Data Processing Addendum

    Last Updated: December 2025

    This Data Processing Addendum ("DPA") is incorporated into and forms part of the MKTGToolkit Terms of Service ("Agreement") and applies to the processing of Personal Data provided by the User ("Controller") to MKTGToolkit ("Processor").

    1. Definitions

    "Controller" refers to the User (the MKTGToolkit subscriber) who determines the purposes and means of processing Personal Data.

    "Processor" refers to MKTGToolkit, which processes Personal Data on behalf of the Controller.

    "Personal Data" means any information relating to an identified or identifiable natural person.

    "Data Subject" means the individual to whom Personal Data relates.

    "Sub-processor" means any third party engaged by the Processor to process Personal Data.

    "Data Protection Laws" means GDPR, UK GDPR, CCPA, and other applicable privacy legislation.

    2. Scope & Purpose of Processing

    This DPA applies when MKTGToolkit processes Personal Data on behalf of the Controller for the purpose of providing:

    • Social media content management and publishing services
    • Email marketing campaign management and delivery
    • Contact management and audience segmentation
    • Analytics and reporting on marketing activities
    • Integration with third-party platforms (ClickUp, social networks)

    3. Processing Instructions

    The Processor shall:

    • Process Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or international organization
    • Not process Personal Data for any purpose other than providing the Services
    • Immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Laws
    • Ensure that persons authorized to process Personal Data have committed to confidentiality

    4. Security of Processing

    MKTGToolkit implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

    Encryption

    • AES-256 encryption for stored API keys and tokens
    • TLS 1.3 for all data in transit
    • Encrypted backups

    Access Controls

    • Role-based access control (RBAC)
    • Multi-factor authentication for administrative access
    • Regular access reviews and audits

    Monitoring & Testing

    • 24/7 infrastructure monitoring
    • Regular security assessments and penetration testing
    • Automated vulnerability scanning

    Business Continuity

    • Regular data backups
    • Disaster recovery procedures
    • Geographic redundancy

    5. Sub-processors

    The Controller provides general authorization for the Processor to engage Sub-processors. The Processor shall:

    • Maintain an up-to-date list of Sub-processors
    • Notify the Controller of any intended changes to Sub-processors
    • Ensure Sub-processors are bound by data protection obligations no less protective than those in this DPA
    • Remain fully liable for the performance of Sub-processor obligations

    Current Sub-processors

    Sub-processorPurposeLocation
    Cloud Infrastructure ProviderHosting & Data StorageUSA/EU (SCCs)
    Stripe, Inc.Payment ProcessingUSA (SCCs)
    Email Service ProviderEmail DeliveryUSA (SCCs)

    6. Assistance to Controller

    Taking into account the nature of the processing, MKTGToolkit shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising Data Subject rights including:

    • Access to Personal Data
    • Rectification of inaccurate data
    • Erasure of Personal Data ("Right to be Forgotten")
    • Data portability
    • Restriction of processing
    • Objection to processing

    We provide self-service tools including Account Deletion and Data Export features to help fulfill these obligations.

    7. Data Breach Notification

    In the event of a Personal Data breach, the Processor shall:

    • Notify the Controller without undue delay and within 72 hours of becoming aware of the breach
    • Provide information about the nature of the breach, categories and approximate number of Data Subjects affected
    • Describe likely consequences and measures taken or proposed to address the breach
    • Cooperate with the Controller in investigating and remediating the breach

    8. International Data Transfers

    For transfers of Personal Data to countries outside the EEA/UK that do not provide adequate protection:

    • Standard Contractual Clauses (SCCs) pursuant to EU Commission Decision 2021/914/EU are incorporated into this DPA
    • The Processor conducts Transfer Impact Assessments (TIAs) for transfers to third countries
    • Supplementary measures are implemented where necessary based on TIA findings

    9. Audit Rights

    The Processor shall:

    • Make available to the Controller all information necessary to demonstrate compliance with this DPA
    • Allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller
    • Provide audit reports or certifications (SOC 2, ISO 27001) upon request

    Note: Audits shall be conducted with reasonable notice, during normal business hours, and shall not unreasonably disrupt the Processor's operations.

    10. Deletion and Return of Data

    Upon termination of the Agreement or upon request:

    • The Controller may export their data using our Data Export feature
    • The Processor shall delete all Personal Data within 30 days of request, unless retention is required by law
    • The Processor shall provide certification of deletion upon request
    • Data in backups will be deleted according to our backup rotation schedule (maximum 30 days)

    11. Term & Termination

    This DPA shall remain in effect for the duration of the Agreement and for as long as the Processor processes Personal Data on behalf of the Controller. Sections relating to confidentiality, data deletion, and audit rights shall survive termination.

    12. Liability

    Liability under this DPA shall be subject to the limitations set forth in the Agreement. Each party shall be liable for damages caused by processing that infringes Data Protection Laws or this DPA.

    13. Contact Information

    For DPA-related inquiries or to request a signed copy:

    Data Protection Officer: privacy@mktgtoolkit.com

    Legal Department: legal@mktgtoolkit.com

    Enterprise customers requiring a custom DPA or additional terms should contact our legal department.