Kliksight
Kliksight (Pty) Ltd · Registration 2026/622670/07 · South Africa

Data Processing Agreement

Version 34 · effective 25 August 2026

DATA PROCESSING AGREEMENT

incorporating operator provisions under the Protection of Personal Information Act 4 of 2013 (South Africa), processor terms under Article 28 GDPR and the UK GDPR, and United States state privacy addendum

Version 34 · 25 August 2026

between

KLIKSIGHT (PTY) LTD (registration number 2026/622670/07), a private company incorporated in the Republic of South Africa, with its registered address at Stanley and Dock Road, Cape Town, Western Cape, 8001 ("Kliksight")

and

THE CUSTOMER, being the Party accepting this Agreement by the electronic acceptance mechanism described in clause 21.6, whose name, registration number and address are those recorded in the Customer’s account with Kliksight at the Acceptance Date ("Customer")

(each a "Party" and together the "Parties")

This Agreement forms part of, and is incorporated into, the Kliksight Terms of Service or other agreement between the Parties for the provision of the Services (the "Principal Agreement").

BACKGROUND

(A) Kliksight provides an invalid-traffic detection, measurement and reporting service, delivered by means of a JavaScript tag (the "Tag") deployed on websites operated by the Customer or by the Customer's own clients, together with dashboards, white-label reporting and dispute-evidence tooling (the "Services"). Classification under the Services is event-level only: traffic and click events may be classified as invalid; no natural person or device is classified as fraudulent.

(B) In providing the Services, Kliksight processes personal information on the Customer's behalf and on its documented instructions. The Parties intend this Agreement to satisfy sections 19 to 21 of POPIA as regards the operator relationship, Article 28(3) of the GDPR and the UK GDPR where those laws apply, and applicable US State Privacy Laws as set out in Annex 6.

(C) The Customer may enter into this Agreement in its own capacity as responsible party / controller, or as an operator / processor acting for its own clients. Clause 2 governs both configurations.

NOTICE: LIMITATION OF LIABILITY AND INDEMNITY PROVISIONS (section 49, Consumer Protection Act 68 of 2008)
The Customer's attention is specifically drawn to clause 2.3 (authority warranty and indemnity), clause 6.2 (consent indemnity), clause 7.3 (child-directed indemnity) and clause 19 (limitation of liability), each of which is set in bold type below and each of which limits Kliksight's risk or liability, constitutes an assumption of risk by the Customer, or imposes an obligation on the Customer to indemnify Kliksight. The Customer confirms that it has read those clauses, that they are in plain language, and that it had an adequate opportunity to consider them and to request an explanation of their meaning and effect before entering into this Agreement.

1. DEFINITIONS AND INTERPRETATION

1.1 In this Agreement, unless the context indicates otherwise:

"Aggregated Data" means detections, statistical aggregates, scores, models and Evidence Records derived by Kliksight from Customer Personal Data in the course of providing the Services, in a form that is no longer attributable to an identifiable data subject, as further described in clause 15 and Annex 4.

"Anonymisation and Aggregation Methodology" means the document of that title maintained by Kliksight and made available in the dashboard, as updated from time to time, provided that no update materially degrades the level of de-identification achieved under it.

"Benchmark Data" means the aggregate, cross-customer comparative performance statistics described in clause 4A, limited to the Permitted Benchmark Set.

"Claim Outcome Intelligence" means the records of the adjudication of Claim Packages by advertising platforms described in clause 4B, limited to the fields listed in clause 4B.2 and containing no personal information / personal data.

"Claim Package" means a compilation of event-level records (including click identifiers, timestamps, IP-derived indicators, user-agent strings and related metadata) assembled by Kliksight for submission to an advertising platform in support of an invalid-activity credit claim or dispute, as authorised under clause 5. A Claim Package comprises the compiled event-level records themselves; summary or status information about a claim or prospective claim (including claimable amounts, filing deadlines and adjudication status) is not part of the Claim Package, is retained under its own class, and, where it falls within clause 4B.2, is governed by clause 4B.

"Customer Personal Data" means personal information / personal data processed by Kliksight on behalf of the Customer in connection with the Services, as particularised in Annex 1. Shared Threat Signals, Benchmark Data, Claim Outcome Intelligence and Aggregated Data fall outside this definition only to the extent that they do not in fact constitute personal information / personal data; clauses 4.5, 4A.6 and 4B.5 govern the position where they do.

"Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under this Agreement, including POPIA, the GDPR, the UK GDPR and the Data Protection Act 2018 (UK), the ePrivacy Directive 2002/58/EC and PECR as implemented, the US State Privacy Laws listed in Annex 6, and COPPA, in each case as amended or replaced.

"Evidence Records" means the per-detection records retained by Kliksight to substantiate a detection determination, comprising the fields listed in Annex 4.

"GDPR" means Regulation (EU) 2016/679, and "UK GDPR" has the meaning given in the Data Protection Act 2018 (UK).

"POPIA" means the Protection of Personal Information Act 4 of 2013 (South Africa). "Responsible party", "operator", "personal information", "data subject", "special personal information" and "Regulator" bear the meanings given in POPIA.

"Security Compromise" means a "personal data breach" as defined in the GDPR / UK GDPR and the circumstances contemplated in section 22 of POPIA, namely reasonable grounds to believe that Customer Personal Data has been accessed or acquired by an unauthorised person.

"Shared Threat Signals" means the aggregate, cross-customer invalid-traffic intelligence signals described in clause 4, limited to the Permitted Signal Set.

"Sub-operator" means any third party appointed by Kliksight to process Customer Personal Data on Kliksight's behalf (a sub-processor for the purposes of the GDPR and UK GDPR).

"US State Privacy Laws" means the laws listed in Annex 6, including the CCPA as amended by the CPRA.

"Acceptance Date" means the date on which the Customer accepts the Principal Agreement, whether by signature or by the electronic acceptance mechanism Kliksight presents at sign-up, that acceptance being the date this Agreement commences under clause 20.1.

1.2 Terms defined in one Data Protection Law shall be read, where another Data Protection Law applies, as referring to the equivalent concept under that law (in particular: responsible party / controller / business; operator / processor / service provider; personal information / personal data).

1.3 If there is a conflict between this Agreement and the Principal Agreement in relation to the processing of Customer Personal Data, this Agreement prevails. If there is a conflict between the body of this Agreement and an Annex, the Annex prevails to the extent of the conflict, save that nothing in an Annex reduces the protections in clauses 4, 4A, 4B, 15 or 16; provided always that the Standard Contractual Clauses and the UK Addendum incorporated under Annex 5 prevail over this Agreement, including this clause 1.3, to the extent of any conflict.

1.4 Any entry in this Agreement, including in an Annex, that is expressed conditionally or by reference to a capability or occurrence ("where enabled", "once in operation", "compiled on demand", "from first use" and like expressions) describes processing, measures or data classes that apply where and from the time the relevant capability is enabled or the relevant occurrence first takes place. No such entry is a representation or warranty that the capability exists, or that the occurrence has taken place, at the Acceptance Date.

