Data Processing Agreement
Last updated: August 13, 2026
How this is accepted (electronic / clickwrap)
This DPA is incorporated by reference into the CriterionIQ Terms of Service. The Client accepts it by one of:
- Checking "I have read and agree to the Data Processing Agreement" during onboarding, or
- Continuing to use the CriterionIQ Services after being presented with a link to this DPA, or
- Signing an Order Form that references this DPA.
Per GDPR Art. 28(9), a processor agreement in electronic form satisfies the "in writing" requirement. Acceptance is logged with a timestamp, the accepting user's account ID, and the DPA version. The version in force for a given Client is the one published at criterioniq.com/legal/dpa on the date that Client accepted it, subject to Section 15.4 (Amendments).
What the click does and does not do. Accepting this DPA executes the processor contract between CiQ and the Client. It does not by itself satisfy the Client's own front-end obligations: lawful basis / end-user consent, a public privacy notice disclosing ad-platform sharing, and honoring opt-outs (GPC / "Do Not Sell or Share"). CiQ's Loader consent controls (Google Consent Mode v2, GPC enforcement) are tools that help the Client comply; they do not transfer the Client's controller responsibility to CiQ. See Section 2 and the CCPA & State Privacy Law Addendum below.
Parties
- Processor: Last Best Digital LLC, a Montana limited liability company, d/b/a CriterionIQ ("CiQ"), 1087 Woodbridge Drive, Helena, MT 59601.
- Controller: the entity identified as the accepting "Client" in CriterionIQ's signature record for this DPA, the company legal name, signer name, and signer role captured at acceptance (see "How this is accepted" above), together with the address that entity has on file with CiQ ("Client").
Each a "party," together the "parties." This DPA is effective on the date of acceptance (the "Effective Date") and forms part of the Agreement (the Terms of Service and any Order Form between the parties).
1. Definitions
Terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.
- "Data Protection Law": all laws applicable to the processing under this DPA, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the CCPA as amended by the CPRA ("CCPA"), and other U.S. state comprehensive privacy laws applicable to the Processing, including the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and successor or comparable state privacy laws as they take effect during the term (collectively with CCPA, "State Privacy Laws").
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach": as defined in the GDPR. "Business," "Service Provider," "Sell," "Share," "Consumer": as defined in the CCPA. Equivalent terms under other State Privacy Laws ("controller"/"processor," "consumer," "sale," etc.) are incorporated with the same meaning as used in the applicable statute.
- "Client Personal Data": Personal Data that CiQ Processes on the Client's behalf under the Agreement, as described in Annex I.
- "Services": the CriterionIQ measurement, tag-delivery, identity, and activation services, including the Tier 3 Pulse monitoring layer, the Loader (server-side tag delivery / conversion API relay), and the CiQ Identity Spine (durable
ciqid, cross-device and household resolution). - "Sub-processor": any third party engaged by CiQ that Processes Client Personal Data on CiQ's behalf.
- "Recipient Platform": an advertising or analytics platform to which Client Personal Data is transmitted on the Client's instruction (e.g., via CAPI or Custom Audience upload), and which Processes that data as an independent or joint controller under its own terms. Recipient Platforms are listed in Annex III. These are not CiQ Sub-processors; see Section 6.4.
2. Roles and scope
2.1 Client is the Controller of Client Personal Data and is responsible for the lawfulness of the Processing, including obtaining any required consent, providing end-user notice, configuring the Loader's consent and opt-out controls, having the necessary rights to instruct CiQ to transmit data to Recipient Platforms, and confirming that the website(s) or app(s) using the Services are not directed to children under 13 within the meaning of COPPA (or the equivalent age threshold under applicable law) unless the parties have separately agreed on additional terms for that use case.
2.2 CiQ is the Processor and Processes Client Personal Data only for the purposes in Annex I and on the Client's documented instructions (Section 3).
