/ DPA
Try free Back home
Legal

Data Processing Agreement

Last updated July 20, 2026 · TDS GLOBAL, Georgia

1. Parties and scope

This Data Processing Agreement ("DPA") is entered into between TDS GLOBAL, an individual entrepreneur registered in Georgia, Reg. No. 345849610, Georgia, Batumi, Airport Highway Street, N 186, Apartment N33 ("we", "us", "Provider"), and the person or entity that holds a TDS.SO account ("Customer", "you").

This DPA forms part of the Terms of Service and applies automatically from the moment you create an account. No signature is required. If you need a countersigned copy for your own compliance file, email privacy@tds.so and we will sign and return one.

Capitalised terms not defined here have the meaning given in the Terms of Service. "GDPR" means Regulation (EU) 2016/679; "UK GDPR" means the GDPR as retained in UK law; "Georgian DP Law" means the Law of Georgia on Personal Data Protection, in force 1 March 2024. "Controller", "processor", "sub-processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR.

Where the GDPR or UK GDPR does not apply to a given processing activity, this DPA still applies as a matter of contract, and the Georgian DP Law governs.

2. Who is controller and who is processor

The Service involves two distinct categories of personal data, and our role differs between them. This section is the operative allocation and prevails over any contrary implication elsewhere in our documentation.

2.1 Where we are the controller

We are the controller, and determine the purposes and means of processing, for:

  • Customer account data — email, name or handle, Telegram ID, account settings and configuration.
  • Billing data — payment method, amount, status, invoices, tax records.
  • Support interactions — tickets, chat transcripts, correspondence with us.
  • Security and audit logs — dashboard sign-in IP and User-Agent, action logs, abuse and fraud investigation records.
  • Product metrics in aggregated or account-level form.

Our processing of that data is described in the Privacy Policy, which sets out the legal bases we rely on. This DPA does not govern that processing except where it says so expressly.

2.2 Where we are the processor

We are a processor acting on your documented instructions for click-level data about your end users — the technical data we process when a visitor follows a link you created through the Service, as described in Section 3 below. You are the controller of that data.

You decide which links exist, which routing rules apply, which tracking parameters are passed, which landing pages are served, and which third parties receive postbacks. We supply the routing, filtering, storage and analytics infrastructure that executes those decisions.

2.3 No joint controllership

Nothing in this DPA makes us joint controllers. We do not determine the purposes for which click-level data is collected, and we do not use it for our own purposes beyond what Section 4.2 permits. We do not combine click-level data across customers into a cross-customer visitor profile, and we do not sell it.

3. Subject matter, duration, nature and purpose

This section is the description required by Article 28(3) GDPR.

3.1 Subject matter and duration

Subject matter: processing of click-level personal data about your end users in order to provide the Service to you.

Duration: from account creation until the account is deleted, plus the wind-down period in Section 13. There is currently no automatic time-to-live on click-level data: it is retained for the life of the account so that your analytics remain available, and is deleted when the account is deleted. If you need shorter retention, tell us and we will delete on request under Section 13.3.

3.2 Nature and purpose of processing

  • Conditional routing of HTTP traffic by GEO, device, source and your custom rules.
  • Bot filtering — JS-fingerprint and behavioural antibot analysis, and proxy / VPN / Tor signal assessment.
  • Serving landing pages built with the landing builder or the AI generator.
  • Click-level analytics and reporting in your dashboard.
  • Server-to-server integration — S2S API calls and postbacks to destinations you configure.
  • Storage of the resulting click records in our ClickHouse analytics database.
  • Security and abuse prevention in relation to the traffic you route, as permitted by Section 4.2.

3.3 Types of personal data

  • IP address.
  • Approximate geolocation derived from the IP address — country, region, city.
  • Internet service provider (ISP).
  • User-Agent string, browser, operating system, device type.
  • Browser language, timezone, screen size.
  • Bot, proxy, VPN and Tor signals.
  • Referrer.
  • Sub-ID and other tracking parameters passed in the link — whatever you choose to put in them.

