Web Dot Club Pty Ltd dba LinkDM
ABN 58 126 161 117 | ACN 126 161 117
Effective date: 1 August 2026
This Data Processing Addendum (“DPA”) forms part of the agreement governing a customer’s use of LinkDM, including the LinkDM Terms of Use and any applicable order form or other written agreement (the “Agreement”). It applies automatically to the extent LinkDM processes Customer Personal Data on behalf of the Customer in providing the Services.
Customer acts as controller, or processor for its own client, and LinkDM acts as processor or subprocessor.
EU transfers are covered by the 2021 EU Standard Contractual Clauses, using Module 2 or Module 3 as applicable.
UK restricted transfers are covered by the ICO International Data Transfer Addendum to those EU SCCs.
Authorized subprocessors are listed in Schedule 3 of this DPA.
Terms of Use: https://www.linkdm.com/terms
Privacy Policy: https://www.linkdm.com/privacy
1.1 This DPA applies only to Customer Personal Data processed by LinkDM as a processor or subprocessor in connection with the Services. Personal data that LinkDM processes as an independent controller, such as account administration, billing, website analytics, marketing, or support relationship data, is governed by the LinkDM Privacy Policy and is outside the scope of this DPA.
1.2 “Customer Personal Data” means personal data that LinkDM processes on behalf of Customer through the Services, including personal data relating to Customer’s audience, followers, commenters, message recipients, leads, and other end users.
1.3 “Data Protection Laws” means applicable laws governing privacy, data protection, or the processing of personal data, including, where applicable, the GDPR, UK GDPR and Data Protection Act 2018, and applicable United States state privacy laws.
1.4 “GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning given under United Kingdom data protection law. “SCCs” means the standard contractual clauses in the Annex to Commission Implementing Decision (EU) 2021/914 dated 4 June 2021.
1.5 “Services” means LinkDM’s Instagram and Facebook messaging automation, lead-generation, analytics, workflow, and related software services made available under the Agreement.
1.6 Capitalized terms not defined in this DPA have the meanings given in the Agreement or applicable Data Protection Laws.
2.1 Customer determines the purposes and essential means of processing Customer Personal Data through LinkDM, including which social accounts are connected, which automations are enabled, the trigger criteria, message content, recipients, lead fields, integrations, and retention or deletion actions available through the Services.
Customer is the controller of Customer Personal Data unless Customer processes that data on behalf of another controller, in which case Customer is a processor and LinkDM is Customer’s subprocessor.
2.2 LinkDM will process Customer Personal Data only on Customer’s documented instructions, including as necessary to provide, secure, maintain, and support the Services and as otherwise required by applicable law.
The Agreement, Customer’s configuration and use of the Services, and Customer’s support requests constitute documented instructions.
2.3 If LinkDM is legally required to process Customer Personal Data other than on Customer’s instructions, LinkDM will inform Customer before that processing unless prohibited by law.
2.4 LinkDM may generate and use aggregated or de-identified statistics that do not identify Customer or any data subject for service operations, security, capacity planning, product improvement, and internal analytics.
This DPA does not restrict processing of information that is no longer personal data under applicable law.
3.1 Customer is responsible for ensuring that its instructions and use of the Services comply with Data Protection Laws, including providing required notices, establishing a lawful basis, obtaining any required consent, honoring data-subject rights and messaging preferences, and configuring automations lawfully.
3.2 Customer will not instruct LinkDM to process personal data in a manner that violates Data Protection Laws.
The Services are not designed to require special-category or highly sensitive personal data. Customer should not collect or submit such data through custom lead fields or messages unless it has determined that doing so is lawful and appropriate.
3.3 Customer acknowledges that LinkDM relies on Customer’s lawful access to and instructions concerning connected Meta accounts and third-party integrations selected or authorized by Customer.
4.1 LinkDM will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only on a need-to-know basis for providing, supporting, securing, or troubleshooting the Services.
4.2 LinkDM will restrict administrative access to authorized personnel and apply reasonable access controls appropriate to the nature of the Services and the data processed.
5.1 Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, LinkDM will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
5.2 The measures currently maintained by LinkDM are described in Schedule 2.
Customer is responsible for using available security features appropriately and protecting credentials for its LinkDM and connected third-party accounts.
6.1 LinkDM will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notice will include information reasonably available to LinkDM that Customer may need to meet applicable breach-notification obligations.
6.2 LinkDM will take reasonable steps to contain, investigate, and remediate the Personal Data Breach and will reasonably cooperate with Customer.
Notification or cooperation under this section is not an admission of fault or liability.
