Data Processing Agreement
Last updated: 29 June 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by New North Digital ("NND", the processor) on behalf of the client using the Conversion Uploader (the controller). It forms part of, and is subject to, the service agreement between the parties. Where this DPA conflicts with the service agreement on data protection, this DPA prevails. It implements Article 28 of the EU GDPR.
This page is the standard DPA. For a counter-signed copy, or to record acceptance, contact hello@newnorth.nl.
1. Roles
For all personal data processed through the tool to upload a client's conversions, the client is the controller and determines the purposes and means of the processing. NND is the processorand processes that data only on the controller's documented instructions, including the configuration the controller sets in the tool (the source, the field mapping, the destination account, and the consent signal supplied per source).
2. Subject matter, nature, purpose and duration
- Subject matter & purpose: uploading offline and online conversions to Google Ads and Google Analytics 4 for advertising measurement, and reconciling what Google accepted or rejected.
- Nature of processing: reading a fixed set of fields from a controller-controlled source, hashing contact identifiers, de-duplicating, enforcing the consent gate, transmitting to Google, and recording reconciliation results.
- Duration: for the term of the service agreement, after which the deletion terms in clause 9 apply.
3. Categories of data subjects and personal data
Data subjects:the controller's customers and leads whose conversions are uploaded.
Personal data (limited to the conversion contract):
- Contact identifiers — email and/or phone, hashed with SHA-256 before transmission; raw email and phone are not stored.
- Online identifiers — Google click ids (gclid, gbraid, wbraid) and the GA4 client id, where present.
- Conversion details — transaction id, value, currency, conversion time.
- Consent signals — consent for ad user data and ad personalization, as supplied by the source.
No special categories of personal data are processed.
4. Controller obligations and the consent allocation
The controller warrants that it has, and will maintain, a valid legal basis (including any consent required) for processing the personal data and for using contact data for advertising measurement and personalization, and that its instructions comply with applicable law. Collecting, recording, maintaining and evidencing that legal basis, and supplying an accurate consent signal per source, is and remains the controller's sole responsibility. NND's technical consent gate (dropping EEA rows without the required consent) is a safeguard and does not transfer or reduce that responsibility.
5. Processor obligations
- Instructions. Process the personal data only on the controller's documented instructions, including for international transfers, unless required otherwise by law (in which case NND informs the controller unless the law forbids it).
- Confidentiality. Ensure persons authorized to process the data are bound by confidentiality.
- Security. Implement appropriate technical and organizational measures under Article 32 (see clause 6).
- Assistance. Assist the controller, taking into account the nature of the processing, in responding to data subject requests and in meeting its obligations under Articles 32 to 36 (security, breach notification, impact assessments).
- Data subject requests. Promptly forward any request received directly from a data subject to the controller and not respond itself except on the controller's instructions.
- Audits. Make available the information necessary to demonstrate compliance with this clause and allow for and contribute to audits, including inspections, by the controller or a mandated auditor, on reasonable notice and subject to confidentiality.
6. Security measures
NND applies, among others: encryption in transit and at rest; SHA-256 hashing of contact identifiers before transmission so no raw contact identifier leaves the system; access control on the operator console; secrets held in environment configuration, not in code; encryption of stored OAuth and source credentials; a global upload kill-switch and per-run volume and value caps; and deletion of raw webhook and CSV payloads on a configurable schedule (30 days by default). Measures may be updated provided the level of protection is not reduced.
7. Sub-processors
The controller gives a general authorization for NND to engage the sub-processors listed at /subprocessors, which is incorporated into this DPA. NND imposes data protection obligations on each sub-processor that are no less protective than this DPA, and remains liable for their performance. NND will give the controller reasonable prior notice of any new or replaced sub-processor (by updating that page and, on request, by email), during which the controller may object on reasonable data-protection grounds; if an objection cannot be resolved, the controller may terminate the affected service.
8. International transfers and data location
The application and database are currently hosted in the United States, and Google processes the conversions in the United States. Transfers of personal data outside the EEA are covered by appropriate safeguards, in particular the EU Standard Contractual Clauses (and, for the conversions, Google's Ads Data Processing Terms). EU-region hosting (database and application in the EU) is available for controllers that require EU data residency; contact NND to arrange it before onboarding.
9. Return and deletion
On termination, and at the controller's choice, NND deletes or returns the personal data processed under this DPA and deletes existing copies, unless law requires storage. In practice, raw payloads are already deleted on the retention schedule; hashed and pseudonymous references and aggregate reconciliation counts are deleted on termination on request.
Data subject erasure.On a verified erasure request relayed by the controller, NND removes the data subject from the Customer Match audience lists it manages (by hashed identifier) and deletes any stored source events carrying their identifiers. Conversions already reported to Google carry only hashed identifiers and cannot be recalled; erasure of the underlying customer record remains the controller's responsibility in its own systems, which also stops the identifier from being sent in future uploads.
10. Breach notification
NND notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information the controller reasonably needs to meet its own notification obligations.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the service agreement. Nothing in this DPA limits liability that cannot be limited under applicable data protection law. (The specific liability and indemnity terms are subject to the parties' signed agreement and to legal review.)
12. Governing law
This DPA is governed by the laws of the Netherlands, and disputes are subject to the competent court in the Netherlands, unless the service agreement provides otherwise. Contact: hello@newnorth.nl.