You control the sub-ID fields. We do not require, expect or inspect their contents. If you place directly identifying data, or any data falling within Article 9 or Article 10 GDPR, into a sub-ID or a URL parameter, you do so on your own instruction and your own legal basis. We do not knowingly process special-category data, and the Service is not designed for it.

3.4 Categories of data subjects

  • Visitors and end users who follow links you created through the Service.
  • Visitors to landing pages you serve through the Service.

4. Processing on documented instructions

4.1 Your instructions

We process click-level personal data only on your documented instructions, including as regards transfers to a third country. Your documented instructions consist of: this DPA, the Terms of Service, and the configuration you set in the dashboard and via the API — your links, routing rules, filters, landing pages, tracking parameters and postback destinations. Instructions outside that set must be sent in writing to privacy@tds.so; we may charge for instructions that require engineering work.

4.2 Where we process without your instruction

We process click-level data outside your instructions only where required by law applicable to us, or where strictly necessary to:

  • protect the security, availability and integrity of the Service, including DDoS mitigation and defence against attacks on our infrastructure;
  • detect, investigate and act on abuse of the Service under our Acceptable Use Policy and Trust & Safety commitments; and
  • respond to valid legal process (see Section 4.4).

When we do so for our own security and anti-abuse purposes, we act as a controller for that limited purpose. We do not use your click-level data to train AI models, to build advertising profiles, or to benefit other customers.

4.3 Unlawful instructions

You must not give us an instruction that would put us in breach of the GDPR, the UK GDPR, the Georgian DP Law or any other law applicable to us. If, in our reasonable opinion, an instruction appears to infringe applicable data protection law, we will inform you without undue delay and may suspend performance of that instruction until it is withdrawn, amended or confirmed in writing with an explanation. We are not obliged to carry out a legal review of your instructions and giving no notice is not an endorsement.

4.4 Legally required processing

If a law applicable to us requires us to process click-level data beyond your instructions, we will inform you of that requirement before processing, unless that law prohibits us from doing so on important grounds of public interest. Law-enforcement and regulatory requests are handled as set out in Trust & Safety Section 7: we disclose only what the request lawfully covers, and where we are legally permitted to notify you, we do.

5. Your obligations as controller

You warrant and undertake that:

  • You have a valid legal basis under Article 6 GDPR (and, where relevant, a condition under Articles 9 or 10) for the collection and processing of the click-level data you instruct us to process, including for any transfer to us in Georgia.
  • You have given your end users the information required by Articles 13 and 14 GDPR — including that traffic is routed and measured through a third-party traffic distribution system, the categories of data processed, the retention position, and how to exercise their rights — and, where consent is the basis (including under the ePrivacy Directive for storage of or access to information on a device), that you have obtained valid, freely given, specific, informed and unambiguous consent, and can evidence it.
  • Your instructions, including your routing rules and tracking parameters, comply with applicable law, and you will not instruct processing that infringes the rights of your end users.
  • You will not place special-category, criminal-offence or directly identifying personal data into sub-IDs or URL parameters unless you have a lawful basis and have told us in writing beforehand.
  • You remain responsible for the accuracy, quality and legality of the personal data you route through the Service and for the lawfulness of the destinations to which you route it.
  • You will respond to your own end users' requests, complaints and regulator enquiries as the controller. We will assist under Section 10; we will not respond to your end users on your behalf.

If you fail to meet these obligations, that is your breach, not ours. Nothing in this DPA transfers controller responsibility for your traffic to us.

6. Confidentiality

We keep click-level personal data confidential and do not disclose it except as this DPA permits.

