Data Protection Agreement
This Data Protection Agreement sets out the data protection terms applicable to marketing campaigns routed by us on our own opt-in audiences for business customers.
1. Purpose
This Data Protection Agreement defines the respective data protection responsibilities of the parties when we provide email, SMS or multichannel marketing campaign services using our own opt-in audiences.
It is intended to clarify the roles of the parties, the allocation of responsibilities, the handling of opt-in audience data, the management of unsubscribe and SMS STOP requests, the handling of complaints and the limitations applicable to liability in relation to data protection matters.
This Agreement is an autonomous contractual document and applies alongside any applicable order form, quotation, campaign confirmation, terms and conditions of sale or other agreement entered into between the customer and us.
2. Parties
The customer is the business customer, advertiser, agency or intermediary ordering a campaign or service from us.
Where the customer acts on behalf of an advertiser or another third party, the customer warrants that it has full authority to enter into this Agreement, approve the campaign and bind the final advertiser to the relevant data protection responsibilities.
3. Definitions
Agreement means this Data Protection Agreement.
Applicable Data Protection Laws means all data protection and privacy laws applicable to the relevant processing, including the UK GDPR, the EU GDPR where applicable, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations and any equivalent or related laws applicable to electronic marketing, privacy, direct marketing or personal data.
Audience Data means personal data relating to individuals included in our own opt-in audiences and used by us for the purpose of selecting, routing, measuring, suppressing or managing marketing campaigns.
Campaign means any email, SMS or multichannel marketing campaign ordered by the customer and routed by us on our own opt-in audiences.
Customer Content means the campaign content, commercial offer, text, creatives, links, landing pages, forms, brand elements, legal notices and any other materials provided, approved or controlled by the customer.
Recipient means an individual included in our opt-in audiences who receives or may receive a campaign routed by us.
Terms such as controller, personal data, processing, data subject and supervisory authority have the meanings given to them under Applicable Data Protection Laws.
4. Scope of this Agreement
This Agreement applies only to campaigns routed by us on our own opt-in audiences, without sale, rental, transfer or delivery of contact files to the customer.
This Agreement does not govern situations where the customer provides us with its own contact databases for processing on its behalf. Such processing, if ever agreed, would require separate written terms.
The parties acknowledge that the standard service covered by this Agreement is based on audience selection and routing by us, not on the transfer of personal data or contact files to the customer.
5. Roles of the parties
For campaigns routed on our own opt-in audiences, we act as an independent controller in relation to the Audience Data, including the collection, management, selection, suppression, routing and compliance records relating to that Audience Data.
The customer acts as an independent controller in relation to the Customer Content, the promoted offer, the landing page, any forms or digital environments operated by or for the customer, and any personal data collected by the customer after a Recipient clicks on a campaign or otherwise interacts with the customer.
The parties do not act as joint controllers unless this is expressly agreed in writing. Nothing in this Agreement is intended to appoint us as a processor of the customer in relation to our own Audience Data.
6. No sale, rental or delivery of contact files
The customer acknowledges that our services do not include the sale, rental, licensing, transfer, disclosure or delivery of contact files, databases or individual Audience Data to the customer.
The customer may select targeting criteria, countries, channels, volumes and campaign parameters, but the technical routing of the campaign is carried out by us or by authorised technical providers acting under our responsibility.
The customer shall not attempt to identify, extract, scrape, reconstruct, copy, enrich or otherwise obtain the underlying Audience Data, except where a Recipient voluntarily provides data directly to the customer through a customer-controlled landing page, form or process.
7. Our responsibilities
We are responsible for ensuring that the Audience Data used for campaigns is managed in accordance with Applicable Data Protection Laws, including where applicable the collection and maintenance of opt-in records, suppression records and compliance records.
We are responsible for selecting Recipients according to the available criteria and campaign parameters accepted by us, routing the campaign, managing unsubscribe requests relating to our email campaigns, processing SMS STOP requests relating to our SMS campaigns and maintaining appropriate suppression mechanisms.
We are also responsible for handling complaints and regulatory requests relating to our Audience Data, our opt-in records, our routing activities and our own compliance obligations, subject to the customer providing reasonable cooperation where the complaint or request relates to Customer Content, the promoted offer or the customer’s landing page.
8. Customer responsibilities
The customer is solely responsible for the lawfulness, accuracy and compliance of the Customer Content, including the promoted offer, advertising claims, prices, commercial terms, landing page, website, forms, privacy notices, consent mechanisms and any subsequent processing of personal data.
The customer warrants that the Customer Content does not infringe any third-party rights, is not misleading, unfair, fraudulent, unlawful, discriminatory, defamatory or contrary to Applicable Data Protection Laws, consumer protection laws, advertising rules or sector-specific regulations.
The customer is responsible for ensuring that any products or services promoted through a campaign may lawfully be advertised, offered and sold in the countries targeted by the campaign.
Where the campaign directs Recipients to a customer-controlled landing page, form or website, the customer is responsible for providing all required privacy information, identifying a valid lawful basis, collecting any required consent and responding to rights requests relating to the data it collects.
