Legal / Engagement
Data Processing Terms
The processor terms that apply when we handle personal data inside your accounts.
Effective 11 August 2026
These terms form part of the Terms of Engagement and apply whenever Kickstart Labs LLC DBA Gold Label Media handles personal data on your behalf rather than for our own purposes. They matter most where a route requires access to an account you control, because at that moment we can see personal data belonging to people who are not you.
Two different relationships run at once, and confusing them is how obligations get dropped. For your own enquiry and contact details we are the controller and our Privacy Notice governs. For personal data inside your account, meaning your audience, your customers and your correspondents, you are the controller and we are your processor. This page governs the second.
Scope and instructions
- Subject matter: the matter set out in your written scope. Duration: the engagement, plus the retention periods in our Data Retention Schedule.
- We process personal data only on your documented instructions, which the agreed scope constitutes, and to comply with law. If we are legally required to process beyond your instructions we will tell you first, unless the law forbids us from telling you.
- We will tell you if, in our opinion, an instruction you give us infringes data protection law. We will not simply carry it out.
- We never use personal data inside your account for our own purposes. Not to market, not to build a list, not to train anything, not to compile a benchmark.
Account access, specifically
- We use the least access a route allows. Where a route can be worked without account access, we do not ask for any.
- Where access is needed, it is always as an authorised or delegated user — partner access on a Meta Business Portfolio, or the equivalent role on the platform concerned — because that is revocable by you, auditable by you, and does not require you to hand over a credential.
- We do not ask for, accept or hold account credentials. Not a password, not a two factor code, not a backup code, not a session token. Where a route cannot be worked through delegated access, we decline the matter. We tell you in writing which delegated access a route needs and why before you grant anything, and you may decline and stop the matter at that point with no fee for work not done.
- We will confirm in writing when we have finished with access, and we will remind you to revoke it and review active sessions.
- We act inside your account only to do the agreed work. We do not read, export or copy anything the work does not require, and we do not retain a copy of your account data after the matter closes.
Confidentiality and people
Everyone with access to personal data processed for you is bound by a written confidentiality obligation that survives the end of their engagement with us. Access is limited to the people working your file. We do not operate a shared inbox or a pooled login for client matters.
Security
We apply the measures described in our Security and Anti Fraud notice: encryption in transit and at rest, access control on a need to know basis, and least privilege for account access. Where a platform offers a delegated access model with an audit trail, we use it in preference to a shared credential, because the audit trail protects you rather than us.
Sub-processors
Our current sub-processors are named on the Sub-processors page. You give general authorisation for us to use them. We will tell you before a new one begins processing, you may object, and if an objection cannot be resolved you may end the engagement for work not yet done without penalty. Each sub-processor is bound by obligations no weaker than these, and we remain liable to you for their acts.
Assisting you
- If a person exercises a data subject right against you in relation to something we hold for you, we will pass it to you promptly and help you answer it. We will not answer it ourselves unless you ask us to.
- We will help you with data protection impact assessments and with prior consultation of a regulator, so far as the work we did is relevant.
- We will make available the information reasonably needed to show these obligations are met, and allow an audit on reasonable notice, once a year unless a regulator or a breach requires otherwise.
Breach
If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay and in any event within forty eight hours of becoming aware, with what we know at that point, and we will keep telling you as we learn more. We will not wait until the picture is complete before making the first call.
International transfers
We are in the United States and so is our infrastructure. Where you are in the UK or the European Economic Area and the work involves transferring personal data to us or our sub-processors, the transfer relies on the European Commission's standard contractual clauses together with the UK Addendum. These terms incorporate those clauses by reference, and we will execute a separate signed copy on request.
Annex I. Parties, transfer and data
- Data exporter: you, the client named in the scope, acting as controller. Data importer: Kickstart Labs LLC DBA Gold Label Media, a limited liability company registered in Florida, United States, an address on the public record of the Florida Division of Corporations under registration number L23000438948, provided on request through the desk, acting as processor. Where the standard contractual clauses apply, Module Two applies: controller to processor.
- Categories of data subject: the people whose personal data appears inside the account or asset a matter concerns. Typically your own personnel who administer the account, and your audience, customers or correspondents whose data the platform holds.
- Categories of personal data: account and profile identifiers, administrator and authorised-user records, message and comment content where a route requires it to be evidenced, and the identity documentation a platform submission itself demands. We do not seek any other category.
- Sensitive data: none is requested and none is wanted. Where a platform's own submission form requires an identity document, it is handled for that submission only and deleted once the submission is accepted or refused, as set out in the Data Retention Schedule.
- Frequency of transfer: one-off, for the duration of the matter, rather than continuous.
- Nature and purpose: preparing, evidencing and submitting appeals, recovery requests, rights-based claims and editorial or entity records through the published channels of the platform or publisher concerned.
- Duration: the term of the matter, plus the periods set out in the Data Retention Schedule where law or a limitation period requires it.
- Competent supervisory authority: where the exporter is established in the European Economic Area, the supervisory authority of that member state. Where the exporter is in the United Kingdom, the Information Commissioner's Office.
Annex II. Technical and organisational measures
- Encryption of personal data in transit and at rest.
- Access control on a need-to-know basis. Only the people working a file can open it, and there is no shared inbox or pooled login for client matters.
- Least privilege for account access, taken as a delegated or authorised user that you grant and revoke yourself. We do not request, accept or hold account credentials in any circumstance, so there is no credential store to compromise.
- Written confidentiality obligations on everyone with access, surviving the end of their engagement with us.
- Data minimisation at intake: the enquiry form is not built to receive credentials, identity documents or financial details, and says so.
- Retention limits set per category in the Data Retention Schedule, with deletion as the default rather than accumulation.
- Breach notification to you within forty eight hours of our becoming aware, which is tighter than the seventy two hours Article 33 allows a controller.
- Sub-processor changes published before a new provider begins processing, with a right to object.
Annex III. Sub-processors
The authorised sub-processors are those named on the Sub-processors page, which forms Annex III and is kept current. It is updated before a new provider begins processing, never after, and you may object to an addition and end the engagement without penalty for work not yet done if the objection cannot be resolved.
Liability under these terms
Each of us is liable to the other for damage caused by our own breach of these processing terms. Our liability under these terms is subject to the same limit as the Terms of Engagement, except that no limit applies to liability that cannot be limited by law, including a data subject's own right to compensation under Article 82 of the UK or EU General Data Protection Regulation, which is unaffected by anything agreed here. Where the standard contractual clauses apply and anything in these terms conflicts with them, the standard contractual clauses prevail.
Deletion and return
At the end of the engagement we delete or return personal data processed for you, at your choice, except where law requires us to keep it. Our Data Retention Schedule sets out those exceptions and how long they run.
Contact
The desk is reached by email at sales@goldlabelmedia.net. We do not run an email support queue, and no one from Gold Label Media will ever contact you first asking for a password, a two factor code or a payment to an individual.
The entity
Kickstart Labs LLC DBA Gold Label Media, a limited liability company registered in Florida, United States, registration L23000438948. The registered address is on the public record of the Florida Division of Corporations under registration number L23000438948, and is provided on request through the desk.
