Data processing addendum

Last updated

This addendum applies where you are a publisher or advertiser using Trovewall and data protection law makes you a controller of personal data that we process for you. It forms part of the terms of service and takes precedence over them on anything it covers.

Read the privacy policy first. The privacy policy describes what we actually collect and why. This document is the contractual layer over the top of it and does not describe anything different.

1. Who is what

Roles depend on the data, not on the account type, so they are set out per category rather than declared once:

DataYou areWe are
Your end users' interactions with an offerwall you embed Controller Processor, acting on your instructions
Your own account: name, email, company, bank details Data subject Controller
Fraud signals derived across the whole network Controller, for our own legitimate interest in preventing fraud

The third row matters and is easy to skip. Fraud prevention necessarily looks across publishers — a device converting the same offer through four different apps is only visible from the middle — so we cannot do it purely on one customer's instructions, and we act as a controller for that purpose.

2. What we process on your behalf

For a publisher's end users, only what serving and paying for an offer requires:

  • The opaque user_id you supply. We cannot resolve it to a person. It is your identifier, chosen by you, and we hold no mapping.
  • IP address, reduced to a country code for targeting and retained for fraud investigation.
  • User agent, and the device, operating system and browser derived from it.
  • Clicks, conversions and their timestamps.
  • Any sub-parameters you choose to pass. Do not put personal data in them. They are yours to fill and we cannot filter them.

We do not receive names, email addresses, phone numbers, precise location or payment details of your end users, and we do not want them. Where an offer requires such details, the user gives them to the advertiser directly, on the advertiser's own site.

3. Purpose and instructions

We process that data only to provide the platform: selecting eligible offers, recording clicks, verifying and paying conversions, preventing fraud, producing your reports, and meeting our own legal obligations. Your instructions are the documented use of the platform and its settings; anything beyond that needs to be agreed in writing.

We will not sell it, will not use it to build advertising profiles, and will not use it to train models.

4. Sub-processors

We keep the list short deliberately, because every entry is a place data can go wrong:

Sub-processorPurposeData reaching them
Our hosting provider Running the platform Everything, at rest and in transit
Mailgun Transactional email Account holders' email addresses and message content. No end-user data.

We will give reasonable notice before adding a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may terminate without penalty for the unused portion of any balance.

5. Transfers

Trovewall LLC. operates one platform rather than regional installations, so data is processed centrally wherever the user is. Where a transfer requires a lawful mechanism, we will put an appropriate one in place and will tell you what it is on request. See also geographic restrictions.

6. Security

  • HTTPS everywhere, enforced by redirect and HSTS.
  • Passwords stored only as modern one-way hashes. We cannot read them and cannot tell you what yours is.
  • Access to production data limited to staff who need it, with administrative actions written to an audit log that records who did what and when.
  • Every money movement recorded in an append-only ledger that can be replayed and checked against the balance it claims to produce.
  • API access authenticated per account and signed, with a timestamp window that limits replay.

Staff with access to personal data are bound by confidentiality obligations that survive the end of their engagement.

7. Breach notification

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware, at the email address on your account. The notification will describe what we know, what we do not yet know, what we are doing, and what we suggest you do. We will not delay a notification to make it more complete.

8. Helping you meet your obligations

We will assist you, at our own cost for reasonable volumes, with:

  • Data subject requests. Give us the user_id — it is the only handle we have — and we will export or delete everything associated with it. We cannot act on a name or an email address for an end user, because we hold neither.
  • Impact assessments and consultations, by answering questions about how the platform works.
  • Demonstrating compliance, through this document, the privacy policy and reasonable written answers. Where an on-site audit is legally required, we will agree a scope and timing that does not compromise other customers' data.

9. Retention and deletion

Retention periods are in the privacy policy and are the same ones the platform actually enforces — clicks that never converted are pruned automatically, not kept indefinitely because nobody wrote the job.

On termination we delete or return end-user data we process for you within 90 days, except where retention is required by law or is necessary to close out money already moved. Financial records are the exception and are kept. A ledger with entries removed no longer reconciles, and a network that cannot prove what it paid cannot operate.

10. Liability and precedence

Liability under this addendum is subject to the limitations in the terms of service. Where this document and those terms conflict on a data protection matter, this document governs.

11. Accepting it

This addendum applies automatically to every account, with no signature required — a DPA that has to be requested is one most customers never get. If your organisation needs a countersigned copy or a specific transfer mechanism, write to [email protected] with what you need.


Who you are dealing with

Trovewall is operated by Trovewall LLC., registered at Office 251 House of Francis, Ile du Port, Mahe, Seychelles.

Questions about this document [email protected]
Publisher accounts and traffic [email protected]
Advertiser accounts and campaigns [email protected]
Everything else [email protected]