2. ROLES OF THE PARTIES; DUAL CONFIGURATION

2.1 As between the Parties, Kliksight is an operator (processor / service provider) and the Customer is, in respect of each website on which the Tag is deployed (each a "Property"), either:

(a) the responsible party / controller of the Customer Personal Data collected from that Property ("Controller Configuration"); or

(b) an operator / processor acting on behalf of its own client, which is the responsible party / controller for that Property ("Processor Configuration"), in which case Kliksight acts as the Customer's sub-operator / sub-processor and, where the GDPR applies, Module 3 of the SCCs applies as set out in Annex 5.

2.2 The Customer shall designate the applicable configuration for each Property in writing (including, where that functionality is made available, in the Kliksight dashboard) and keep that designation accurate. Absent a designation, the Controller Configuration is deemed to apply.

2.3 Where the Processor Configuration applies, the Customer warrants that: (a) it is authorised by the relevant responsible party / controller to appoint Kliksight on the terms of this Agreement, including the authorisations in clauses 4 and 5, the international transfers in clause 14 and the Sub-operators in Annex 3; (b) its contract with that responsible party / controller permits the processing described in this Agreement; and (c) it will pass through to Kliksight, and promptly relay, only instructions that originate from or are consistent with the instructions of that responsible party / controller. The Customer indemnifies Kliksight against losses arising from a breach of this clause 2.3; this indemnity is uncapped in respect of third-party claims, administrative fines and data-subject compensation arising directly from the absence of the warranted authorisation, and is otherwise subject to clause 19.

2.4 Nothing in this Agreement transfers to Kliksight any responsibility of the Customer or its clients as responsible party / controller, including the duties of notification to data subjects, lawful basis and consent under clause 6.

3. INSTRUCTIONS AND SCOPE OF PROCESSING

3.1 Kliksight shall process Customer Personal Data only on the Customer's documented instructions, including as regards cross-border transfers, unless required to do otherwise by a law to which Kliksight is subject; in that case Kliksight shall inform the Customer of the legal requirement before processing, unless that law prohibits doing so on important grounds of public interest.

3.2 The Parties agree that this Agreement, the Principal Agreement, the configuration options selected by the Customer in the dashboard, and the authorisations in clauses 4 and 5 together constitute the Customer's complete documented instructions at the Acceptance Date. Additional instructions require written agreement, and Kliksight may charge reasonable fees for instructions that materially exceed the scope of the Services.

3.3 Kliksight shall immediately inform the Customer if, in its opinion, an instruction infringes a Data Protection Law, and may suspend execution of that instruction until it is confirmed or varied. Kliksight is not obliged to undertake a legal review of the Customer's instructions.

3.4 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

3.5 Where report verification is made available, the Customer may elect, in writing (including, where that functionality is made available, in the Kliksight dashboard), that reports issued to it carry a verification code and link permitting any holder of the code to confirm, without authentication, that Kliksight issued the report, its date, the account and period it covers, the figures it stated, the version of the method that produced them, and that the document is unaltered since issue. That election is the Customer’s documented instruction to disclose those figures to any holder of the code, and the Customer warrants that it is authorised, by the person or entity to whom it supplies the report, to make that election in respect of that report. Absent an election, no verification code or link is issued. The Customer may suppress verification for an individual report and may instruct revocation of an issued code at any time, on which Kliksight shall cause the code to cease to verify. A verification response discloses only the attested figures and the matters listed above; it shall not disclose Customer Personal Data, event-level records, Claim Packages or any part of them, and the safeguards in Annex 2 apply to the verification surface. Disclosure made in accordance with this clause is not a breach of clause 8.

4. SHARED THREAT SIGNAL AUTHORISATION

4.1 The Customer expressly instructs and authorises Kliksight to derive Shared Threat Signals from Customer Personal Data and to use them across Kliksight's customer base for the sole purposes of detecting, measuring, preventing and mitigating invalid traffic, automated and bot activity and related threats to advertising integrity (the "Invalid Traffic Purpose"). The Parties record that this processing is carried out on the Customer's documented instructions and, accordingly, that Article 28(10) GDPR / UK GDPR and the equivalent principles under POPIA do not operate to make Kliksight a responsible party / controller in respect of it.

4.2 The Shared Threat Signals are limited to the following exhaustive list (the "Permitted Signal Set"):

(a) network prefix at /24 granularity only (IPv4; IPv6 events carry no prefix pending a documented generalisation policy);

(b) autonomous system number (ASN), ASN organisation and country;

(c) datacenter classification of the originating network;

(d) generalised user-agent attributes limited to browser family, browser major version, operating system family and device class; and

(e) timing profiles expressed as distribution parameters only (median, variance and bucketed histograms).

4.3 Kliksight shall not: (a) produce any output that discloses to one customer information about an identified or identifiable visitor to another customer's Property; (b) include in the Shared Threat Signals any raw IP address, IP hash, click identifier, raw user-agent string, per-visitor event sequence, or content of any Property; (c) use Shared Threat Signals for any purpose other than the Invalid Traffic Purpose (including advertising, profiling for marketing, or enrichment services); or (d) classify any natural person or device as fraudulent, or create any person-level or device-level fraud score.

4.4 Derivation of Shared Threat Signals is subject to the safeguards documented in Annex 2, including a minimum contributor threshold counting both distinct Properties and distinct customers before any signal is emitted, exclusion of test traffic and of Properties declared or determined to be child-directed, and provenance controls preventing a signal derived from the shared layer from contributing back to it. These thresholds and suppression parameters are calibrated against singling-out, linkability and inference risks and are periodically reviewed and adjusted as traffic volumes and re-identification techniques evolve; no threshold is treated as achieving anonymity once and for all.

4.5 The Parties agree that Shared Threat Signals, once derived in accordance with this clause 4, are anonymous, do not constitute personal information / personal data, and are the sole property of Kliksight, which may retain and use them after termination for the Invalid Traffic Purpose. This clause is without prejudice to clause 16 (no re-identification). To the extent that any Shared Threat Signal is nonetheless found to constitute personal information / personal data in any configuration, it is processed on the instruction in clause 4.1, and clauses 8 (confidentiality), 9 (security), 14 (transfers), 15 (retention and deletion) and 16 apply to it as if it were Customer Personal Data.

4.6 Contribution to and consumption of Shared Threat Signals is a severable feature: the Customer may disable contribution for any Property by written notice to Kliksight (or, where that functionality is made available, in the dashboard), with effect within five (5) business days, and clause 17 governs suspension.

4.7 If, notwithstanding clause 4.1, Kliksight is finally determined by a competent supervisory authority, the Regulator or a court to act as a responsible party / controller in respect of the derivation or use of Shared Threat Signals, then: (a) that processing is conducted on the lawful basis of the legitimate interests of Kliksight and its customers in ensuring the security and integrity of advertising systems and preventing invalid traffic, being interests of the kind expressly recognised in Recitals 47 and 49 GDPR and in section 11(1)(f) of POPIA; (b) Kliksight maintains a documented legitimate interests assessment for that processing, available to the Customer on request; (c) the validity of the remainder of this Agreement and the Parties' respective positions under it are unaffected; and (d) the feature-scoped severability in clause 17 applies to any resulting suspension or restriction.