Access to production data is restricted to persons who need it to operate, support or secure the Service, on a need-to-know basis, with audit logging. Those persons are bound by a duty of confidentiality — by contract where they are contractors or service providers, and by statutory duty where applicable — which survives the end of their engagement. We are a one-person business: in practice, access is limited to the operator and to the sub-processors listed in Section 8. If that changes, any additional personnel will be brought under equivalent written confidentiality obligations before being granted access.

7. Security measures (Article 32)

Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk to data subjects, we implement the following technical and organisational measures:

  • Encryption in transit — all connections over HTTPS with TLS 1.3.
  • Credential protection — passwords stored as a bcrypt hash; API and unsubscribe tokens stored hashed with SHA-256.
  • Authentication — optional two-factor authentication (TOTP), available and recommended for all accounts.
  • Backups — daily, encrypted at rest.
  • Access control — access to production data limited to authorised personnel on a need-to-know basis, with audit logging.
  • Segregation — click-level data is held per account and is not combined into a cross-customer visitor profile.
  • Perimeter protection — DDoS mitigation and a web application firewall at the edge (Cloudflare).
  • Resilience and restoration — the ability to restore availability and access to personal data from encrypted backups after an incident.

These measures are those we actually operate. We hold no security certifications — no ISO 27001, no SOC 2 — and we do not claim any. We have not appointed a data protection officer, because we are not required to under Article 37 GDPR.

We may update these measures over time. We will not make a change that materially reduces the overall level of security.

8. Sub-processors

8.1 General authorisation

You give us general written authorisation to engage sub-processors for the processing described in this DPA, subject to this Section 8.

8.2 Terms we impose

We engage each sub-processor under a written contract that imposes data protection obligations no less protective than those in this DPA, in particular the obligation to provide sufficient guarantees of appropriate technical and organisational measures under Article 28(4) GDPR. We remain fully liable to you for the performance of each sub-processor's obligations.

8.3 Current sub-processors

As at the date of this DPA, we engage:

  • Cloudflare — DDoS protection, WAF, CDN.
  • Our server and object-storage providers — hosting and storage of the platform and its data.
  • NowPayments — cryptocurrency payment processing (billing data only; not click-level data).
  • Google — Analytics and Tag Manager (loaded only after consent), reCAPTCHA, Fonts.
  • Chatwoot — live chat and support ticketing (support data only; not click-level data).
  • Our transactional email / SMTP provider — delivery of service and notification email.
  • AI providers — text and image generation, when you use the AI features.
  • Domain-safety, bot-protection and IP-intelligence / geolocation providers — block-list monitoring, traffic-quality assessment and IP-to-location resolution.

The current list is available on request from privacy@tds.so.

8.4 Changes and your right to object

We give you at least 30 days' advance notice by email before adding or replacing a sub-processor that processes click-level data. You may object on reasonable data protection grounds by replying within 30 days of that notice.

If you object, we will work with you in good faith to find a workaround — a different provider, a different configuration, or excluding your account from the change. If no reasonable workaround is available within 30 days, you may terminate the affected part of the Service by written notice, and we will refund any prepaid fees for the unused period. That is your sole remedy for an objection.

Where a change is urgently required to protect security or availability, or where an existing sub-processor must be replaced at short notice, we may make it immediately and notify you as soon as possible afterwards. Your right to object under this Section still applies.

9. International transfers

9.1 Where data goes

We are established in Georgia. Our sub-processors are located in various jurisdictions, including outside the European Economic Area and the United Kingdom. Processing click-level data therefore involves a transfer out of the EEA and the UK where the data originates there.

