Third Party Index

Snapshot 44831

Document
Data processing addendum
URL
https://gaconnector.com/about-us/ga-connector-data-processing-agreement.pdf
Fetched
HTTP status
200
Content type
application/pdf
Fetch mode
pdf
Size
597982 bytes
SHA-256 (raw)
0fe7697d718cd66c8c58a96182add116acb1b2af882323eae99d3ce6838ff1b5
SHA-256 (normalized text)
9bf26e25294655d61b5f5e21eb03b956ae79bac7ea97495716e2de64c7e2c5f5

Normalized text

Scripts and page chrome removed; this is what change detection compares.

DATA PROCESSING AGREEMENT
Effective date: 13.10.2025

This Data Processing Agreement (hereinafter referred to as the “DPA”) forms part of and is subject to the
provisions of the Terms of Service (“Terms/Main Service Agreement”) between The Company (“Us”) and
the Customer. This Data Processing Agreement supplements the Terms of Services, which are available
at: https://gaconnector.com/about-us/terms.php. In the event of a conflict between the terms of this
DPA and the Terms (“The Agreement”), the terms and conditions of this Data Processing Agreement shall
prevail with respect to the subject matter of Processing of Personal Data.

1. Definitions
   1.1. “Applicable Data Protection Law” covers any applicable legislative or regulatory regime enacted
       by a recognized government, or governmental or administrative entity, with the purpose of
       protecting the privacy rights of natural persons or households consisting of natural persons.

   1.2. “Customer”, “You”, “Company” and “Data Controller” refer to the Entity that determines, as a
       legal person alone or jointly with others, the purposes and means of the processing of Personal
       Data. In the context of this Agreement, it refers to the entity that processes various categories of
       personal data through our platform and services.

   1.3. “Data Processor", “We”, and “Us” refer to the entity that processes Personal Data on behalf of
       the Controller. Processor or "data importer" in this Agreement refers to a Customer who performs
       his/her services.

   1.4. “Customer Personal Data” / “End-customer Personal Data” means the personal data (as defined
       by Applicable Data Protection Law) that is transferred to, disclosed to, processed through our
       platform and services, or otherwise made available to Us, regardless of the method of disclosure.

   1.5. “Data Subject” means individuals whose personal data are collected and provided to Us

   1.6. “Personal Data" means any information relating to an identified or identifiable natural person,
       including information that could be linked, directly or indirectly, with a particular Data Subject.

   1.7. “Sub-Processor” means an authorised sub-processor engaged by Us that Processes Personal
       Data to provide Services.

   1.8. “Platform” refers to our web platform at: https://gaconnector.com/

   1.9. “Services” refers to all the services we provide, which enable our Customers to collect data
       about their website visitors and leads and to better analyse lead source, and merge different data
       sources.
2. Parties

  Data Controller                                      Data processor

  Business Name: Name of the customer who              Business name:
  signs up for our platform and services               MarTech Solutions LLC

  Authorized individual: An Individual who fills out   Authorised individual:
  the sign-up form on our website on behalf of the     Sergii Zuiev
  Data Controller

  Business address: Registered address of the          Business Address:
  Data Controller that signs up for our services       #12578, 8 The Green,
                                                       Dover, DE, Kent, US, 19901

3. Details of Data Processing
Subject Matter. The subject matter of the data processing under this DPA is the transfer of personal data
of Concerned Individuals, including but not limited to:

Name, surname, company name, email address, phone number, other form field data, UTM parameters,
pages visited by the Customer’s users, geographical location data such as country and city from which
the leads come from, browser type, operating system, referral page, landing page, IP address, first and
last touch attribution data, tracking ID, session ID

Duration. The duration of the data processing under this DPA is for the lifetime of the relationship
between the parties.

Purpose. The purpose of the data processing under this DPA is the following: To enable Customers to
better understand where their leads come from and to merge different data sets to better analyze their
customers by inserting our tracking code on their website.

