Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Hyperse Group Ltd. ("Processor") and the Customer ("Controller") and reflects Article 28 UK GDPR / EU GDPR. In case of conflict this DPA prevails over the Terms for data-protection matters.

1. Subject matter, duration, nature and purpose

Processing of measurement data (clicks, installs, in-app events, identifiers, IP-derived signals) to provide click tracking, attribution, analytics and invalid-traffic protection for the Controller's advertising, for the duration of the Terms plus the deletion period.

2. Categories of data subjects and data

End users who click the Controller's advertisements or use its apps and websites. Data categories: online identifiers, advertising identifiers, hashed device identifiers, IP addresses (hashed, or raw for flagged traffic), user agent, coarse location, behavioural interaction data on landing pages, in-app events and revenue values. No special categories are permitted.

3. Processor obligations

  • Process personal data only on documented instructions of the Controller, including the configuration made in the dashboard, SDK and API, unless required by law (in which case we inform the Controller where permitted).
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement the technical and organisational measures in Annex 2.
  • Assist the Controller, at the Controller's cost where reasonable, with data-subject requests, DPIAs and consultations with supervisory authorities.
  • Notify the Controller without undue delay, and in any event within 48 hours of confirmation, of a personal-data breach affecting Controller data.
  • Delete or return personal data at the end of the Services (deletion within 30 days unless retention is required by law).
  • Make available information necessary to demonstrate compliance and allow audits, no more than once per year, on 30 days' notice, at the Controller's cost, by an independent auditor bound by confidentiality, without disrupting operations; SOC/ISO reports satisfy this where available.

4. Sub-processors

The Controller gives general authorisation to the sub-processors listed at whichclick.is/legal/dpa#subprocessors (hosting, managed PostgreSQL, Redis, CDN/edge network, transactional email, error monitoring, IP intelligence). We will give 14 days' notice of changes; the Controller may object on reasonable data-protection grounds, failing resolution of which either party may terminate the affected Services. We remain liable for our sub-processors.

Current sub-processors

  • Cloud hosting and managed database (UK/EU/US regions as selected)
  • Cloudflare, Inc. — edge network, DNS, DDoS protection, queues
  • Transactional email provider
  • Error and performance monitoring provider
  • IP intelligence provider (optional; network-level data only)

5. Controller obligations

The Controller warrants that it has a lawful basis, provides all required notices and obtains all required consents (including for identifiers under ePrivacy/PECR and App Tracking Transparency), that its instructions are lawful, and that it will not instruct processing of children's or special-category data. The Controller is responsible for the settings it configures, including retention periods, probabilistic attribution, IP exclusions and automated campaign actions.

6. International transfers

Where personal data is transferred outside the UK or EEA, the parties incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (Module 2, controller-to-processor) and the EU SCCs (Decision 2021/914), with the Controller as data exporter and the Processor as data importer, together with the supplementary measures in Annex 2.

7. Liability

The liability of each party under this DPA is subject to the exclusions and limitations in the Terms. The Controller shall indemnify the Processor against fines, claims and costs arising from the Controller's instructions, lack of lawful basis or notices, or breach of this DPA.

Annex 1 — Processing details

As set out in sections 1–2. Frequency: continuous. Retention: per Terms and Privacy Policy.

Annex 2 — Technical and organisational measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256); hashed identifiers; no cookies on redirect endpoints.
  • Role-based access, MFA for staff, least privilege, audit logs, secrets in a managed vault, key rotation.
  • Network segregation, rate limiting, DDoS mitigation, edge isolation of the redirect path from the control plane.
  • Backups with point-in-time recovery, tested restores, documented incident response and breach notification process.
  • Vendor due diligence, staff confidentiality and training, secure development lifecycle and annual penetration testing.