2.3 CiQ as independent Controller (limited carve-out). CiQ acts as an independent Controller, not a Processor, when it Processes data for: (a) billing and account administration; (b) securing and monitoring the Services; (c) meeting legal obligations; and (d) producing aggregated, de-identified benchmarks and internal model improvements (e.g., cross-client convergence and cohort analytics). For (d), CiQ will only use data that has been aggregated or de-identified such that it does not identify the Client or any Data Subject, CiQ will not attempt to re-identify it, and CiQ will not use it to train or improve any third-party or foundation model outside CiQ's control.
2.4 CiQ will notify the Client if, in its opinion, an instruction infringes Data Protection Law (CiQ is not obligated to provide legal advice).
3. Processing instructions
3.1 The Client's complete and documented instructions are: (a) this DPA and the Agreement; (b) the configuration the Client sets in the CiQ dashboard (tracked events, PII field maps, consent mode, GPC enforcement, connected Recipient Platforms, audience rules); and (c) written instructions the parties agree to.
3.2 CiQ will not Process Client Personal Data for any purpose other than performing the Services and the permitted purposes in Annex I, and specifically will not Sell or Share Client Personal Data (see the CCPA & State Privacy Law Addendum).
4. Confidentiality
CiQ ensures that personnel authorized to Process Client Personal Data are bound by confidentiality obligations and are granted access only on a need-to-know basis, enforced by role-based access controls and per-tenant isolation (Annex II).
5. Security
CiQ implements and maintains the technical and organizational measures in Annex II, appropriate to the risk, and will not materially degrade them during the term. Given that the Tier 3 + Spine configuration resolves individuals across devices, CiQ treats the identity graph (ciqid, person_id, household_id, hashed identifiers) as high-sensitivity data subject to the access and pseudonymization controls in Annex II.
6. Sub-processors
6.1 General authorization. The Client authorizes CiQ to engage the Sub-processors listed in Annex III and to appoint new ones subject to this section.
6.2 Flow-down. CiQ imposes data protection obligations on each Sub-processor that are no less protective than this DPA and remains liable for its Sub-processors' performance.
6.3 Changes and objection. CiQ maintains the current Sub-processor list in Annex III below. CiQ will give at least 30 days' notice before adding or replacing a Sub-processor. The Client may object on reasonable data-protection grounds within that window; the parties will work in good faith to resolve it, and if they cannot, the Client may terminate the affected Services.
6.4 Recipient Platforms are not Sub-processors. When the Client instructs CiQ to transmit Client Personal Data to a Recipient Platform (Annex III, Part B), e.g., hashed email to Meta for a Custom Audience, or a conversion event to Google/TikTok via CAPI, that platform Processes the data as its own independent (or joint) controller under its own terms. CiQ discloses these flows and delivers the data as instructed, but does not and cannot control the platform's downstream Processing. The Client is responsible for accepting each Recipient Platform's business/data terms (e.g., Meta Business Tools Terms + Custom Audiences Terms, Google Ads Data Processing Terms, TikTok Business Products (Data) Terms) and for having a lawful basis to share. See also Section 14.2 (Indemnification).
7. Data subject rights
7.1 Taking into account the nature of the Processing, CiQ will assist the Client with appropriate technical and organizational measures to respond to Data Subject requests (access, erasure, restriction, portability, objection, opt-out of Sale/Share), and will use commercially reasonable efforts to respond to the Client's requests for assistance under this Section within 10 business days.
7.2 Because the Spine keys on a durable pseudonymous identifier (ciqid), CiQ provides tooling to look up, export, and delete records associated with a given ciqid or hashed identifier. An erasure carried out under this Section covers, for the identifier supplied: event-level and delivery records; the durable visitor record and every anchor that could restore it; hashed-identifier mappings; cross-device and household cluster membership; behavioural and performance records; and lead, messaging, and offline-conversion records held against that identifier. Session-level rows are retained in de-identified form as described in Section 11.1. If a Data Subject contacts CiQ directly, CiQ will refer them to the Client unless legally required to respond.