Categories of data subjects: Customer’s website visitors and leads who visit their website/platform

Nature of the Processing: Collection of Concerned Individuals’ personal data through our tracking
technology and subsequent processing of this data in accordance with the Customer's instructions.
4. Processing Roles
This DPA governs the collection and transfer of end-customers' Personal Data by Customers to Us. In
this regard, Customer will act as a “Data Controller” and we will act as a “Data Processor”.

5. Description of the Data Processing Activities
You will use our Services to collect personal data of your website visitors and end customers, and store
such data on our servers to carry out analytics.

6. Obligations of the Data Processor
We shall process end-customer Personal Data only in accordance with the instructions received from
You, including in accordance with the Agreement.

You can issue Instructions either in writing or via email.

The Customer shall only provide instructions to Us that comply with all Applicable Laws, including data
protection laws.

In the event that We reasonably believe that an instruction issued by the Customer would violate any
Applicable Data Protection Law, We shall promptly notify the Customer.

If We cannot comply with the terms of this DPA for whatever reason, then we shall promptly inform the
Customer of our inability to comply.

We hereby warrant that, upon the Customer's request, We will cooperate with the Customer to enable
the Customer to:

   (a) comply with reasonable requests of access, rectification, and/or deletion of Personal Data arising
       from a Data Subject;

   (b) enforce rights of Data Subjects under the Applicable Data Protection Law; and/or

   (c) comply with all requests from a supervisory authority, including but not limited to in the event of
       an investigation.

We shall notify the Customer in the event We receive any request, complaint, or communication relating
to the Customer’s obligations under Applicable Data Protection Law (including from data protection
authorities and/or supervisory authorities).
7. Obligations of the Data Controller - Compliance with Laws

The Customer hereby represents, warrants, and undertakes that:

Its use of the Data Processor’s services, its instructions concerning the processing of Customer Personal
Data, and its access to, handling, use, transfer, and storage of such data shall at all times comply with all
Applicable Data Protection Laws, Regulations, and Guidance issued by relevant regulatory authorities.

The Data Controller shall have exclusive responsibility for carrying out thorough evaluations to confirm
that the technical and organizational security measures implemented, maintained, and operated by the
Data Processor are suitable, adequate, and sufficient for their intended purposes.

The Data Controller expressly warrants and undertakes to promptly notify the Data Processor in writing
if, at any time, it becomes aware that it is unable to comply with, or anticipates any difficulty in
complying with, any of its obligations, responsibilities, duties, or warranties set out in this Data
Processing Agreement or any related documentation.

The Data Controller expressly and continuously warrants that all instructions, directions, and
requirements provided to the Data Processor regarding the processing of Customer Personal Data will be
lawful, appropriate, and fully compliant with all relevant legal and regulatory obligations.

The Data Controller shall bear sole responsibility for ensuring full compliance with the obligations set out
in this section.

8. Notification of Personal Data Breach
In the event of a Personal Data Breach arising during the provision of the Services by the Data Processor,
the Data Processor shall:

   1. Notify the Customer about the Breach without undue delay, but in no event less than seventy-
      two (72) hours, after becoming aware of the Personal Data Breach; as part of the notification
      under Section of this DPA, to the extent reasonably available at the time of notice;

   2. Provide a description of the nature of the breach, the categories and approximate number of
      Data Subjects affected, the categories and approximate number of data records affected, the
      likely consequences of the Breach, and the risks to affected Data Subjects; promptly update
      Customer as additional relevant information becomes available;

   3. Take all actions as may be required by Applicable Data Protection Law;

   4. Maintain records of all information relating to the Breach, including the results of its own
      investigations and authorities’ investigations as well as remedial actions taken; and
9. Security Measures
The Data Processor shall take and implement appropriate technical and organizational security and
confidentiality measures designed to provide a level of security appropriate to the risk to Personal Data
against unauthorized use, modification, loss, compromise, destruction, or disclosure of, or access.

