Data processing addendum
Last updated 4 October 2026
This addendum forms part of the terms of service between the organization operating this service (the “processor”) and the customer (the “controller”) for Kinetiq. It applies where the processor processes personal data on the customer's behalf, and is intended to meet Article 28 of the GDPR and the UK GDPR and the service provider requirements of the CCPA as amended by the CPRA.
Roles
The customer is the controller and decides why and how personal data is processed. The processor processes it only on the customer's documented instructions, which are these terms, the order form and the customer's use and configuration of the service. The processor tells the customer if it believes an instruction breaks the law. Under the CCPA the processor acts as a service provider: it does not sell or share the personal data, and does not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service.
Subject matter and duration
The subject matter is the provision of the service. Processing lasts for the term of the order form and the deletion period that follows it, described below.
Nature and purpose
Collection, storage, organization, retrieval, use, disclosure by transmission to the customer's connected systems and sponsors as the customer configures, erasure and destruction, for the purpose of running sponsor activations, capturing fan sign-ups and consent, issuing offers, attributing outcomes and reporting to the customer and its sponsors.
Categories of data and data subjects
Data subjects: fans and attendees who sign up at the customer's activations; the customer's console members; and contacts at the customer's sponsors whom it invites. Categories of personal data:
- Fan contact details. The email address, and the name and postal code when an activation asks for them, given by a fan who signs up at a scan.
- Consent and privacy choices. The consent wording a fan agreed to with its policy version, age confirmation, opt-out of sale or sharing, and the preference link.
- Scan, offer and outcome activity. When and where a fan scanned, offers issued and redeemed, and outcomes such as purchases linked to the fan.
- Device and network identifiers. IP addresses and a random device identifier, used to ignore repeat scans, flag bursts and record sign-ins.
- Console member accounts. Members' sign-in email, password hash, single sign-on subject and sign-in times.
- Messages to connected systems. Event messages queued and delivered to the organization's own systems by signed webhook, and stored ingest responses.
- Privacy requests. Records of access, rectification and erasure requests, kept as evidence that each was handled.
- Assistant conversations. The questions members ask the assistant, its answers and their feedback on them, kept 90 days. Conversations are included in the organization export.
- Audit trail. The hash-chained record of who did what in the console, with the IP address of sign-ins and other actions.
The service is not designed for special categories of personal data or for data about children; fans confirm they are 18 or older when they sign up.
Processor obligations
- Personnel with access to personal data are bound by confidentiality.
- The processor maintains the technical and organizational measures described on the security page, and does not materially reduce them during the term.
- The processor notifies the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, with the information the customer reasonably needs to meet its own obligations.
Sub-processing
The customer gives general authorization for the subprocessors on the subprocessors page. The processor imposes data protection terms on each that are no less protective than this addendum, stays responsible for them, and notifies the customer 30 days before a new subprocessor processes the customer's personal data. The customer may object on reasonable data protection grounds within 30 days of notice; if the parties cannot resolve the objection, the customer may terminate the affected service.
Assistance
The service gives the customer the tools to answer data subject requests itself: it records access, rectification and erasure requests with their due dates, prepares a copy of a fan's information, corrects an email address, and erases a profile. Fans can withdraw consent and opt out of sale or sharing from the preference link in every email. The processor also provides reasonable assistance with data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing.
Deletion and return
During the term, the service erases each fan profile automatically when no activity has been recorded for the customer's configured retention period, and on request. At the end of the term the customer can export its data with the service's exports, after which the processor deletes the customer's personal data within the period stated in the order form, unless the law requires it to keep a copy.
Audits
The processor makes available the information needed to demonstrate compliance with this addendum: this documentation, the customer's own audit log in the console with its hash-chain verification, and answers to reasonable security questionnaires. Where that is not enough, the customer may conduct an audit, at most once a year on 30 days' notice, at its own cost and under confidentiality, or as the order form provides.
International transfers
Customer data is hosted in the United States (Google Cloud region us-central1); the subprocessors page states where each subprocessor processes it. Where a transfer of personal data from the European Economic Area, Switzerland or the United Kingdom requires it, the parties incorporate by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) and, where the customer is itself a processor, Module Three (processor to processor), with the UK International Data Transfer Addendum for transfers from the United Kingdom. The details the clauses require are those in this addendum; the governing law and forum are those stated in the order form.