9. Campaign approval and compliance review
Before a campaign is routed, the customer must provide and approve all elements necessary for the campaign, including the message content, commercial offer, destination URL, targeting criteria, country, channel, volume and any required legal or commercial notices.
We may review Customer Content for operational, technical, reputational or compliance purposes. Any such review does not transfer responsibility for Customer Content to us and does not constitute legal validation of the campaign or the customer’s offer.
We reserve the right to refuse, suspend, delay or cancel any campaign that we reasonably consider to present a legal, regulatory, privacy, reputational, deliverability, technical or operational risk.
10. Lawful bases and consent
We are responsible for determining and documenting the lawful bases applicable to our processing of Audience Data, including the use of consent where required for electronic marketing to individuals.
The customer is responsible for determining and documenting the lawful bases applicable to any processing it carries out after a Recipient clicks through to a customer-controlled environment or otherwise provides personal data directly to the customer.
The customer shall not make any statement suggesting that it owns, controls or has received the underlying Audience Data unless we have expressly authorised such statement in writing.
11. Data subject rights
We are responsible for handling data subject rights requests relating to our Audience Data, including requests for access, rectification, erasure, restriction, objection, withdrawal of consent and suppression from future campaigns, where applicable.
The customer is responsible for handling data subject rights requests relating to any personal data it collects or processes through its own website, landing page, forms, CRM, sales process or other customer-controlled systems.
Each party shall provide reasonable cooperation to the other party where a rights request, complaint or regulatory enquiry concerns both the campaign routed by us and a customer-controlled process.
12. Unsubscribe, objection and SMS STOP requests
We manage unsubscribe, objection and SMS STOP requests relating to campaigns routed on our own audiences, and we maintain suppression records where necessary to ensure that such requests are respected.
The customer shall not interfere with, disable, obscure or remove any unsubscribe link, STOP instruction, sender information or other mechanism required for compliance with Applicable Data Protection Laws or electronic communications rules.
Where a Recipient contacts the customer directly to object, unsubscribe, complain or request removal in connection with a campaign routed by us, the customer shall promptly forward the relevant information to us so that we can apply the appropriate suppression or complaint handling measures.
13. Complaints and supervisory authority requests
If either party receives a complaint, enquiry or request from a Recipient, supervisory authority, telecom operator, platform, mailbox provider or other competent body relating to a campaign, it shall notify the other party without undue delay where the matter concerns the other party’s responsibilities.
We will manage complaints and authority requests relating to our Audience Data, our opt-in records, our routing activity and our suppression systems.
The customer shall manage complaints and authority requests relating to the Customer Content, the promoted offer, the customer’s landing page, the customer’s subsequent lead collection, sales process or data processing activities.
The customer shall provide prompt and reasonable cooperation, including copies of relevant landing pages, forms, privacy notices, customer communications, offer details and any other information reasonably required to respond to a complaint or authority request.
14. Security
Each party shall implement appropriate technical and organisational measures designed to protect the personal data for which it is responsible against unauthorised access, unlawful processing, accidental loss, destruction or damage.
We shall maintain security measures appropriate to the nature of the Audience Data and the risks associated with our campaign routing services, which may include access controls, secure hosting, confidentiality obligations, monitoring, backups, encryption or pseudonymisation where appropriate and internal compliance procedures.
The customer shall maintain appropriate security measures for any personal data it collects or processes through its landing pages, websites, forms, CRM systems, sales tools or other customer systems.
15. Technical providers and subcontractors
The customer gives us a general authorisation to use technical providers, subcontractors and service providers where necessary to host data, operate our services, route email or SMS campaigns, manage security, measure performance, provide support, maintain systems or comply with legal obligations.
We are not required to publicly name our technical providers or subcontractors, but we shall ensure that providers processing personal data for us are subject to appropriate contractual, confidentiality and security obligations.
We remain responsible for selecting providers that are appropriate for the services they perform and for imposing contractual protections appropriate to the nature of the processing.
16. International transfers
Personal data may be processed in the United Kingdom, the European Economic Area and other countries where we, the customer or our respective providers operate.
Where a party transfers personal data outside the United Kingdom, the European Economic Area or the country of residence of the relevant individual, that party shall ensure that an appropriate transfer mechanism is in place where required by Applicable Data Protection Laws.
Such mechanisms may include adequacy regulations or adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard recognised by Applicable Data Protection Laws.
17. Retention of data and compliance records
We may retain Audience Data, campaign records, suppression records, consent evidence, complaint records and related compliance records for as long as necessary to operate our services, respect opt-out requests, demonstrate compliance, handle complaints, respond to authorities, resolve disputes and defend legal claims.
Consent evidence and related compliance records may be retained for the duration of the relevant processing and for up to five years after the end of that processing, where necessary to demonstrate compliance, manage complaints, defend legal claims or respond to competent authorities.
Unsubscribe, objection and SMS STOP records may be retained for as long as necessary to ensure that the relevant individual is not contacted again in breach of their request.