9.2 Standard Contractual Clauses

Where you are established in the EEA, or the transfer is otherwise subject to Chapter V GDPR, and the personal data is transferred to us in Georgia, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer. You are the data exporter; we are the data importer. Completed as follows:

  • Clause 7 (docking): applies.
  • Clause 9 (sub-processors): Option 2, general written authorisation, with the notice period set in Section 8.4.
  • Clause 11 (redress): the optional independent dispute-resolution paragraph does not apply.
  • Clause 17 (governing law): the law of Ireland.
  • Clause 18(b) (forum): the courts of Ireland. This applies to the SCCs only and does not displace Section 15 of this DPA for other disputes.
  • Annex I.A (parties): as set out in Section 1. Annex I.B (description of transfer): as set out in Section 3. Annex I.C (supervisory authority): the competent authority of the EEA Member State in which you, as exporter, are established.
  • Annex II (security measures): as set out in Section 7.
  • Annex III (sub-processors): as set out in Section 8.3.

Where the transfer is subject to the UK GDPR, the SCCs above apply as amended by the UK International Data Transfer Addendum (the ICO Addendum, version B1.0), which is likewise incorporated by reference, with Tables 1 to 4 completed from the corresponding provisions of this DPA and the importer permitted to end the Addendum under Section 19.

Where the transfer is subject to Swiss law, the SCCs apply with the adaptations required by the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

9.3 Onward transfers and adequacy

For onward transfers to our sub-processors we rely, in this order of preference, on: an adequacy decision of the European Commission (or the UK equivalent) where one covers the destination; otherwise the SCCs, Module Three (processor to processor) or Module Two as appropriate, concluded with the sub-processor; otherwise another valid Chapter V transfer mechanism. We supplement these with the technical and organisational measures in Section 7.

9.4 If a mechanism fails

If the transfer mechanism we rely on is invalidated, or a supervisory authority or court requires it to be suspended, we will notify you without undue delay and work with you in good faith on an alternative. If none can be put in place, either party may suspend the affected transfers or terminate the affected part of the Service.

10. Assisting with data subject rights

You are responsible for responding to requests from your end users under Articles 12 to 23 GDPR. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible.

In practice:

  • Your dashboard and the export function let you search, export and delete click-level data for your account without needing us.
  • Where a request cannot be handled through the dashboard, email privacy@tds.so. We will respond within 10 business days and, where we can, provide what you need in time for you to meet your own one-month deadline under Article 12(3).
  • If a data subject contacts us directly about data we process on your behalf, we will not respond substantively. We will tell them to contact you, and forward the request to you without undue delay where we can identify the account.

Assistance is free for reasonable and proportionate requests. For requests that are repetitive, manifestly unfounded, or require substantial engineering work, we may charge our reasonable costs, notified to you in advance.

11. Assisting with Articles 32 to 36

Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR:

  • Article 32 (security) — by maintaining the measures in Section 7 and describing them to you on request.
  • Articles 33 and 34 (breach notification) — as set out in Section 12.
  • Article 35 (data protection impact assessment) — by providing the information we hold about how the Service processes click-level data, so you can carry out a DPIA. We do not carry out the DPIA for you; that is the controller's obligation.
  • Article 36 (prior consultation) — by providing information reasonably needed for a consultation with your supervisory authority.

This DPA, together with the Privacy Policy, is intended to be the primary source for that information. If you need more, ask.

12. Personal data breach

We notify you of a personal data breach affecting click-level data processed on your behalf without undue delay and, where feasible, within 72 hours of becoming aware of it.

The notification goes to the email address on your account and includes, to the extent known at the time:

  • the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address it and to mitigate its effects; and
  • a contact point for further information.

Where we cannot provide all of that at once, we provide it in phases without further undue delay. We will not delay an initial notification in order to complete our investigation.

Notifying your supervisory authority under Article 33, and your end users under Article 34, is your responsibility as controller. We will not do it for you, and our notification to you is not an admission of fault. We will provide reasonable assistance and the information we hold.

Report a suspected breach or vulnerability to security@tds.so. Machine-readable contacts are published at /.well-known/security.txt.

13. Deletion and return on termination

13.1 On account deletion

When your account is deleted, click-level data processed on your behalf is deleted with it. Deletion follows the retention position in Privacy Policy Section 8: a 30-day soft-delete window during which the account is recoverable, then full deletion, including from backups as they roll over on their normal cycle.

