Data Processing Agreement
Nathan Marketing Management LLC (“Nathan & Brank”) · Effective Date: 2 July 2026
This Data Processing Agreement (“DPA”) forms part of, and supplements, the Professional Services Terms of Use and applies wherever Nathan & Brank (“Nathan & Brank”, “we”, “us”) processes personal data on a Client's behalf in the course of delivering the Services. It is published here as a reference template; the version incorporated into a specific client engagement is the one executed as part of that Client's Order.
Purpose and Scope
This DPA sets out the terms on which Nathan & Brank processes personal data on behalf of a Client in connection with the Services described in the Professional Services Terms of Use. It applies only to the extent that Nathan & Brank processes personal data for which the Client is the controller (or, under POPIA, the responsible party).
Definitions
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Sub-processor” have the meanings given to them under applicable Data Protection Law, including the UAE Personal Data Protection Law (UAE PDPL), the EU/UK GDPR, South Africa's POPIA, and the Kenya Data Protection Act, as applicable to the processing in question. “Order” means the applicable order or statement of work entered into under the Professional Services Terms of Use.
Roles of the Parties
As between the parties, the Client is the controller and Nathan & Brank is the processor of any personal data processed under this DPA. Nathan & Brank will process personal data only for the purpose of delivering the Services and in accordance with the Client's documented instructions, unless required to do otherwise by applicable law.
Processor Obligations
Nathan & Brank will:
- process personal data only on the Client's documented instructions;
- ensure personnel authorised to process personal data are subject to confidentiality obligations;
- implement the technical and organisational measures set out in Schedule 2;
- provide reasonable assistance to the Client in responding to data subject rights requests and regulatory enquiries relating to the personal data processed under this DPA; and
- delete or return personal data on termination in accordance with the Term and Termination section below.
Sub-processing
The Client authorises Nathan & Brank to engage the sub-processors and platform providers listed in Schedule 3. Nathan & Brank will impose data protection obligations on its sub-processors that are consistent with this DPA and will notify the Client of any material change to Schedule 3 (such as the addition or replacement of a Core Subprocessor), giving the Client a reasonable opportunity to object on legitimate data protection grounds.
International Transfers
Given Nathan & Brank's multi-jurisdictional operations, personal data may be transferred between the UAE, Kenya, South Africa, and other countries in which Nathan & Brank's sub-processors operate. Where such transfers occur, Nathan & Brank applies appropriate safeguards, which may include Standard Contractual Clauses approved by the European Commission and the UK Addendum, adequacy-based mechanisms, contractual protections consistent with UAE PDPL cross-border transfer requirements, POPIA section 72 requirements, and Kenya's data transfer regulations, as applicable to the specific transfer.
Security Measures
Nathan & Brank implements the technical and organisational security measures set out in Schedule 2.
Personal Data Breach Notification
Nathan & Brank will notify the Client without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA, and will cooperate with the Client and provide reasonably requested information to assist the Client in meeting its own breach notification obligations under applicable law.
Audit and Compliance
On reasonable prior written notice, and no more than once per year (except where required by a regulator or following a personal data breach), the Client may request reasonable information and documentation to verify Nathan & Brank's compliance with this DPA, subject to the confidentiality obligations set out in the Professional Services Terms of Use.
Liability
Liability arising out of or in connection with this DPA is subject to the limitation of liability set out in the Professional Services Terms of Use, including the cap on Nathan & Brank's aggregate liability under the applicable Order.
Term, Termination, and Return or Deletion of Data
This DPA remains in effect for as long as Nathan & Brank processes personal data on the Client's behalf under the applicable Order. On termination of the Order, Nathan & Brank will, at the Client's election, return or delete the personal data processed under this DPA, unless applicable law requires Nathan & Brank to retain some or all of it.
Governing Law and Jurisdiction
This DPA is governed by the laws of the United Arab Emirates and is subject to the exclusive jurisdiction of the courts of Dubai, consistent with the Professional Services Terms of Use.