The Data Controller shall have exclusive responsibility for carrying out thorough evaluations to confirm
that the technical and organizational security measures implemented, maintained, and operated by the
Data Processor are suitable, adequate, and sufficient for their intended purposes.

10. Sub-Processors
The Data Controller hereby provides the Data Processor with general written authorization to appoint,
engage, change, or remove Sub-Processors to access and process Personal Data. We have currently
appointed, as Sub-Processors, the third parties listed in Annex III to this DPA.

The Data Processor will impose contractual obligations on its Sub-Processors, and contractually obligate
its Sub-Processors to impose contractual obligations on any further subcontractors which they engage to
process Personal Data, which provide the same level of data protection for Personal Data in all material
respects as the contractual obligations imposed in this DPA.

Data Processor will notify the Customer at least 30 days in advance (by email) of any changes to the list
of Sub-Processors in place.

The Data Controller may raise an objection to the appointment, replacement, or removal of any sub-
processor by sending written notice via email to the Data Processor within seven (7) calendar days after
receiving notice of the proposed sub-processor. If no such objection is received within this deadline, the
Data Processor shall assume that the Data Controller does not object to the appointment of the new
sub-processor.

An objection will be considered reasonable if it is based on the belief that the proposed sub-processor
would materially weaken the safeguards for Customer Personal Data or create a substantial risk of non-
compliance with applicable data protection laws.

The Data Controller’s notice of objection must clearly outline the specific grounds that make the
objection reasonable.

Upon receiving a valid objection, the Data Processor shall use commercially reasonable efforts to provide
an alternative arrangement within the Services that allows the Data Controller to continue using the
Services without involving the proposed sub-processor in the processing or access of Customer Personal
Data.

If it is not commercially feasible for the Data Processor to implement such an alternative within thirty
(30) days, either Party may terminate the main Service Agreement (“Terms of Service”) by providing thirty
(30) days’ written notice.
Termination under this clause shall not entitle the Data Controller to a refund of any prepaid fees. The
Data Controller shall have no claim for compensation solely based on objecting to the appointment of a
new sub-processor.

If the Data Controller does not submit a timely objection in accordance with this clause, the Data
Processor shall assume that the Data Controller consents to the engagement and use of the proposed
sub-processor.

11. Limitations of Liability
The Data Processor shall not be liable to the Data Controller, whether in contract, tort (including
negligence), breach of statutory duty, strict liability, indemnity, or otherwise, for any losses, damages,
costs, or expenses of any kind arising from or in connection with this Data Processing Agreement, the
provision or use of the Data Processor’s Services, or any breach of this Data Processing Agreement or the
main Terms of Service between the Parties.

Such exclusion of liability shall apply to, without limitation, the following types of loss or damage:

   •   direct damages, to the extent such exclusion is permitted by applicable law;

   •   indirect, incidental, special, exemplary, or consequential damages of any kind;

   •   loss of profits, loss of revenue, or loss of anticipated savings;

   •   loss of business, loss of contracts, or loss of business opportunities;

   •   loss of goodwill, reputation, or business standing;

   •   business interruption or downtime;

   •   loss or corruption of data, systems, or records, or the costs associated with data recovery;

   •   costs incurred in the procurement or substitution of goods, services, or rights;

   •   third-party claims, demands, or actions, including those arising from or related to alleged
       breaches of data protection, privacy, or confidentiality obligations;

   •   statutory damages, regulatory penalties, fines, or sanctions, including but not limited to fines
       imposed under applicable data protection laws such as the EU General Data Protection
       Regulation (GDPR), the UK GDPR, or any equivalent data protection legislation; and

   •   any other economic or non-economic loss, damage, or expense of any nature, whether
       foreseeable or unforeseeable, arising out of or relating to this Data Processing Agreement or the
       use or performance of the Data Processor’s Services.
The maximum aggregate liability of the Data Processor, whether arising in contract, tort (including
negligence or breach of statutory duty), misrepresentation, restitution, or otherwise, and whether arising
directly or indirectly out of or in connection with the provision of its Services, the operation or use of its
Platform, or this Data Processing Agreement, shall be limited to direct damages only, including legal fees,
and shall not exceed an amount equivalent to the proportionate part of the total annual fees paid by the
Data Controller to the Data Processor under the main Agreement between the Parties during the twelve
(12) months immediately preceding the event giving rise to the claim.

