Data processing addendum

Last updated 4 October 2026

This addendum forms part of the terms of service between the organization operating this service (the “processor”) and the customer (the “controller”) for Kinetiq. It applies where the processor processes personal data on the customer's behalf, and is intended to meet Article 28 of the GDPR and the UK GDPR and the service provider requirements of the CCPA as amended by the CPRA.

Roles

The customer is the controller and decides why and how personal data is processed. The processor processes it only on the customer's documented instructions, which are these terms, the order form and the customer's use and configuration of the service. The processor tells the customer if it believes an instruction breaks the law. Under the CCPA the processor acts as a service provider: it does not sell or share the personal data, and does not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service.

Subject matter and duration

The subject matter is the provision of the service. Processing lasts for the term of the order form and the deletion period that follows it, described below.

Nature and purpose

Collection, storage, organization, retrieval, use, disclosure by transmission to the customer's connected systems and sponsors as the customer configures, erasure and destruction, for the purpose of running sponsor activations, capturing fan sign-ups and consent, issuing offers, attributing outcomes and reporting to the customer and its sponsors.

Categories of data and data subjects

Data subjects: fans and attendees who sign up at the customer's activations; the customer's console members; and contacts at the customer's sponsors whom it invites. Categories of personal data:

The service is not designed for special categories of personal data or for data about children; fans confirm they are 18 or older when they sign up.

Processor obligations

Sub-processing

The customer gives general authorization for the subprocessors on the subprocessors page. The processor imposes data protection terms on each that are no less protective than this addendum, stays responsible for them, and notifies the customer 30 days before a new subprocessor processes the customer's personal data. The customer may object on reasonable data protection grounds within 30 days of notice; if the parties cannot resolve the objection, the customer may terminate the affected service.

Assistance

The service gives the customer the tools to answer data subject requests itself: it records access, rectification and erasure requests with their due dates, prepares a copy of a fan's information, corrects an email address, and erases a profile. Fans can withdraw consent and opt out of sale or sharing from the preference link in every email. The processor also provides reasonable assistance with data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing.

Deletion and return

During the term, the service erases each fan profile automatically when no activity has been recorded for the customer's configured retention period, and on request. At the end of the term the customer can export its data with the service's exports, after which the processor deletes the customer's personal data within the period stated in the order form, unless the law requires it to keep a copy.

Audits

The processor makes available the information needed to demonstrate compliance with this addendum: this documentation, the customer's own audit log in the console with its hash-chain verification, and answers to reasonable security questionnaires. Where that is not enough, the customer may conduct an audit, at most once a year on 30 days' notice, at its own cost and under confidentiality, or as the order form provides.

International transfers

Customer data is hosted in the United States (Google Cloud region us-central1); the subprocessors page states where each subprocessor processes it. Where a transfer of personal data from the European Economic Area, Switzerland or the United Kingdom requires it, the parties incorporate by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) and, where the customer is itself a processor, Module Three (processor to processor), with the UK International Data Transfer Addendum for transfers from the United Kingdom. The details the clauses require are those in this addendum; the governing law and forum are those stated in the order form.