1. Scope
This addendum forms part of the Terms of service between Webook (the processor) and the customer (the controller). It applies whenever we process personal data on the customer's behalf through Pixel Relay, and meets the requirements of Article 28 of the UK GDPR and, where it applies, the EU GDPR.
2. Processing details
| Subject matter | Receiving, sanitising, logging and forwarding website events to the Meta Conversions API. |
|---|---|
| Duration | For as long as the customer uses the service, plus the deletion period in section 7. |
| Purpose | Delivering conversion events to the customer's Meta Pixel and showing the customer delivery status and analytics. |
| Data subjects | Visitors to the customer's websites, and people who click the customer's short links. |
| Personal data | IP address and browser user agent; page URL and referrer; Meta browser identifiers (_fbp, _fbc, fbclid); and any contact details or customer ID the website chooses to send (hashed with SHA-256 before forwarding and never stored). |
| Special category data | Not intended. The service removes health-related terms from URLs and text fields, and the customer must not deliberately send special category data. |
| Retention | Sanitised event logs and short-link clicks are deleted automatically after 90 days. Raw IP addresses, raw URLs and full referrers are never stored. |
3. Our obligations
We will:
- Process personal data only on the customer's documented instructions, which are the terms, the customer's settings in the dashboard and any other written instructions. We will tell the customer if we believe an instruction breaks data protection law.
- Make sure everyone who can access the data is bound by confidentiality.
- Apply the technical and organisational measures in the annex below, and keep them appropriate to the risk.
- Help the customer, taking into account the nature of the processing, to respond to data subject requests and to meet its obligations on security, breach notification, impact assessments and consultation with regulators.
- Not use the data for our own purposes, and not sell it.
Sending events to Meta is the core of the service and is done on the customer's instruction, to the Pixel the customer configures. Meta receives that data under its own terms with the customer and is not our subprocessor.
4. Subprocessors
The customer gives general authorisation for us to use subprocessors. We currently use:
| Subprocessor | Service | Location |
|---|---|---|
| Hostinger International Ltd | Server infrastructure | United Kingdom |
We will give at least 30 days' notice by email before adding or replacing a subprocessor. The customer may object on reasonable data protection grounds; if we cannot address the objection, the customer may end the affected service. We impose data protection terms on each subprocessor that are no less protective than this addendum and remain responsible for their work.
5. International transfers
We store and process customer personal data in the United Kingdom. We will not transfer it outside the UK unless an adequacy decision applies or we have put in place appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum.
6. Personal data breaches
We will notify the customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the customer's data. The notice will describe what happened, the data and people likely to be affected, the likely consequences and what we are doing about it, with further details as they become available.
7. Deletion at the end
When the service ends we will stop processing, and within 30 days delete the customer's personal data, unless the law requires us to keep it. On request before the end date, we will export the customer's event logs and analytics.
8. Audits
We will make available the information reasonably needed to show compliance with this addendum and answer reasonable written questions. Where that is not enough, the customer may carry out an audit, at its own cost, once a year with at least 30 days' notice, during business hours and under confidentiality.
Annex: security measures
- Minimisation: query strings are dropped, health terms and customer-blocked terms are replaced, contact fields are SHA-256 hashed, and IP forwarding to Meta is off unless the customer enables it.
- Storage: only sanitised values are logged; IP addresses are stored as keyed hashes; logs are deleted automatically after 90 days.
- Encryption: TLS on every connection with HTTPS enforced (HSTS); Meta access tokens, sessions and two-factor secrets are encrypted at rest; passwords are hashed.
- Access control: accounts are created by our team only, with role and per-site permissions and two-factor authentication.
- Endpoint protection: event endpoints accept requests only from each site's allowed domains and are rate limited per visitor.
- Operations: application logging is kept at warning level, servers receive security updates, and changes are reviewed and tested before release.
Questions about this addendum: info@weboook.co.uk.