Data Processing Agreement
Effective date: January 10, 2025
For the purposes of this Agreement, the Customer acts as the data controller and TG Tracker acts solely as the data processor. The Customer determines the purposes and means of processing personal data, and TG Tracker processes personal data only on the Customer's behalf and in accordance with documented instructions.
As controller, the Customer is solely responsible for ensuring that all processing of personal data is lawful, including obtaining all necessary consents and legal bases required to collect, use, and share personal data (including through cookies, pixels, and other tracking technologies).
1. Definitions
- Telegram Ecosystem: Controller-owned Telegram assets including Bots, Channels, Mini Apps, and Personal Accounts.
- CAPI: Conversion APIs provided by platforms such as Meta, Google, TikTok, and others.
- Ad Provider Account: Controller's accounts on Meta, Google, YouTube, TikTok, or similar advertising platforms.
- Platform: TG Tracker's web service at https://tg-tracker-one.vercel.app.
- End-User: Any person who interacts with the Controller's Telegram Ecosystem or domains.
- End-User Data: Personal data collected from End-Users and processed by TG Tracker on the Controller's behalf under this Agreement.
2. Scope and Duration
2.1 Scope of Processing
The Processor provides a platform that allows the Controller to:
- Connect and manage the Controller's Telegram Ecosystem and end-user interactions
- Connect Ad Provider metadata (e.g. Meta Pixel) to attribute Telegram actions to advertisements
- Purchase or connect domains via Cloudflare
- Create redirect pages to match tracking parameters with Telegram metadata
- Create message flows for Telegram Bot automation
- Collect end-user data including Telegram identifiers, web metadata, and event logs
- View and visualize end-user data and analytics
- Send push notifications through Telegram Bots
- Communicate with end-users via chat interface through Telegram Bots or personal accounts
- Integrate external event sources and forward them to Ad Provider accounts
2.2 Duration
Processing begins on the account creation date and continues until the Platform account is deleted by the Controller. Personal data is retained only as long as necessary to fulfill the purposes of processing or as required by law, after which it is securely deleted or anonymized.
3. Nature and Purpose of Processing
3.1 Nature and Purpose
Processing activities include: collecting, sorting, saving, transferring, restricting, and deleting data. The purpose is to enable the Controller to manage their Telegram Ecosystem and attribution of end-user interactions to advertising campaigns.
3.2 Type of Data
- Web data including technical device and browser information, tracking identifiers, cookies, URL parameters, and interaction metadata
- Telegram metadata such as usernames, IDs, and first/last names collected through the Controller's Telegram Ecosystem
- Messages, chat content, or other information provided by end-users through the Controller's platforms
3.3 Categories of Data Subjects
End-users of the Controller who interact with the Controller's Telegram Ecosystem or domains.
4. Obligations of the Processor
- Process personal data only as instructed by the Controller or as legally required
- Maintain strict confidentiality when processing data
- Ensure all personnel processing data are trained on applicable data protection requirements
- Support the Controller in responding to supervisory authority inspections or data subject rights requests
- Only share data with third parties with the Controller's prior consent or per Controller instructions
- Assist the Controller in security compliance, breach notifications, and data protection impact assessments
5. Technical and Organisational Measures
TG Tracker implements appropriate technical and organizational security measures including:
- Data minimization
- Encryption of sensitive data at rest
- Encryption in transit (subject to correct Cloudflare configuration by the Controller)
- Regular backups and recovery procedures
- Access controls restricting data to authorized personnel
For full details, see our Security Overview.
6. Data Correction, Deletion, and Blocking
The Processor may only correct, delete, or block personal data in accordance with this Agreement or the Controller's documented instructions. Upon the Controller's request, the Processor shall destroy or return all processed data, including copies held by sub-processors.
7. Sub-Processing
TG Tracker may engage sub-processors only where bound by written contracts with equivalent data protection obligations. The Controller provides general authorization for sub-processor engagement. TG Tracker will notify the Controller at least 10 business days before engaging any new sub-processor.
Appendix A — Current Sub-Processors:
| Name | Country | Scope of Use |
|---|---|---|
| Vultr | United Kingdom | Cloud hosting of database(s) containing personal data |
| BackBlaze | United States | Cloud storage of images and other media potentially containing personal data |
8. Rights and Obligations of the Controller
The Controller is solely responsible for:
- Assessing the lawfulness and admissibility of all processing instructions
- Ensuring compliance with all applicable data protection laws
- Determining the lawful basis for any processing instructions provided to TG Tracker
The Controller may appoint an independent auditor (with 4 weeks' prior written notice, no more than every 12 months) to inspect TG Tracker's compliance with this Agreement. All audit costs are borne by the Controller.
9. Breach Notification
TG Tracker will notify the Controller of any personal data breach within 72 hours of becoming aware. Notifications will include:
- Description of the breach including categories and approximate number of affected persons
- Contact details for further information
- Description of probable consequences
- Description of measures taken or proposed to address the breach
10. International Data Transfers
Personal data transfers outside the country of collection shall only occur:
- To countries with an adequacy decision from the European Commission and UK Secretary of State (such as Canada), or
- Where Standard Contractual Clauses or other approved transfer mechanisms are in place
11. Liability
- TG Tracker's liability is limited to failures to comply with applicable Data Protection Legislation or actions taken without or against the Controller's lawful instructions
- TG Tracker's liability under this Agreement is limited to the amount paid by the Controller in the three months preceding the incident
- The Controller is liable for damage caused by unauthorized processing or incorrect instructions
12. Termination
The Controller may terminate this Agreement without notice if TG Tracker commits a serious infringement of data protection regulations or refuses to comply with the Controller's rights under this Agreement. For minor breaches, TG Tracker will be given a reasonable period to remedy the situation.
13. Governing Law
This Agreement is governed by the laws of Ontario, Canada. The parties submit to the exclusive jurisdiction of the courts of Ontario, Canada.
14. Contact
Questions regarding this Agreement: noreply.tgtrackerx@gmail.com