Online ordering and payments are not currently active. Contact our service team for current availability.
Legal · socialmediaboost.it.com

Data Processing Addendum

Effective date · 2026-07-30Reviewed by legal on 2026-07-30

The contractual framework we operate under when we process personal data on behalf of business customers — GDPR / UK-GDPR compatible, SCCs included.

1. Parties

This Data Processing Addendum ("DPA") forms part of the Agreement between socialmediaboost.it.com ("Processor") and any customer ("Controller") that submits personal data to the socialmediaboost.it.com service in the course of using it.

2. Subject matter and duration

The Processor will process personal data on behalf of the Controller for the duration of the Agreement, solely for the purpose of providing the socialmediaboost.it.com service.

3. Nature and purpose of processing

Processing consists of: hosting, storing, transmitting and analysing personal data submitted by the Controller through the socialmediaboost.it.com service, and providing customer support in relation to that data.

4. Types of personal data and data subjects

Data subjects. The Controller's end users, staff and any third parties whose personal data the Controller submits to the service.

Types of data. Contact details, account credentials (hashed), order metadata (target URLs, quantities, timestamps), payment metadata (method type, last four digits, transaction reference — never full card numbers or CVV), IP addresses, device fingerprints, support-conversation contents.

5. Obligations of the Processor

  • Process personal data only on documented instructions from the Controller.
  • Ensure that persons authorised to process the personal data have committed themselves to confidentiality.
  • Take all measures required pursuant to Article 32 GDPR (security of processing).
  • Assist the Controller in fulfilling data-subject-rights requests.
  • Notify the Controller without undue delay of any personal-data breach.
  • Return or delete all personal data at the end of the Agreement, at the choice of the Controller.
  • Make available all information necessary to demonstrate compliance and allow for audits by the Controller or an auditor mandated by the Controller.

6. Sub-processors

The Controller authorises the Processor to engage the following categories of sub-processor:

  • Cloud infrastructure.
  • Approved payment processors such as JazzCash after activation.
  • Email delivery, if configured for transactional messages.
  • Customer-support tooling.

Current sub-processors are listed at /legal/sub-processors. The Processor will notify the Controller at least 30 days before adding or replacing any sub-processor.

7. International data transfers

Where personal data of EU / UK / Swiss data subjects is transferred outside those regions, the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) module 2 (Controller → Processor), and, where the recipient is in the UK, the UK International Data Transfer Addendum to the EU SCCs.

8. Liability

Liability under this DPA is subject to the limitations in the Agreement.

Questions about this policy?

Email us at support@socialmediaboost.it.com or reach out on WhatsApp / Telegram — we'll respond within 24 hours.