Legal / Engagement
Data Processing Terms
The processor terms that apply when we handle personal data inside your accounts.
Effective 11 August 2026
These terms form part of the Terms of Engagement and apply whenever Kickstart Labs LLC DBA Gold Label Media handles personal data on your behalf rather than for our own purposes. They matter most where a route requires access to an account you control, because at that moment we can see personal data belonging to people who are not you.
Two different relationships run at once, and confusing them is how obligations get dropped. For your own enquiry and contact details we are the controller and our Privacy Notice governs. For personal data inside your account, meaning your audience, your customers and your correspondents, you are the controller and we are your processor. This page governs the second.
Scope and instructions
- Subject matter: the matter set out in your written scope. Duration: the engagement, plus the retention periods in our Data Retention Schedule.
- We process personal data only on your documented instructions, which the agreed scope constitutes, and to comply with law. If we are legally required to process beyond your instructions we will tell you first, unless the law forbids us from telling you.
- We will tell you if, in our opinion, an instruction you give us infringes data protection law. We will not simply carry it out.
- We never use personal data inside your account for our own purposes. Not to market, not to build a list, not to train anything, not to compile a benchmark.
Account access, specifically
- We use the least access a route allows. Where a route can be worked without account access, we do not ask for any.
- Where access is needed, we prefer being added as an authorised or delegated user, because that is revocable by you, auditable by you, and does not require you to hand over a credential.
- Where a route leaves no alternative and a credential is genuinely required, we tell you in writing which access the route needs and why before you send anything, and you may decline and stop the matter at that point with no fee for work not done.
- Credentials are used only for the matter, are never stored in the enquiry database, and are deleted at the close of the matter. We will confirm in writing when we have finished with access, and we will remind you to change the password and review active sessions.
- We act inside your account only to do the agreed work. We do not read, export or copy anything the work does not require, and we do not retain a copy of your account data after the matter closes.
Confidentiality and people
Everyone with access to personal data processed for you is bound by a written confidentiality obligation that survives the end of their engagement with us. Access is limited to the people working your file. We do not operate a shared inbox or a pooled login for client matters.
Security
We apply the measures described in our Security and Anti Fraud notice: encryption in transit and at rest, access control on a need to know basis, and least privilege for account access. Where a platform offers a delegated access model with an audit trail, we use it in preference to a shared credential, because the audit trail protects you rather than us.
Sub-processors
Our current sub-processors are named on the Sub-processors page. You give general authorisation for us to use them. We will tell you before a new one begins processing, you may object, and if an objection cannot be resolved you may end the engagement for work not yet done without penalty. Each sub-processor is bound by obligations no weaker than these, and we remain liable to you for their acts.
Assisting you
- If a person exercises a data subject right against you in relation to something we hold for you, we will pass it to you promptly and help you answer it. We will not answer it ourselves unless you ask us to.
- We will help you with data protection impact assessments and with prior consultation of a regulator, so far as the work we did is relevant.
- We will make available the information reasonably needed to show these obligations are met, and allow an audit on reasonable notice, once a year unless a regulator or a breach requires otherwise.
Breach
If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay and in any event within forty eight hours of becoming aware, with what we know at that point, and we will keep telling you as we learn more. We will not wait until the picture is complete before making the first call.
International transfers
We are in the United States and so is our infrastructure. Where you are in the UK or the European Economic Area and the work involves transferring personal data to us or our sub-processors, the transfer relies on the European Commission's standard contractual clauses together with the UK Addendum. These terms incorporate those clauses by reference, and we will execute a separate signed copy on request.
Deletion and return
At the end of the engagement we delete or return personal data processed for you, at your choice, except where law requires us to keep it. Our Data Retention Schedule sets out those exceptions and how long they run.
Contact
The desk is reached by email at sales@goldlabelmedia.net. We do not run an email support queue, and no one from Gold Label Media will ever contact you first asking for a password, a two factor code or a payment to an individual.
The entity
Kickstart Labs LLC DBA Gold Label Media, a limited liability company registered in Florida, United States. 2041 NE 179th St, North Miami Beach, FL, 33162, United States
