Data Processing Addendum

Version 1.0 · Effective August 23, 2026 · Forms part of the Terms of Service · No signature required

What this is, in one paragraph. Most of what the Service handles is your own business data, and the Privacy Policy covers it. But when a landing page we host for you collects a lead, that lead is a real person who has no relationship with us at all - they filled in your form, about your business. For their data you are the controller and we are your processor, and the law requires that relationship to be written down. This is that document. It applies automatically to every customer, with nothing to sign and nothing to request.

1. Definitions and Roles

“Data Protection Law” means the EU General Data Protection Regulation, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended, and any other law applicable to the processing described here. “Controller,” “processor,” “personal data,” “processing,” and “data subject” take their meaning from that law. “Customer Personal Data” means personal data we process on your behalf as described in Section 2.

You are the controller of Customer Personal Data. We are your processor. You decide why it is collected and what happens to it; we act on your instructions. Under the CCPA we are a “service provider” and we do not sell or share Customer Personal Data, nor use it for cross-context behavioural advertising.

For your own account data - your name, your email, your Google Ads performance figures, how you use the platform - we are the controller, and the Privacy Policy governs it rather than this Addendum. Nothing here makes us your processor for that.

2. What We Process for You

Subject matter and duration. Providing the Service to you, for as long as your account exists, plus the retention window in Section 8.

Nature and purpose. Receiving a form submission from a landing page we host for you; storing it so you can act on it; showing it to you in your dashboard; and reporting the conversion to your Google Ads account.

Categories of data subject. People who visit a landing page we host for you and complete its form or tap its phone number - your prospects and enquirers.

Categories of personal data. Name, email address, telephone number, company name, and whatever else your form asks for; the message they write; the Google advertising click identifier that brought them to the page; their IP address, used to reject automated spam; and a record of the consents they gave - the wording, which boxes, and when.

Special category data. The Service is not designed for it and you must not configure a form to collect it. If your business needs to - health, beliefs, biometrics, and the rest of Article 9 - do not use hosted landing pages for that purpose.

3. Our Obligations

We will:

  • Process only on your instructions. Your instructions are these Terms, this Addendum, and the settings and requests you make in the product. We will not process Customer Personal Data for our own purposes, will not sell it, will not market to your leads, and will not use it to train any AI model - ours or anyone else's.
  • Tell you if an instruction looks unlawful. If we believe an instruction of yours breaches Data Protection Law we will say so, and may pause that processing rather than carry it out.
  • Keep it confidential. Access is limited to personnel who need it to run the Service, each bound by confidentiality obligations.
  • Secure it. The measures are set out on the Security page, which is incorporated into this Addendum. We will not materially weaken them during your subscription.
  • Help you answer your data subjects. See Section 5.
  • Tell you about a breach. See Section 7.
  • Delete or return it when we are done. See Section 8.
  • Give you the information you need to show your own compliance, including for a data protection impact assessment. See Section 9.

4. Your Obligations

  • You need a lawful basis. You are responsible for having one for the collection and use of every lead, and for the accuracy and lawfulness of the instructions you give us.
  • You are responsible for what your form asks. If you add fields, you decide what is collected and why.
  • You are responsible for Google. Uploading a conversion into your Google Ads account is done on your behalf, and your obligations to Google - including its EU user consent policy and its rules on data you send it - remain yours.

What we do for you here, and it is not nothing. We provide the consent wording on the form and the privacy notice it links to, and we keep both accurate to what the Service actually does with a submission. Specifically: the required box permits you to reply, a separate optional box permits advertising measurement, and only that second box allows a one-way hashed email address to be sent to Google with consent signals set. Where it is not ticked, nothing personal is sent and only the anonymous click identifier is reported. You may replace our notice with your own; if you do, keeping it accurate becomes yours.

5. Data Subject Requests

Requests from your leads are yours to answer - they are your data subjects. Your dashboard lets you find, export, and delete any lead yourself, which is normally the fastest route for access, correction, erasure, and portability requests alike.

If a request needs something the dashboard cannot do, write to privacy@bidhelm.com and we will help, at no charge, within a time that lets you meet your own statutory deadline. If a lead contacts us directly we will not respond substantively on your behalf; we will tell them to contact you and let you know it happened.

6. Sub-processors

You authorise us to use sub-processors, each engaged under written terms no less protective than this Addendum, and we remain responsible to you for what they do. The current list, with what each one does and where, is at Sub-processors.

A new sub-processor is published there at least 30 days before it starts. If you object on reasonable data protection grounds within those 30 days, tell us at privacy@bidhelm.com. We will try to make the Service work for you without it. If we cannot, you may terminate the affected part of the Service, and we will refund any fee you have already paid for a period after that termination. That is your remedy, and it is a real one - but it is the remedy, rather than a right to block the change for everyone.

7. Personal Data Breach

If we become aware of a breach affecting Customer Personal Data we will notify you without undue delay and in any event within 48 hours, at the email address on your account and in your dashboard.

The notice will describe what we know: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed. Where we do not yet know something, we will say so and follow up rather than delay the first notice until the picture is complete.

Notifying a supervisory authority or the data subjects is yours to do, since you are the controller and the deadline runs against you. We will give you what you need to do it and will not require you to wait on us.

8. Deletion and Return

  • At any time, you can delete an individual lead, a landing page and its leads, or your whole account, and you can export your leads in a machine-readable format.
  • Cancelling your plan does not delete anything by itself. Data is kept so you can come back to it. Ask us and we will delete it - see the next line.
  • On request, or on account deletion, Customer Personal Data is deleted within 30 days, including from our sub-processors and from routine backups as they age out on their normal cycle.
  • The exception is anything we are required by law to keep, which we will keep only for as long as that requires and only for that purpose.

Email privacy@bidhelm.com to ask for deletion. You do not have to cancel first.

9. Audit and Information Rights

On reasonable written request, and no more than once a year unless Data Protection Law or a supervisory authority requires otherwise, we will give you the information you reasonably need to satisfy yourself that we are meeting this Addendum - the measures in force, the sub-processors in use, the processing locations, and answers to a security questionnaire.

We are a small company and we will say so plainly: we do not hold a SOC 2 or ISO 27001 certificate today, and we would rather tell you that than let a security page imply otherwise. An audit that would require us to disclose another customer's data, or our own security-sensitive detail, will be answered by description rather than by access.

10. International Transfers

The database holding Customer Personal Data is in the European Union. Where personal data is transferred out of the EEA or the UK - to a sub-processor in the United States, for example - that transfer is made under the European Commission's Standard Contractual Clauses, module two (controller to processor), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this Addendum by reference. Where they require a choice: the governing law is the law of Ireland and the forum is the courts of Ireland; the annexes are populated by Sections 2, 6, and the Security page.

11. Liability, and How This Fits the Terms

This Addendum forms part of the Terms of Service. Where it conflicts with them on the processing of Customer Personal Data, this Addendum wins; on everything else the Terms win. The limitation of liability in the Terms applies to this Addendum, and the two together are one cap rather than two.

This Addendum ends when your account does, except that Sections 7, 8, and 10 continue for as long as we hold any Customer Personal Data.

12. Contact

Data protection: privacy@bidhelm.com · Security: security@bidhelm.com · Legal: legal@bidhelm.com

If you need this Addendum as a countersigned document for your own records, ask at legal@bidhelm.com and we will sign it. You do not need to in order to rely on it.