Skip to content

Legal

Data processing addendum

Last updated 28 July 2026

This summary describes how ABP.Marketing processes personal data on behalf of a customer. The executable addendum is provided during contracting and forms part of the agreement.

Roles

The customer is the controller of workspace data, including any personal data contained in connected CRM, ecommerce or analytics records. We are the processor and act only on documented instructions.

Scope of processing

Subject matter: provision of the ABP.Marketing platform. Duration: the term of the agreement plus the deletion window. Nature: collection, storage, structuring, analysis, disclosure to the customer and, where authorised, transmission of changes to provider APIs.

Categories of data subjects may include customer staff, agency staff and the end customers recorded in connected business systems.

Security measures

Row level security on tenant tables, encryption in transit and at rest, encrypted credential storage isolated from application logs, least-privilege OAuth scopes, multi-factor authentication for staff accounts, immutable audit trails and time-limited, consent-based support access.

Sub-processors

We engage sub-processors for hosting, database, email delivery, payments, error monitoring, product analytics and language model inference. Each is bound by written terms no less protective than these. A current list is available on request, and we notify customers of material changes before they take effect.

International transfers

Where personal data is transferred across borders we rely on recognised transfer mechanisms and contractual safeguards appropriate to the jurisdictions involved.

Assistance and breach notification

We assist the controller with data subject requests, impact assessments and regulator engagement. We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information available at the time.

Return and deletion

On termination the customer may export workspace data through the product. We then delete or anonymise personal data within the period stated in the executed addendum, except where retention is required by law.

Audit

We provide security documentation and answer reasonable diligence questions. On-site or third-party audits are available where the agreement and applicable law require them.

This document is a plain-English summary maintained by the product team. It is not legal advice, and the executed contract you sign takes precedence where the two differ.