7.1 Taking into account the nature of the processing, LinkDM will provide reasonable assistance, including through available product functionality, to help Customer respond to requests by data subjects to exercise rights under applicable Data Protection Laws.
7.2 If LinkDM receives a request directly from a data subject concerning Customer Personal Data and can reasonably identify the relevant Customer, LinkDM will, where legally permitted, direct the request to Customer and will not independently respond on Customer’s behalf except as required by law.
7.3 Taking into account the nature of the processing and information available to LinkDM, LinkDM will provide reasonable assistance with Customer’s obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
8.1 Customer grants LinkDM general written authorization to engage the subprocessors listed in Schedule 3 and to add or replace subprocessors as reasonably necessary to provide the Services.
8.2 Where required by Data Protection Laws or the SCCs, LinkDM will provide at least 30 days’ advance notice of a new subprocessor that will materially process Customer Personal Data.
Notice may be provided by email, in-product notice, or an update to this DPA.
Shorter notice may be used where necessary to address an emergency, security issue, service interruption, or legal requirement.
8.3 Customer may object to a new subprocessor on reasonable and documented data-protection grounds by contacting support@linkdm.com during the notice period.
The parties will work in good faith to address the objection. If no commercially reasonable alternative is available, Customer may stop using the affected feature or terminate the affected Services in accordance with the Agreement.
8.4 LinkDM will impose data-protection obligations on each subprocessor that are no less protective, in substance, than those required of LinkDM under this DPA to the extent applicable to the subprocessor’s processing.
LinkDM remains responsible for its subprocessors to the extent required by applicable Data Protection Laws.
8.5 Third-party platforms and integrations independently selected, connected, or directed by Customer are not LinkDM subprocessors to the extent they process personal data under their own terms and for their own purposes.
Payment providers and advertising or website analytics providers used by LinkDM for LinkDM’s own account, billing, website, or marketing activities are likewise outside the scope of Customer Personal Data under this DPA.
9.1 During the term, Customer may access, export, or delete Customer Personal Data using available Service functionality, including lead exports and account deletion controls where available.
9.2 When Customer uses LinkDM’s self-service account deletion function, LinkDM’s current workflow permanently deletes the LinkDM account and associated Customer Personal Data from active systems, including captured leads, and cancels active LinkDM subscriptions.
LinkDM does not provide a customer-facing restore period after account deletion.
9.3 Upon termination or expiration of the Agreement, LinkDM will delete or return Customer Personal Data as required by applicable Data Protection Laws and Customer’s instructions, unless applicable law requires retention.
Any data retained solely because of a legal requirement will remain protected and will not be processed for other purposes.
10.1 LinkDM will make available information reasonably necessary to demonstrate compliance with processor obligations under applicable Data Protection Laws.
Customer will first use available documentation, responses, and third-party reports, if any, before requesting an on-site audit.
10.2 If an audit is required by applicable Data Protection Laws and the available information is insufficient, Customer may request an audit no more than once annually, except following a material Personal Data Breach or where a supervisory authority requires otherwise.
Audits must be reasonable in scope, during normal business hours, subject to confidentiality and security restrictions, and must not unreasonably interfere with LinkDM’s operations or expose data relating to other customers.
10.3 Customer will bear its own audit costs and reimburse LinkDM for reasonable costs of extraordinary audit assistance unless the audit identifies a material breach by LinkDM of this DPA.
11.1 Customer acknowledges that LinkDM operates from Australia and uses infrastructure and service providers in Australia, the United States, and other locations identified in Schedule 3.
Where Customer Personal Data is transferred internationally, LinkDM will use a transfer mechanism required by applicable Data Protection Laws.
11.2 EEA Transfers. If Customer Personal Data protected by the GDPR is transferred to LinkDM in a country not recognized as providing adequate protection and no other valid transfer mechanism applies, the SCCs are incorporated into this DPA and apply as set out in Schedule 4.
11.3 UK Transfers. If Customer Personal Data protected by the UK GDPR is transferred in a restricted transfer and no adequacy regulation or other valid transfer mechanism applies, the UK International Data Transfer Addendum to the EU SCCs applies as set out in Schedule 5.
11.4 LinkDM will, where required, implement reasonable supplementary measures and cooperate with Customer’s reasonable requests for information needed to conduct a transfer impact or transfer risk assessment.
Each party remains responsible for any transfer assessment obligations allocated to it by applicable law.
11.5 If a legally valid alternative transfer mechanism becomes available, including an applicable adequacy decision or certification framework, LinkDM may rely on that mechanism for the relevant transfer to the extent permitted by law.
