Back to site

Data Processing Addendum

Last updated: 17 August 2026

The short version. When you run a campaign, you decide whose deadlines to set and we carry them out, which makes you the controller and us the processor. This addendum is the contract that data protection law requires between those two roles. It applies automatically to every account, so there is nothing to sign. What we actually hold about your contacts is deliberately tiny: a keyed hash, a random token, and some timestamps. This summary is written for clarity and is not a substitute for the terms below.

1. Scope, roles, and how this fits together

This Addendum forms part of the Terms of Service between you and [[LEGAL ENTITY NAME]], of [[REGISTERED ADDRESS]]. It applies whenever we process personal data about your contacts on your behalf. You do not need to sign or return anything: it takes effect with the Terms.

In this Addendum, Contact Data means personal data about your contacts that we process for you, described in Annex A. Data Protection Law means the UK GDPR, the EU GDPR, the California Consumer Privacy Act as amended, and any other privacy law that applies to that processing.

2. Our instructions from you

We will process Contact Data only on your documented instructions, including for international transfers, unless the law requires otherwise. Your instructions are: the Terms, this Addendum, and the settings you choose in the Service. Configuring a campaign is an instruction to process the contacts who enter it.

If we believe an instruction breaches Data Protection Law, we will tell you. If the law requires us to process Contact Data for some other reason, we will tell you before doing so unless the law forbids that.

We will not sell Contact Data, share it for cross-context behavioral advertising, use it to build advertising profiles, or use it for our own purposes. We will not combine it with data from other sources except as permitted by Data Protection Law.

3. Confidentiality

Access to Contact Data is limited to people who need it to run or support the Service. Everyone with access is bound by confidentiality obligations that survive the end of their engagement with us.

4. Security

We maintain appropriate technical and organizational measures to protect Contact Data, described in Annex B. Those measures reflect the state of the art, the cost of implementation, and the risk to the people involved.

The most significant measure is architectural rather than procedural: the Service is built so that the sensitive values are never in our possession. We do not store your contacts' email addresses, and we do not record their IP addresses.

5. Sub-processors

You give us general authorization to engage the sub-processors listed in Annex C. We impose data protection obligations on each of them that are no less protective than those in this Addendum, and we remain fully liable to you for their performance.

If we intend to add or replace a sub-processor, we will give you reasonable notice by email or in the Service before it starts processing Contact Data. If you have a reasonable objection on data protection grounds, tell us and we will work with you to find a solution. If we cannot, you may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees for the unused period.

6. Helping you meet your own obligations

Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with:

A practical note on erasure, because the design decides what is possible. You can erase a contact yourself from the Service. Doing so deletes the contact record and permanently strips the identifying values from the associated campaign entries. The entries themselves remain as anonymous rows, since they are also the campaign's statistics, and after erasure they no longer identify anyone. This is irreversible: the identity cannot be recomputed afterwards.

A second practical note, on access requests. Because we store only a keyed hash of each contact identifier, we cannot produce a list of your contacts, and neither can you. We can confirm and act on a value you already hold. That is a limit of the design, chosen to hold less data, and it means data subject requests generally have to start from you.

7. Personal data breach

If we become aware of a personal data breach affecting Contact Data, we will notify you without undue delay, and in any event in time to let you meet your own reporting deadlines. The notification will describe what we know: the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we are taking.

We will not make a public statement identifying you in connection with a breach without consulting you first, unless the law requires it. Notifying you is not an admission of fault.

8. Deletion and return

You can export your campaign data at any time while your account is open.

Deleting a campaign removes the Contact Data belonging to it. Cached deadline state expires automatically shortly after the deadline it describes has passed. When your account is closed, we will delete or anonymize remaining Contact Data within a reasonable period, unless the law requires us to keep something, in which case we will keep only that and only for as long as required.

Please export anything you want to keep before asking us to close your account.

9. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this Addendum, and will respond to reasonable security questionnaires about the processing.

Where that is not enough to satisfy an audit obligation you have under Data Protection Law, you may audit us, or appoint an independent auditor to do so, on the following terms: no more than once in any twelve month period unless a regulator requires otherwise or we have had a breach affecting your Contact Data; on at least 30 days' written notice; during business hours; without unreasonable disruption to the Service or access to other customers' data; subject to confidentiality; and at your cost.

10. International transfers

Contact Data is stored in [[HOSTING REGION]]. Our sub-processors operate globally, so data may be processed in other countries.

