Effective 10 September 2026 · Version 1.0 · Incorporated into the MetricFabric.io Terms of Service
This Addendum is entered into between Platform Foundry Ltd, 128 City Road, London EC1V 2NX, United Kingdom, registered in England and Wales ("Processor", "we", "MetricFabric.io") and the customer identified in the Agreement ("Controller", "you"). It forms part of and is subject to the Terms of Service (the "Agreement") and takes precedence over the Agreement to the extent of any conflict on the subject of personal data.
It applies where we process personal data on your behalf in providing the Service, and is designed to satisfy Article 28 of the UK GDPR and EU GDPR. By accepting the Agreement you accept this Addendum; no signature is required, though we will countersign a copy on request.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, Regulation (EU) 2016/679 and any implementing or successor legislation applicable to the processing. "Customer Personal Data" means personal data contained in the data we ingest from your connected Google accounts and in your account records, as described in Annex A. "Sub-processor" means a processor engaged by us to process Customer Personal Data. "SCCs" means the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914; "UK Addendum" means the ICO's International Data Transfer Addendum to the SCCs. Other capitalised terms carry the meaning given in Data Protection Law or the Agreement.
2.1 You are the Controller of Customer Personal Data and we are your Processor. Where you connect Google accounts belonging to your own clients — for example as an agency — you confirm that you have the authority and lawful basis to do so and that you act as controller or as processor for those clients with the necessary permissions in place. We remain your sub-processor in that chain.
2.2 We act as an independent controller for a limited set of processing that is ours rather than yours: account administration, billing, security monitoring, fraud prevention and aggregate operational metrics. That processing is described in our Privacy Policy and is outside the scope of this Addendum.
2.3 Where you configure an MCP client or any other external destination to retrieve data from the Service, that transfer is made on your instruction to a recipient you selected. As between the parties, you are the controller of that transfer; we are neither controller nor processor of the recipient's subsequent processing, and the recipient is not our Sub-processor. Section 8.4 and Annex C set this out further.
3.1 We will process Customer Personal Data only (a) as necessary to provide the Service in accordance with the Agreement, (b) as set out in Annex A, (c) on your further documented instructions where those are consistent with the Agreement, and (d) as required by law. We will not process it for our own purposes.
3.2 Your authorisation of a Google OAuth scope, and your selection of properties and accounts to ingest, constitute documented instructions to process the corresponding data. Withdrawing a scope or disconnecting a source withdraws that instruction.
3.3 We will not sell Customer Personal Data, will not use it for advertising, and will not use it to develop, train, retrain, fine-tune or improve any generalised or generative artificial-intelligence or machine-learning model. We impose the same restriction on every Sub-processor. This commitment survives termination.
3.4 If we consider an instruction to infringe Data Protection Law we will inform you without undue delay and may suspend performance of that instruction until it is amended or confirmed.
Access to Customer Personal Data is restricted to personnel who need it to deliver or support the Service. All such personnel are bound by written confidentiality obligations that survive the end of their engagement, receive data-protection training appropriate to their role, and hold access only for as long as the role requires. No person accesses the contents of your ingested data except where you have specifically requested support, where required for security or legal compliance, or where the data has been aggregated and de-identified.
We implement and maintain the technical and organisational measures set out in Annex B, having regard to the state of the art, the cost of implementation and the risks presented by the processing. We may update those measures provided the level of protection is not reduced. You are responsible for the security of your own account: keeping credentials confidential, enabling multi-factor authentication, managing which of your people have workspace access, and controlling the distribution of MCP access tokens you create.
6.1 You give general authorisation for us to engage the Sub-processors listed in Annex C, and any replacement or additional Sub-processor notified under 6.3.
6.2 We impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this Addendum, and we remain liable to you for their performance.
6.3 We will give you at least 30 days' notice by email before a new Sub-processor begins processing Customer Personal Data. If you reasonably object on data-protection grounds within that period we will use reasonable efforts to offer an alternative; if none is available you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.
7.1 The Service gives you direct means to satisfy most requests: search, export in CSV or Parquet, correction of account records, and immediate deletion of ingested data.
7.2 Where you nonetheless need our help, we will provide reasonable assistance with data subject requests, data protection impact assessments and consultations with supervisory authorities, at no charge for the first two requests in any twelve-month period and thereafter at our then-current professional rates. If a data subject contacts us directly about Customer Personal Data, we will not respond substantively but will refer them to you and inform you promptly.
8.1 Customer Personal Data ingested from your Google accounts is stored and processed in Germany.
8.2 Where a Sub-processor listed in Annex C processes data outside the UK or EEA, the transfer is governed by the SCCs (Module Three, processor to processor) as supplemented by the UK Addendum where UK data is involved, with the docking clause disapplied, Clause 17 governed by the law of England and Wales and Clause 18 disputes heard in the courts of England and Wales. Annex A serves as the SCCs' Annex I.B, Annex B as Annex II, and Annex C as the list of authorised sub-processors.
8.3 We maintain transfer risk assessments for each such transfer and will make them available on reasonable request.
8.4 Transfers you initiate to an MCP client or other external destination fall outside 8.2. Those transfers are your instruction to a recipient you chose, and you are responsible for establishing a lawful transfer mechanism with that recipient. We will tell you, in the Service, which tools were called and when, so you can evidence what was disclosed.
We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken or proposed, and a contact point. We will provide further information as the investigation progresses and reasonable assistance with any notification you must make to a supervisory authority or to data subjects. Our notification is not an admission of fault.