The indemnification clause in the Agreement shall apply to this Data Processing Agreement.

12. Conflict and Termination of this Agreement
In the event of a conflict between this DPA and the Agreement, this DPA will prevail. This DPA shall
continue in force until the termination of the Agreement.

13. Governing Law
This DPA shall be governed by and construed in accordance with the Laws of England and Wales. English
Courts shall have exclusive jurisdiction to resolve disputes that arise out of or in relation to this DPA.

14. Deletion or return of Company Personal Data
Subject to this section and all applicable laws and regulations, Processor shall promptly and in any event
within 45 business days of the date of cessation of any Services involving the Processing of Personal
Data (the "Cessation Date"), delete and procure the deletion of all copies of the Customer Personal Data.
Processor shall provide written certification to Company that it has fully complied with this section
within 45 business days of the Cessation Date.

15. Data Protection Impact Assessment and Prior Consultation
Processor shall provide reasonable assistance to the Customer with any data protection impact
assessments, and prior consultations with Supervising Authorities or other competent data privacy
authorities, which the Company reasonably considers to be required by article 35 or 36 of the GDPR or
equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of
Customer Personal Data by, and taking into account the nature of the Processing and information
available to, the Contracted Processors.

16. Audit rights
Subject to this section, Processor shall make available to the Customer on request all information
necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits,
including inspections, by the Customer or an auditor mandated by the Customer in relation to the
Processing of the Customer Personal Data by the Sub-Processors. Information and audit rights of the
Customer only arise under this section to the extent that the Agreement does not otherwise give them
information and audit rights meeting the relevant requirements of Data Protection Law.

The Data Controller shall give the Processor reasonable prior written notice of any audit or inspection to
be conducted under this Section and shall use (and ensure that each of its mandated auditors uses) its
best efforts to avoid causing any damage, injury, or disruption to the Data Processor.
The Data Controller and the Data Processor shall mutually agree upon the scope, timing, and duration of
the audit or inspection and any reimbursement of expenses for which the Data Controller shall be
responsible.

The scope of audit rights does not extend to physical premises where the Customer Data is processed.

17. Confidentiality
Each Party must keep this Agreement and information it receives about the other Party and its business
in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose
that Confidential Information without the prior written consent of the other Party, except to the extent
that:

   (a) disclosure is required by law;

   (b) The relevant information is already in the public domain.

The data processor shall ensure that any personnel whom it authorizes to Process Personal Data on its
behalf are subject to appropriate confidentiality obligations (whether a contractual or statutory duty)
with respect to that Personal Data.

18. International Data Transfers
The Data Controller hereby authorises the Data Processor to make international data transfers of
personal Data in accordance with this DPA, so long as Applicable Privacy Laws for such transfers are
respected.

    •   Transfers out of the UK

The UK Data Transfer Addendum, as issued on 21 March 2022, incorporating the EU SCCs approved by
Commission Decision (EU) 2021/914, issued by the UK ICO, applies to a transfer from the United
Kingdom of Personal Data Processed under this DPA between you and us and is incorporated into this
DPA.

You agree that the UK Data Transfer Addendum is completed and supplemented as follows:

   (a) You are the data exporter, and We are the data importer.

