Data Processing Addendum (DPA)

Last Updated: 13th January 2026

This Data Processing Addendum (“DPA”) forms part of and supplements any agreement, terms, or arrangements (“Agreement”) between Techwize Media (“Techwize”, “we”, “us”, or “Processor”) and its clients, partners, or customers (“Controller”).

This DPA governs the processing of Personal Data in accordance with applicable data protection laws, including the UK GDPR, EU GDPR, and other relevant privacy regulations.

1. Definitions

Unless otherwise defined in this DPA, capitalised terms shall have the meanings given to them under applicable data protection laws.

  • “Personal Data” means any information relating to an identified or identifiable natural person.
  • “Processing” means any operation performed on Personal Data.
  • “Controller” means the entity that determines the purposes and means of Processing.
  • “Processor” means the entity that processes Personal Data on behalf of the Controller.
  • 2. Roles of the Parties

    For the purposes of this DPA:

  • The Controller determines the purposes and means of Processing Personal Data.
  • Techwize Media acts as a Data Processor, processing Personal Data solely on documented instructions from the Controller.
  • Techwize shall not process Personal Data for its own purposes.

    3. Scope of Processing

    3.1 Subject Matter

    The Processing relates to performance marketing, user acquisition, media optimisation, analytics, attribution, and related growth services.

    3.2 Categories of Data

    Personal Data may include:

  • Business contact information
  • Campaign and performance data
  • Device or usage identifiers (where applicable)
  • Aggregated or pseudonymised data
  • 3.3 Data Subjects

    Data subjects may include:

  • Business representatives
  • End users (where applicable and instructed)
  • Publishers or partners
  • 4. Processor Obligations

    Techwize shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure personnel are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Assist the Controller in meeting data protection obligations
  • Notify the Controller without undue delay in the event of a Personal Data breach
  • 5. Security Measures

    Techwize maintains appropriate safeguards, including:

  • Access controls and role-based permissions
  • Secure data storage and transmission
  • Internal data handling policies
  • Regular monitoring and risk assessments
  • Security measures are reviewed and updated as appropriate.

    6. Sub-Processors

    The Controller authorises Techwize to engage sub-processors to perform Processing activities, provided that:

  • Sub-processors are subject to equivalent data protection obligations
  • Techwize remains responsible for sub-processor compliance
  • A list of sub-processors may be provided upon request.

    7. International Data Transfers

    Where Personal Data is transferred outside the UK or EEA, Techwize shall ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)
  • Other lawful transfer mechanisms recognised under applicable law
  • 8. Assistance with Data Subject Rights

    Taking into account the nature of Processing, Techwize shall reasonably assist the Controller in responding to:

  • Access requests
  • Rectification or erasure requests
  • Objections or restrictions
  • Data portability requests
  • 9. Data Retention & Deletion

    Upon termination of the Agreement, Techwize shall, at the Controller’s choice:

  • Delete Personal Data, or
  • Return Personal Data
  • Unless retention is required by law.

    10. Audits & Compliance

    Upon reasonable written request, Techwize shall make available information necessary to demonstrate compliance with this DPA.

    Audits, where required, shall be:

  • Reasonable in scope
  • Conducted with prior notice
  • Subject to confidentiality
  • 11. Liability

    Liability under this DPA shall be subject to the limitations set out in the applicable Agreement, except where prohibited by law.

    12. Governing Law & Jurisdiction

    This DPA shall be governed by and construed in accordance with the laws of England and Wales.

    Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of England and Wales.

    13. Order of Precedence

    In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.

    14. Contact Information

    For data protection enquiries, please contact:

    Scroll to Top