On reasonable written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a breach, we will make available the information reasonably necessary to demonstrate compliance with this Addendum — including our security documentation, penetration test summaries and Sub-processor contract terms. Where that is insufficient for your regulatory obligations, we will accommodate an audit conducted by you or an independent auditor bound by confidentiality, at your cost, on at least 30 days' notice, at a mutually agreed time, and subject to reasonable restrictions to protect our other customers' data and the security of our systems.
11.1 You may export Customer Personal Data in a structured, machine-readable format at any time during the term and during the 90-day period following termination.
11.2 We will delete all Customer Personal Data 90 days after termination or, if earlier, when you trigger deletion in the Service. Deletion removes data from live systems immediately; encrypted backups age out within 35 days thereafter, during which the data is not accessible for ordinary use. We may retain data where required by law, in which case this Addendum continues to apply to it. On request we will certify deletion in writing.
Each party's liability under this Addendum is subject to the limitations and exclusions in the Agreement, save that nothing limits liability that cannot lawfully be limited, including liability to data subjects under Article 82 of the GDPR. This Addendum takes effect when you accept the Agreement and continues until all Customer Personal Data has been deleted or returned.
| Subject matter | Provision of the MetricFabric.io Service: ingestion, storage, querying and reporting of search and advertising performance data from the Controller's connected Google accounts, and provision of a read-only MCP interface to that data. |
| Duration | For the term of the Agreement, plus the 90-day post-termination period in clause 11. |
| Nature and purpose | Automated retrieval from Google APIs and, where configured, from the Controller's BigQuery bulk export; storage in a multi-tenant database with row-level tenant isolation; deterministic rule-based analysis; presentation in dashboards, exports, scheduled reports and MCP tool responses. |
| Categories of data subjects | The Controller's personnel and authorised users; where applicable, the Controller's own clients' personnel. Search and advertising performance data is aggregated by Google and is not intended to identify individuals, though free-text search queries may incidentally contain personal data entered by end users of search engines. |
| Categories of personal data | (a) User identity and contact data: name, email address, workspace membership, authentication credentials. (b) Google service data: Search Console search-analytics rows (query, page, country, device, date and metrics); GA4 aggregate report rows (sessions, engaged sessions, conversions and key events by landing page, channel and date); Google Ads campaign, ad group, keyword and search-term reports with cost and conversion metrics. (c) OAuth tokens for the connected accounts. (d) Service logs: IP address, user agent, authentication events, ingestion job records, MCP tool-call records. |
| Special category data | None is requested or required. The Controller must not use the Service to process special category data, and acknowledges that free-text search queries are outside either party's control. |
| Frequency of transfer | Continuous for the Service; scheduled daily for ingestion; on demand for exports, reports and MCP requests. |
| Encryption | TLS 1.2 or better for all data in transit, HSTS enforced. AES-256 at rest for databases, object storage and backups. OAuth tokens and MCP tokens held in a dedicated secrets store with envelope encryption and excluded from all logs. |
| Tenant isolation | Every row carries a tenant identifier; isolation is enforced in the data layer by row-level security rather than by application code alone. MCP tokens are scoped to a single workspace. |
| Access control | Least privilege, named individual accounts, mandatory multi-factor authentication for production access, no shared credentials, quarterly access review, revocation within one working day of role change or departure. |
| Logging and monitoring | Administrative and authentication events logged to append-only storage retained 12 months; alerting on anomalous access and on failed ingestion; MCP calls logged per workspace and surfaced to the Controller. |
| Secure development | Peer-reviewed changes, automated dependency and vulnerability scanning, secrets scanning in CI, separate staging environment with no production data, and third-party penetration testing. |
| Resilience | Encrypted daily backups with 35-day retention, restore tested quarterly, documented recovery objectives of RPO 24 hours and RTO 8 hours. |
| Physical security | Inherited from Hetzner's ISO/IEC 27001-certified German data centres; we operate no premises holding Customer Personal Data. |
| Organisational | Written security and incident-response policies, annual review; confidentiality obligations and data-protection training for all personnel; records of processing maintained; deletion routines executed on a schedule and verifiable on request. |
| Entity | Processing | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Hosting, database and object storage — all ingested data | Germany | None required (EEA) |
| Cloudflare, Inc. | DNS, TLS termination, CDN, DDoS protection | EU points of presence; US parent | SCCs + UK Addendum |
| Stripe Payments Europe, Ltd | Billing and payments — billing identity only; no ingested Google data | Ireland, with US affiliate access | SCCs + UK Addendum |
| Resend, Inc. | Transactional email and scheduled report delivery — recipient address and report contents | United States | SCCs + UK Addendum |
Controller-directed recipients (not Sub-processors). Where the Controller connects an MCP client — for example Anthropic's Claude, OpenAI's ChatGPT, or any other MCP-capable client — that provider receives Customer Personal Data only in response to requests the Controller initiates from a client the Controller configured and authorised with a token the Controller created. Those providers act on the Controller's instructions under the Controller's own terms with them; they are not engaged by us, we do not select them, and clause 8.2 does not cover the transfer. The Controller is responsible for the lawful basis and transfer mechanism for that disclosure.
Where MetricFabric.io itself uses a language model to narrate the output of its own deterministic analyses, that provider will be listed here as a Sub-processor before the feature is enabled, with 30 days' notice under clause 6.3, and will be contractually prohibited from training on the content.