4A. BENCHMARK DATA AUTHORISATION (COMPARATIVE STATISTICS)

4A.1 The Customer expressly instructs and authorises Kliksight to derive Benchmark Data from Customer Personal Data, exclusively by way of the deidentified aggregate layer described in clause 4A.4, and to display Benchmark Data to Kliksight’s other customers within the Services, for the sole purpose of enabling customers to assess the performance of their advertising traffic and invalid-traffic recovery against population-level statistics (the "Benchmark Purpose"). The Parties record that this processing is carried out on the Customer’s documented instructions and, accordingly, that Article 28(10) GDPR / UK GDPR and the equivalent principles under POPIA do not operate to make Kliksight a responsible party / controller in respect of it.

4A.2 Benchmark Data is limited to the following exhaustive list of metrics (the "Permitted Benchmark Set"), each expressed as a ratio, rate or percentage only:

(a) arrival rate;

(b) invalid-traffic rate;

(c) platform-credited rate;

(d) recoverable rate; and

(e) unattributed share.

4A.3 Kliksight shall not: (a) include in any Benchmark Data output any currency amount, spend figure or revenue figure; (b) produce any output that attributes a statistic to, or permits the identification of, an individual customer, client, Property or campaign of another customer, whether directly or through narrowing of the comparison population; (c) include in Benchmark Data any personal information / personal data, any element of the Permitted Signal Set, or any event-level record; (d) use Benchmark Data for any purpose other than the Benchmark Purpose (including advertising, marketing or enrichment services); or (e) compute or display any benchmark statistic unless the contributor thresholds in clause 4A.4 are satisfied for the relevant comparison population.

4A.4 Benchmark Data is derived exclusively from detections and statistical aggregates that have already been aggregated and deidentified in accordance with Annex 2, and not from raw event data. A benchmark statistic is computed or displayed only where the comparison population comprises at least ten (10) distinct customers and twenty-five (25) distinct end-client accounts, with no single customer’s data comprising more than twenty-five per cent (25%) of the events in the comparison population, and is in any event sufficient to prevent the singling out of any customer, Property or data subject; outputs are limited to medians, percentile bands and population distributions. Benchmark statistics are computed as point-in-time releases, no less frequently than monthly, and not in response to individual queries; each comparison population is fixed at release time and cannot be narrowed, filtered or segmented at display time. These thresholds are calibrated against singling-out, linkability and inference risks and are periodically reviewed and adjusted in the same manner as clause 4.4; no threshold is treated as achieving anonymity once and for all.

4A.5 For the purposes of the US State Privacy Laws, the Parties record that: (a) Benchmark Data is derived from, and constitutes, deidentified and aggregate consumer information within the meaning of sections 1798.140(m) and 1798.140(b) CCPA, processed subject to clause 16, which the Parties adopt as the contractual commitment required by section 1798.140(m); and (b) no personal information is retained, used or disclosed to perform services on behalf of another person within the meaning of Cal. Code Regs. tit. 11, § 7050(a)(3), the comparative statistics being computed solely within the deidentified aggregate layer. Annex 6 applies.

4A.6 The Parties agree that Benchmark Data, once derived in accordance with this clause 4A, is anonymous, does not constitute personal information / personal data, and is the sole property of Kliksight, which may retain and use it after termination for the Benchmark Purpose. This clause is without prejudice to clause 16 (no re-identification). To the extent that any Benchmark Data is nonetheless found to constitute personal information / personal data in any configuration, it is processed on the instruction in clause 4A.1, and clauses 8 (confidentiality), 9 (security), 14 (transfers), 15 (retention and deletion) and 16 apply to it as if it were Customer Personal Data.

4A.7 If, notwithstanding clause 4A.1, Kliksight is finally determined by a competent supervisory authority, the Regulator or a court to act as a responsible party / controller in respect of the derivation or display of Benchmark Data, then clause 4.7(a) to (d) applies mutatis mutandis, the relevant legitimate interests being those of Kliksight and its customers in the measurement and improvement of advertising traffic quality and invalid-traffic recovery across the customer base.

4A.8 Contribution to and inclusion in Benchmark Data is a severable feature, separate from and independent of clauses 4 and 4B: the Customer may disable contribution for any Property by written notice to Kliksight (or, where that functionality is made available, in the dashboard), with effect within five (5) business days, and clause 17 governs suspension. Disabling contribution removes the Customer’s data from every release computed after the effective date of disablement. A benchmark statistic is “published” for the purposes of this clause when it is included in a release made available for display under clause 4A.4; a release computed before the effective date is not recomputed, but a superseded release ceases to be displayed once its successor is available, so that the exclusion takes full display effect no later than one release cycle after the effective date.

4B. CLAIM OUTCOME INTELLIGENCE

4B.1 The Customer expressly instructs and authorises Kliksight to record, for each Claim Package submitted to an advertising platform, the adjudication outcome and evidence-shape descriptors listed in clause 4B.2, and to aggregate those records across Kliksight’s customer base for the sole purpose of improving the assembly, substantiation and success of invalid-activity claims and disputes (the "Claim Improvement Purpose"). The Parties record that this processing is carried out on the Customer’s documented instructions and, accordingly, that Article 28(10) GDPR / UK GDPR and the equivalent principles under POPIA do not operate to make Kliksight a responsible party / controller in respect of it.

4B.2 Claim Outcome Intelligence is limited to the following exhaustive fields: (a) the advertising platform and platform product / campaign type; (b) claim status (filed, accepted, partially accepted, rejected or credited) and any credited proportion expressed as a percentage only, with no currency amount; (c) dates of filing and adjudication and the elapsed interval; (d) the categories of evidence fields included in the Claim Package, by field type and count only, and the detection rule categories relied on; and (e) the stated ground of any rejection. Claim Outcome Intelligence shall not include click identifiers, IP-derived indicators, user-agent strings, event timestamps, any other event-level value from a Claim Package, or any personal information / personal data. The Parties record their common intention that Claim Outcome Intelligence describes the adjudication conduct of an advertising platform and relates to no identified or identifiable data subject.

4B.3 Derivation occurs only while the source Claim Package is retained under Annex 4; the retention of Claim Packages is not extended by this clause. Once derived, Claim Outcome Intelligence is severable from its source: it contains no Customer Personal Data, is not subject to clause 15, and survives the deletion or purge of the source Claim Package, Customer Removal and Permanent Deletion. Kliksight shall not re-derive Claim Outcome Intelligence from any record after that record has been deleted.

4B.4 The Parties record that claim outcomes are, as between the Parties, the Customer’s Confidential Information under the Principal Agreement, and that the licence to use them in aggregate form for the Claim Improvement Purpose is granted in the clause of the Principal Agreement headed "Claim Outcome Intelligence Licence" (howsoever numbered). This clause 4B governs only the processing of Customer Personal Data involved in derivation; neither instrument is to be read as the exhaustive statement of the permission, and each cross-refers to the other.

