LEGAL Data processing addendum
Data processing addendum
Article 28 terms covering data Tracepointer processes on your behalf.
Template — not yet reviewed by a solicitor
This document is scaffolding written to match how the platform actually
handles data. It is not legal advice and must be reviewed and amended
before the site goes live. Remove this notice by setting
'reviewed' => true
in config/policies.php.
Other documents
Scope
This addendum forms part of the agreement between Tracepointer Ltd — the processor — and the customer — the controller — and applies wherever we process personal data on the customer's behalf. It takes precedence over the terms of service on any point about data protection.
Subject matter and duration
Subject matter: provision of marketing attribution and conversion measurement.
Duration: for as long as the agreement is in force, plus the deletion period set out below.
Nature and purpose: collection, storage, organisation, analysis, and onward transmission of conversion signals to advertising platforms on the controller's instruction.
Categories of data subject: visitors to the controller's websites, and the controller's leads and customers.
Processing instructions
We process personal data only on documented instructions from the controller, which include the configuration choices made in the dashboard — retention period, whether raw identifiers are stored, and which conversion exports are enabled.
We will tell the controller if, in our opinion, an instruction infringes data protection law.
Security measures
We maintain, at minimum:
- Encryption in transit (TLS 1.2 or higher) and at rest for credentials and stored secrets.
- Tenant isolation enforced in the application layer on every query, with automated tests that fail the build if a tenant-owned model is missing its scope.
- Role-based access, least privilege for staff, and audit logging of any administrative access to a customer company, including the reason for access.
- Backups with tested restores, and change management with peer review before deployment.
Subprocessors
The controller gives general authorisation for the subprocessors listed on our subprocessors page. We give at least 30 days' notice before adding or replacing one, and the controller may object on reasonable data protection grounds.
Assistance
We assist the controller with data subject requests, data protection impact assessments and consultations with a supervisory authority, taking into account the nature of processing and the information available to us.
Deletion of an individual can be executed directly by the controller, which removes stored identifiers and raw personal data while preserving aggregate counts.
Personal data breach
We notify the controller without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting their data, with the information needed for the controller to meet its own notification duties.
Return and deletion
On termination we delete personal data within 30 days, except where retention is required by law. Backups age out on their normal cycle, within 35 days.
Audit
We make available the information needed to demonstrate compliance and allow audits, including inspections, by the controller or an auditor it mandates, on reasonable notice and no more than once a year unless a supervisory authority requires otherwise.
Questions about this document? Write to privacy@tracepointer.com.