1.1This addendum forms part of the terms of service and applies wherever Admarket and you process personal data in connection with the platform and either of us is subject to the UK GDPR, the EU GDPR, or another data protection law that requires terms of this kind.
1.2It takes effect when you accept the terms of service. There is nothing to sign and nothing to return. If your organisation needs a countersigned copy for its own records, ask us through the support system and we will provide one naming your workspace.
1.3Where this addendum and the terms of service differ on data protection, this addendum governs. Where it and the privacy policy differ on how the platform actually works, the privacy policy is the description and this one is the contract; they are written to say the same thing.
1.4Words defined in the UK GDPR and the EU GDPR — controller, processor, personal data, processing, data subject, personal data breach, supervisory authority — carry those meanings here.
2.1Most data protection addenda assume one shape: the customer instructs, the supplier processes. That is not how a marketplace works, and writing it that way would misdescribe almost everything Admarket does.
2.2For the platform itself, Admarket is the controller. We decide what an account holds, what an order records, how long proof is kept and what the audit log captures. We are not doing that on your instructions and we could not stop doing it if you instructed us to.
2.3For data that reaches you through a transaction, you are a separate and independent controller. When you receive the buyer behind a booking, the applicant behind a CV or the guardian behind a sponsorship enquiry, you decide for yourself what you do with it, and you answer for it.
2.4There is a third, narrower case: content you put into your own workspace, and material delivered into it for you, which we hold and transmit for you and do not use for our own purposes. There we act on your instructions and Part B applies.
| Data | Admarket's role | Your role | Which part applies |
|---|---|---|---|
| Your account, workspace, members, listings, orders, held payments, proof, claims, invoices, tickets and the audit record behind them | Controller | Data subject, or controller of your own team's data | Part A |
| The other party's details that a transaction shows you — buyer or seller identity, billing details, creative, proof, messages | Controller of the platform record | Independent controller of what you then do with it | Part A |
| Applications, enquiries and messages delivered into your workspace because you posted a job, a sponsorship post or a listing | Controller of delivery; processor of the copy held in your workspace | Controller | Part A and Part B |
| Content you upload into your workspace that contains personal data — creative files, case studies, documents, attachments, your own records | Processor | Controller | Part B |
| Payment and payout data collected by our payment partner | Controller for our purposes; the partner is a controller for its own | Data subject, or controller of your payee data | Part A |
Why the split is stated rather than smoothed over — An addendum that called Admarket your processor for everything would be unenforceable in the places it mattered and would give you a right of instruction over records — orders, proof, the audit log — that we cannot take instructions about. The narrow processor part is real, and it is where you need Article 28 language.
3.1This part applies to the data in the first, second and fifth rows of the table above. Neither of us processes it on the other's instructions, and neither of us is the other's processor for it.
3.2Each of us, independently, will:
3.3Data a transaction gives you may be used for that transaction and for the records, accounting and tax obligations that follow it. It may not be used to build a marketing list, sold, shared with anyone who was not party to the transaction, or enriched against another source. That restriction is in section 8 of the terms of service and it is a contractual limit as well as a legal one.
3.4You must keep it no longer than your own purpose and your own law allow, and delete it when that period ends. We do not supervise this and cannot; it is yours.
3.5If we tell you that a data subject has exercised a right that affects data you received from us — erasure, objection, withdrawal of consent — you will act on it in respect of your own copy unless you have your own lawful basis to keep it, and you will tell us which.
3.6Neither of us is liable for the other's processing. Where a claim, fine or award arises from one party's own processing, that party bears it.
4.1This part applies to workspace content: what you upload into your own workspace, and what is delivered into it for you. In respect of it you are the controller and Admarket is your processor.
4.2We process it only on your documented instructions. Your instructions are: the terms of service, this addendum, and the operations you perform through the platform and its settings. There is no separate instruction channel, and a request outside those is a change we have to agree.
4.3We will tell you if an instruction appears to us to infringe data protection law, and we may decline to act on it until it is resolved.
4.4Where a law that applies to us requires us to process it otherwise, we will tell you before doing so unless that law forbids us from telling you on important grounds of public interest.
4.5We will not use workspace content to build a profile of anyone, sell it, or disclose it to anyone other than the sub-processors named under section 6 and the recipients the platform's own operation requires.
4.6Automated screening and machine translation run over content published to the platform, as described in sections 6 and 7 of the privacy policy. Those are part of operating the platform rather than a separate purpose, and they are covered by your instructions here.
