sale. Not stored.
  • Delivery address — read when booking a courier or producing a shipping label. Not stored.

Personal data is never sold, never used to train AI models, never used for advertising, and never shared with other merchants. Anookz has no marketing relationship with your customers and sends them nothing.

Sub-processors

The current register — every provider we engage, what it does, where it operates and whether it touches personal data — is maintained at anookz.com/legal/subprocessors. It is kept there rather than duplicated here so there is exactly one list: an inline copy is a list that goes stale, and a stale sub-processor list is a broken promise rather than a formatting problem.

We give at least 30 days’ notice before a new sub-processor that can access personal data starts work. Email privacy@anookz.com to be notified.

Security

  • TLS on every connection, and database storage encrypted at rest.
  • Integration credentials are additionally sealed with AES-256-GCM before being written, so a database dump does not yield a usable credential.
  • Access tokens are held server-side only and are never returned to a browser.
  • Administrative access is limited to an allowlist, and administrative actions are recorded in an audit log.
  • Development runs without production data; production credentials are held separately.
  • A daily canary compares row counts on append-only tables and raises a critical alert on unexplained shrinkage.

Retention and erasure

Personal data is retained while your account is active. On erasure, data belonging solely to you is purged; records that must survive for tax and accounting, or that belong jointly to a counterparty — a wholesale order belongs to both sides — are retained and de-identified so they no longer point at a person.

Where a connected platform issues an erasure instruction, we honour it on receipt. A Shopify customer redaction unlinks that customer from your sales records within the required window while leaving the sale itself intact as a financial record; a shop redaction deletes the stored credential.

Data subject requests

You remain responsible for responding to your customers. We provide export and erasure tooling and will help with anything you can’t fulfil yourself. Requests arriving through a connected platform’s compliance webhooks are logged with identifiers and counts only — never with the personal data the request concerns.

Incidents

We notify affected merchants without undue delay after becoming aware of a personal data breach, with what is known, what is affected, and what is being done — including where information is still incomplete. Where a breach has caused or is likely to cause serious harm, we also notify the Office of the Privacy Commissioner as required by the Privacy Act 2020.

International transfers

Anookz is operated from New Zealand and hosted in the United States. If you are in the EEA or UK, treat the sub-processor list above as the transfer inventory.

Audits and certifications

Anookz holds no third-party security certification — no SOC 2, no ISO 27001 — as at the date above. We state this plainly rather than omit it, because you are entitled to know what has and has not been independently verified.

Questions

Email hello@anookz.com.