8. Personal Data Breaches
CiQ will notify the Client without undue delay and no later than 72 hours after becoming aware of a Personal Data Breach affecting Client Personal Data, and will provide the information the Client reasonably needs to meet its own notification obligations, including nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and remediation taken. This obligation does not apply to unsuccessful attempts that do not compromise the security of Client Personal Data (e.g., pings, port scans, or failed login attempts).
9. DPIAs and prior consultation
CiQ will provide reasonable assistance to the Client with data protection impact assessments and prior consultations with supervisory authorities, where required and relevant to the Processing.
10. International transfers
10.1 CiQ is established in the United States. Where CiQ Processes Client Personal Data originating in the EEA or UK, the parties incorporate:
- the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (Controller-to-Processor), with the following elections: the optional docking clause (Clause 7) applies; Clause 9 governs Sub-processors using Option 2 (general written authorization), with the notice period set out in Section 6.3; the optional language in Clause 11(a) does not apply; Clause 17 is governed by the law of Ireland; and Clause 18(b) submits disputes to the courts of Ireland; and
- the UK International Data Transfer Addendum to the EU SCCs, with Tables 1–3 populated using Annex I and Annex II of this DPA and Table 4 marked as neither party being permitted to end the Addendum.
10.2 Competent supervisory authority. For the purposes of Annex I(C) of the SCCs, the competent supervisory authority is the Irish Data Protection Commission, consistent with the choice of Irish law and forum in Clauses 17 and 18(b). For transfers subject to the UK Addendum, the competent authority is the UK Information Commissioner's Office.
10.3 Switzerland. Where Client Personal Data originating in Switzerland is Processed, the EU SCCs apply with the following adaptations: the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to the GDPR are read as references to the Swiss FADP in respect of such data; the term "Personal Data" includes data relating to legal entities to the extent the FADP protects it; and Data Subjects in Switzerland may enforce their third-party beneficiary rights and bring claims in Switzerland.
10.4 The Annexes to this DPA populate Annexes I–III of the SCCs. If CiQ adopts a new or successor version of the SCCs, the UK Addendum, an approved certification such as the EU–US Data Privacy Framework, or another lawful transfer mechanism, that mechanism automatically applies in place of the one described above to the extent it continues to comply with Data Protection Law and covers the transfers described in Annex I.
11. Deletion and return
11.1 Operational retention. Retention differs by class of data, and CiQ states each separately rather than generalizing from the event stream:
- Event-level data (
pipeline_eventsand platform delivery records), retained 365 days from the event, then deleted. - Durable visitor records and identity anchors: deleted after 365 days without activity.
- Session and page-level behavioural data: retained beyond 365 days in de-identified form. At 365 days the durable identifier, IP address, and user-agent are permanently removed from these rows and the remaining behavioural columns are kept as anonymous analytics. At that point CiQ no longer has a reason to know whose visit a session was, which is a different claim from the visit not having happened.
- Identity-graph records (hashed-identifier mappings, cross-device and household clusters), removed when the durable identifier they key on is deleted under this Section or erased under Section 7.
- Lead, messaging, and offline-conversion records: these are the Client's own business records, retained while the Client's account is active and deleted or returned on termination under Section 11.2. The Client may delete them at any time.
- Raw request and diagnostic stores (inbound webhook payloads, verification captures, delivery logs), retained no longer than 90 days.
- Network-intelligence caches: see Annex II. Held as an operational lookup cache keyed on network address, not linked to a Data Subject and not attributed to a tenant.
Backup copies containing since-purged data are retained only within CiQ's standard backup rotation window (see Annex II) and are not otherwise accessed or Processed except to restore service. Derived, de-identified, or aggregated data may be retained under Section 2.3.
11.2 On termination, CiQ will, at the Client's choice, delete or return Client Personal Data within 90 days, except where retention is required by law, after which CiQ will delete or de-identify it. Backup copies are deleted or overwritten in the ordinary course of CiQ's backup rotation described in Annex II.
12. Audit
12.1 Self-serve compliance information. Upon request, no more than once every 12 months, CiQ will provide the Client with its current security documentation, a summary of the measures in Annex II, and written responses to reasonable questionnaires regarding its Processing of Client Personal Data. Where reasonably available, third-party certifications or audit summaries may be provided in place of, or alongside, this information.