   (b) Tables 1, 2, and 3 of the UK Addendum will be deemed completed with the information set out in
       the Annexes I, II, and III of this DPA;

   (c) For Table 2 of the UK Data Transfer Addendum, the version of the “Approved EU SCCs” (including
       the appendix information, modules, and selected clauses) appended to the UK Data Transfer
       Addendum is the EEA SCCs Module II as incorporated into this Agreement by the Parties in
       accordance with this section:

   (d) The optional docking clause under Clause 7 of the EEA SCCs will not apply;
   (e) Option 2 under Clause 9 of the EEA SCCs applies, and You generally authorize Us to engage Sub-
       processors according to the “Sub-processors” section of this DPA, and the time period for
       notification is the period set out in the “Sub-processors” section of this DPA;

   (f) the optional redress language under Clause 11(a) of the EEA SCCs will not apply;

   (g) The “neither party” option applies for the purposes of Table 4 of the UK Data Transfer
       Addendum;

   (h) Under Part 2, the mandatory clauses of the UK Data Transfer Addendum will apply, and any
       conflict between the terms of the Standard Contractual Clauses and the UK Addendum will be
       resolved in accordance with Section 10 and Section 11 of the UK Addendum.

By registering for and using our services, you will be deemed to have signed the UK Data Transfer
Addendum.

   •   Transfers out of Switzerland

With respect to Personal Data transferred from Switzerland for which Swiss law (and not the law in any
European Economic Area jurisdiction) governs the international nature of the transfer, references to the
GDPR in Clause 4 of the New EU SCCs are, to the extent legally required, amended to refer to the Swiss
Federal Data Protection Act or its successor, instead, and the concept of the supervisory authority shall
include the Swiss Federal Data Protection and Information Commissioner.

   •   Transfers out of the EEA

With respect to Personal Data transferred from the European Economic Area, the New EU SCCs issued
by the EU Commission on 04.06.2021 are hereby incorporated by reference and shall apply, and take
precedence over the rest of this DPA as set forth in the New EU SCCs.

The Module Two terms apply to the extent Customer is a Controller, and the Module Three terms apply
to the extent Customer is a Processor of Customer Personal Data, along with the populated Annex I, II,
and III below.

   (i) In Clause 7, the optional docking clause will not apply;

   (ii) Clause 9, Option 2 applies, and you authorize us to make changes to Sub-Processors pursuant to
        the ‘Sub-Processors’ section of this DPA;

   (iii) in Clause 11, the optional language is deleted;
   (iv) In Clauses 17 and 18, the parties agree that the governing law and forum for disputes for
        the Standard Contractual Clauses will be the Republic of Ireland (without reference to conflicts
        of law principles);

   (v) the Annexes of the Standard Contractual Clauses will be deemed completed with the information
       set out in the Annexes of this DPA; and

   (vi) If and to the extent the Standard Contractual Clauses conflict with any provision of this DPA,
        the Standard Contractual Clauses will prevail to the extent of such conflict.

   (vii) The supervisory authority that will act as the competent supervisory authority will be determined
         in accordance with GDPR.

19. Changes to this DPA
We may update or amend this Data Processing Agreement from time to time, at our sole discretion. Any
such updates or amendments shall become effective immediately upon being posted on our Website,
and your continued use of our services following such publication shall constitute your acceptance of the
revised terms.

ANNEX I

A. LIST OF PARTIES

Data exporter:

Name: Name of Customer / Data Controller who registers for and uses our services on our website at:
https://gaconnector.com/.

Address: Business address of the Customer

Contact person’s name, position, and contact details: Contact details are provided when the Customer
registers on our platform.

Activities relevant to the data transferred under these Clauses: The data importer provides the Services
to the data exporter in accordance with this Agreement.

Signature and date:

The data exporter will be deemed to have signed this Annex I on the transfer of Personal Data in
connection with the Services.

Data importer:
Name: Data Processor as specified in this DPA. Address: As specified in this DPA. Contact person’s name,
position, and contact details: Contact details are specified in this DPA.

