Skip to content
  • The Audit
  • Recovery Sprint
  • Management
  • About
  • Book My Audit
Mint Choc Media Store - Home
  • The Audit
  • Recovery Sprint
  • Management
  • About
  • Book My Audit
  • Account

    Legal

    Data processing addendum

    Terms that apply where Mint Choc Media Ltd processes personal data on behalf of a client, as a processor acting on that client's instructions.

    Last updated: 21 August 2026

    This addendum does not apply to every engagement. It applies where we act as a processor on a client's behalf. In much of our work each party is a controller for its own purposes.

    On this page

    1. When this addendum applies
    2. Subject matter, duration, nature and purpose
    3. Categories of data and data subjects
    4. Our obligations
    5. Security
    6. Subprocessors
    7. Personal data breaches
    8. Data subject requests
    9. Deletion and return
    10. Audit and information
    11. International transfers
    12. Order of precedence

    When this addendum applies

    This Data Processing Addendum applies where Mint Choc Media Ltd processes personal data on behalf of a client and on the client's documented instructions. In that situation the client is the controller and we are the processor.

    It does not apply automatically to every engagement. In much of our work each party acts as a controller for its own purposes. Where this addendum applies it forms part of our Terms of Business.

    Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in UK data protection law.

    Subject matter, duration, nature and purpose

    Subject matter: the provision of paid acquisition diagnosis, implementation and management services described in the agreed Scope.

    Duration: the term of the engagement, plus any period needed to return or delete data as set out below.

    Nature and purpose: analysing advertising and ecommerce performance, configuring and operating advertising campaigns and measurement, and producing reports and recommendations for the client.

    Categories of data and data subjects

    Categories of personal data may include contact details of the client's staff, and such personal data as is contained within the client's own advertising, analytics and ecommerce accounts to which we are given access. This may include customer identifiers, order and transaction data, audience and event data, and pseudonymous online identifiers.

    Categories of data subjects may include the client's staff, the client's customers, and visitors to the client's website.

    We do not seek special category personal data and ask clients not to provide it. Where the client's platforms contain such data, we do not process it beyond what is unavoidable in accessing the account.

    Our obligations

    We will:

    • process personal data only on the client's documented instructions, including the agreed Scope, unless required otherwise by law, in which case we will inform the client unless the law prohibits it
    • tell the client if, in our opinion, an instruction infringes data protection law
    • ensure that people authorised to process the personal data are subject to an appropriate duty of confidentiality
    • implement appropriate technical and organisational measures as described below
    • assist the client, taking into account the nature of the processing and the information available to us, with data subject requests, security, breach notification, impact assessments and prior consultation
    • make available information reasonably necessary to demonstrate compliance with these obligations

    Security Review before launch

    We implement appropriate technical and organisational measures having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, and the risks to individuals.

    In practice this includes: requesting the minimum access necessary and read-only access where read-only is sufficient; using platform user or partner permissions rather than shared passwords; multi-factor authentication on accounts where the platform supports it; access limited to those who need it for the engagement; and prompt removal of access when an engagement ends.

    We do not hold any security certification. We do not claim ISO 27001, SOC 2 or any equivalent, and we will not claim one unless it has actually been obtained.

    Subprocessors

    The client gives general authorisation for us to appoint subprocessors. Our current subprocessors are listed on the Subprocessors page.

    We will give the client reasonable notice of any intended addition or replacement, and the client may object on reasonable data protection grounds. If we cannot resolve an objection, either party may terminate the affected part of the engagement.

    We will impose on each subprocessor obligations equivalent to those in this addendum, and we remain responsible to the client for their performance.

    Involvement in delivery does not by itself make a specialist a subprocessor. Someone is treated as a subprocessor only where they actually process personal data for which the client is the controller.

    Personal data breaches

    We will notify the client without undue delay after becoming aware of a personal data breach affecting personal data processed on the client's behalf, and will provide the information reasonably available to us to help the client meet its own obligations.

    Data subject requests

    If we receive a request from a data subject relating to personal data we process on the client's behalf, we will not respond directly unless the client instructs us to, and we will pass the request to the client without undue delay. We will provide reasonable assistance in responding.

    Deletion and return

    On termination, and at the client's choice, we will delete or return the personal data processed on the client's behalf, and delete existing copies, unless we are required by law to keep it.

    Personal data held within the client's own platforms remains in those platforms under the client's control. Our part is to remove our access.

    Audit and information Review before launch

    We will make available to the client the information reasonably necessary to demonstrate compliance with this addendum, and will allow for and contribute to audits, including inspections, conducted by the client or an auditor it mandates.

    Audits will be on reasonable prior written notice, during business hours, no more than once in any twelve month period unless required by a regulator or following a personal data breach, and subject to confidentiality. Each party bears its own costs unless the audit reveals a material breach by us.

    International transfers Review before launch

    Where processing under this addendum involves a transfer of personal data outside the United Kingdom, that transfer will be made only where an appropriate safeguard recognised under UK data protection law is in place, such as UK adequacy regulations or the International Data Transfer Agreement or Addendum.

    We will provide details of the mechanism relied on for a given transfer on request.

    Order of precedence

    If there is a conflict between this addendum and the Terms of Business or an agreed Scope, this addendum takes precedence on data protection matters.

    A client who needs this addendum signed, or who wishes to propose its own, should contact us.

    Mint Choc Media Ltd, company number 14391808. Registered office: 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom.

    Data protection enquiries: robert@mintchocmedia.com

    Mint Choc Media Store

    Paid acquisition diagnosis and growth for Shopify brands.

    Mint Choc Media Ltd
    Registered in England and Wales
    Company No. 14391808
    167-169 Great Portland Street
    5th Floor
    London
    W1W 5PF
    United Kingdom
    robert@mintchocmedia.com
    Services
    • Revenue Leak Audit
    • Revenue Recovery Sprint
    • Meta Growth Management
    • About
    • Contact
    Legal
    • Terms of Business
    • Service Delivery & Refunds
    • Data Processing Addendum
    • Subprocessors
    • Accessibility
    Privacy & choices
    • Privacy Policy
    • Cookie Policy
    • Marketing Preferences

    © 2026 Mint Choc Media Ltd. All rights reserved.

    Mint Choc Media services are intended for businesses and professionals purchasing for purposes relating to their trade, business or profession.

    Your cart is empty

    Have an account? Log in to check out faster.

    Continue shopping

    Search

    Products

    • Revenue Leak Audit
      Revenue Leak Audit

      Revenue Leak Audit

      £650.00 GBP