4B.5 The Parties record that no unique identifier of a data subject is processed under this clause 4B for a purpose other than that for which it was collected with the aim of linking information across responsible parties, and that section 57(1)(a) of POPIA is accordingly not engaged; and that Claim Outcome Intelligence, containing no personal information / personal data, falls outside clause 15 and Annex 4. To the extent that any element of it is nonetheless found to constitute personal information / personal data, it is processed on the instruction in clause 4B.1, and clauses 8, 9, 14, 15 and 16 apply to it as if it were Customer Personal Data; and if Kliksight is finally determined to act as a responsible party / controller in respect of it, clause 4.7(a) to (d) applies mutatis mutandis.

4B.6 Recording and contribution of Claim Outcome Intelligence is a severable feature, separate from and independent of clauses 4 and 4A: the Customer may disable it by written notice to Kliksight (or, where that functionality is made available, in the dashboard), with effect within five (5) business days, and clause 17 governs suspension.

5. CLAIM PACKAGE AUTHORISATION

5.1 The Customer expressly instructs and authorises Kliksight to compile Claim Packages from Customer Personal Data and, at the Customer's direction on a per-claim basis, to disclose them to the relevant advertising platform (including Google Ads, Microsoft Advertising, Meta, TikTok and LinkedIn) solely to pursue invalid-activity credits, adjustments and disputes for the Customer or (in the Processor Configuration) its client.

5.2 The Parties acknowledge that each advertising platform receives a Claim Package as a separate responsible party / controller (or under its own advertiser terms) and that Kliksight is not responsible for the platform's subsequent processing. Kliksight shall disclose only the fields reasonably required by the platform's dispute process.

5.3 Claim Packages are retained for the period stated in Annex 4 and are then deleted in accordance with clause 15.

5.4 Kliksight does not retain raw IP addresses in any detection datastore and shall not be required to include them in any Claim Package; transient queue copies pending derivation and perimeter firewall logs (Annex 2) are retained solely for delivery and security purposes, are not available to detection processing, and are not included in any Claim Package or other output. Where an advertising platform's dispute process requires raw IP addresses, these are supplied by the Customer (or the relevant responsible party) from its own web server logs, and Kliksight shall provide the click identifiers, timestamps and trend analysis needed to correlate them.

5.5 Claim Package functions come into operation on release of that capability. Until release, no Claim Package exists, is compiled or is retained, and references to Claim Packages elsewhere in this Agreement (including clauses 15.1 and 17.1 and Annexes 1 and 4) are to be read accordingly, consistently with clause 1.4. The capability shall not be released without the retention, Customer Removal purge and Permanent Deletion mechanisms that Annex 4 and clause 15 require for the class, which apply from the first Claim Package compiled.

6. CONSENT, TRANSPARENCY AND THE TAG

6.1 The Customer warrants, on a continuing basis, that for every Property on which the Tag is deployed:

(a) a consent management or equivalent mechanism is implemented that complies with the Data Protection Laws applicable to that Property, including the ePrivacy rules on storage of and access to information on terminal equipment;

(b) the Tag is gated to, and fires only upon consent to, the advertising purpose category (or the applicable jurisdiction's equivalent), and is not classified or released under an analytics or strictly-necessary category;

(c) data subjects are provided with the transparency information required by the applicable Data Protection Laws, including disclosure of Kliksight as a recipient / operator;

(d) where the Processor Configuration applies, the relevant responsible party / controller has been informed of and has authorised the deployment of the Tag; and

(e) the Property's privacy notice includes the template paragraph set out in Annex 7, or materially equivalent wording, naming Kliksight and accurately describing the cross-customer derivation enabled for that Property: the derivation of aggregate invalid-traffic signals (clause 4) and, where contribution to Benchmark Data is enabled for the Property, of aggregate comparative statistics (clause 4A). Where a contribution is disabled for a Property, the corresponding descriptive wording may be omitted from that Property's notice without breach of this clause; and a Property's contribution to Shared Threat Signals or Benchmark Data may not be enabled or re-enabled unless that Property's privacy notice then includes the corresponding wording. No additional notice wording is required in respect of Claim Outcome Intelligence, which contains no personal data of any data subject.

6.2 The Customer indemnifies Kliksight against losses, claims, fines and regulatory action arising from a breach of clause 6.1, subject to clause 19 save that this indemnity is uncapped in respect of fines and data subject compensation directly attributable to the absence of a lawful consent mechanism on a Property.

6.3 Kliksight may suspend collection for any individual Property immediately upon reasonable evidence that clause 6.1 is not satisfied for that Property, and shall notify the Customer and restore collection once the non-compliance is remedied. Suspension under this clause is Property-scoped and does not affect the remainder of the Services.

6.4 Where storage of the landing-page path component is enabled for a Property (which the Customer may disable per Property in the dashboard), the Customer shall disable it, or instruct Kliksight in writing to disable it, for any Property whose URL paths, to the Customer’s knowledge, embed identifiers of natural persons (such as names, account numbers or personal reference numbers) or would reveal special personal information / special categories of personal data. The path minimisation safeguards in Annex 2 apply in any event and do not depend on the Customer’s compliance with this clause. A breach of this clause 6.4 is remediable by Property-scoped disablement under clause 6.3 and does not of itself engage the indemnity in clause 6.2.

6.5 Kliksight shall publish and maintain a public privacy policy describing its processing under this Agreement, incorporating the public deidentification commitment contemplated by clause 16 and the US State Privacy Laws, before the earlier of the Acceptance Date and the first deployment of the Tag for any Customer. References in this Agreement to Kliksight’s privacy policy take effect from publication, consistently with clause 1.4. 6.6 Where conversion-event measurement is made available, the Customer shall declare for each Property, in writing (including, where that functionality is made available, in the Kliksight dashboard), whether the Property falls within any excluded vertical listed in Annex 1 for conversion events, and shall keep that declaration accurate. Absent a declaration for a Property, conversion-event measurement is not enabled for it and no conversion-event data is captured. Conversion-event measurement is not available for any Property declared, or which Kliksight reasonably determines, to fall within an excluded vertical. A declaration under this clause does not derogate from clause 7, which prohibits deployment on child-directed Properties entirely; the inclusion of child-directed services in the excluded verticals is deliberate belt-and-braces and clause 7 prevails. A breach of this clause 6.6 is remediable by Property-scoped disablement of conversion-event measurement under clause 6.3 and does not of itself engage the indemnity in clause 6.2.

7. CHILD-DIRECTED PROPERTIES

7.1 The Customer warrants that it shall not deploy the Tag on any Property that is directed to children (including "child-directed" or mixed-audience sites within the meaning of COPPA, Properties directed at or targeting children within the meaning of the Protection of Personal Information Act, 2013 (persons under the age of 18), and services likely to be accessed by children under the UK Age Appropriate Design Code or equivalent). This prohibition is absolute and admits no exception by agreement: the Tag collects persistent identifiers and supports disclosures to advertising platforms, and section 34 of POPIA prohibits, and following the amendments to the COPPA Rule effective 23 June 2025 (in full effect from 22 April 2026, including separate verifiable parental consent for third-party disclosures and a published written data retention policy) COPPA does not permit, the operation of the Tag on such a Property.

