Data Processing Addendum

LAST UPDATED: 6 AUGUST 2026

1. Scope and roles

This Data Processing Addendum forms part of the agreement between Omega Union Limited (“Processor”) and the client (“Controller”). It applies where we process personal data on the Controller’s behalf while delivering an engagement. For our own account, enquiry and billing data we act as an independent controller, and the Privacy Policy covers that. Where this addendum and the agreement conflict on the processing of Controller personal data, this addendum governs.

2. Definitions

“Personal data”, “processing”, “controller”, “processor” and “data subject” carry the meanings given in the UK GDPR and the EU GDPR, and the equivalent meanings under the Turkish KVKK and the CCPA and CPRA where those apply. “Applicable data protection law” means the data protection law that applies to the processing.

3. Subject matter and duration

We process Controller personal data only to deliver the engagement, and only for its duration plus the deletion period below. The nature and purpose of processing is the operation of a company’s digital side: building and running the site or store, producing and publishing work, running advertising, email, outreach and messaging, and reporting on all of it.

4. Categories of data and data subjects

  • Data subjects: the Controller’s personnel, its customers and prospects, and end users who interact with the accounts we operate.
  • Data categories: contact details, account identifiers, order and transaction records, engagement and advertising metrics, creative assets, and anything else the Controller submits or connects.
  • We do not intentionally process special categories of personal data, and the Controller agrees not to submit them.

5. Processor obligations

  • Process personal data only on the Controller’s documented instructions, which include this addendum and the agreement.
  • Bind everyone authorised to process the data to confidentiality.
  • Apply the technical and organisational measures in section 7.
  • Assist the Controller with data subject requests and with its own obligations under Applicable data protection law, taking the nature of the processing into account.
  • Make available the information needed to demonstrate compliance with this addendum.

6. Subprocessors

The Controller authorises us to engage subprocessors, each bound by terms no less protective than this addendum. The current list:

  • Supabase, for database, authentication and storage.
  • Cloudflare, for DNS, edge delivery and object storage.
  • Hetzner, for the servers the execution engine runs on.
  • Apple iCloud, for the calendar that holds booked calls.
  • Stripe and iyzico, for payment processing.
  • Resend, for transactional and campaign email delivery.
  • DeepSeek, Google, Kling, Higgsfield and ElevenLabs, for text, image, video and voice generation.

We give notice before adding or replacing a subprocessor, and the Controller may object on reasonable data protection grounds.

7. Security measures

  • Encryption in transit, and encryption at rest for credentials and tokens.
  • Tenant isolation enforced at the database layer through row-level security.
  • Least-privilege service credentials, restricted production access and audit logging.
  • Every action recorded as an event, so the sequence can be reconstructed.
  • Periodic review of access and of the security configuration.

8. International transfers

Where personal data leaves the UK, the EEA or Türkiye, we rely on an appropriate transfer mechanism, such as the European Commission Standard Contractual Clauses with the UK International Data Transfer Addendum, plus any supplementary measures required.

9. Personal data breach

We notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller personal data, and provide the information reasonably available to help the Controller meet its own notification duties.

10. Audit

On reasonable prior written request, and no more than once a year unless a supervisory authority requires otherwise, we make available the information needed to demonstrate compliance and contribute to an audit by the Controller or an auditor it appoints, subject to confidentiality.

11. Return and deletion

On termination we delete or return Controller personal data within 30 days, except where retention is required by law. See also the Data Deletion page.

12. Contact

Omega Union Limited, United Kingdom. To request a signed copy of this addendum: [email protected].