← Back to ChamTracker

ChamTracker Data Processing Agreement _Last updated: 7 August 2026. These terms govern ChamTracker's processing of personal data on your behalf and apply to your use of the service. No signature is required; email aidanryancham@gmail.com if you need a countersigned copy._ **Parties.** "Customer" (the controller) is the account holder — you, or the business on whose behalf you set. "Processor" is JIRTEC LTD, trading as ChamTracker, a company registered in England and Wales (No. 14592030), registered office 4 Stanhope Road, St. Albans, England, AL1 5BL, contact aidanryancham@gmail.com. **1. Subject matter and duration.** The Processor processes the personal data described below to provide the ChamTracker service, for as long as the Customer's account exists. **2. Nature and purpose.** Receiving the direct-message conversations of the Instagram professional account the Customer connects (via the Instagram API; the connection can be removed at any time), storing them, classifying them with AI to produce sales-activity metrics, and displaying those metrics and conversations to the Customer's authorised users — the setter whose inbox it is and, where the setter and the business have both approved team access, a manager acting for the same business; and, from the counts of those classifications, generating suggested content topics for the Customer's own marketing, using no message content; and, where an authorised user chooses to join the optional cross-ChamTracker leaderboard, displaying that user's own activity counts and chosen display name to other participants, using no message content and no lead data. Nothing else. **3. Data types and subjects.** Message content, sender/timestamps, and contact identifiers (Instagram user ID and username) of (a) the Customer and (b) the people the Customer messages ("leads"); and, where team access is used, (c) the Customer's authorised users (setters and managers), whose invitation, consent and access events are recorded in the consent and access logs described in §6. **4. Controller instructions.** The Processor processes personal data only on the Customer's documented instructions — which are: the actions the Customer takes in the product (connecting or disconnecting the Instagram account, granting or revoking a manager's access to a setter's data, deleting data) — unless UK/EU law requires otherwise, in which case the Processor informs the Customer before processing unless that law forbids it. A manager-access grant is a documented instruction only when both the setter and the manager have accepted it in the product, each affirming they act for the same business. **5. Confidentiality.** Access to personal data is limited to the Processor, who is bound to confidentiality; the Processor has no staff. Within the Customer's business, access is limited to the Customer's authorised users: the setter whose inbox it is and, only after the dual acceptance described in §4, an approved manager — read-only, and only until either side revokes the link. **6. Security (Art. 32).** Encryption in transit (TLS) and at rest (managed by Supabase), per-account row-level isolation, secrets kept server-side, PII masking before AI processing, automatic deletion of raw message text after the retention window, and audit logging of all data-request operations. Manager access is a per-business access model layered on top: it exists only after dual consent (§4), is strictly read-only, is cut off instantly on revocation, and every manager read of a setter's data is recorded in an access log. **7. Sub-processors.** The Customer authorises: Supabase (database/auth, EU), Vercel (hosting, US), Anthropic (AI classification, US), Resend (transactional email, US). The Processor will give 14 days' notice by email before adding or replacing a sub-processor; the Customer may object by closing the account. Sub-processors are bound by data protection terms no weaker than this DPA. Where a sub-processor processes personal data outside the UK or EEA (Vercel, Anthropic and Resend, US), the transfer is made under appropriate safeguards - the UK International Data Transfer Addendum or an equivalent mechanism. **8. Data subject rights.** The Processor provides tooling and assistance so the Customer can answer access, rectification, erasure, restriction and portability requests (export and erasure are built into the product; requests can also be sent to aidanryancham@gmail.com and are handled within one month). **9. Assistance.** The Processor assists the Customer, taking account of the nature of the processing, with security, breach notification, and — where required — data protection impact assessments (see the risk factsheet available on request). **10. Breach notification.** The Processor notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with enough detail to meet the Customer's own 72-hour notification duties. **11. Deletion on termination.** When the account is closed, all personal data is deleted (immediately via the deletion endpoint; within 30 days at the latest), except where law requires retention. One documented exception: the manager-link consent and access-log evidence (§3(c), §6) is kept for up to 6 years after it is recorded, to establish or defend legal claims about who had access to what and with whose agreement. On account deletion the account's internal user id is detached from the consent history; the email addresses in that evidence are retained as the evidence itself for the remainder of the 6-year window, and the records are then deleted automatically. **12. Audit.** The Processor makes available the information reasonably necessary to demonstrate compliance with Article 28 and, at the Customer's reasonable request and cost, permits audits limited to the Customer's own data, no more than once per year, on 30 days' notice.

See also the privacy policy and the notice for message recipients.