12.1 To the extent LinkDM processes Customer Personal Data subject to a United States state privacy law that distinguishes controllers/businesses from processors/service providers/contractors, LinkDM will act as the processor, service provider, or contractor, as applicable, for Customer Personal Data.
12.2 LinkDM will not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising on Customer’s behalf.
LinkDM will not retain, use, or disclose Customer Personal Data outside the business purposes specified in the Agreement and this DPA except as permitted by applicable law.
LinkDM will notify Customer if LinkDM determines it can no longer meet an applicable statutory obligation.
12.3 Customer may take reasonable and appropriate steps to help ensure LinkDM uses Customer Personal Data consistently with Customer’s obligations under applicable state privacy laws, subject to the audit and security protections in this DPA.
13.1 If LinkDM receives a legally binding request from a public authority for Customer Personal Data, LinkDM will, where legally permitted, notify Customer, assess the validity and scope of the request, and disclose only the minimum Customer Personal Data legally required.
13.2 Where LinkDM reasonably believes a request is unlawful or disproportionate and applicable law permits a challenge, LinkDM will take reasonable steps appropriate to the circumstances to challenge or seek limitation of the request.
14.1 This DPA remains in effect for as long as LinkDM processes Customer Personal Data on Customer’s behalf.
14.2 If this DPA conflicts with the Agreement concerning the processing of Customer Personal Data, this DPA controls.
If the SCCs or UK Addendum conflict with this DPA, the SCCs or UK Addendum control for the applicable transfer.
14.3 Except as modified by this DPA, the Agreement remains unchanged, including its limitations of liability, dispute resolution, and governing-law provisions, to the extent those provisions may lawfully apply.
Nothing in the Agreement or this DPA limits rights of data subjects under the SCCs or UK Addendum.
14.4 LinkDM may update this DPA to reflect changes in law, regulatory guidance, the Services, or subprocessors, provided that any update will not materially reduce the overall level of protection for Customer Personal Data during an active subscription without a valid legal basis.
14.5 Notices concerning this DPA may be sent to support@linkdm.com.
Notices to Customer may be sent to the email associated with Customer’s LinkDM account or provided through the Services.
Provision of LinkDM’s Instagram and Facebook DM automation, lead-generation, workflow, analytics, support, and related services configured by Customer.
For the term of the Agreement and any limited period necessary to complete deletion or comply with applicable law.
Collection or receipt through connected platforms and customer inputs; storage; organization; retrieval; matching against automation triggers; transmission of automated messages; workflow execution; lead capture; analytics; export; support; security; and deletion.
To provide the Services according to Customer’s instructions and configuration; maintain and secure the Services; provide support; and comply with applicable law.
Customer’s followers, audience members, commenters, direct-message participants, message recipients, leads, prospective customers, and other individuals whose personal data Customer processes through the Services.
Social-platform identifiers and usernames; profile information made available through authorized platform APIs; comments; direct messages and message content; interaction and engagement history; automation-trigger data; link/open/click events; tags and segment membership; lead-form responses such as name, email address, phone number, date of birth, multiple-choice and custom responses; and related technical metadata necessary to operate the Services.
Not intentionally required by the Services.
Customer should not submit special-category or highly sensitive data unless Customer has a lawful basis and determines the processing is appropriate.
Continuous or event-driven while Customer uses the Services, depending on Customer configuration and end-user interactions.
As described in the Agreement, this DPA, Customer’s account and automation configuration, connected-platform permissions, and Customer’s support requests.
Generally for as long as needed to provide the Services and according to Customer configuration.
Self-service account deletion permanently removes the LinkDM account and associated Customer Personal Data from active systems without a customer-facing restoration period, subject to legally required retention.
LinkDM maintains security measures appropriate to the nature of its SaaS platform and the Customer Personal Data processed.
These measures include, as applicable:
Customer acknowledges that security is a shared responsibility and must maintain appropriate security for its own LinkDM account, connected Meta accounts, devices, credentials, integrations, and automation configurations.
The following providers may process Customer Personal Data on LinkDM’s behalf when the relevant service is used.
Processing locations may include vendor support locations and permitted onward-transfer locations under the vendor’s applicable data-processing terms.
Purpose: Cloud hosting, compute, storage, networking, and infrastructure.
Primary / expected processing locations: Australia (Sydney) and United States (US East); support may occur from other authorized AWS locations.
Purpose: Managed database infrastructure and related support.
Primary / expected processing locations: Australia and United States depending on deployment; authorized support locations may vary.
Purpose: Transactional email delivery and related email infrastructure.
Primary / expected processing locations: United States and other locations permitted under Twilio’s data-processing terms.
Purpose: Email delivery and communications infrastructure.