12.2 On-site / deeper audit. Where the information in Section 12.1 is not sufficient to satisfy the Client's own compliance obligations under Data Protection Law, the Client (or a mutually agreed independent auditor bound by confidentiality) may, on at least 30 days' written notice and no more than once every 12 months, audit CiQ's compliance with this DPA. Such audits: (a) are at the Client's expense; (b) must not unreasonably interfere with CiQ's normal operations; (c) are subject to a mutually agreed scope, timing, and duration; and (d) do not extend to CiQ's internal financial or accounting records, trade secrets or proprietary algorithms (including identity-resolution logic), or any other CiQ client's data; CiQ's multi-tenant architecture (Annex II) means audit access must be scoped to the Client's own tenant.
13. Government and law enforcement requests
CiQ does not voluntarily provide government agencies, authorities, or law enforcement with access to Client Personal Data, including the identity graph (ciqid, person_id, household_id). If CiQ receives a legally binding demand (subpoena, court order, search warrant, or similar legal process) for Client Personal Data, CiQ will first attempt to redirect the requesting authority to seek the data directly from the Client. If CiQ is required to disclose Client Personal Data, CiQ will give the Client reasonable advance notice so the Client may seek a protective order or other appropriate remedy, unless CiQ is legally prohibited from doing so.
14. Liability and Indemnification
14.1 Liability cap. Except for a party's indemnification obligations under this Section, and to the extent permitted by Data Protection Law, each party's total aggregate liability arising out of or related to this DPA is subject to, and will not exceed, the cap stated in the Agreement (currently CriterionIQ Terms of Service Section 11: the fees paid by Client in the twelve (12) months preceding the claim, or $1,000 if Client has paid nothing). This DPA intentionally does not restate that number as an independent figure; it inherits whatever cap is in the Agreement, so the two can't drift out of sync. Nothing in this Section limits liability that cannot lawfully be limited.
14.2 Client indemnification. Client will defend, indemnify, and hold CiQ harmless from third-party claims, fines, and reasonable costs arising from: (a) Client's failure to obtain required consent or provide required notice to Data Subjects; (b) Client's instructions to CiQ, including instructions to transmit data to a Recipient Platform, that violate Data Protection Law; (c) Client's transmission of special-category or sensitive Personal Data through the Services in violation of Annex I; or (d) Client's breach of this DPA.
14.3 CiQ indemnification (narrow). CiQ will defend, indemnify, and hold Client harmless from third-party claims arising directly from CiQ's material breach of its security obligations under Annex II or CiQ's Processing of Client Personal Data outside the Client's documented instructions, in each case subject to the cap in Section 14.1.
15. General
15.1 Precedence. In case of conflict, the order of precedence is: the SCCs (where applicable) → this DPA → the Agreement.
15.2 Governing law. This DPA is governed by the laws of the State of Montana, consistent with the Agreement (CriterionIQ Terms of Service Section 14), without prejudice to the SCCs and mandatory Data Protection Law. Disputes arising under this DPA are resolved through the same binding AAA arbitration process the Agreement requires, except that nothing here limits a Data Subject's third-party beneficiary rights or forum choice under the SCCs (Section 10) or any right that cannot lawfully be arbitrated or subjected to a class-action waiver under applicable Data Protection Law.
15.3 Notices. Notices under this DPA go to [email protected] and to the Client's account/admin email on file.
15.4 Amendments. CiQ may update this DPA to reflect changes in Data Protection Law, its Sub-processors, or its Services. CiQ will notify the Client of material changes by email or in-app notice at least 15 days before they take effect, except that a change adding or replacing a Sub-processor carries the 30-day notice period and objection right in Section 6.3, which controls over this Section for that change. If a material change reduces the Client's rights or CiQ's obligations under this DPA, the Client may object in writing within that window; if the parties cannot resolve the objection, the Client may terminate the affected Services as its sole remedy. Continued use of the Services after a change's effective date constitutes acceptance of the updated DPA.
