Data processing agreement
Last updated 9 September 2026
This agreement forms part of the agency terms. It sets out how AdStck ("the processor") processes personal data on behalf of your agency and its clients ("the controller"), as UK GDPR Article 28 requires.
What is processed
| Subject matter | Running enquiry funnels and handling the enquiries they produce |
| Duration | For as long as the agency has an AdStck account, and until deletion afterwards |
| Nature and purpose | Collecting, storing and displaying enquiries; sending confirmation and reminder emails; passing enquiry events to advertising platforms the controller has configured; producing statistics about funnel use |
| Types of personal data | Name, phone number, email address, answers given on a form, booking details, IP address, browser and device information, advertising click identifiers |
| Categories of data subject | Visitors to the controller's funnels; the controller's own staff and its clients' staff who use the dashboard or portal |
The processor's obligations
AdStck will:
- Process personal data only on the controller's documented instructions, which are given through the settings and actions available in the service — and tell the controller if an instruction appears to break the law.
- Make sure the people it authorises to access personal data are bound by confidentiality.
- Keep personal data secure with measures appropriate to the risk: access-controlled databases, encrypted connections, hashing of contact details before they are sent to advertising platforms, and role-based access within the service.
- Help the controller respond to requests from data subjects, using the export and erasure tools in the service.
- Help the controller with its own obligations on security, breach notification, and impact assessments, so far as the processor is able.
- Tell the controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting its data.
- At the end of the service, delete personal data or return it, at the controller's choice, and delete remaining copies — except where the law requires the processor to keep them.
- Make available what the controller reasonably needs to show these obligations are met, and allow audits on reasonable notice, no more than once a year unless a breach has occurred.
Sub-processors
The controller gives general authorisation for AdStck to use the sub-processors listed at adstck.com/legal/subprocessors. AdStck will update that page and tell the controller by email at least 14 days before adding or replacing one. The controller may object in writing within that period; if the objection cannot be resolved, either party may end the agreement.
AdStck remains responsible for its sub-processors' performance.
Transfers
Personal data may be processed outside the UK by sub-processors. Where it is, AdStck relies on UK adequacy regulations or the International Data Transfer Agreement, as the sub-processor page records.
Advertising platforms
Meta and Google are not sub-processors. They receive data only because the controller has connected them, and only for visitors who have consented. Each is an independent controller of what it receives, under its own terms with the controller.
The controller's obligations
The controller will make sure it has a lawful basis for the personal data it collects through AdStck, that its funnels and published documents are accurate, and that its instructions to AdStck comply with the law.
Liability
The liability provisions of the agency terms apply to this agreement.
Changes
AdStck may update this agreement to reflect changes in the law or the service, with 30 days' notice by email.