7.2 Where the Customer declares a Property to be directed to children (including through any dashboard control provided for that purpose), or Kliksight otherwise acquires actual knowledge or reasonably determines that a Property is directed to children within the meaning of clause 7.1, Kliksight shall:

(a) immediately disable collection for that Property, such disablement being Property-scoped and not affecting the remainder of the Services;

(b) notify the Customer, which shall remove the Tag from the Property without delay;

(c) delete the personal information collected from that Property, including raw event data, advertising-platform responses and Claim Packages, whether or not a claim has been filed or resolved, notwithstanding clause 15 and the retention periods in Annex 4, with copies held in backup media expiring in the ordinary course of the backup rotation, save that Kliksight may retain records to the minimum extent, and for the minimum period, necessary for the defence of a claim, investigation or proceeding brought or threatened against Kliksight or the Customer, or to comply with a legal obligation;

(d) retain derived data relating to that Property, including any contribution to Shared Threat Signals made before this clause 7.2 was engaged, only where and to the extent it is de-identified in accordance with the Anonymisation and Aggregation Methodology, Shared Threat Signals otherwise remaining subject to clauses 4.3 and 4.4, including the exclusion warranted under clause 4.4; and

(e) withdraw any claim pending with an advertising platform in respect of that Property, assemble no further Claim Package for that Property, and notify each advertising platform to which a Claim Package for that Property was submitted that the submission included personal information collected from a Property directed to children, requesting deletion of the submitted materials.

The restoration obligation in clause 6.3 does not apply to disablement under this clause 7.2, and nothing in this clause limits Kliksight’s rights or remedies in respect of a breach of clause 7.1.

7.3 The Customer indemnifies Kliksight against losses, claims, fines and regulatory action arising from deployment of the Tag on a Property in breach of clause 7.1, subject to clause 19 save that this indemnity is uncapped in respect of fines, penalties and data subject compensation directly attributable to the processing of children’s personal information resulting from that breach. This indemnity does not apply to the extent a loss arises from Kliksight’s failure to perform clause 7.2 after it is engaged.

8. CONFIDENTIALITY AND PERSONNEL

8.1 Kliksight shall treat Customer Personal Data as confidential, in accordance with section 20 of POPIA, and shall not disclose it except as permitted by this Agreement, as required in the course of properly performing the Services, or as required by law.

8.2 Kliksight shall ensure that persons authorised to process Customer Personal Data are subject to binding obligations of confidentiality (contractual or statutory), are limited to those who need access to perform the Services, and receive appropriate data protection training.

9. SECURITY MEASURES

9.1 Kliksight shall implement and maintain appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of Customer Personal Data as required by section 19 of POPIA and Article 32 GDPR / UK GDPR, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. The measures in place at the Acceptance Date are described in Annex 2; clause 1.4 applies to entries expressed conditionally.

9.2 Kliksight may update Annex 2 from time to time, provided that no update materially degrades the overall level of security. Kliksight shall make the current version available in the dashboard and shall give notice of material changes. The measures are not subject to the Customer's prior approval; the Customer's remedies are the audit rights in clause 18 and, where a change materially degrades security, termination of the affected Services on notice.

9.3 Kliksight shall take reasonable steps to identify reasonably foreseeable internal and external risks, establish and maintain safeguards against them, regularly verify their effective implementation, and update them in response to new risks and deficiencies, in accordance with section 19(2) of POPIA.

10. SUB-OPERATORS (SUB-PROCESSORS)

10.1 The Customer grants Kliksight a general written authorisation to appoint Sub-operators. The Sub-operators approved at the Acceptance Date are listed in Annex 3, which also reserves categories of Sub-operator that Kliksight may appoint in future.

10.2 Kliksight shall give the Customer at least thirty (30) days' prior notice (via the dashboard or email) of the addition or replacement of a Sub-operator. The Customer may object in writing within that period on reasonable, data-protection-related grounds. The Parties shall then discuss the objection in good faith; if it cannot be resolved, the Customer may, as its sole remedy, terminate the affected Services on notice without penalty, with a pro rata refund of prepaid fees. The appointment of a Sub-operator within a category reserved in Annex 3, on the terms stated there, is a notice event and not a renegotiation of this Agreement.

10.3 Kliksight shall impose on each Sub-operator, by written contract, data protection obligations materially no less protective than those in this Agreement, in particular as regards security, confidentiality and international transfers, and remains fully liable to the Customer for the performance of each Sub-operator's obligations.

11. DATA SUBJECT REQUESTS; ASSISTANCE AND ITS LIMITS

11.1 As a matter of recorded fact, Kliksight holds online identifiers and event metadata only. It holds no name, contact detail, account record or directory linking any event record to a named individual; IP hashes are salted per site so that records cannot be matched across Properties; and raw IP addresses are never stored. Kliksight is not required, in accordance with Article 11(1) GDPR / UK GDPR, to maintain, acquire or process additional information in order to identify a data subject for the sole purpose of complying with data protection law.

11.2 Kliksight's obligation to assist the Customer with data subject requests under Article 28(3)(e) GDPR / UK GDPR, the equivalent provisions of POPIA and the US State Privacy Laws is accordingly limited to: (a) searching Customer Personal Data by click identifier and/or timestamp where the data subject or the Customer supplies them; and (b) reporting on, providing copies of, correcting or deleting the matching records at the Customer's direction. Kliksight is not obliged to attempt identification by any other means, and assistance with excessive or repetitive requests is at the Customer's reasonable cost.

11.3 If Kliksight receives a request from a data subject or a regulator relating to Customer Personal Data, Kliksight shall not respond substantively (except to acknowledge receipt, to direct the data subject to the Customer, or as required by law) and shall forward the request to the Customer within five (5) business days. Where a request cannot be actioned because no identifying information within clause 11.2(a) is supplied, Kliksight shall, at the Customer's direction, provide the Customer with a written statement of the facts in clause 11.1 for the Customer to use in its own response.

11.4 Whether the Customer or any other responsible party / controller may rely on Article 11(2) GDPR / UK GDPR, or any equivalent provision, in respect of its own obligations to data subjects is a matter for that party's own assessment, having regard to all information it holds and all means reasonably likely to be used by it or by another person. Nothing in this Agreement constitutes advice, or a representation or warranty by Kliksight, on that question.

12. SECURITY COMPROMISE NOTIFICATION

12.1 Kliksight shall notify the Customer immediately upon becoming aware of a Security Compromise affecting Customer Personal Data, and in any event within seventy-two (72) hours of becoming aware, and shall thereafter provide information as it becomes available, including the nature of the compromise, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. For the purposes of this clause 12, Kliksight becomes aware of a Security Compromise when it has a reasonable degree of certainty, following such investigation as is reasonably practicable in the circumstances, that a Security Compromise has occurred; an unverified alert, anomaly or third-party report does not of itself constitute awareness, but must be investigated without delay.

