1. Roles
The customer is the controller of personal data it brings into Deltryx. RACTING, as provider of Deltryx, is the processor and processes that data only on the customer's documented instructions, which are given through the customer's configuration and use of the service.
2. Nature and purpose
Processing consists of collecting, storing, matching, aggregating and analysing marketing and sales data to provide measurement, attribution, modelling, reporting and, where enabled, sending conversions to advertising platforms chosen by the customer.
3. Categories of data and data subjects
Data subjects are the customer's shoppers, leads and website visitors, and the customer's own users.
- Order and refund records, products and values
- Hashed email and phone identifiers (SHA-256)
- Lead name, phone and email in lead-generation workspaces
- Website sessions: pages, referrers, campaign tags, click IDs, device type, country and browser user agent
- User account data and audit records
4. Confidentiality and security
Personnel with access are bound by confidentiality. Technical measures include row-level tenant isolation, encryption of secrets at rest with AES-256-GCM, hashed identifiers, two-step verification, role-based access control, audit logging and a strict content security policy, as described on the security page.
5. Subprocessors
The customer authorises the subprocessors listed in the privacy policy: Cloudflare, Hostinger, Anthropic (only when AI features are enabled), Stripe (when online billing is enabled), an email delivery provider, and the platforms the customer connects. We will give notice of new subprocessors so the customer can object.
6. Assistance
The service provides tools to export or erase an individual's data. We will help the customer respond to requests from data subjects and authorities, and notify the customer without undue delay after becoming aware of a personal data breach affecting its data.
7. International transfers
Some subprocessors may process data outside the customer's country. Where the law requires safeguards for such transfers, we rely on the mechanisms the relevant provider offers.
8. Retention and deletion
Raw payload archives expire after 90 days. Other customer data is kept for the life of the organisation and deleted on request at the end of the service, after the customer has had the opportunity to export it.
9. Contact
Questions or requests under this addendum: [email protected].
Questions about this document: [email protected]