15.5 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the parties will work in good faith to replace the invalid provision with one that achieves its intended effect.
15.6 Assignment. Neither party may assign this DPA without the other's prior written consent, except that either party may assign it without consent to a successor in connection with a merger, acquisition, or sale of substantially all assets, provided the successor agrees in writing to be bound by this DPA and, where the assignment is by CiQ, CiQ gives the Client at least 30 days' notice before the identity graph or any Client Personal Data is transferred to the successor.
CCPA/CPRA & State Privacy Law Addendum (Service Provider)
This Addendum applies where the Client is a Business and CiQ is a Service Provider under the CCPA, and applies on equivalent terms where the Client is a "controller" and CiQ a "processor" under other State Privacy Laws (as defined in Section 1).
C.1 CiQ Processes Client Personal Data (which may include "personal information" of California consumers or the equivalent under other State Privacy Laws) only to perform the Services and the business purposes in Annex I, and for no other purpose.
C.2 CiQ will not: (a) Sell or Share the personal information; (b) retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes specified, including combining it with personal information from other sources except as permitted by applicable State Privacy Law to perform a business purpose; or (c) retain, use, or disclose it outside the terms of the Agreement.
C.3 CiQ certifies that it understands and will comply with these restrictions.
C.4 CiQ will assist the Client in responding to consumer requests (know, delete, correct, opt-out of Sale/Share, limit use of sensitive PI), and will honor opt-out signals (including Global Privacy Control) that the Client's configuration passes through the Loader.
C.5 Transmitting identifiers to Recipient Platforms for cross-context behavioral advertising may constitute a Share by the Client under the CCPA. CiQ provides the opt-out plumbing (GPC enforcement, Consent Mode), but the Client is responsible for its "Do Not Sell or Share My Personal Information" notice and for honoring opt-outs. CiQ, as Service Provider, does not Sell or Share.
C.6 If CiQ makes a determination that it can no longer meet its obligations as a Service Provider/Processor under this Addendum, CiQ will promptly notify the Client.
C.7 If the Client reasonably believes CiQ is using Client Personal Data in an unauthorized manner, the Client may direct CiQ to stop and remediate the unauthorized use, and CiQ will take reasonable steps to investigate and cure within a reasonable time, in addition to any other rights the Client has under this DPA.
Annex I: Description of Processing
Data exporter (Controller): the accepting Client identified in the applicable signature record, the business operating the website/app being measured.
Data importer (Processor): Last Best Digital LLC d/b/a CriterionIQ.
Categories of Data Subjects
- The Client's website/app visitors, leads, and customers (including form submitters and purchasers).
Categories of Personal Data
- Online identifiers:
ciqid(durable, hashed first-party identifier),device_anonanchor, first-party cookies (_ciqid, and the_shopify_ydurability bridge on Shopify). - Hashed direct identifiers: SHA-256–hashed email address and phone number, used for conversion matching and Custom Audiences. Identifiers captured through the Loader are hashed at the edge and the plaintext is not retained.
- Plaintext direct identifiers, where the Client enables a feature that requires them: name, email address, and telephone number contained in lead records the Client instructs CiQ to receive and relay (advertising lead forms, lead-relay destinations, CRM and commerce connectors), and in messaging identities. These are the Client's own business records and are stored in the form the source platform delivers them. Features that use plaintext identifiers are optional and are listed as such in the dashboard.
- Message content: where the Client connects a messaging surface, the text of messages sent by an end user to the Client's business account on Meta Messenger, Instagram, and WhatsApp Business, together with the associated sender profile identifier, display name, and profile image.
- Network identifiers: IP address and user-agent string (consent-gated; used as the household-resolution substrate and for CAPI event quality). IP is retained in raw form for the bounded window in Section 11.1 and then removed.
- Network operator and organization data: the autonomous-system number, network operator name, and reverse-DNS domain associated with a visitor's IP address, used to distinguish organizational from residential traffic and to exclude internal traffic. Where a visitor connects from a corporate network, this may identify the organization they are connecting from.
