Data Processing Addendum

The terms under which SourceTrack processes personal data on behalf of customers.

Last updated: 7 October 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the customer (“you”, the controller) and SourceTrack (“we”, the processor, operated by the individual identified in our Legal Notice). It applies to personal data we process on your behalf under the EU General Data Protection Regulation (GDPR), the UK GDPR, Spanish Organic Law 3/2018 and, where they apply, US state privacy laws. It takes effect when you accept the Terms. For a countersigned copy, email support@sourcetrack.ai.

1. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the GDPR.

“Customer personal data” means personal data that we process on your behalf in providing the service. It includes data collected by our tracking script on your websites, and data sent to us by your payment, store, form or other connected providers. It does not include data about you as a customer (account, billing and support), which we handle as a controller under our Privacy Policy.

2. Roles

You are the controller of customer personal data, and we are your processor. If you act as a processor for someone else (for example as an agency for a client), you confirm that your controller has authorised you to appoint us, and we are your subprocessor.

When you connect an advertising or analytics platform (such as Meta, Google, Microsoft, TikTok, LinkedIn or OpenAI) and turn on conversion forwarding, that platform receives data at your direction as a separate controller under its own terms. It is not our subprocessor.

3. Details of the processing (Annex I)

Subject matterProviding the SourceTrack marketing attribution service
DurationFor as long as you use the service, until you delete your workspace, plus the deletion periods in section 10
Nature of the processingCollection, recording, storage, matching, aggregation, analysis, reporting, transmission at your direction, and erasure
PurposeSo you can see which marketing sources lead to visits, leads, conversions and revenue, and, if you turn it on, to forward conversions to the advertising platforms you connect. Forwarded conversions can include the visitor’s IP address and browser information (user agent), with contact details such as email addresses hashed before they are sent.
Types of personal dataOnline identifiers: pseudonymous visitor and session identifiers and, where you enable it, device identifiers derived from the IP address and browser information, kept per website (or per group of your own linked websites) and never shared between different companies’ websites (used only after consent for visitors in the EU, the EEA, the UK or Switzerland or whose country is unknown, and by default with an opt-out elsewhere); IP addresses (used to determine country, filter bots and derive identifiers; not stored in our event database, and kept elsewhere only temporarily in the cases our Privacy Policy describes); page views, page URLs, titles and referrers; engagement and custom events; campaign parameters and advertising click identifiers; browser, device type, operating system and country; identifiers set by advertising platforms’ own pixels; conversions, orders, subscriptions, amounts and currency; names, email addresses, phone numbers and company names that your website or providers send us, or that the tracking script reads from submitted forms where you turn on form lead capture; post-purchase survey answers; lead status and notes your team adds
Special categoriesNone. You must not send special categories of personal data, data about criminal convictions, or payment card numbers.
Categories of data subjectsVisitors to your websites, and your leads, customers and buyers
FrequencyContinuous, for as long as the tracking script or a connected source sends data
RetentionAs set out in section 11 of our Privacy Policy and your workspace’s data retention setting

4. Your obligations as controller

You will:

  • have a lawful basis for the processing you instruct, and give your visitors the information the law requires, for example in your own privacy notice;
  • obtain any consent the law requires before the tracking script stores or reads information on a visitor’s device, before identifiers are used, and before data is shared with advertising platforms. Use your consent tool and the controls we provide for this: consent mode, Google Consent Mode v2, region-based consent, and Do Not Track and Global Privacy Control handling;
  • turn on optional features, such as device identifiers, device matching, form lead capture and conversion forwarding, only where you have assessed that you may lawfully use them;
  • not send us special categories of personal data, payment card numbers, or data about children where the law prohibits it;
  • make sure your instructions comply with data protection law.