12.2 Kliksight shall provide reasonable assistance to the Customer (and, in the Processor Configuration, to the relevant responsible party) in meeting its notification obligations to the Regulator, supervisory authorities and data subjects under section 22 of POPIA, Articles 33 and 34 GDPR / UK GDPR and applicable US State Privacy Laws. Notification by or on behalf of Kliksight is not an admission of fault.

13. ASSISTANCE AND COOPERATION

13.1 Taking into account the nature of the processing and the information available to it, Kliksight shall provide reasonable assistance to the Customer with data protection impact assessments, prior consultations with supervisory authorities or the Regulator, and demonstrations of compliance with Article 28 GDPR / UK GDPR and section 21 of POPIA, at the Customer's reasonable cost where the assistance exceeds the standard documentation and dashboard tooling.

14. CROSS-BORDER TRANSFERS

14.1 Kliksight shall not transfer Customer Personal Data outside South Africa, the EEA, the United Kingdom or another jurisdiction of origin except in accordance with this clause 14 and Annex 5. The locations of processing at the Acceptance Date are stated in Annex 3.

14.2 Transfers from South Africa shall comply with section 72 of POPIA, including by way of this Agreement and the contractual safeguards in Annex 5, which the Parties agree provide an adequate level of protection upholding principles substantially similar to the conditions in POPIA.

14.3 Where the GDPR applies to a transfer to Kliksight in a third country, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated as set out in Annex 5: Module Two (controller-to-processor) for the Controller Configuration and Module Three (processor-to-processor) for the Processor Configuration. Where the UK GDPR applies, the UK International Data Transfer Addendum (or the IDTA) applies as set out in Annex 5.

14.4 If the European Commission adopts standard contractual clauses for the situation contemplated by Article 3(2) GDPR (importer directly subject to the GDPR), or an adequacy decision or other valid mechanism becomes available that removes the need for the SCCs, the Parties shall in good faith migrate to that instrument within a reasonable period, without renegotiating the commercial terms of this Agreement.

15. RETENTION, REMOVAL AND DELETION

15.1 The retention schedule in Annex 4 constitutes the Customer’s documented instruction to Kliksight on retention: raw event data for ninety (90) days; detections, statistical aggregates and Evidence Records for two (2) years from creation; and Claim Packages for the applicable platform dispute window plus a buffer of sixty (60) days or, if a claim to which the package relates is then still pending, sixty (60) days after final resolution of that claim (including any appeal or pushback process). The Parties record the necessity justification for the two-year period: platform credit claims and their adjudication, renewal-period disputes and the demonstration of detection accuracy each extend well beyond the platform dispute window itself, and a shorter period would destroy the evidential basis of a claim before it is finally resolved. On expiry of each period the relevant records are deleted or anonymised automatically.

15.2 On termination or expiry of the Services for a Customer, or on the Customer's instruction in respect of a Property, Kliksight shall perform Customer Removal, namely:

(a) purge all raw event data and stored advertising-platform provider responses relating to the Customer (or Property) from live systems;

(b) permanently retire the associated site keys so that the Tag ceases to collect data; and

(c) retain detections, statistical aggregates and Evidence Records solely under, and until expiry of, the two-year period in Annex 4, after which they are deleted or anonymised. The asymmetry between this sub-clause and the treatment of Claim Packages, which Annex 4 purges on Customer Removal, is deliberate: a Claim Package is event-level personal data compiled on, and for, the specific Customer’s instruction and falls with that Customer’s data, while the records retained under this clause 15.2(c) are aggregate, identifier-free findings retained to their own expiry under this clause and clause 15.3, independently of any single customer. Customer Removal purges Claim Packages even where a related claim remains pending; the Customer retains the packages disclosed to it for filing, and Kliksight shall, where practicable, notify the Customer of any claim still pending before executing Customer Removal.

15.3 The Parties agree that Customer Removal, together with the automatic expiry in clause 15.1, discharges Kliksight's obligations under Article 28(3)(g) GDPR / UK GDPR and the return-or-destruction principles of POPIA (including section 14), on the basis that the records retained under clause 15.2(c) are not attributable to an identifiable data subject. Separately and in the alternative, if and to the extent any such record is found to constitute personal data, it is retained under the Customer’s documented instruction in clause 15.1 for the period stated there, and its retention notwithstanding an erasure request is justified as necessary for the establishment, exercise or defence of legal claims (Article 17(3)(e) GDPR / UK GDPR) in respect of invalid-activity credit claims and disputes.

15.4 The Customer may separately instruct Kliksight in writing to perform Permanent Deletion, in which case Kliksight shall, within thirty (30) days of the instruction, additionally delete the detections, statistical aggregates and Evidence Records referred to in clause 15.2(c), subject to clause 15.5.

15.5 Deletion under this clause 15 means purging from live systems without undue delay. Backup copies expire within thirty-five (35) days, point-in-time recovery with a rolling thirty-five (35) day window being the sole backup mechanism operated, so that no copy can outlive that period; data deleted from live systems is not restored from backup except in the course of a disaster-recovery restoration, in which event the deleted data is re-deleted promptly upon completion of the restoration. Nothing in this Agreement shall be read as a representation that data is erased from all media instantaneously.

15.6 Kliksight is not required to certify deletion by a fixed deadline. On the Customer's written request made after completion of Customer Removal or Permanent Deletion (as applicable) and the expiry of the backup cycle in clause 15.5, Kliksight shall provide written confirmation of the deletions performed.

15.7 Kliksight may retain Customer Personal Data to the extent required by a law to which it is subject, for the duration and purposes required by that law, and shall inform the Customer of that requirement unless prohibited from doing so. This clause 15 does not apply to Shared Threat Signals, Benchmark Data, Claim Outcome Intelligence or Aggregated Data once anonymised, which are governed by clauses 4, 4A and 4B.

16. NO RE-IDENTIFICATION

16.1 Neither Party shall attempt to re-identify, or permit or assist any third party to re-identify, any data subject from Shared Threat Signals, Benchmark Data, Claim Outcome Intelligence, Aggregated Data or any other deidentified or anonymised data derived under this Agreement, save for controlled adversarial re-identification testing conducted by or for Kliksight, under the safeguards in Annex 2, solely to assess and verify the effectiveness of the anonymisation and safeguards under this Agreement, with results recorded, used for no other purpose and disclosed to no third party.

16.2 Each Party shall (a) implement technical safeguards and business processes that prohibit re-identification and prevent inadvertent release of deidentified data, and (b) impose this clause 16 by contract on any recipient of such data. The Parties intend this clause to satisfy the deidentification conditions in section 1798.140(m) CCPA and the equivalent provisions of the other US State Privacy Laws.

17. SEVERABILITY OF THE SHARED SIGNAL, BENCHMARK AND CLAIM INTELLIGENCE LAYERS

17.1 The Shared Threat Signal contribution described in clause 4 is architecturally severable from the core detection Services: disabling contribution for the Customer, a Property, or a jurisdiction does not degrade the core detection, reporting or Claim Package functions for that Customer or Property. The same applies, separately and independently, to Benchmark Data under clause 4A and to Claim Outcome Intelligence under clause 4B: each layer is severable from the core Services and from each other layer, and disabling any one of them does not degrade the others.

