These terms apply where ARKTOP LLC (“ARKTOP”) processes personal information on behalf of a client in the course of delivering services. They form part of, and are incorporated by reference into, the ARKTOP Service Terms and each Order or Statement of Work.
Where a client requires a separately executed data processing agreement, these terms serve as the baseline and may be superseded by a signed agreement between the parties.
This document is directed to ARKTOP clients. If you are a visitor to arktop.com, see our Privacy Policy and Cookie Notice instead.
When delivering services, ARKTOP processes personal information belonging to the client’s customers, subscribers, and website visitors. In doing so:
ARKTOP is prohibited from, and will not:
ARKTOP certifies that it understands and will comply with these restrictions. ARKTOP will notify the client promptly if it determines it can no longer meet its obligations under applicable privacy law.
Subject matter | Digital marketing, advertising, analytics, SEO, and web development services |
Duration | The term of the applicable Order, plus any retention period stated in Section 6 |
Nature and purpose | Campaign delivery and optimization, audience creation and targeting, performance measurement and reporting, email marketing, website development and maintenance |
Types of personal information | Contact details (name, email, phone), postal address, hashed identifiers used for audience matching, order and transaction history, website and app usage data, device and cookie identifiers, marketing engagement data |
Categories of individuals | The client’s customers, prospective customers, newsletter subscribers, and website visitors |
Sensitive personal information | None. ARKTOP does not process sensitive personal information on behalf of clients, and clients must not provide it. |
ARKTOP uploads client customer lists to Meta (Custom Audiences) and Google (Customer Match) to build targeted and lookalike audiences.
Client obligations. The client represents and warrants that it has:
The client acknowledges that Meta’s Custom Audiences Terms and Google’s Customer Match policies impose obligations directly on the client as the data owner, and that ARKTOP performs the upload on the client’s instruction. ARKTOP will transmit lists using the hashing and transfer mechanisms the platforms require, and will not retain a copy beyond what Section 6 permits.
ARKTOP will not upload a list where it has actual knowledge that required consents were not obtained, and will raise the issue with the client in writing.
ARKTOP is granted access to client Google Analytics 4 properties and Google Tag Manager containers to configure measurement, build reports, and diagnose tracking. ARKTOP accesses these systems solely to deliver the services and will not export, retain, or use the data for any other purpose. Access is provisioned to named ARKTOP personnel and revoked on termination under Section 8.
ARKTOP is granted access to client email platforms, including Klaviyo and Mailchimp, to build campaigns, manage segments, and report on performance. Suppression lists and unsubscribe requests are honored as configured by the client. ARKTOP does not export subscriber lists except where necessary to deliver a service the client has requested in writing.
ARKTOP accesses and exports client Shopify order and customer data for revenue reporting, conversion analysis, and blended performance measurement. Exports are handled under Sections 5 and 6.
ARKTOP will:
ARKTOP maintains the following measures to protect client personal information:
Worth strengthening before client security reviews. The controls above are accurate but thin for an agency handling customer lists and ecommerce exports. The gaps a reviewer will ask about: MFA on client platform access (not just Google Workspace), documented deprovisioning when staff or contractors leave, a password manager for shared credentials, and a written incident response procedure. None are expensive. Each one you add here is one fewer objection in a vendor questionnaire.
ARKTOP retains client personal information only as long as necessary to deliver the services. ARKTOP retains client personal information for as long as necessary to deliver the services, determined by the following criteria:
Data | Retention criterion |
Customer lists provided for audience uploads | Retained while the audience is in active use for the client’s campaigns, and while needed to verify the accuracy of reported data. Deleted within 60 days of termination of the applicable Order, or on the client’s written request. |
Exported ecommerce and analytics data | Retained for the term of the engagement and for historical and year-over-year performance reporting thereafter. |
Reports and deliverables | Retained as a record of work performed and for historical comparison. |
Client platform access | Revoked within 5 business days of termination. |
On termination, ARKTOP will delete or return client personal information at the client’s election, except where retention is necessary for the purposes above or required by law. The client may request deletion at any time and ARKTOP will comply unless retention is legally required.
The client authorizes ARKTOP to engage the subprocessors listed below. ARKTOP will impose data protection obligations on each subprocessor no less protective than these terms, and remains liable for their performance.
Subprocessor | Purpose | Location |
Google LLC | Analytics, tag management, advertising | United States |
Meta Platforms, Inc. | Advertising and audience matching | United States |
Google LLC (Workspace) | Email, document and file storage | United States |
Google LLC (Looker Studio) | Client performance dashboards and reporting | United States |
Canva Pty Ltd | Client report production | Australia |
Asana, Inc. | Project management | United States |
This is the section that will be scrutinized. Any developer, specialist, or contractor who can access client data is a subprocessor and must be named here with their location — including personnel working outside the United States. Omitting them is the most common gap in agency DPAs, and it surfaces in client security reviews rather than being caught internally.
The client may object on reasonable data protection grounds, in which case the parties will discuss in good faith; if no resolution is reached, the client may terminate the affected Order without penalty.
On expiry or termination of an Order, and at the client’s written direction, ARKTOP will:
The client may, no more than once in any 12-month period and on at least 30 days’ written notice, request information reasonably necessary to verify ARKTOP’s compliance with these terms. ARKTOP will respond to a reasonable security questionnaire and provide available documentation.
On-site audits will be conducted only where required by law or a regulator, during business hours, in a manner that does not disrupt ARKTOP’s operations, and subject to confidentiality obligations.
In the event of conflict, a data processing agreement separately executed between ARKTOP and the client takes precedence over these terms. These terms take precedence over the ARKTOP Service Terms and any Order with respect to the processing of personal information.
ARKTOP LLC Skyline Tower, 3 Court Square West, Suite 4008, Long Island City, NY 11101, United States info@arktop.com +1 212-518-6049