Skip to content

Legal

Data processing agreement

Last updated October 5, 2026 · Impact Lab LLC

Draft, pending legal review. This document is a working draft and may change. Highlighted items are still being confirmed. Questions? Email hello@impactlabgroup.com.

This page summarizes the terms that apply when Impact Lab LLC (“Impact Lab”, “we” or “us”) processes personal data on behalf of a client while providing marketing services. It is a summary for convenience, not the agreement itself.

A signed data processing agreement (DPA) is available on request and forms part of the client agreement. If this summary differs from a signed DPA or client agreement, the signed document prevails. For personal data we collect through our own website, see our privacy policy instead.

1. Scope

This applies when our work gives us access to personal data about your customers, leads or website visitors, for example in your ad accounts, pixels and conversion tracking, analytics tools, customer relationship management (CRM) systems, email lists, custom audiences or lead forms.

  • People concerned: your customers, prospects, leads, website and app visitors, and others whose data you hold in the systems we work in.
  • Types of data: typically contact details, online identifiers (such as cookie IDs, device IDs and hashed email addresses), website and app activity, conversion and purchase data, and lead form answers.
  • Sensitive data: our services do not require special categories of personal data (such as health information). Please do not share them with us unless we have agreed in writing how they will be handled.
  • Duration: for the length of the engagement, plus any time needed to return or delete data at the end.

2. Roles and ownership

You are the controller (a “business” under US state privacy laws such as the CCPA), and Impact Lab is your processor (a “service provider” or “contractor”). You decide why and how the data is used; we process it only to provide the services you engaged us for.

Your ad accounts, pixels, analytics and data remain owned by you. We work inside them using the access you grant, and you can change or remove that access at any time. You are responsible for having a lawful basis for the processing, for your own privacy notices, and for collecting any consents your websites and apps need, such as cookie consent for tracking pixels.

3. Processing only on your instructions

We process client personal data only on your documented instructions. These are set out in the client agreement, proposal or statement of work, and in any written instructions you give us during the engagement. If we believe an instruction breaks data protection law, we will tell you.

Where US state privacy laws apply, we will not:

  • sell or share client personal data;
  • keep, use or disclose it for any purpose other than providing the services to you, or outside our direct business relationship with you; or
  • combine it with personal data we receive from other sources, except as the law allows.

4. Confidentiality

We keep client personal data confidential. Anyone we authorize to process it on our behalf is bound by a duty of confidentiality.

5. Security measures

We use appropriate technical and organizational measures to protect client personal data, taking into account the risks involved. These include working through the user permissions you grant in your own systems, rather than copying data out of them where possible. [To confirm: the security measures in place, e.g. two-factor authentication on all accounts, encrypted devices, password manager, least-privilege access and no shared logins]

6. Sub-processors

We may use other companies (sub-processors) to help deliver the services. You give us general authorization to use them, provided that:

  • each sub-processor is bound by written data protection terms at least as protective as these;
  • we tell you before adding or replacing a sub-processor, giving you [To confirm: notice period for new sub-processors, e.g. 30 days] to object on reasonable grounds; and
  • we remain responsible for our sub-processors’ work.

Current sub-processors: [To confirm: list of sub-processors with their purpose and location, e.g. email and file storage, project management, reporting or dashboard tools, and any freelancers or UGC creators who may access client data]

Advertising platforms such as Meta, Google and TikTok are not our sub-processors. You hold those accounts directly, and your use of them is governed by your own agreements with each platform.

7. Help with individuals’ requests

If we receive a request from someone exercising their privacy rights about data we process for you, we will pass it to you [To confirm: time to forward requests, e.g. within 5 business days] and will not respond to it ourselves unless you ask us to. We will give you reasonable help to respond to these requests, and to meet your other obligations, such as data protection impact assessments, taking into account the nature of our work.

8. Personal data breaches

If we become aware of a personal data breach affecting client data, we will notify you without undue delay and within [To confirm: breach notification timeframe, e.g. 48 hours] of becoming aware of it. We will share what we know about the breach, its likely consequences and the steps taken to address it, and will update you as we learn more, so you can meet your own notification duties.

9. International transfers

Impact Lab is based in the United States. Where client personal data from the EEA, the UK or Switzerland is transferred to us or our sub-processors in countries without an adequacy decision, the transfer will be covered by the European Commission’s Standard Contractual Clauses, together with the UK addendum or Swiss amendments where required, or by another transfer safeguard recognized by law.

10. Deletion or return at the end

When the engagement ends, we will, at your choice, return or delete the client personal data we hold within [To confirm: time to return or delete data, e.g. 30 days], unless the law requires us to keep it. We will also stop using our access to your accounts and tools, and you can remove it at any time. Data that lives in your own accounts stays with you.

11. Audits and information

We will make available the information reasonably needed to show that we meet these obligations, and will allow and contribute to reasonable audits by you or an auditor you appoint. [To confirm: audit terms, e.g. advance notice, frequency limits, confidentiality and who pays the costs]

12. Requesting a signed DPA

To request a signed DPA, or if you have questions about how we handle client data, email hello@impactlabgroup.com. Legal notices can be sent to Impact Lab LLC, 212 N. 2nd St. STE 100, Richmond, KY 40475, USA.