Primary / expected processing locations: European Union and other locations permitted under Brevo’s data-processing terms.
Purpose: Application error monitoring, diagnostics, and reliability tooling.
Primary / expected processing locations: United States and other locations permitted under Sentry’s data-processing terms.
Providers used solely for LinkDM’s own billing, website analytics, advertising, or marketing activities, such as Stripe or advertising pixels, are not listed as subprocessors for Customer Personal Data.
Third-party platforms and integrations selected by Customer that process data independently under their own terms are also not listed as LinkDM subprocessors.
For a transfer of Customer Personal Data subject to the GDPR that requires appropriate safeguards under Chapter V GDPR, the parties incorporate the Standard Contractual Clauses in the Annex to Commission Implementing Decision (EU) 2021/914.
Official SCC text:
https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
The SCCs are incorporated without modification except for the elections and Appendix information expressly completed below.
Any additional terms in this DPA apply only to the extent they do not contradict the SCCs or prejudice data-subject rights under them.
Module 2 (Controller to Processor) applies where Customer is a controller and LinkDM is a processor.
Module 3 (Processor to Processor) applies where Customer is a processor and LinkDM is Customer’s subprocessor.
Clause 7 — Docking: Applies.
Clause 9(a) — Subprocessors: Option 2, general written authorization.
The notice period is 30 days, subject to Section 8.2 of this DPA.
Clause 11 — Independent Dispute Resolution: Optional language does not apply.
Clause 17 — Governing Law: Option 1. Laws of the Republic of Ireland.
Clause 18(b) — Courts: Courts of the Republic of Ireland.
Customer.
Name, address, contact details, and activities are those identified in Customer’s LinkDM account and the Agreement.
Role: controller under Module 2 or processor under Module 3.
Customer’s acceptance of the Agreement and this DPA constitutes its agreement to the SCCs.
Web Dot Club Pty Ltd dba LinkDM
ABN 58 126 161 117
ACN 126 161 117
Victoria 3000, Australia
Contact: support@linkdm.com
Activities: provision of the LinkDM Services described in this DPA.
Role: processor under Module 2 or subprocessor under Module 3.
LinkDM’s provision of the Services under the Agreement constitutes its agreement to the SCCs.
The categories of data subjects, categories of personal data, sensitive-data limitations, frequency, nature, purpose, duration, and retention are set out in Schedule 1.
Transfers may occur continuously or on an event-driven basis for the duration of Customer’s use of the Services.
The subject matter and nature of processing by authorized subprocessors are described in Schedule 3.
The competent supervisory authority is determined in accordance with Clause 13 of the SCCs and applicable GDPR rules.
The measures in Schedule 2 are incorporated as Annex II to the SCCs.
LinkDM may update those measures from time to time provided the overall level of protection is not materially reduced.
The subprocessors listed in Schedule 3 are incorporated as Annex III to the SCCs.
Customer grants general authorization for those subprocessors subject to Clause 9 and Section 8 of this DPA.
5.1 Where a restricted transfer is subject to the UK GDPR and the EU SCCs do not independently provide a valid UK transfer mechanism, the parties agree that the ICO-approved International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Approved Addendum B1.0, in force from 21 March 2022 and as revised in accordance with its terms, applies to and forms part of this DPA.
Official ICO information and approved Addendum:
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/
Exporter and Importer are the parties identified in Schedule 4, Annex I.A.
The start date is the effective date of this DPA for the relevant Customer, or the date the relevant restricted transfer first occurs, whichever is later.
The EU SCCs and Module 2 or Module 3 selections in Schedule 4 apply.
Clause 7 applies.
Clause 9 uses general written authorization with 30 days’ notice.
Clause 11 optional language does not apply.
Clause 17 uses Irish law.
Clause 18 uses Irish courts for the EU SCCs.
Schedule 4 Annex I information, Schedule 2 security measures, and Schedule 3 subprocessor information.
Both the Importer and Exporter may exercise any termination right made available under the Approved Addendum when the ICO-approved form changes.
5.3 The mandatory provisions of the ICO-approved Addendum are incorporated by reference in their official, unmodified form.
If this DPA conflicts with the Approved Addendum, the Approved Addendum controls for the relevant UK restricted transfer.
This DPA is intended to be incorporated into the Agreement and accepted electronically.
No separate signature is required unless the parties agree otherwise.
For purposes of the SCCs and UK Addendum, the parties agree that electronic acceptance of the Agreement and this DPA evidences their intent to be bound by the applicable transfer clauses to the maximum extent permitted by law.
Data protection and DPA inquiries: support@linkdm.com