13.2 Export before deletion

Export your data before you delete the account. The dashboard provides export in JSON and CSV. If you need an export after deletion has been requested, ask within the 30-day soft-delete window; after full deletion we cannot reconstruct it.

13.3 Deletion on request

You may instruct deletion of specific click-level data, or of all click-level data older than a period you specify, at any time by writing to privacy@tds.so. We will action reasonable requests within 30 days. There is currently no automatic time-to-live on click-level data — if you want a shorter retention period than the life of the account, you must ask for it.

13.4 What we keep

We retain data after termination only where a law applicable to us requires it, or where it is needed to establish, exercise or defend legal claims, or to investigate abuse under our AUP. In practice that means billing records for 7 years and security logs for 90 days, as set out in the Privacy Policy. Retained data stays subject to the confidentiality and security obligations in this DPA.

14. Information and audit rights

We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, on the following practical terms — which reflect that we are a one-person business.

14.1 Written information requests

The primary route is a written information request to privacy@tds.so. We will answer reasonable questions about our processing, security measures, sub-processors and this DPA, and complete a reasonable security questionnaire, within 30 days. This is free once per twelve-month period.

14.2 On-site and third-party audits

An on-site or third-party audit is available only where a supervisory authority requires it, or where it is required by applicable law, or following a confirmed personal data breach affecting your data. In that case:

  • you give at least 30 days' written notice;
  • the audit takes place during normal business hours, no more than once per twelve-month period, and does not unreasonably disrupt the Service;
  • the auditor is independent, is not a competitor of ours, and signs a confidentiality undertaking before starting;
  • the audit is limited to systems and records relating to the processing of your data, and does not extend to other customers' data, our source code, or shared multi-tenant infrastructure where access would compromise the confidentiality or security of others; and
  • you bear the cost, including our reasonable time at our then-current rates, unless the audit reveals a material breach of this DPA by us, in which case we bear it.

14.3 Findings

Audit findings are confidential. Where an audit identifies a shortcoming on our side, we will remediate it within a reasonable period agreed with you, prioritised by risk to data subjects.

15. Term, precedence and general

Term. This DPA takes effect when you create an account and continues for as long as we process personal data on your behalf, plus the wind-down period in Section 13. Sections 6, 9, 13, 14 and 15 survive termination.

Precedence. In the event of conflict, the order of precedence is: (1) the Standard Contractual Clauses incorporated under Section 9; (2) this DPA; (3) the Terms of Service; (4) the Privacy Policy. Where this DPA and the Privacy Policy describe the same processing differently, this DPA governs the controller / processor allocation and the Privacy Policy governs the description of our own controller processing.

Liability. The limitations and exclusions of liability in the Terms of Service apply to this DPA, and to both parties together, except where applicable data protection law does not permit them to be limited. Nothing in this DPA limits a data subject's rights under the SCCs.

Governing law. This DPA is governed by the laws of Georgia, and disputes are resolved as set out in Terms Section 15 — arbitration administered by the Georgian International Arbitration Centre (GIAC), seat Tbilisi, language English. This does not affect the governing law and forum chosen for the SCCs in Section 9.2, or any mandatory right of a data subject.

Changes. We may update this DPA to reflect changes in the Service, our sub-processors or the law. For material changes we give 14 days' notice by email and dashboard banner, except that sub-processor changes follow the 30-day notice in Section 8.4.

Languages. This DPA is published in English and Russian. In the event of any discrepancy or conflict between the two versions, the English version prevails.

16. Contact

TDS GLOBAL
Individual entrepreneur
Georgia, Batumi, Airport Highway Street, N 186, Apartment N33
Reg. No.: 345849610
Data protection and DPA requests: privacy@tds.so
Security and breach reports: security@tds.so
Legal process: legal@tds.so

We have not appointed a data protection officer. Address all data protection correspondence to the addresses above.