17.2 If the Regulator, a supervisory authority, or a court directs or a Data Protection Law requires the suspension of processing relating to the shared layer, the benchmark layer or Claim Outcome Intelligence (including a direction under section 58(2) of POPIA following prior authorisation proceedings), the Parties agree that the required suspension is feature-scoped: Kliksight shall disable the affected layer for the affected scope while continuing the remainder of the Services, and such feature-scoped suspension is not a breach of, and does not give rise to a right to terminate, the Principal Agreement.

18. AUDIT AND DEMONSTRATION OF COMPLIANCE

18.1 Kliksight shall make available to the Customer the information reasonably necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to the limitations in this clause 18, which the Parties agree give effect to Article 28(3)(h) GDPR / UK GDPR.

18.2 The Customer's audit rights are satisfied in the first instance by Kliksight providing, on request: (a) its then-current third-party certifications and audit reports (for example ISO/IEC 27001 certification or SOC 2 reports, to the extent held); (b) the current Annex 2; and (c) written responses to a reasonable security questionnaire not more than once in any twelve-month period.

18.3 An on-site or remote inspection may be conducted only: (a) not more than once in any twelve-month period, except following a Security Compromise affecting the Customer or where required by a supervisory authority or the Regulator; (b) on at least thirty (30) days' written notice; (c) during business hours, without unreasonable disruption, and subject to Kliksight's confidentiality and security policies; (d) at the Customer's cost, including Kliksight's reasonable time charged at its standard rates where the inspection exceeds one business day; and (e) without access to other customers' data, Kliksight's proprietary detection logic beyond what is necessary, or third-party confidential information.

18.4 The Customer shall provide Kliksight with a copy of any audit findings and shall treat them as Kliksight's confidential information.

19. LIABILITY

19.1 Subject to clause 19.2, each Party's total aggregate liability to the other under or in connection with this Agreement, whether in contract, delict/tort (including negligence), under an indemnity or otherwise, shall not exceed the fees paid or payable by the Customer for the Services in the twelve (12) months preceding the event giving rise to liability, and neither Party is liable for loss of profits, revenue, goodwill or anticipated savings, or for indirect or consequential loss.

19.2 The cap and exclusions in clause 19.1 do not apply to: (a) liability that cannot be limited by law; (b) a Party's wilful misconduct or gross negligence; (c) the Customer's liability under the authority indemnity in clause 2.3 and the consent indemnity in clause 6.2, in each case to the extent stated there; (d) breach of clause 16 (no re-identification); (e) the Customer's payment obligations; and (f) either Party's liability to data subjects under Clause 12 of the Standard Contractual Clauses incorporated by Annex 5, Article 82 GDPR / UK GDPR or section 99 of POPIA, none of which is limited or affected by clause 19.1.

19.3 Where both Parties are involved in the same processing and are, under Article 82 GDPR / UK GDPR or section 99 of POPIA, liable to a data subject, each Party shall be responsible, as between the Parties, for that portion of the compensation corresponding to its share of responsibility, and the Party that has paid full compensation may claim back from the other Party the portion corresponding to the other Party's share.

19.4 This clause 19 supersedes and replaces any limitation of liability, exclusion or indemnity provision in the Principal Agreement in respect of the subject matter of this Agreement.

20. TERM AND TERMINATION

20.1 This Agreement commences on the Acceptance Date and continues for as long as Kliksight processes Customer Personal Data. Clauses 4.5, 4.7, 4A.6, 4A.7, 4B.3, 4B.5, 8, 15, 16, 17, 18 (for records relating to the processing period), 19 and 21 survive termination, together with any other provision which by its nature is intended to survive.

21. GENERAL

21.1 This Agreement is governed by the laws of the Republic of South Africa, and the Parties submit to the non-exclusive jurisdiction of the South African courts, save that nothing in this clause deprives a data subject or supervisory authority of rights or competence under a Data Protection Law of another jurisdiction, and the SCCs and UK Addendum carry their own governing-law provisions as stated in Annex 5.

21.2 If any provision of this Agreement is held invalid or unenforceable, the remainder continues in force, and the Parties shall replace the invalid provision with a valid one that most closely achieves its purpose. No variation is effective unless in writing and signed (which may be by electronic signature).

21.3 Any notice under this Agreement must be in writing and is validly given: (a) by email to the address stated in the Principal Agreement or subsequently notified in writing (for Kliksight: hello@kliksight.com); (b) in the case of notices from Kliksight to the Customer, additionally by prominent notification within the Kliksight dashboard, which the Parties agree is valid written notice for the purposes of clauses 4.6, 4A.8, 4B.6, 9.2, 10.2 and 15; or (c) by hand or courier to a Party’s registered address. A notice is deemed received: if by email, on transmission where sent before 17:00 on a business day at the recipient’s location, and otherwise at 09:00 on the next business day; if by dashboard notification, at 09:00 on the next business day; and if by hand or courier, on delivery.

21.4 The Customer may not assign, cede, delegate or transfer this Agreement or any right or obligation under it without Kliksight’s prior written consent. Kliksight may assign, cede or novate this Agreement, together with the Principal Agreement, in whole to an acquirer of Kliksight (Pty) Ltd, of all or substantially all of its assets, or of the Kliksight business or product line, or to an affiliate, on written notice to the Customer and without the Customer’s consent, provided the assignee assumes Kliksight’s obligations under this Agreement in writing; the Customer shall sign any document reasonably required to give effect to such novation.

21.5 The Customer acknowledges that, before entering into this Agreement, its attention was specifically drawn (by the notice preceding clause 1 and by the bold type in which they are set) to clauses 2.3, 6.2, 7.3 and 19; that those clauses limit risk or liability, constitute an assumption of risk, or impose indemnity obligations; that they are expressed in plain language; and that the Customer had an adequate opportunity to consider them and to request an explanation of their meaning and effect, in accordance with section 49 of the Consumer Protection Act 68 of 2008 to the extent that Act applies to the Customer.

21.6 This Agreement may be accepted by the Customer by the electronic acceptance mechanism Kliksight presents at sign-up, and such acceptance constitutes signature for the purposes of section 13(3) of the Electronic Communications and Transactions Act 25 of 2002 and satisfies the requirement of a written contract in section 21 of POPIA and Article 28(9) of the GDPR and the UK GDPR. Kliksight shall record, and produce to the Customer on request, the version of this Agreement accepted, the date and time of acceptance, and the account and individual by whom it was accepted, and shall retain each numbered version together with its Schedule to Annex 4 so that the accepted text can be reproduced. Where this Agreement is accepted in that manner, the Customer particulars for Annex 1 are those recorded in the Customer’s account with Kliksight at the Acceptance Date. Either Party may request a counterpart signed by both Parties, which does not affect the validity of an acceptance already given.

Acceptance of this Agreement is captured by the electronic acceptance mechanism described in clause 21.6; acceptance constitutes signature under section 13(3) of the Electronic Communications and Transactions Act 25 of 2002, and no signature is required. A counterpart signed by both Parties is available on request under clause 21.6.