- Approximate location: country, region, city, and time zone derived from the IP address. CiQ does not derive or store precise (device-level) geolocation.
- Environmental and temporal context: local weather conditions, air-quality index, daylight state, day of week, and time-of-day bucket for the approximate location, together with derived calendar and market-condition indicators. These describe conditions at a place and time, not a person, and are joined to an event rather than to an individual.
- Device and browser characteristics: device type, operating system and browser and their versions, screen and viewport dimensions, pixel ratio, colour depth, hardware concurrency, device memory, language, time-zone offset, and network connection type. Used for compatibility, bot and fraud assessment, and household resolution.
- Cross-device / identity-graph data:
person_id,household_id, and platform/customer-ID linkages (including Shopify customer-ID stitching). - Advertising click identifiers:
fbclid,ttclid,gclid, and equivalents. - Third-party and DSP identifiers, where the Client enables exposure-based measurement: mobile advertising identifiers and interoperable advertising identifiers supplied by the Client or its media partners.
- Behavioural and engagement data: page views, tracked events, conversions, scroll depth, active time on page, interaction and repeat-interaction counts, text-selection and copy counts, navigation patterns, form interaction, and web performance measurements.
- Transactional data: conversion and purchase value, currency, order and cart references, and equivalent records received from connected commerce, point-of-sale, and CRM systems.
Special categories of data. The Services are not designed to process special-category or sensitive Personal Data, CiQ does not intentionally collect it, and no feature infers it. The Client must not transmit special-category or sensitive data, including health, biometric, precise geolocation, or government identification numbers, through the Loader or any connected source. See Section 14.2(c) for the consequence of a Client violation of this restriction.
The Client should note that certain optional features accept free-text content the Client's own end users author: message bodies on a connected messaging surface, and the fields of a lead form the Client itself designs. CiQ does not control what an end user types into such a field. Where the Client enables these features, the Client is responsible for the questions it asks, for the lawful basis to collect the answers, and for not designing a form or flow that solicits special-category data.
Nature and purpose of Processing
- Conversion and signal measurement; tracking-integrity/health monitoring (Tier 3 Pulse).
- Server-side tag delivery and Conversions-API relay to Recipient Platforms (Loader).
- Durable identity resolution and cross-device / household attribution (Spine).
- Audience assembly and activation on the Client's instruction.
- Consent enforcement (Consent Mode v2, GPC) and de-identified benchmarking under Section 2.3.
- Receipt and relay of lead, messaging, commerce, and CRM records the Client connects, to destinations the Client configures.
- Automated inspection of the Client's own properties to assess tracking configuration and detect faults.
- AI-generated narrative interpretation of precomputed/aggregated metrics for the Client's own dashboard (not raw event-level or identity data), and AI-assisted analysis of the Client's own advertising creative; see the AI Policy for scope and the Sub-processors engaged.
Frequency of Processing: continuous (real-time event ingestion), with scheduled synchronization from connected platforms.
Duration of Processing: for the term of the Agreement, plus the post-termination period in Section 11.2. Retention: by data class, per Section 11.1, subject to the backup rotation window in Annex II and to Section 2.3.
Annex II: Technical and Organizational Measures (TOMs)
- Pseudonymization / minimization: identifiers captured through the Loader (email, phone) are SHA-256 hashed at the edge before storage and transmission, and the plaintext is not retained; the durable identifier (
ciqid) is itself a hashed value. Event-level data is retained for a bounded 365-day window, and session-level data is de-identified at the same boundary. - Access control & tenant isolation: application access is authenticated (Clerk); database access is enforced by row-level security with per-tenant scoping (
client_profile_id) and a privileged server role; end-user (anon) access cannot read another tenant's data. - Credential protection: access tokens and API credentials for platforms the Client connects are held in two places, both access-controlled and encrypted at rest: a dedicated token vault (Okta / Auth0), and, for connections the vault does not cover, per-tenant credential fields in the application database subject to the same row-level security and privileged-role restrictions as all other tenant data. No credential is held in application source code or in plaintext configuration files. Client personnel authenticate to the dashboard through Clerk; CiQ does not hold Client personnel passwords.
