Legal · Effective 17 August 2026
Data Processing Addendum
Processor terms that apply when Trakio processes personal data for a customer.
1. Scope and roles
This DPA forms part of the Trakio agreement. The customer is the controller or Data Fiduciary and Trakio is the processor or Data Processor for customer personal data. Processing covers click collection, redirect tracking, advertiser-reported conversion attribution, fraud review, postbacks, reporting, exports, support, security, and deletion for the agreement term.
2. Instructions and compliance
Trakio processes customer personal data only on documented instructions, including the agreement and platform configuration, unless law requires otherwise. Trakio will notify the customer if an instruction appears unlawful. The customer is responsible for a valid legal basis, transparency, data accuracy, and responding to individuals.
3. People and security
Personnel with access are bound by confidentiality. Trakio maintains proportionate technical and organisational measures including role-based access, tenant isolation, authentication controls, TLS, encryption of sensitive identifiers and backups, logging, monitoring, recovery testing, vulnerability remediation, and retention enforcement.
4. Subprocessors and transfers
The customer authorises the providers on the Subprocessors page. Trakio remains responsible for their processing obligations and will provide reasonable advance notice of a new provider so the customer may object on substantiated data-protection grounds. Where required, transfers use the EU Standard Contractual Clauses or another valid safeguard.
5. Assistance and incidents
Taking account of the processing, Trakio will reasonably assist with data subject requests, security assessments, impact assessments, consultations, and regulator enquiries. Trakio will notify the customer without undue delay after confirming a personal-data breach and provide available information needed for the customer’s legal duties.
6. Return, deletion, and audits
At termination Trakio will delete or return customer personal data as agreed, except where law requires retention. Backup copies expire on their normal protected cycle. Trakio will provide information reasonably necessary to demonstrate compliance and permit a proportionate audit once yearly, subject to confidentiality, security, scope, scheduling, and cost safeguards.
7. International terms
If GDPR restricted transfers apply, the 2021 controller-to-processor EU SCCs are incorporated: Module Two applies, the customer is exporter, Trakio is importer, optional docking applies, and the competent authority and governing law follow the exporter unless the Order Form specifies valid alternatives. The service description, data categories, security measures, retention page, and subprocessor list complete the relevant annex information.