Data Processing Addendum
Last updated: 3 September 2026 · Equaliser Ltd (company number 15428137)
This DPA applies when Equaliser Ltd, trading as Equaliser AI (“Processor”), processes personal data on behalf of a customer (“Controller”) under UK GDPR / EU GDPR. It forms part of the Terms of Service and takes precedence over anything conflicting in those Terms for matters of personal data processing.
1. Subject matter & duration
Processing is the service described in the Terms, for as long as the Controller maintains an active subscription plus any agreed retention period.
2. Nature & purpose of processing
Providing AI-driven paid-media intelligence, reports, and audits. This includes connecting to the Controller’s advertising and commerce platforms (Google Ads, Meta Ads, Microsoft Advertising, TikTok Ads, OpenAI Ads, GA4, Google Merchant Center and Shopify, each connected only where the Controller runs it), aggregating and analysing the resulting data, generating recommendations, and delivering reports to recipients the Controller nominates.
3. Categories of data subjects
- Customer’s employees and team members using the platform
- Report recipients the Customer nominates (e.g. their clients)
- End-users whose interactions with the Controller’s advertising and analytics platforms are reflected in aggregated performance data. The Processor does not ingest identified end-user records; incidental personal data in free-text fields is redacted as described in section 7
4. Categories of personal data
- Identification & contact data: email, name, role, organisation
- Authentication data: password hashes, session tokens
- Usage telemetry: feature interactions, agent outputs, tenancy-scoped reports
- Aggregate advertising-performance data imported from connected platforms
5. Sub-processors
The Controller grants general authorisation for the sub-processors in the live register published at equaliser.ai/trust/subprocessors, which governs; the snapshot below is as of the date above (register last updated 4 September 2026). The Processor gives 30 days’ written notice before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected service with a pro-rata refund of prepaid fees. The Processor imposes data-protection obligations on every sub-processor equivalent to those in this DPA, and remains fully liable for their performance.
- Vercel, Inc.: Application hosting (Next.js) + serverless function execution. Region: EU (fra1) primary. Failover to US East under outage.
- Supabase Inc.: Primary application database (Postgres), authentication, file storage, Vault for OAuth tokens. Region: eu-west-2 (London). No replication outside EU/UK.
- Google Cloud (BigQuery): Performance data warehouse: ingestion exports + derived views. Region: europe-west2 (London).
- Anthropic, PBC: Claude API for agent reasoning, AI-Read, strategy chat. Region: EU API endpoint where available, US otherwise. Zero-retention contract; no model training on customer data.
- Funnel.io AB: Source-of-truth ingestion for paid-media platforms into BigQuery: Google Ads, Meta Ads, Microsoft Advertising, TikTok Ads and OpenAI Ads, each connected only where the client runs that platform. Region: EU.
- Stripe Payments Europe Ltd.: Subscription billing, setup-fee invoicing. Region: Ireland (EU).
- Resend, Inc.: Transactional email delivery (weekly digests, NPS surveys, alerts). Region: EU.
- Sentry (Functional Software, Inc.): Application error monitoring. Region: EU (de.sentry.io).
- Langfuse GmbH: AI observability: tracing agent runs for quality and cost. Region: EU (Germany).
- GitHub, Inc.: Source code hosting + CI/CD. No customer data. Region: US.
- PostHog Inc.: Product analytics: feature usage, page-view metrics, AI-Read engagement. Region: EU (eu.posthog.com). Zero replication outside EU.
6. International transfers
Where data flows to jurisdictions outside the UK / EEA, we rely on EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Details per sub-processor available on request.
7. Technical & organisational measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Multi-tenant row-level security (RLS) on every tenant-scoped table
- Role-based access control with least-privilege default
- Documented automated release controls covering authentication, tenancy isolation and data handling on every release
- A redaction layer that strips common identifiers (emails, phone numbers, postcodes, National Insurance numbers, IP addresses) from free-text fields before any prompt is sent to an AI sub-processor
- An append-only audit log of configuration and identity events, exportable by the Controller
- All infrastructure sub-processors independently hold SOC 2 Type II or ISO 27001. The Processor’s own SOC 2 Type I attestation is in progress (Type II follows); independent penetration testing is planned prior to general availability
7a. Instructions & confidentiality
The Processor processes personal data only on the Controller’s documented instructions (including this DPA and the service’s configuration surfaces), and will inform the Controller if an instruction appears to infringe UK or EU data-protection law. Every person authorised to process personal data is bound by a contractual or statutory duty of confidentiality. The Processor assists the Controller, taking into account the nature of the processing, with its obligations under Articles 32 to 36 (security, breach notification, impact assessments and prior consultation).
8. Data subject rights
The Processor assists the Controller in responding to data subject requests (access, rectification, erasure, portability, objection) at no additional cost for paid plans.
9. Breach notification
The Processor notifies the Controller without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the Controller’s data. Notification includes the nature of the breach, affected data, mitigation taken, and likely consequences.
10. Audit rights
Once per calendar year, the Controller may request (with 30 days’ notice) a summary of the Processor’s security posture and sub-processor register. On-site audits are available at the Controller’s expense.
11. Deletion on termination
On termination or expiry, the Controller elects return or deletion of personal data. Deletion from live systems completes within 30 days of the election (or of termination where no election is made); encrypted backups roll off within a further 90 days. Retention required by law (e.g. accounting records) is excepted. Written confirmation of deletion is provided on request.
Contact
Privacy contact: contact@equaliser.co.uk
A countersigned copy of this DPA is available on request for procurement / legal review processes.