1. Scope and roles
This Addendum applies where TODO: registered company name (“processor”) processes personal data on behalf of a customer (“controller”) in providing UTMCAP. It supplements the Terms of Service and prevails over them on any point about processing personal data.
You are the controller of the click and visitor data you collect through the service. We are your processor for it. For data about your own account we are the controller — see the Privacy Policy.
2. What is processed
| Subject matter | Recording, routing and reporting on advertising clicks. |
| Duration | For as long as your account is open, plus the retention window in section 9. |
| Categories of data subject | Visitors who click your tracked links, and any people identified in conversion data you send us. |
| Categories of personal data | IP address; derived location and network (country, region, city, ISP, network number); user agent, device, browser and operating system; referring URL; campaign parameters; identifiers you choose to pass, such as an order or subscriber reference; conversion values. |
| Special categories | None requested and none required. Do not pass special category data through campaign parameters; the service is not designed to hold it. |
3. Our instructions
We process personal data only on your documented instructions, which are given by your configuration of the service and this Addendum, and otherwise where a law we are subject to requires it — in which case we will tell you first unless that law forbids it.
Everyone with access is bound by confidentiality. Access to production data is limited to what is needed to run and support the service.
We will tell you if, in our view, an instruction of yours would break data protection law. We are not obliged to act on it.
4. Security measures
- Encryption in transit for all traffic to and from the service.
- Encrypted backups, verified by restoring them rather than by assuming.
- Passwords stored with a memory-hard hashing function, never reversibly.
- Tenant isolation: each account’s data is separated, and nothing is pooled or aggregated across customers.
- Key-based administrative access; no shared passwords for production systems.
- Rate limiting and abuse detection on authentication.
- Least-privilege credentials between the application and its data stores.
These are measures we maintain, not aspirations. If a specific control is a condition of your own compliance, ask before you rely on it.
5. Sub-processors
You give general authorisation for the sub-processors below. Each is engaged under written terms no less protective than this Addendum.
| Sub-processor | Purpose | Where |
|---|---|---|
| Cloudflare, Inc. | Edge delivery, DNS, certificates, and the redirect itself | Global — the location nearest the visitor |
| Oracle Cloud Infrastructure | Application and database hosting | TODO: confirm the region the production VM runs in |
| TODO: email delivery provider | Transactional email — invitations, password resets, alerts | TODO |
| TODO: payment processor | Payment and invoicing, once billing is switched on | TODO |
We will give at least 30 days’ notice by email before adding or replacing one. If you reasonably object on data protection grounds, tell us within that period; if we cannot resolve it, you may end the affected part of the service and be refunded the unused part of any prepaid term.
6. Assistance
Taking into account the nature of the processing, we will help you with:
- requests from data subjects — if one reaches us directly we will refer them to you and, where you ask, help you respond;
- data protection impact assessments and prior consultations;
- demonstrating compliance with this Addendum.
7. Breach notification
We will notify you without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting data we process for you. The notice will say what we know at the time — what happened, what data is involved, what we are doing — rather than waiting until the picture is complete.
8. Transfers
Clicks are answered at the Cloudflare location nearest the visitor, so processing is by nature international. Where personal data is transferred out of the EEA, the UK or another jurisdiction with transfer restrictions, it is transferred under the Standard Contractual Clauses or another mechanism recognised for that jurisdiction, with the supplementary measures set out in section 4.
9. Return and deletion
Click data is deleted at the end of your plan’s retention period in the ordinary course. On termination we retain data for 30 days so an accidental closure can be undone, then delete it, unless a law requires us to keep it — in which case we keep only what that law requires, and keep protecting it.
You can export your data at any time while the account is open, and can ask for an export during the 30 days.
Backups are on a rolling schedule and are deleted as they age out rather than being opened to remove individual records. Data in a backup is not restored into service.
10. Audits
On reasonable notice, and no more than once a year unless an authority requires otherwise, we will make available the information needed to demonstrate compliance with this Addendum and will cooperate with an audit. We may satisfy this with existing documentation and written answers where those genuinely address the question.
Contact for anything in this document: [email protected].