Activities relevant to the data transferred under these Clauses: The data importer provides the Services
to the data exporter in accordance with this DPA.

Signature and date:

The data importer will be deemed to have signed this Annex I on the transfer of Personal Data in
connection with the Services.

B. DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is transferred

Data subjects are individuals who visited the Customer's website/platform/app and provided their data
and contact details to the Customer.

Categories of personal data transferred

Name, surname, company name, email address, phone number, other form field data, UTM parameters,
pages visited by the Customer’s users, geographical location data such as country and city from which
the leads come from, browser type, operating system, referral page, landing page, IP address, first and
last touch attribution data, tracking ID, session ID

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into
consideration the nature of the data and the risks involved, such as for instance, strict purpose limitation,
access restrictions (including access only for staff having followed specialised training), keeping a record of
access to the data, restrictions for onward transfers, or additional security measures.

None

The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis).

Customer Personal Data may be transferred on a continuous basis until it is deleted in accordance with
the DPA.

Nature of the processing

The data exporter will use the data importer’s tracking technology to collect personal data and will store
it on the data importer’s servers.

Purpose(s) of the data transfer and further processing
To enable the Customer to analyze their leads, merge customer data, better understand their customer
profiles, and carry out analytics on the collected data

The period for which the personal data will be retained, or, if that is not possible, the criteria used to
determine that period

For the duration of the Agreement until deletion in accordance with the provisions of the DPA.

For transfers to (sub-) processors, also specify the subject matter, nature, and duration of the processing

As above.

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent supervisory authority/ies in accordance with Clause 13

The Irish Supervisory Authority - The Data Protection Commission, unless the data exporter notifies the
data importer of an alternative competent supervisory authority.

ANNEX II

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL
MEASURES TO ENSURE THE SECURITY OF THE DATA

Data is encrypted in transit.

We implement robust access controls to ensure that customer data is only accessible to authorized
personnel. Access is granted strictly on a need-to-know basis.

Multi-factor authentication (MFA) is enforced for all administrative accounts with access to customer
personal data.

We maintain detailed logs of all user account changes made within the administrative dashboard.

Our development processes follow secure coding best practices to minimize vulnerabilities.

We also perform regular data backups to ensure data integrity and availability.
      ANNEX III

      LIST OF SUB-PROCESSORS

      The Data Controller has authorised the following sub-processors:

SUB-
                                                              TRANSFER          SUPPLEMENTARY         CONTACT
PROCESSOR          PURPOSE       DATA           LOCATION
                                                              MECHANISM         MEASURES              DETAILS
NAME

Amazon             Cloud         Name,          EU&EEA        SCCs as           AWS takes             AWS
Web                services      surname,       servers       detailed in the   technical and         Compliance
Services           data          geographic                   ASW’s Data        contractual           Contact US
                   storage       all location                 Processing        measures to protect   410 Terry
                                 data such                    Agreement:        data:                 Avenue
                                 as country                                                           North,
                                 and the city                                   Encryption of data    Seattle, WA
                                 from                                           in transit and at     98109-
                                 which the                                      rest.                 5210, USA
                                 leads come                                     Encryption key
                                 From,                                          stored in the EU.
                                 browser
                                 type,
                                 operating
                                 system,
                                 referral
                                 page
SIGNATURES

 Data Controller                                      Data processor

 Business Name: Name of the Customer who signs        Business name:
 up for our Services
                                                      MarTech Solutions LLC

 Authorized individual: An Individual who fills out
                                                      Authorised individual:
 the sign-up & free trial form on our website on
                                                      Sergii Zuiev
 behalf of the Data Controller to use our Services

 Business address: Registered address of the
                                                      Business Address:
 Data Controller that signs up for our services
                                                      #12578, 8 The Green,
                                                      Dover, DE, Kent, US, 19901

 The Data Controller agrees to the execution of       The Data Processor agrees to the execution of
 this Agreement in its entirety.                      this Agreement in its Entirety.