Data Processing Addendum
The contractual framework we operate under when we process personal data on behalf of business customers — GDPR / UK-GDPR compatible, SCCs included.
1. Parties
This Data Processing Addendum ("DPA") forms part of the Agreement between socialmediaboost.it.com ("Processor") and any customer ("Controller") that submits personal data to the socialmediaboost.it.com service in the course of using it.
2. Subject matter and duration
The Processor will process personal data on behalf of the Controller for the duration of the Agreement, solely for the purpose of providing the socialmediaboost.it.com service.
3. Nature and purpose of processing
Processing consists of: hosting, storing, transmitting and analysing personal data submitted by the Controller through the socialmediaboost.it.com service, and providing customer support in relation to that data.
4. Types of personal data and data subjects
Data subjects. The Controller's end users, staff and any third parties whose personal data the Controller submits to the service.
Types of data. Contact details, account credentials (hashed), order metadata (target URLs, quantities, timestamps), payment metadata (method type, last four digits, transaction reference — never full card numbers or CVV), IP addresses, device fingerprints, support-conversation contents.
5. Obligations of the Processor
- Process personal data only on documented instructions from the Controller.
- Ensure that persons authorised to process the personal data have committed themselves to confidentiality.
- Take all measures required pursuant to Article 32 GDPR (security of processing).
- Assist the Controller in fulfilling data-subject-rights requests.
- Notify the Controller without undue delay of any personal-data breach.
- Return or delete all personal data at the end of the Agreement, at the choice of the Controller.
- Make available all information necessary to demonstrate compliance and allow for audits by the Controller or an auditor mandated by the Controller.
6. Sub-processors
The Controller authorises the Processor to engage the following categories of sub-processor:
- Cloud infrastructure.
- Approved payment processors such as JazzCash after activation.
- Email delivery, if configured for transactional messages.
- Customer-support tooling.
Current sub-processors are listed at /legal/sub-processors. The Processor will notify the Controller at least 30 days before adding or replacing any sub-processor.
7. International data transfers
Where personal data of EU / UK / Swiss data subjects is transferred outside those regions, the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) module 2 (Controller → Processor), and, where the recipient is in the UK, the UK International Data Transfer Addendum to the EU SCCs.
8. Liability
Liability under this DPA is subject to the limitations in the Agreement.
Questions about this policy?
Email us at support@socialmediaboost.it.com or reach out on WhatsApp / Telegram — we'll respond within 24 hours.