Legal
Data processing addendum
Terms that apply where Mint Choc Media Ltd processes personal data on behalf of a client, as a processor acting on that client's instructions.
Last updated: 21 August 2026
When this addendum applies
This Data Processing Addendum applies where Mint Choc Media Ltd processes personal data on behalf of a client and on the client's documented instructions. In that situation the client is the controller and we are the processor.
It does not apply automatically to every engagement. In much of our work each party acts as a controller for its own purposes. Where this addendum applies it forms part of our Terms of Business.
Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in UK data protection law.
Subject matter, duration, nature and purpose
Subject matter: the provision of paid acquisition diagnosis, implementation and management services described in the agreed Scope.
Duration: the term of the engagement, plus any period needed to return or delete data as set out below.
Nature and purpose: analysing advertising and ecommerce performance, configuring and operating advertising campaigns and measurement, and producing reports and recommendations for the client.
Categories of data and data subjects
Categories of personal data may include contact details of the client's staff, and such personal data as is contained within the client's own advertising, analytics and ecommerce accounts to which we are given access. This may include customer identifiers, order and transaction data, audience and event data, and pseudonymous online identifiers.
Categories of data subjects may include the client's staff, the client's customers, and visitors to the client's website.
We do not seek special category personal data and ask clients not to provide it. Where the client's platforms contain such data, we do not process it beyond what is unavoidable in accessing the account.
Our obligations
We will:
- process personal data only on the client's documented instructions, including the agreed Scope, unless required otherwise by law, in which case we will inform the client unless the law prohibits it
- tell the client if, in our opinion, an instruction infringes data protection law
- ensure that people authorised to process the personal data are subject to an appropriate duty of confidentiality
- implement appropriate technical and organisational measures as described below
- assist the client, taking into account the nature of the processing and the information available to us, with data subject requests, security, breach notification, impact assessments and prior consultation
- make available information reasonably necessary to demonstrate compliance with these obligations
Security Review before launch
We implement appropriate technical and organisational measures having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, and the risks to individuals.
In practice this includes: requesting the minimum access necessary and read-only access where read-only is sufficient; using platform user or partner permissions rather than shared passwords; multi-factor authentication on accounts where the platform supports it; access limited to those who need it for the engagement; and prompt removal of access when an engagement ends.
We do not hold any security certification. We do not claim ISO 27001, SOC 2 or any equivalent, and we will not claim one unless it has actually been obtained.
Subprocessors
The client gives general authorisation for us to appoint subprocessors. Our current subprocessors are listed on the Subprocessors page.
We will give the client reasonable notice of any intended addition or replacement, and the client may object on reasonable data protection grounds. If we cannot resolve an objection, either party may terminate the affected part of the engagement.
We will impose on each subprocessor obligations equivalent to those in this addendum, and we remain responsible to the client for their performance.
Involvement in delivery does not by itself make a specialist a subprocessor. Someone is treated as a subprocessor only where they actually process personal data for which the client is the controller.
Personal data breaches
We will notify the client without undue delay after becoming aware of a personal data breach affecting personal data processed on the client's behalf, and will provide the information reasonably available to us to help the client meet its own obligations.
Data subject requests
If we receive a request from a data subject relating to personal data we process on the client's behalf, we will not respond directly unless the client instructs us to, and we will pass the request to the client without undue delay. We will provide reasonable assistance in responding.
Deletion and return
On termination, and at the client's choice, we will delete or return the personal data processed on the client's behalf, and delete existing copies, unless we are required by law to keep it.
Personal data held within the client's own platforms remains in those platforms under the client's control. Our part is to remove our access.
Audit and information Review before launch
We will make available to the client the information reasonably necessary to demonstrate compliance with this addendum, and will allow for and contribute to audits, including inspections, conducted by the client or an auditor it mandates.
Audits will be on reasonable prior written notice, during business hours, no more than once in any twelve month period unless required by a regulator or following a personal data breach, and subject to confidentiality. Each party bears its own costs unless the audit reveals a material breach by us.
International transfers Review before launch
Where processing under this addendum involves a transfer of personal data outside the United Kingdom, that transfer will be made only where an appropriate safeguard recognised under UK data protection law is in place, such as UK adequacy regulations or the International Data Transfer Agreement or Addendum.
We will provide details of the mechanism relied on for a given transfer on request.
Order of precedence
If there is a conflict between this addendum and the Terms of Business or an agreed Scope, this addendum takes precedence on data protection matters.
A client who needs this addendum signed, or who wishes to propose its own, should contact us.