18. Personal data breaches
Each party shall be responsible for handling personal data breaches affecting the personal data for which it acts as controller.
Where a personal data breach affects our Audience Data or our campaign routing systems, we shall assess the breach and make any notifications to supervisory authorities or affected individuals required from us under Applicable Data Protection Laws.
Where a personal data breach affects the customer’s landing page, forms, website, CRM, sales systems, customer databases or other customer-controlled processing, the customer shall assess the breach and make any required notifications.
Where a breach may affect both parties’ responsibilities, the parties shall cooperate reasonably and without undue delay, while each party remains responsible for its own legal obligations.
19. Audits and compliance information
We may provide reasonable information to the customer regarding our data protection practices applicable to the services, where such information is reasonably necessary to demonstrate compliance with this Agreement.
Any request for compliance information must be reasonable, proportionate, limited to the services concerned and subject to appropriate confidentiality obligations.
Physical audits, unrestricted system access, access to confidential technical infrastructure, access to information relating to other customers, or access to underlying Audience Data are not permitted unless required by Applicable Data Protection Laws or expressly agreed in writing by us.
We may refuse or limit any audit or information request that is excessive, repetitive, disproportionate, commercially sensitive, security-sensitive or likely to compromise the rights of third parties.
20. Customer indemnity
The customer shall indemnify and hold us harmless against any claim, complaint, investigation, loss, cost, liability, damage, penalty, fine, settlement, legal cost or expense arising from or in connection with Customer Content, the promoted offer, the customer’s landing page, the customer’s forms, the customer’s subsequent lead collection or processing, or any breach by the customer of this Agreement or Applicable Data Protection Laws.
This indemnity includes claims or complaints alleging that Customer Content was misleading, unlawful, unfair, non-compliant, harmful, inadequately disclosed, unsupported by appropriate legal notices or otherwise contrary to applicable marketing, advertising, consumer protection or data protection rules.
The customer shall not settle any claim or complaint in a way that admits liability on our behalf, imposes obligations on us or affects our Audience Data or compliance records without our prior written consent.
21. Limitation of liability
Nothing in this Agreement excludes or limits liability for death or personal injury caused by negligence, fraud, fraudulent misrepresentation or any liability that cannot lawfully be excluded or limited.
Subject to the preceding paragraph, we shall not be liable for any indirect, incidental, consequential, punitive or special loss or damage, including loss of revenue, loss of profit, loss of margin, loss of business, loss of goodwill, loss of reputation, loss of opportunity, loss of anticipated savings, loss of data, loss of contracts, business interruption or costs of substitute services.
We shall not be liable for any administrative fine, regulatory penalty, sanction, investigation cost, enforcement cost or other amount imposed on the customer by a supervisory authority or other competent body, except to the extent that such amount results directly from our proven breach of this Agreement and cannot lawfully be excluded.
Subject to the exclusions and limitations set out in this Agreement, our aggregate liability arising out of or in connection with a campaign shall not exceed the fees actually paid by the customer to us for the campaign giving rise to the claim.
Where a claim is not linked to a specific campaign, our aggregate liability shall not exceed the fees actually paid by the customer to us during the three months preceding the event giving rise to the claim.
The limitations set out in this section are agreed by the parties as reasonable and proportionate having regard to the nature of the services, the absence of delivery of contact files, the customer’s responsibility for Customer Content and customer-controlled processing, and the fees payable for the services.
22. Confidentiality
Each party shall keep confidential any non-public information received from the other party in connection with this Agreement, including technical, commercial, operational, security, compliance or legal information.
Confidential information may be disclosed only where necessary for the performance of the services, required by law, requested by a competent authority, disclosed to professional advisers under a duty of confidentiality or authorised by the disclosing party.
The customer shall not disclose, publish or use any information relating to our Audience Data, compliance methods, consent sources, routing infrastructure, providers or suppression mechanisms except as expressly authorised by us in writing.
23. Order of priority
In the event of conflict between this Agreement and any commercial terms, quotation, order form or terms and conditions of sale, this Agreement shall prevail only in relation to the specific data protection subject matter it covers.
All commercial, payment, cancellation, performance and general liability provisions not specifically addressed in this Agreement remain governed by the applicable commercial terms agreed between the parties.
24. Reference language
This Agreement may be made available in several languages to facilitate understanding by customers located in different countries.
In the event of any discrepancy, contradiction or difficulty of interpretation between the different language versions of this Agreement, the English version shall prevail.
25. Governing law and disputes
This Agreement is governed by the laws of England and Wales, without prejudice to any mandatory rules that may apply under Applicable Data Protection Laws.
The parties shall seek to resolve any dispute arising from this Agreement amicably before commencing legal proceedings.
Failing amicable resolution, the dispute shall be submitted to the competent courts, subject to any mandatory rules that may apply.
26. Contact
For any question relating to this Data Protection Agreement, data protection responsibilities, complaints, unsubscribe requests, SMS STOP requests or privacy rights, the customer may contact us by email.
Contact us about data protection