Legal · updated 2026-10-03

Data processing addendum

How Hookloop processes personal data about your app’s users on your behalf, through the SDK, tracked links, landing pages and revenue webhooks.

Draft

This document is a working draft and hasn’t been reviewed by a lawyer yet. It will be finalised before Hookloop takes its first paying customer.

1. Roles

You are the controller of personal data about your app’s users; Hookloop is your processor. This addendum forms part of the Terms of service.

2. Data processed

Categories of data subjects: users of your app and visitors to your tracked links and landing pages.

Categories of data: app user IDs from your subscription provider, attribution IDs, hashed IP addresses, click time, country, referrer, install referrer and clipboard hand-off tokens, deep-link tokens, creator codes, survey answers, and subscription events (trials, purchases, renewals, refunds, amounts).

No special-category data is processed, and the SDK does not collect advertising identifiers.

3. Purpose and instructions

We process the data only to attribute installs and revenue to your links, creators and content and to show you the results, following your documented instructions (your configuration of Hookloop). Modeled IP-and-time matching runs only if you turn it on.

4. Your obligations

You are responsible for having a lawful basis, for your in-app privacy notice and any consent your users’ jurisdictions require (for example for clipboard access or IP matching), and for honouring app store privacy disclosures.

5. Security

Encryption in transit and at rest, IP addresses stored only as keyed hashes, least-privilege access, row-level isolation between workspaces, and logging of administrative access.

6. Sub-processors

You authorise the sub-processors listed at [sub-processor URL]. We will give 30 days’ notice of new sub-processors, and you may object.

7. Assistance and breaches

We help you respond to data-subject requests and impact assessments, and notify you without undue delay (and within 72 hours) of a personal data breach affecting your data.

8. Deletion and audits

On termination we delete your app users’ data within 30 days unless the law requires otherwise. We make available the information needed to demonstrate compliance, including reasonable audits on notice.

9. Transfers

Where data leaves the EEA or UK we rely on the Standard Contractual Clauses (and UK addendum), incorporated by reference.