Schedules and Contact
This DPA includes the following Schedules:
- Schedule 1 — Details of Processing
- Schedule 2 — Technical and Organisational Security Measures
- Schedule 3 — Subprocessor & Platform Provider Schedule
Questions about this DPA can be directed to legal@nathanbrank.com. Questions specifically about Schedule 3 (subprocessors and platform providers) can be directed to support@nathanbrank.com.
Schedule 1 — Details of Processing
Subject matter and duration
For the term of the engagement under the applicable Order.
Nature and purpose of processing
Delivery of the Services as described in the Professional Services Terms of Use.
Categories of data subjects
The Client's customers, prospects, employees, and business contacts.
Categories of personal data
- Client and account data — company name, contacts, contracts, invoices, brand ownership, client portal user records
- Lead and prospect data — lead source, contact details, pipeline stage, research outputs, scoring assessments, opportunity notes
- Brand and creative data — brand guides, logos, assets, briefs, final deliverables, social content, ad copy
- Campaign and channel data — ad account IDs, campaign names, spend, clicks, impressions, conversion data, audiences, lead form submissions
- Website and analytics data — website events, search console data, session behaviour, SEO performance, GA4 metrics
- Email and messaging data — email addresses, message content, campaign sends, opens, clicks, WhatsApp notifications, bounce and complaint events
- Platform activity data — user actions, audit logs, approvals, comments, task actions, notification records
- AI processing data — prompts, retrieved context, generated content, recommendations, summaries, lead research outputs, document generations
Schedule 2 — Technical and Organisational Security Measures
Nathan & Brank implements the following technical and organisational measures:
- Encryption of sensitive data where appropriate.
- Role-based access controls for internal systems.
- Continuous monitoring of tracking and analytics scripts.
- Vendor risk management and confidentiality agreements with third-party providers.
- Regular internal security audits and reviews to ensure compliance with jurisdiction-specific laws.
Access to personal data is restricted to authorised personnel only and used solely for the purposes described in this DPA.
Schedule 3 — Subprocessor & Platform Provider Schedule
Nathan & Brank may use trusted third-party vendors, subprocessors, infrastructure providers, advertising platforms, AI providers, analytics tools, communications platforms and operational tools to support the delivery of its marketing, advertising, analytics, reporting, automation, client portal, campaign management, creative and related services.
These third parties may process personal data only where necessary to provide the contracted services, maintain and secure the relevant platforms, support integrations, deliver communications, manage campaigns, generate reports, provide analytics, support AI-assisted content generation and enable operational delivery.
Classification Model
Nathan & Brank classifies third-party providers as follows:
Data Categories Processed
The below categories of data are processed:
- Client and account data — company name, contacts, contracts, invoices, brand ownership, client portal user records
- Lead and prospect data — lead source, contact details, pipeline stage, research outputs, scoring assessments, opportunity notes
- Brand and creative data — brand guides, logos, assets, briefs, final deliverables, social content, ad copy
- Campaign and channel data — ad account IDs, campaign names, spend, clicks, impressions, conversion data, audiences, lead form submissions
- Website and analytics data — website events, search console data, session behaviour, SEO performance, GA4 metrics
- Email and messaging data — email addresses, message content, campaign sends, opens, clicks, WhatsApp notifications, bounce and complaint events
- Platform activity data — user actions, audit logs, approvals, comments, task actions, notification records
- AI processing data — prompts, retrieved context, generated content, recommendations, summaries, lead research outputs, document generations
Subprocessor & Provider Schedule
a) Core subprocessors
b) Client-authorized platforms
c) Social listening sources
Platform Module to Provider Mapping
Schedule 3 Data Retention
Nathan & Brank and its relevant providers retain personal data only for as long as necessary to provide the services, meet contractual obligations, comply with legal requirements, resolve disputes, maintain security, support audits, or operate backup and disaster recovery processes.
Changes to Schedule 3
Nathan & Brank may update Schedule 3 from time to time to reflect changes in providers, services, platform functionality, security requirements, legal obligations or operational needs, subject to the notice requirements set out in the Sub-processing section above.