Short version: Web Tonic acts as a data processor for client personal data, signs a GDPR Article 28 Data Processing Agreement with Standard Contractual Clauses for international transfers, publishes its subprocessors, and returns or deletes client data within 30 days of termination on request.
What we process, and why
CategoryTypical dataPurposeWebsite and campaign visitorsOnline identifiers, device and browser data, behavioural events, consent stateMeasurement, attribution, campaign optimizationLeads and enquiriesName, email, phone, message content, sourceLead routing, CRM configuration, nurture campaignsCustomers of our clientsOrder and transaction records, lifetime value indicatorsAudience modelling, ROAS and revenue reportingClient staffNames, business contact details, platform access recordsAccount administration and communicationSpecial-category or health dataOnly where explicitly contracted, under a BAA and additional safeguardsExcluded from advertising platforms entirely — see HIPAA & healthcare data
Our DPA terms in plain language
- Instruction-bound. We process only for the services in your contract, never for our own purposes, and never to build products from your data.
- Security measures. The controls published at /trust/security form the technical and organizational measures schedule.
- Subprocessors. Authorized by the published list at /trust/subprocessors, with 30 days’ notice before additions and a right to object.
- Transfers. SCCs, plus the UK IDTA where applicable; transfer risk assessment on request.
- Data subject rights. Assistance actioned within 10 business days of your instruction.
- Breach notification. Notice to you within 48 hours of confirming an incident involving your data, so you can meet your own 72-hour supervisory-authority deadline.
- Audit. We answer security questionnaires and support reasonable audits. Our published control matrix is the reference point for that review — see the security program.
- Deletion and return. Within 30 days of termination on request, subject to legal retention obligations.
- Retention. Deliverables and working files for the engagement term plus 12 months unless your contract specifies otherwise.
Consent and tracking, done properly
Most of our GDPR exposure as an agency sits in tag management, so that is where we are strictest. We implement consent management with Google Consent Mode signals, block non-essential tags until an affirmative choice, keep a consent record, honour withdrawal, and configure IP handling and data retention conservatively in analytics. On regulated properties we go further and move collection server-side so identifiers can be stripped before anything leaves the client’s control.
How far our assurance extends
- ISO/IEC 27001 and SOC 2: alignment and control mapping, not third-party certification.
- Web Tonic operates from the UAE, so international transfers rely on Standard Contractual Clauses rather than an adequacy decision.
- Where your DPA requires an appointed EU representative under Article 27, raise it before signature so we can put one in place for your engagement.
- Nothing here is legal advice, and it does not replace your own DPIA or vendor assessment.
Frequently asked by privacy teams
Are you a controller or a processor?
For client marketing data we are a processor — you decide the purposes and means, we act on your documented instructions. For our own website visitors, prospects and staff we are a controller. Both roles are handled separately: the processor role is governed by our DPA, the controller role by our privacy policy.
Will you sign our DPA?
Yes. We will review and sign your Article 28 DPA, or provide ours. Either way it covers scope and purpose of processing, confidentiality, security measures, subprocessor authorization and notice, assistance with data subject rights, breach notification, audit cooperation, and deletion or return at termination.
What is your transfer mechanism outside the EEA and UK?
Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is in scope, supported by a transfer risk assessment on request. Web Tonic operates from the UAE with a distributed team, so transfers are the norm rather than the exception and we document them accordingly.
How do you handle a data subject access or deletion request?
You receive it as controller; we assist as processor. Practically, we locate the data across the systems we operate for you, action the deletion or export, and confirm in writing — within 10 business days of your instruction, well inside the one-month GDPR window.
What about Canadian and US privacy law?
For Canadian clients we work to PIPEDA and Quebec’s Law 25, including consent requirements and the confidentiality-by-default expectations that apply to technology used to collect personal information. For US clients we act as a service provider under CCPA/CPRA: we do not sell or share client personal information, and we use it only to deliver the contracted services.
Request the DPA
Ask for our current DPA and subprocessor schedule at [email protected], or send yours for review. Related: Trust & Compliance · HIPAA & healthcare data · Security program · Subprocessors.