- Encryption in transit: TLS/HTTPS for all ingestion and API traffic, terminated at the edge (Cloudflare). Data at rest is encrypted by the managed database and object-storage providers.
- Consent gating: IP/UA and identifier capture are gated by the Client's configured consent state (Consent Mode v2) and GPC enforcement.
- Network-intelligence cache: CiQ maintains an operational cache resolving network addresses to their network operator. It is keyed on network address, holds no Data Subject identifier, is not attributed to any tenant, and is used only to classify traffic. It is not readable through any tenant-facing interface.
- Network / edge protection: WAF, DDoS protection, and rate limiting at the Cloudflare edge; first-party gateway isolation for CAPI traffic.
- Segregation of the identity graph: cross-device linkage tables are access-restricted and used only for the resolution and attribution purposes in Annex I.
- Logging & monitoring: administrative access and processing operations are logged; the Services include self-monitoring (Pulse) for drift and anomalies.
- Backup & recovery: Client Personal Data is included in routine encrypted backups retained on a rolling 30-day window for disaster-recovery purposes; backups are not accessed for any purpose other than restoration and are subject to the same access controls as production data.
- Data subject tooling: lookup/export/delete by
ciqidor hashed identifier to support Section 7 requests.
Annex III: Sub-processors and Recipient Platforms
Part A: Sub-processors (Process on CiQ's behalf)
| Sub-processor | Service provided | Data location |
|---|---|---|
| Cloudflare, Inc. | Edge/CDN, WAF, Workers, object storage, first-party CAPI gateway | US / global edge |
| Supabase, Inc. | Managed Postgres storage & compute | US |
| Render Services, Inc. | Application hosting and compute | US |
| Okta, Inc. (Auth0) | Token vault for Client platform connections | US |
| Clerk, Inc. | Dashboard authentication (Client personnel) | US |
| Resend, Inc. | Transactional / alert email | US |
| Apple Inc. | Push notification delivery to the CritIQ mobile application (APNs). Carries alert metadata and device tokens for Client personnel, not end-user Personal Data. | US |
| Browserless.io | Headless browser rendering used to inspect the Client's own properties during tracking audits | US / EU |
| Anthropic, PBC | AI-generated narrative interpretation of precomputed/aggregated metrics, and analysis of the Client's advertising creative (see AI Policy) | US |
| OpenAI, L.L.C. | Speech-to-text transcription of the audio track of the Client's own advertising creative (see AI Policy) | US |
Part B: Recipient Platforms (independent / joint controllers; data sent on Client instruction; see Section 6.4)
Meta (Facebook/Instagram), Google (Ads / GA4), TikTok, LinkedIn, Snap, Pinterest, Reddit, X, Nextdoor, Roku, Spotify, and any additional platform the Client connects and enables in the CiQ dashboard.
Part B members Process under their own terms; the Client must accept those terms directly.
Part C: Connected Sources (systems the Client connects as a source of data)
Where the Client connects one of the following, CiQ receives Personal Data from it on the Client's instruction and in the scope the Client authorizes. Like Part B, these are not CiQ Sub-processors: each operates under its own agreement with the Client, and the Client is responsible for having the right to connect it and to instruct CiQ to receive data from it.
- Commerce and payments: Shopify, Stripe, Square, Toast.
- CRM and marketing systems: HubSpot, Salesforce, Pipedrive, Zoho, Mindbody, Klaviyo.
- Messaging surfaces: Meta Messenger, Instagram, WhatsApp Business.
- Advertising lead delivery: Meta, TikTok, and LinkedIn lead forms.
- Automation: Zapier and equivalent connectors the Client configures.
- Analytics: Google Analytics 4 properties the Client connects.
A source the Client connects may deliver Personal Data in plaintext; see Annex I. The Client controls which sources are connected and may disconnect any of them at any time.