5. Our obligations

We will:

  • Instructions. Process customer personal data only on your documented instructions, unless the law requires otherwise; in that case we will tell you first, unless the law prohibits it. Your instructions are this DPA, the Terms, your configuration of the service and your use of its features. If we believe an instruction breaches data protection law, we will tell you.
  • Confidentiality. Make sure everyone authorised to process customer personal data is bound by confidentiality. Staff access it only to provide support you ask for, to investigate security or abuse, or where the law requires it.
  • Security. Apply appropriate technical and organisational measures, as described on our Security page, which forms Annex II to this DPA. These include encryption in transit, encryption of integration secrets at rest, tenant isolation and limited staff access. We may update these measures, but not in a way that lowers the overall level of protection.
  • No other use. Not sell customer personal data, not use it for our own purposes, and not combine it with data from other customers. We never share visitor identifiers between different companies’ websites.
  • Records. Keep the records of processing that Article 30(2) of the GDPR requires.

6. Subprocessors

  • Authorisation. You give us general authorisation to use the subprocessors listed on our Subprocessors page, with their purpose and location.
  • Their obligations. We bind each subprocessor by written contract to data protection obligations no less protective than this DPA. We remain responsible for their performance.
  • Changes. We update the page before a new subprocessor starts processing customer personal data. If you have asked us to (email support@sourcetrack.ai with the subject “Subprocessor updates”), we also email you in advance.
  • Objections. If you object on reasonable data protection grounds, tell us in writing within 30 days. We will work with you on an alternative. If we cannot offer one, you may stop using the affected part of the service, or terminate, and we will refund any fees prepaid for the period after termination.

7. International transfers

Core customer personal data is stored in the European Union. Where a subprocessor processes customer personal data outside the European Economic Area, we make sure it is covered by an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or by the European Commission’s Standard Contractual Clauses, together with any additional measures needed. For the UK and Switzerland, we rely on the equivalent mechanisms. On request, we will give you a copy of the relevant safeguards.

8. Assisting you

Taking into account the nature of the processing and the information we hold, we will help you:

  • Answer data subject requests. We provide tools to erase a single visitor, to answer an access request about a visitor, to export your workspace data and to delete your workspace. After an erasure, we block the same visitor’s data from being stored again. If we receive a request directly from one of your visitors, we will pass it to you and will not answer it ourselves, unless the law requires us to.
  • Meet your other obligations on security, breach notification, data protection impact assessments and prior consultation with supervisory authorities.

9. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting customer personal data. Our notice will include, as far as we know it:

  • the nature of the breach, the categories and approximate number of people and records affected;
  • the likely consequences;
  • the measures taken or proposed;
  • a contact point for more information.

We will give you further information as it becomes available, and take reasonable steps to contain the breach.

10. Deletion and return

  • When you delete your workspace, we permanently delete its customer personal data. Before deleting, you can export your data, which is how we return it to you.
  • If the agreement ends and you ask us in writing, we will delete the customer personal data we hold for you, or first return it to you by export if you ask.
  • We keep data only where the law requires it, for example billing records.

11. Audits

We will give you the information reasonably needed to show that we comply with Article 28 of the GDPR. We will also allow audits, including inspections, by you or an independent auditor you appoint who is bound by confidentiality, on reasonable written notice. Audits are at your cost and no more than once a year, unless a supervisory authority requires otherwise or after a personal data breach. We may first answer your questions in writing and point you to our documentation.

12. US state privacy laws

Where US state privacy laws apply (including the California Consumer Privacy Act, as amended), we act as your service provider or processor. We will not:

  • sell or share customer personal information;
  • retain, use or disclose it for any purpose other than providing the service to you, or outside our direct business relationship with you;
  • combine it with personal information from other sources, except as those laws allow.

We will tell you if we can no longer meet these obligations. Disclosures to advertising platforms happen only when you turn on conversion forwarding, and at your direction.

13. Liability, precedence and governing law

Each party’s liability under this DPA is subject to the limitations in the Terms, except where the law does not allow liability to be limited. If this DPA and the Terms conflict on data protection, this DPA prevails. Spanish law governs this DPA, and the courts of Tarragona, Spain, have jurisdiction, subject to mandatory rules.

Contact

Questions about this DPA: support@sourcetrack.ai.