GDPR · Last updated 28 July 2026
For personal data contained in your Microsoft directory and processed to deliver the service, you are the data controller and Footer365 is the data processor. This addendum applies where we process such personal data on your behalf, and forms part of the terms of service.
| Item | Detail |
|---|---|
| Subject matter | Provision of the Footer365 email signature and marketing service |
| Duration | For the term of the subscription, plus deletion period |
| Nature & purpose | Syncing directory attributes and injecting signatures into outbound mail |
| Types of personal data | Names, work contact details, job titles, photos and similar directory attributes; account contact details |
| Categories of data subject | Your staff and mailbox owners, and your named account contacts |
We process personal data only on your documented instructions, including as set out in the agreement and this addendum, unless required by law - in which case we will inform you where legally permitted.
Personnel authorised to process personal data are bound by appropriate confidentiality obligations.
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, least-privilege access controls, and audit logging. See our security page.
You authorise our use of the sub-processors listed on our sub-processors page. We impose data protection obligations on each sub-processor no less protective than those in this addendum, and remain responsible for their performance. We will give notice of intended changes so you may object on reasonable grounds.
Taking into account the nature of processing, we will assist you by appropriate measures to respond to requests from data subjects exercising their rights, and to meet your obligations relating to security, breach notification, impact assessments and consultation.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.
You may select the processing region. Where personal data is transferred outside the UK or EEA, we rely on an appropriate transfer mechanism such as the UK International Data Transfer Agreement or Standard Contractual Clauses, together with any required supplementary measures.
On termination, or on your instruction, we will delete or return the personal data we process on your behalf and delete existing copies, unless retention is required by law. Offboarding re-enables native Microsoft signature handling and removes synced directory data.
We will make available information necessary to demonstrate compliance with this addendum and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and security conditions.