This Data Processing Addendum ("DPA") is incorporated into and forms part of the MKTGToolkit Terms of Service ("Agreement") and applies to the processing of Personal Data provided by the User ("Controller") to MKTGToolkit ("Processor").
1. Definitions
"Controller" refers to the User (the MKTGToolkit subscriber) who determines the purposes and means of processing Personal Data.
"Processor" refers to MKTGToolkit, which processes Personal Data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Data Subject" means the individual to whom Personal Data relates.
"Sub-processor" means any third party engaged by the Processor to process Personal Data.
"Data Protection Laws" means GDPR, UK GDPR, CCPA, and other applicable privacy legislation.
2. Scope & Purpose of Processing
This DPA applies when MKTGToolkit processes Personal Data on behalf of the Controller for the purpose of providing:
Social media content management and publishing services
Email marketing campaign management and delivery
Contact management and audience segmentation
Analytics and reporting on marketing activities
Integration with third-party platforms (ClickUp, social networks)
3. Processing Instructions
The Processor shall:
Process Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or international organization
Not process Personal Data for any purpose other than providing the Services
Immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Laws
Ensure that persons authorized to process Personal Data have committed to confidentiality
4. Security of Processing
MKTGToolkit implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Encryption
AES-256 encryption for stored API keys and tokens
TLS 1.3 for all data in transit
Encrypted backups
Access Controls
Role-based access control (RBAC)
Multi-factor authentication for administrative access
Regular access reviews and audits
Monitoring & Testing
24/7 infrastructure monitoring
Regular security assessments and penetration testing
Automated vulnerability scanning
Business Continuity
Regular data backups
Disaster recovery procedures
Geographic redundancy
5. Sub-processors
The Controller provides general authorization for the Processor to engage Sub-processors. The Processor shall:
Maintain an up-to-date list of Sub-processors
Notify the Controller of any intended changes to Sub-processors
Ensure Sub-processors are bound by data protection obligations no less protective than those in this DPA
Remain fully liable for the performance of Sub-processor obligations
Current Sub-processors
Sub-processor
Purpose
Location
Cloud Infrastructure Provider
Hosting & Data Storage
USA/EU (SCCs)
Stripe, Inc.
Payment Processing
USA (SCCs)
Email Service Provider
Email Delivery
USA (SCCs)
6. Assistance to Controller
Taking into account the nature of the processing, MKTGToolkit shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising Data Subject rights including:
Access to Personal Data
Rectification of inaccurate data
Erasure of Personal Data ("Right to be Forgotten")
Data portability
Restriction of processing
Objection to processing
We provide self-service tools including Account Deletion and Data Export features to help fulfill these obligations.
7. Data Breach Notification
In the event of a Personal Data breach, the Processor shall:
Notify the Controller without undue delay and within 72 hours of becoming aware of the breach
Provide information about the nature of the breach, categories and approximate number of Data Subjects affected
Describe likely consequences and measures taken or proposed to address the breach
Cooperate with the Controller in investigating and remediating the breach
8. International Data Transfers
For transfers of Personal Data to countries outside the EEA/UK that do not provide adequate protection:
Standard Contractual Clauses (SCCs) pursuant to EU Commission Decision 2021/914/EU are incorporated into this DPA
The Processor conducts Transfer Impact Assessments (TIAs) for transfers to third countries
Supplementary measures are implemented where necessary based on TIA findings
9. Audit Rights
The Processor shall:
Make available to the Controller all information necessary to demonstrate compliance with this DPA
Allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller
Provide audit reports or certifications (SOC 2, ISO 27001) upon request
Note: Audits shall be conducted with reasonable notice, during normal business hours, and shall not unreasonably disrupt the Processor's operations.
10. Deletion and Return of Data
Upon termination of the Agreement or upon request:
The Controller may export their data using our Data Export feature
The Processor shall delete all Personal Data within 30 days of request, unless retention is required by law
The Processor shall provide certification of deletion upon request
Data in backups will be deleted according to our backup rotation schedule (maximum 30 days)
11. Term & Termination
This DPA shall remain in effect for the duration of the Agreement and for as long as the Processor processes Personal Data on behalf of the Controller. Sections relating to confidentiality, data deletion, and audit rights shall survive termination.
12. Liability
Liability under this DPA shall be subject to the limitations set forth in the Agreement. Each party shall be liable for damages caused by processing that infringes Data Protection Laws or this DPA.
13. Contact Information
For DPA-related inquiries or to request a signed copy:
Data Protection Officer: privacy@mktgtoolkit.com
Legal Department: legal@mktgtoolkit.com
Enterprise customers requiring a custom DPA or additional terms should contact our legal department.