Data Processing Agreement

Effective date: January 10, 2025

This Data Processing Agreement ("Agreement") governs the processing of personal data by TG Tracker ("Processor") on behalf of the Customer ("Controller") in accordance with applicable data protection laws including PIPEDA (Canada), UK GDPR, and EU GDPR.

For the purposes of this Agreement, the Customer acts as the data controller and TG Tracker acts solely as the data processor. The Customer determines the purposes and means of processing personal data, and TG Tracker processes personal data only on the Customer's behalf and in accordance with documented instructions.

As controller, the Customer is solely responsible for ensuring that all processing of personal data is lawful, including obtaining all necessary consents and legal bases required to collect, use, and share personal data (including through cookies, pixels, and other tracking technologies).

1. Definitions

  1. Telegram Ecosystem: Controller-owned Telegram assets including Bots, Channels, Mini Apps, and Personal Accounts.
  2. CAPI: Conversion APIs provided by platforms such as Meta, Google, TikTok, and others.
  3. Ad Provider Account: Controller's accounts on Meta, Google, YouTube, TikTok, or similar advertising platforms.
  4. Platform: TG Tracker's web service at https://tg-tracker-one.vercel.app.
  5. End-User: Any person who interacts with the Controller's Telegram Ecosystem or domains.
  6. End-User Data: Personal data collected from End-Users and processed by TG Tracker on the Controller's behalf under this Agreement.

2. Scope and Duration

2.1 Scope of Processing

The Processor provides a platform that allows the Controller to:

  1. Connect and manage the Controller's Telegram Ecosystem and end-user interactions
  2. Connect Ad Provider metadata (e.g. Meta Pixel) to attribute Telegram actions to advertisements
  3. Purchase or connect domains via Cloudflare
  4. Create redirect pages to match tracking parameters with Telegram metadata
  5. Create message flows for Telegram Bot automation
  6. Collect end-user data including Telegram identifiers, web metadata, and event logs
  7. View and visualize end-user data and analytics
  8. Send push notifications through Telegram Bots
  9. Communicate with end-users via chat interface through Telegram Bots or personal accounts
  10. Integrate external event sources and forward them to Ad Provider accounts

2.2 Duration

Processing begins on the account creation date and continues until the Platform account is deleted by the Controller. Personal data is retained only as long as necessary to fulfill the purposes of processing or as required by law, after which it is securely deleted or anonymized.

3. Nature and Purpose of Processing

3.1 Nature and Purpose

Processing activities include: collecting, sorting, saving, transferring, restricting, and deleting data. The purpose is to enable the Controller to manage their Telegram Ecosystem and attribution of end-user interactions to advertising campaigns.

3.2 Type of Data

  1. Web data including technical device and browser information, tracking identifiers, cookies, URL parameters, and interaction metadata
  2. Telegram metadata such as usernames, IDs, and first/last names collected through the Controller's Telegram Ecosystem
  3. Messages, chat content, or other information provided by end-users through the Controller's platforms

3.3 Categories of Data Subjects

End-users of the Controller who interact with the Controller's Telegram Ecosystem or domains.

4. Obligations of the Processor

  1. Process personal data only as instructed by the Controller or as legally required
  2. Maintain strict confidentiality when processing data
  3. Ensure all personnel processing data are trained on applicable data protection requirements
  4. Support the Controller in responding to supervisory authority inspections or data subject rights requests
  5. Only share data with third parties with the Controller's prior consent or per Controller instructions
  6. Assist the Controller in security compliance, breach notifications, and data protection impact assessments

5. Technical and Organisational Measures

TG Tracker implements appropriate technical and organizational security measures including:

  • Data minimization
  • Encryption of sensitive data at rest
  • Encryption in transit (subject to correct Cloudflare configuration by the Controller)
  • Regular backups and recovery procedures
  • Access controls restricting data to authorized personnel

For full details, see our Security Overview.

6. Data Correction, Deletion, and Blocking

The Processor may only correct, delete, or block personal data in accordance with this Agreement or the Controller's documented instructions. Upon the Controller's request, the Processor shall destroy or return all processed data, including copies held by sub-processors.

7. Sub-Processing

TG Tracker may engage sub-processors only where bound by written contracts with equivalent data protection obligations. The Controller provides general authorization for sub-processor engagement. TG Tracker will notify the Controller at least 10 business days before engaging any new sub-processor.

Appendix A — Current Sub-Processors:

NameCountryScope of Use
VultrUnited KingdomCloud hosting of database(s) containing personal data
BackBlazeUnited StatesCloud storage of images and other media potentially containing personal data

8. Rights and Obligations of the Controller

The Controller is solely responsible for:

  1. Assessing the lawfulness and admissibility of all processing instructions
  2. Ensuring compliance with all applicable data protection laws
  3. Determining the lawful basis for any processing instructions provided to TG Tracker

The Controller may appoint an independent auditor (with 4 weeks' prior written notice, no more than every 12 months) to inspect TG Tracker's compliance with this Agreement. All audit costs are borne by the Controller.

9. Breach Notification

TG Tracker will notify the Controller of any personal data breach within 72 hours of becoming aware. Notifications will include:

  1. Description of the breach including categories and approximate number of affected persons
  2. Contact details for further information
  3. Description of probable consequences
  4. Description of measures taken or proposed to address the breach

10. International Data Transfers

Personal data transfers outside the country of collection shall only occur:

  1. To countries with an adequacy decision from the European Commission and UK Secretary of State (such as Canada), or
  2. Where Standard Contractual Clauses or other approved transfer mechanisms are in place

11. Liability

  1. TG Tracker's liability is limited to failures to comply with applicable Data Protection Legislation or actions taken without or against the Controller's lawful instructions
  2. TG Tracker's liability under this Agreement is limited to the amount paid by the Controller in the three months preceding the incident
  3. The Controller is liable for damage caused by unauthorized processing or incorrect instructions

12. Termination

The Controller may terminate this Agreement without notice if TG Tracker commits a serious infringement of data protection regulations or refuses to comply with the Controller's rights under this Agreement. For minor breaches, TG Tracker will be given a reasonable period to remedy the situation.

13. Governing Law

This Agreement is governed by the laws of Ontario, Canada. The parties submit to the exclusive jurisdiction of the courts of Ontario, Canada.

14. Contact

Questions regarding this Agreement: noreply.tgtrackerx@gmail.com