5.1This section is the description Article 28(3) requires, for the processing in Part B.
| Particular | Detail |
|---|---|
| Subject matter | Hosting, storing, transmitting and displaying the content of your workspace so that the platform can provide the marketplace, messaging, job and sponsorship services to you. |
| Duration | For as long as you hold an account, plus the retention periods set out in section 15 of the privacy policy, plus any period a law requires us to keep a record. |
| Nature of the processing | Collection, recording, organisation, storage, retrieval, transmission, display, translation, automated screening for prohibited content, backup, and erasure. |
| Purpose | Providing the platform to you, keeping it safe and lawful, and meeting our own legal obligations. |
| Types of personal data | Names, business and personal contact details, account identifiers, role and workspace membership, message content and attachments, CVs and application content, images and video that may show identifiable people, location data embedded in submitted media, and billing details. Content you choose to upload may contain other types; you decide what you upload. |
| Categories of data subject | Your team members, your counterparties and their staff, job applicants, sponsorship enquirers, guardians of minors where a sponsorship subject is under 18, and any individual appearing in content you upload. |
| Special category data | Not requested and not required by the platform. If you upload it, you do so on your own lawful basis and you tell us in advance where the law requires additional measures. |
5.2Do not upload special category data, criminal offence data or children's data into workspace content unless you have a lawful basis for it and the platform actually needs it. The marketplace is not designed around any of them.
6.1In respect of Part B processing, Admarket will:
6.2Where a data subject contacts us directly about data we hold for you under Part B, we will not respond substantively on your behalf. We will tell them to contact you, and tell you it happened, unless the law requires otherwise.
6.3Where you need to respond to a request and the data sits in your workspace, the platform's own export and deletion tools are the assistance, and we will help beyond them where they do not reach.
7.1You give Admarket general authorisation to engage sub-processors. The ones we use are named, with what each does and where it processes, on the sub-processor page, which is part of this addendum.
7.2Every sub-processor is engaged under written terms imposing obligations no less protective than these, and we remain fully liable to you for what they do.
7.3We will give at least 30 days' notice before adding or replacing a sub-processor, by updating that page and notifying the account owner of every workspace. Subscribe to it and you will not have to watch it.
7.4You may object on reasonable data protection grounds within those 30 days, by telling us through the support system and saying what the ground is. We will work with you to find a way forward — a different configuration, or an explanation of a safeguard you had not seen.
7.5If we cannot resolve it, you may close your account and stop using the platform, and we will refund any fee paid for a service you have not received. There is no other remedy for an objection, because we cannot operate a marketplace on a different infrastructure for each customer.
7.6We may add a sub-processor without notice where it is needed urgently to protect the platform or its users from a security threat. We will tell you as soon as we reasonably can afterwards.
8.1Admarket is operated from the United States and its providers operate internationally. Personal data will be transferred to and processed in countries other than yours, including the United States.
8.2Where data is transferred out of the United Kingdom or the European Economic Area, the transfer relies on an adequacy decision where one covers it, and otherwise on the Standard Contractual Clauses approved by the European Commission, with the UK International Data Transfer Addendum where the transfer is from the United Kingdom.
8.3Those clauses are incorporated into this addendum by reference and take effect between us on the appropriate module — controller to controller for Part A, controller to processor for Part B. Where the clauses require a selection, it is made as follows: the optional docking clause applies; the governing law and forum are those of Ireland for an EU transfer; the audit and sub-processor provisions operate as described in sections 6 and 10; and the technical and organisational measures annex is section 11 of this addendum together with the sub-processor page.
8.4Where the clauses and this addendum conflict, the clauses prevail to the extent of the conflict.
8.5Automated screening and machine translation are not pinned to a region. Content sent to that provider may be processed in any country in which it operates, and we do not choose which. Messages, applications, tickets and payment data are not sent to it at all.
8.6You can ask us for details of the safeguards applied to a particular transfer, and we will provide what we can without exposing another customer's arrangements.
9.1When your account closes, workspace content is deleted or returned at your choice, within the periods set out in section 15 of the privacy policy.
9.2You can export your own data from the platform while the account is open. Ask before you close it; exporting is easier than requesting.
9.3We keep what a law requires us to keep, and what we need to establish or defend a legal claim — order records, invoices, held payment and payout records, proof relating to a disputed order, and the audit log. Those are retained for the stated period and then deleted.
9.4Backups are cycled rather than edited. Data deleted from the live platform persists in backups until they age out, and is not restored into the live platform once deleted.
10.1We will make available the information reasonably needed to demonstrate compliance with Article 28 — this addendum, the sub-processor page, the privacy policy, the measures in section 11, and answers to a reasonable security questionnaire.
10.2Where that is not enough, you may audit, on 30 days' written notice, once in any twelve months, during business hours, without unreasonable disruption, and under confidentiality. You may audit more often if a supervisory authority requires it or following a personal data breach affecting your data.
10.3An audit covers our processing of your data. It does not extend to another customer's data, to our systems in a way that would expose one, or to physical access to a sub-processor's data centres — for those, we provide what the sub-processor makes available.
