Company and contact information
This Addendum governs personal data that UNLIMITED SERVICES LIMITED processes on behalf of a client. It forms part of the Terms of Service and applies to every engagement in which we handle personal data for a client — which is most of them.
Under this Addendum the client is the controller and UNLIMITED SERVICES LIMITED is the processor within the meaning of Article 4 GDPR. It is written to meet the requirements of Article 28(3).
Running advertising audiences, configuring tracking, operating email and SMS platforms and analysing customer data all involve processing personal data belonging to the client’s customers. The GDPR requires a written contract between controller and processor covering the subject matter, duration, nature and purpose of that processing, the types of data, the categories of data subject, and the obligations of both parties. That is what this page provides.
The subject matter is the provision of the marketing services set out in the applicable Scope of Work. Processing lasts for the duration of the engagement and the return or deletion period in section 11.
Depending on the services engaged, processing may include:
Processing is carried out solely to deliver the agreed services, and never for our own purposes.
We do not knowingly process special categories of personal data under Article 9, nor data relating to criminal convictions. The client must not supply such data without written agreement in advance, and the Acceptable Use Policy sets out sectors we decline.
The client’s customers, prospective customers, website visitors, newsletter subscribers and, where relevant, its own staff whose contact details appear in campaign material.
We will:
The client warrants that:
The client remains responsible for the lawfulness of the data it provides. We will not act on an instruction we believe to be unlawful.
The client gives general authorisation for us to engage subprocessors, on condition that each is bound by data protection obligations equivalent to those in this Addendum, and that we remain fully liable to the client for their performance.
We will inform the client at least 30 days before adding or replacing a subprocessor. The client may object on reasonable data protection grounds within that period; if we cannot resolve the objection, the client may terminate the affected services without penalty.
Which of these apply depends on the services engaged. Only those needed for the agreed work are used, and the named list for a given engagement is confirmed in writing before it starts.
| Subprocessor | Purpose | Role |
|---|---|---|
| Meta Platforms Ireland Ltd | Campaign delivery, custom and lookalike audiences, Conversions API | Independent controller |
| Google Ireland Ltd | Google Ads, Google Analytics 4, Google Tag Manager, Looker Studio | Independent controller / processor |
| TikTok Technology Ltd | Campaign delivery and audience management | Independent controller |
| LinkedIn Ireland Unlimited Company | Campaign delivery and audience management | Independent controller |
| Microsoft Ireland Operations Ltd | Bing Ads campaign delivery | Independent controller |
| Pinterest Europe Ltd | Campaign delivery and audience management | Independent controller |
| Klaviyo Inc. | Email and SMS lifecycle automation | Processor |
| Omnisend (Soundest UAB) | Email and SMS lifecycle automation, where used instead of Klaviyo | Processor |
| Google Workspace / Microsoft 365 | Email correspondence, documents and shared working files | Processor |
| Cloud storage provider | Storage of client assets and working files | Processor |
Several of the platforms above are marked as independent controllers rather than our subprocessors. That is not a technicality worth skipping.
When customer data is uploaded to an advertising platform to build an audience, or when a pixel or the Conversions API sends event data, that platform processes the data for its own purposes as well as for the campaign — improving its models, measuring across advertisers, and its own commercial ends. For that processing it acts as a controller in its own right, and in several cases as a joint controller alongside you.
Two consequences follow, and both are the client’s responsibility as controller:
We will tell you which platforms an engagement involves and in what role, so your own notice can be brought in line. We cannot write that notice for you: it is the controller’s document, and we are not your legal adviser.
An up-to-date list is available at any time from info@marketeragency.online.
Taking account of the state of the art, the costs, and the risk to data subjects, we apply:
We will notify the client without undue delay and in any event within 24 hours of becoming aware of a personal data breach affecting the client’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
We will not notify a supervisory authority or data subjects on the client’s behalf unless instructed in writing, because that notification is the controller’s obligation.
On termination, or on the client’s written request at any time, we will at the client’s choice delete or return the personal data we hold on its behalf, and delete existing copies, within 30 days, unless retention is required by law.
We confirm deletion in writing. Data held inside the client’s own platforms — its advertising accounts, its email platform, its analytics — is not ours to delete; it stays where it is, under the client’s control, and we remove our access within 5 business days.
We will make available all information necessary to demonstrate compliance with Article 28 and, on reasonable written notice and no more than once a year, allow the client or an independent auditor appointed by it to audit that compliance. Audits take place during business hours, must not disrupt our operations or breach the confidentiality of other clients, and the client bears the cost unless the audit reveals a material breach.
UNLIMITED SERVICES LIMITED is established in Hong Kong, for which no adequacy decision exists. Where a client transfers EU or EEA personal data to us as processor, the transfer is made under the Standard Contractual Clauses adopted under Article 46 GDPR — Module Two, controller to processor — which are incorporated into this Addendum by reference and available in full on request.
Where a subprocessor is established outside the EEA, the onward transfer is covered by an adequacy decision or by Standard Contractual Clauses with the additional measures required.
Liability under this Addendum is subject to the limits in the Terms of Service, except where those limits cannot lawfully apply to obligations under the GDPR.
Where this Addendum conflicts with the Terms of Service or a Scope of Work on a matter of data protection, this Addendum prevails.
Data protection matters: info@marketeragency.online. Requests under this Addendum are acknowledged within 1 to 3 business days and acted on within the periods set out above.