Where we transfer Contact Data out of the UK or the European Economic Area to a country without an adequacy decision, that transfer is made under appropriate safeguards. The European Commission's Standard Contractual Clauses, and for the UK the Information Commissioner's International Data Transfer Addendum, are incorporated into this Addendum by reference and apply automatically to any such transfer, with us as data importer and you as data exporter. Annex A supplies the description of processing those clauses require, Annex B the security measures, and Annex C the sub-processors.

11. California

For personal information covered by the California Consumer Privacy Act, we are a service provider and you are the business. We will not sell or share that information, will not retain, use, or disclose it for any purpose other than performing the Service for you, and will not combine it with personal information from another source except as the Act permits.

We certify that we understand these restrictions and will comply with them. You may take reasonable steps to confirm we are using the information consistently with your obligations, and to stop and remediate unauthorized use.

12. Liability, precedence, and changes

Each party's liability under this Addendum is subject to the limitations and exclusions in the Terms. This Addendum is governed by the same law and subject to the same courts as the Terms.

If this Addendum conflicts with the Terms on the processing of Contact Data, this Addendum wins. If it conflicts with the Standard Contractual Clauses, those clauses win.

We may update this Addendum where the law or the Service changes, provided the update does not reduce the protection it gives Contact Data. The date at the top shows the current version, and we will tell customers by email about any material change.

Annex A: description of the processing

ItemDetail
Subject matterProviding the DeadlineFox service: assigning each contact a personal deadline and displaying it consistently across the emails they receive and the pages they visit.
DurationFor as long as the campaign exists, and otherwise for as long as your account is open, plus the deletion periods in section 8.
Nature and purposeStoring, retrieving, and caching deadline records; recognizing a returning contact; recording conversions; producing campaign statistics for you.
Categories of data subjectsYour contacts: the people who receive your campaign emails or visit your campaign pages.
Categories of personal dataA keyed hash (HMAC) of the contact's email address or email platform contact ID. A random visitor token. Timestamps: campaign entry, original and current deadline, any extension, and conversion time.
Data we do not processEmail addresses in their original form, names, IP addresses, location data, device fingerprints, payment data, and any browsing activity outside the campaign pages you register.
Special category dataNone. The Service is not designed for it and you should not submit it.
FrequencyContinuous, for the duration of a campaign.

Campaigns that use one fixed deadline for everyone, and campaigns that recognize returning visitors by cookie alone, create no contact record at all. No Contact Data is processed for those.

Annex B: technical and organizational measures

MeasureWhat we do
Data minimizationContact identifiers are stored only as keyed hashes. Original email addresses are never written to our database. IP addresses are not recorded.
PseudonymizationIdentifiers are hashed with HMAC using a secret held only by us and never exposed to the browser or to customers.
Encryption in transitAll connections to the Service use TLS.
Encryption at restProvided by our database and cache providers. Email platform API keys are separately encrypted by us before storage and are never returned to the browser.
Cookie protectionThe visitor cookie is signed and encrypted, marked HttpOnly and Secure, and cannot be read by scripts running on the page.
Access controlAccess to production data is limited to those who need it, over authenticated accounts. Administrative actions on customer accounts are recorded in an audit log.
Tenant separationEvery query is scoped to the owning account, so one customer's data is not reachable from another's session.
Link and token integrityCampaign links carry signed, campaign-scoped tokens with an expiry, so a link cannot be replayed indefinitely or reused across campaigns.
InfrastructureHosting, database, and cache run on established providers that maintain their own security programs and certifications. We do not operate our own servers.
ResilienceManaged backups and point-in-time recovery are provided by our database provider.

Annex C: sub-processors

These are the parties that process Contact Data on our behalf.

Sub-processorPurpose
SupabasePrimary database. Stores campaign and contact records.
VercelApplication hosting and edge delivery. Contact Data transits it when a timer is served.
UpstashCaching of deadline state and background job queueing.

This list is deliberately shorter than the vendor list in our Privacy Policy, and the difference is meaningful rather than an omission. Our payment processor and our transactional email provider handle your account data, where we are the controller rather than your processor, so they are not sub-processors of Contact Data. Our screenshot provider photographs your public campaign pages and receives no Contact Data at all.

Contact

Questions about this Addendum, and any data protection request, go to [[CONTACT EMAIL]].