10.4You bear your own costs, and ours where an audit goes beyond one a year or beyond a reasonable scope.
11.1These are the measures in place. They are described at a level that is accurate and that does not itself create a weakness, and they are the annex the Standard Contractual Clauses require.
| Area | Measure |
|---|---|
| Transport security | All traffic to the platform and its API is served over TLS through a content delivery network that terminates it at the edge. Session cookies are marked secure in production. |
| Access control in the database | Row level security is enforced in the database itself rather than only in application code, so a query that should not see a row does not see it even if application logic is wrong. The application connects as a role that is subject to those policies. |
| Authentication | Email and password, with sessions carried in an HTTP-only cookie that no script on the page can read. Requests are protected by origin checking. Two-factor authentication is available to any account that wants it. |
| Session revocation | Revoking a session takes effect on the next request rather than at the end of a cache window. A session cache that would have kept a revoked session alive for several minutes was removed for that reason. |
| Role separation | Access follows a member's role in a workspace and the grants attached to it. Staff access to the admin surface is separate from ordinary account access and is not available to a customer account. |
| Audit logging | Staff actions that change customer data are recorded to an append-only audit log with the actor, the action and the time. Coverage is enforced by an automated test that fails the build if a recorded action stops being recorded. |
| Stored files | Media is held in object storage that is not publicly listable and is reached through short-lived signed links. The role that issues them is scoped to the prefixes it is allowed to sign for. |
| Payment data | Card details are collected by our payment partner and never reach Admarket's systems. We hold the partner's identifiers and the amounts, not the instrument. |
| Content screening | Submitted content passes automated screening, and anything flagged reaches a human reviewer. Rejected content is queued for human review rather than decided by machine alone. |
| Timestamps and traceability | Every mutation records when it happened and, where it changes state, when it transitioned. Records are reconstructible from the log rather than from memory. |
| Rate limiting | Requests are throttled per client at the edge and in the application, with the client identified from the trusted proxy chain rather than from a header any caller can set. |
| Segregation | Production is separate from development, and production data is not copied into development environments. |
| Personnel | Everyone with access is under a binding duty of confidentiality, and access is granted by role and removed when it ends. |
| Resilience | The database is backed up on a schedule, and restoration is tested rather than assumed. |
11.2We may change these measures as the platform develops. A change will not materially reduce the overall level of security.
12.1We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed under this addendum.
12.2The notice will describe, as far as we know it at the time:
12.3Where we do not have all of it at once, we will send what we have and follow up rather than wait for a complete picture.
12.4Notifying you is not an admission of fault or of liability by either of us.
12.5Notifying a supervisory authority and the affected data subjects, where that is required, is the controller's decision and obligation. For Part B data that is yours; we will give you what you need to make it.
12.6You will not make a public statement identifying Admarket in relation to a breach without consulting us first, unless the law requires you to.
13.1Each party's liability under this addendum is subject to the limitations and exclusions in section 29 of the terms of service, and those limits apply to all claims arising out of this addendum in aggregate with all other claims under the terms.
13.2Nothing here limits a data subject's rights under data protection law, or either party's liability to a supervisory authority.
13.3Where one of us pays compensation or a fine for which the other is responsible under Article 82, it may recover the other's share.
14.1This addendum runs for as long as we process personal data in connection with the platform, and the obligations that by their nature should survive — confidentiality, deletion, transfers, liability — survive it.
14.2We may update it to reflect a change in law, in the platform, or in our sub-processors. Material changes are notified before they take effect, in the same way as a change to the terms.
14.3If any part of it is held invalid, the rest continues, and the invalid part is read down to the narrowest form that would be valid.
14.4This addendum, the terms of service, the privacy policy, the cookie policy and the sub-processor page are the whole of the data protection arrangement between us. A purchase order, a supplier portal's standard terms, or a form sent with an invoice does not vary it.
15.1Data protection questions, requests for a countersigned copy, sub-processor objections and audit requests reach us through the support system on the platform. If you do not have an account, use the public contact page.
15.2Admarket has not yet appointed representatives in the European Union and the United Kingdom under Article 27. Until it does, direct enquiries to the contact route above and we will route them.
See also the sub-processor list, the privacy policy and the terms of service. Questions? Message the team.
Also kept in the address, so a page you share opens in the language you read it in.
광고를 원하는 국가입니다. 해당 국가의 광고 지면이 목록 상단에 표시됩니다. 언제든지 어디서나 예약할 수 있으며, 설정은 언제든 변경 가능합니다.
Following United Kingdom. Pick one to keep it whichever country you browse.
Prices are converted for reference at an indicative rate (as of 2026-09-23). Every booking is charged in the currency the seller listed in, at the price they set.