Data processing addendum
The terms under which KPI Atlas processes personal data on your agency's behalf.
Last updated 1 September 2026
Note: this text is a structured draft and is pending legal review before launch. It is not yet a binding agreement.
1. Roles of the parties
This addendum applies where KPI Atlas processes personal data on behalf of the customer. The customer is the controller; KPI Atlas is the processor. Where the customer processes its own clients' data, the customer may itself be a processor and this addendum operates on a sub-processing basis.
2. Subject matter and duration
Subject matter: retrieval, storage, transformation and delivery of marketing performance data for reporting purposes. Duration: for as long as the customer maintains an account, plus the 30-day export window.
3. Categories of data and data subjects
Data subjects: the customer's personnel, the customer's clients' personnel who receive or access reports, and end users represented within aggregate marketing metrics.
Categories: names, business contact details, authentication identifiers, and aggregate marketing performance data. No special category data is required by the service and it should not be uploaded through manual imports.
4. Processing instructions
KPI Atlas processes personal data only on the customer's documented instructions, which include the configuration set in the product, unless required otherwise by law. We will inform the customer where we believe an instruction infringes applicable data protection law.
5. Confidentiality and personnel
Personnel with access to personal data are bound by confidentiality obligations and receive data protection training. Access is granted on a least-privilege basis and reviewed periodically.
6. Security measures
Encryption in transit and at rest; network segregation; role-based access control with multi-factor authentication for administrative access; audit logging; vulnerability management; documented backup and restore procedures; and periodic review of these measures.
7. Subprocessors
The customer gives general authorisation for the subprocessors listed in the current subprocessor list. We will give at least 30 days' notice before adding or replacing a subprocessor, and the customer may object on reasonable data protection grounds.
Each subprocessor is bound by data protection obligations no less protective than those in this addendum.
8. Assistance to the controller
We assist the customer, taking into account the nature of processing, with data subject requests, data protection impact assessments and prior consultations, and provide the information reasonably required to demonstrate compliance.
9. Personal data breach
We notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, with the information available at that time, and provide updates as the investigation progresses.
10. Transfers, audit, deletion and return
International transfers rely on Standard Contractual Clauses or an equivalent mechanism. The customer may audit compliance once per year on reasonable notice, or rely on an available third-party report.
On termination, and at the customer's choice, personal data is returned by export or deleted, with deletion completed from production systems within 30 days and from backups on the standard backup cycle.