Skip to content
Sightrz
Legal

Data processing addendum

Last updated: This document is published in English, which is the governing version of the agreement.

This addendum forms part of the agreement between Sightrz and a customer, and governs our processing of personal data on that customer's behalf. Where it conflicts with the terms of service, this addendum prevails for data protection matters.

A countersigned copy is available on request from privacy@sightrz.com.

1. Roles

The customer is the controller of the personal data it makes available to Sightrz. Sightrz is the processor, acting only on the customer's documented instructions.

Where the customer is itself a processor for a third party — an agency acting for its client — Sightrz acts as a sub-processor and the same obligations apply down the chain.

2. Subject matter, duration, nature and purpose

Subject matter: provision of the Sightrz marketing intelligence platform. Duration: the term of the agreement plus the retention periods stated in section 9. Nature and purpose: retrieving marketing performance data from the platforms the customer connects, normalising and storing it, computing metrics and statistics over it, generating reports, alerts and AI-assisted observations, and presenting them to the customer's authorised users.

3. Categories of data

Personal data processed under this addendum is limited to:

  • Data subjects — the customer's employees, contractors and authorised users; the customer's own clients where an agency configures a client workspace.
  • Personal data — name, work email, locale, role, workspace membership, authentication metadata, IP address and user agent in security logs, and audit records of actions taken.
  • Advertising data — campaign, ad set, ad and creative records, and aggregate performance metrics. Sightrz does not ingest advertising audience lists, customer match files, or hashed identifiers, and connectors do not request those scopes.
  • No special categories of personal data are processed, and the service must not be used to send any.

4. Our obligations

Sightrz will:

  • Process personal data only on the customer's documented instructions, including for transfers, unless required otherwise by law — in which case we will inform the customer first unless the law forbids it.
  • Ensure that everyone authorised to process the data is under an appropriate duty of confidentiality.
  • Implement the technical and organisational measures in section 6.
  • Assist the customer, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations on security, breach notification and impact assessments.
  • Delete or return personal data at the end of the agreement, per section 9.
  • Make available the information needed to demonstrate compliance and allow for audits under section 10.
  • Tell the customer promptly if, in our opinion, an instruction infringes applicable data protection law.

5. Sub-processors

The customer gives general authorisation for the sub-processors listed in our privacy policy. Each is bound by written terms imposing obligations no less protective than these, and Sightrz remains fully liable for their performance.

We will give at least 30 days' notice before adding or replacing a sub-processor. If the customer objects on reasonable data protection grounds within that period, we will work to find a solution; if none is available, the customer may terminate the affected service without penalty.

6. Security measures

Measures maintained by Sightrz, appropriate to the risk:

  • Tenant isolation enforced at three independent layers: a tenant-scoped query builder, transaction-local scoping so a pooled connection cannot leak scope between requests, and row-level security policies on every organisation-scoped table. An automated cross-tenant visibility test gates every deploy.
  • Encryption in transit (TLS) for all traffic, and encryption at rest for the database and object storage.
  • Envelope encryption of platform credentials with a per-organisation key, wrapped by a key held in a separate secrets store. Decryption occurs only inside the synchronisation job.
  • Role-based access control within each workspace, and least-privilege access for Sightrz personnel, granted only for a stated support purpose and logged.
  • Append-only audit logging of security-relevant actions, retained 24 months, with update and delete privileges granted to nobody.
  • Automated backups with point-in-time recovery, and a documented restoration procedure.
  • Dependency and secret scanning in continuous integration; security headers and a content security policy that forbids third-party image, script and font sources.
  • A penetration test before general availability and periodically thereafter, with the summary report available to Enterprise customers under NDA.

7. International transfers

Personal data is stored and processed in the European Union — specifically Frankfurt, Germany — unless an Enterprise agreement provides for in-region storage, in which case the region is stated in that agreement.

For customers in Saudi Arabia and the United Arab Emirates, this constitutes a cross-border transfer. It relies on transfer to a jurisdiction offering an adequate level of protection, supported where required by standard contractual clauses and by the measures in section 6. We will provide the transfer documentation on request.

Sightrz will not relocate stored customer data to another jurisdiction without notifying affected customers in advance.

8. Personal data breach

Sightrz will notify the customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting that customer's data.

The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not yet available we will send what we have and follow up rather than delay the first notice.

9. Deletion and return

On termination, the workspace becomes read-only for 30 days so the customer can export its data. After that period Sightrz deletes personal data from active systems within 30 days, and from backups within 90 days as backups age out on their normal cycle.

Sightrz may retain data where required by law, and aggregated de-identified statistics that cannot be resolved back to a data subject, workspace or advertiser.

10. Audit

Sightrz will make available the information reasonably necessary to demonstrate compliance with this addendum, including current security documentation and the most recent penetration test summary.

A customer may audit no more than once in any 12-month period, on 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. Where a recent independent report answers the question, that report will be provided in place of an on-site audit.

11. Liability

Liability under this addendum is subject to the limitations in the terms of service, except where applicable data protection law does not permit that limitation.


Questions about this document: privacy@sightrz.com