Legal
Data Processing Agreement
The terms under which PubTrust processes personal data on behalf of customers, under Article 28 of the GDPR and the UK GDPR.
How do I get the DPA?
The DPA is being finalised with counsel. Until the reviewed version is published here, request the current draft from privacy@pubtrust.cc.
What does it cover?
- Processing only on your documented instructions, for the purposes of providing the service.
- Categories of data subject: visitors to your Sites (tag data) and your users (account data).
- IP truncation by default — IPv4 /24, IPv6 /48 — with full-IP retention only on your explicit opt-in, capped at 30 days.
- Retention: violations 90 days, the clean-impression sample 30 days, aggregates without IP addresses indefinitely.
- Confidentiality of personnel, and staff access to your account that is time-limited, read-only by default and recorded in your audit log.
- Security measures: origin validation at the edge, HMAC-signed batches over HTTPS, an append-only hash-chained audit log.
- Sub-processors listed publicly, notice before any addition, and a right to object.
- Assistance with data-subject requests and impact assessments, personal-data breach notification without undue delay, and deletion of data when the service ends.
- International transfers under Standard Contractual Clauses and the UK Addendum where required.
The current sub-processors are on the sub-processors page.