Legal

Data processing terms

GDPR · Last updated 28 July 2026

1. Roles2. Scope & details3. Instructions4. Confidentiality5. Security6. Sub-processors7. Data subject requests8. Breach notification9. Transfers10. Return & deletion11. Audits

1. Roles of the parties

For personal data contained in your Microsoft directory and processed to deliver the service, you are the data controller and Footer365 is the data processor. This addendum applies where we process such personal data on your behalf, and forms part of the terms of service.

2. Scope, nature and details of processing

ItemDetail
Subject matterProvision of the Footer365 email signature and marketing service
DurationFor the term of the subscription, plus deletion period
Nature & purposeSyncing directory attributes and injecting signatures into outbound mail
Types of personal dataNames, work contact details, job titles, photos and similar directory attributes; account contact details
Categories of data subjectYour staff and mailbox owners, and your named account contacts

3. Processing on instructions

We process personal data only on your documented instructions, including as set out in the agreement and this addendum, unless required by law - in which case we will inform you where legally permitted.

4. Confidentiality

Personnel authorised to process personal data are bound by appropriate confidentiality obligations.

5. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, least-privilege access controls, and audit logging. See our security page.

6. Sub-processors

You authorise our use of the sub-processors listed on our sub-processors page. We impose data protection obligations on each sub-processor no less protective than those in this addendum, and remain responsible for their performance. We will give notice of intended changes so you may object on reasonable grounds.

7. Assisting with data subject requests

Taking into account the nature of processing, we will assist you by appropriate measures to respond to requests from data subjects exercising their rights, and to meet your obligations relating to security, breach notification, impact assessments and consultation.

8. Personal data breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.

9. International transfers

You may select the processing region. Where personal data is transferred outside the UK or EEA, we rely on an appropriate transfer mechanism such as the UK International Data Transfer Agreement or Standard Contractual Clauses, together with any required supplementary measures.

10. Return and deletion

On termination, or on your instruction, we will delete or return the personal data we process on your behalf and delete existing copies, unless retention is required by law. Offboarding re-enables native Microsoft signature handling and removes synced directory data.

11. Audits

We will make available information necessary to demonstrate compliance with this addendum and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and security conditions.