ANNEX 7: END-CLIENT NOTICE WORDING (clause 6.1(e))

The following paragraph is the Kliksight-supplied template contemplated by clause 6.1(e), for inclusion in the privacy notice of each Property on which the Tag is deployed. Sentences in square brackets are included only where the corresponding capability is in operation and enabled for the Property; the aggregate-comparative-statistics words in brackets are included only where contribution to Benchmark Data is enabled for the Property. The Customer replaces [site operator] with the legal name of the responsible party / controller for the Property. Where clause 6.1(e) applies, cross-customer contribution for a Property is not enabled unless its notice includes this wording or materially equivalent wording.

Invalid-traffic measurement. This site uses Kliksight, a service of Kliksight (Pty) Ltd, to measure whether advertising clicks arriving here are genuine. If you arrive via an advertising link and have granted advertising-storage consent, Kliksight processes a click identifier, a truncated network address and a pseudonymised device value derived from your IP address, your browser's user-agent string, your country and network, and the time of arrival, to classify the click event (never you or your device) as valid or invalid, and to derive aggregate invalid-traffic signals [and aggregate comparative statistics] across Kliksight's customer base, in which no visitor is identifiable. [Where enabled, the page path you arrive on is also measured, with identifier-like segments automatically redacted.] [Where enabled, whether your visit results in an enquiry or purchase event is also measured: the fact and time only; nothing you enter, and no order value, is collected.] [Where a claim for an invalid-traffic credit is made, records of the click events supporting that claim may be submitted to the advertising platform concerned, which already holds the click data and acts as a separate responsible party in respect of it.] This data is processed on behalf of [site operator] as responsible party / controller. Retention periods and your rights are described in Kliksight's privacy policy at kliksight.com/privacy.

ANNEX 1: PARTICULARS OF PROCESSING (Article 28(3) GDPR / UK GDPR)

ItemDescription
Subject matterDetection, measurement, reporting and dispute of invalid traffic affecting advertising campaigns run on or for the Customer's Properties.
DurationThe term of the Principal Agreement, plus the retention periods in Annex 4.
Nature of processingCollection via the Tag; transmission; storage; scoring and analysis; aggregation; anonymisation; compilation of Claim Packages; disclosure to advertising platforms at the Customer's direction; deletion.
Purpose(i) Provision of the Services under the Principal Agreement; (ii) the Invalid Traffic Purpose (clause 4); (iii) pursuit of invalid-activity credits, adjustments and disputes (clause 5).
Types of personal dataOnline identifiers and event metadata collected via the Tag only: salted-hashed IP address (per-site derivation; the raw IP address transits a processing queue for up to 4 days (up to 14 in the dead-letter queue), is discarded on derivation of country and network/ASN, is never written to any detection datastore, and appears in perimeter firewall logs retained 90 days); derived /24 network prefix (IPv4 only); country, ASN, ASN organisation and datacenter classification; user-agent string and generalised device attributes (browser family and major version, operating system family, device class, in-app webview identifier); advertising click identifiers (gclid, msclkid, fbclid, ttclid, li_fat_id); event timestamp, assigned server-side by Kliksight’s collection service on receipt of the event at ingestion (the Tag transmits no timestamp), from which the Annex 4 retention period for raw event data runs; where landing-page capture is enabled per Property: the landing-page URL minimised to exclude all query parameters other than the click identifier, and the landing-page path component subject to the path minimisation safeguards in Annex 2 and to clause 6.4 (no landing-page data is captured before enablement); where conversion-event measurement is in operation and enabled per Property: a conversion event type and its timestamp (likewise assigned server-side on receipt at ingestion), recording only the fact that a form-submission or purchase-confirmation event occurred on the same visit (never form contents, entered values, order values or any other payload), and never on Properties in the excluded verticals recorded in the Property’s vertical declaration under clause 6.6 (health and health-adjacent services, legal intake, debt and financial-hardship services, political, religious and trade-union organisations, sexual-wellness services, and child-directed services), with no conversion-event data captured before enablement; consent state and consent purpose; advertising platform identifier. Campaign-level attribution is derived at detection time by combining click identifiers with the Customer’s advertising-platform reporting data. No special personal information / special categories of data; no criminal-conviction data; no directly identifying contact details of visitors; no profiling for advertising, marketing or content-personalisation purposes, and no solely automated decision-making producing legal or similarly significant effects concerning any data subject (Article 22 GDPR / UK GDPR; section 71 POPIA). The detection engine does evaluate device-level behaviour (velocity, repetition and location consistency over rolling windows, grouped by pseudonymous device identifier) solely to classify traffic validity for the Invalid Traffic Purpose; detection determinations are retained per Annex 4, and no natural person is classified as fraudulent. Landing-page paths are subject to clause 6.4 and the path minimisation safeguards in Annex 2 and are not used to infer special personal information / special categories of data. Conversion events record occurrence facts only; are unavailable for the excluded verticals listed above; are excluded from the Shared Threat Signals and from every other cross-tenant derived-data class unless the Permitted Benchmark Set in clause 4A is expressly amended; are subject to the aggregation thresholds in Annex 2 applied per conversion-event cell; and are not used to infer special personal information / special categories of data.
Categories of data subjectsVisitors to, and persons or automated agents interacting with advertisements leading to, the Customer's (or its clients') Properties.
FrequencyContinuous, for as long as the Tag is deployed.

The field composition of each record class as operated is set out in the Schedule to Annex 4, which discloses any field not individually enumerated in this Annex 1 or in Annex 4.

ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES Each entry in this Annex is a warranty of operated reality. Kliksight shall verify every entry against the live system before the earlier of (i) this Agreement first being made available for acceptance and (ii) its execution, whenever this Annex is amended, and whenever a change to the Services or to Kliksight’s systems affects a matter this Annex describes. A version of this Agreement that does not amend this Annex, and does not change what it describes, does not of itself require re-verification.

DomainMeasures
EncryptionTLS 1.2+ for all data in transit; encryption at rest on all datastores, object storage and backups using cloud-provider managed keys.
Pseudonymisation & minimisationThe raw IP address is accepted at the collection endpoint and written to a transient processing queue pending derivation; at the next processing stage, country and network (ASN) are derived and the address is salted-hashed and discarded. The raw address persists in the main queue for up to 4 days and in the dead-letter queue for up to 14 days, is never written to any database or detection datastore, and additionally appears in the perimeter firewall logs described below, retained for 90 days. IP hashes are derived per site using HKDF key derivation with the site key as derivation context, so identical visitors produce different hashes across sites; salts rotate on a 90-day cycle with destruction of the retired salt, and stored hashes carry a version marker. Advertising-platform provider responses are identifier-free from creation: no component writes click identifiers, IP-derived values or user-agent data to that store (its sole writer being the reconciliation component), and the property is verified by a standing allowlist scan that fails on any unrecognised field. The scan covers the provider object corpus, raw event data and Evidence Records, runs automatically on a recurring schedule not exceeding six hours (with an alarm on failure or non-execution), and is additionally re-run as further advertising platforms are integrated, so any schema change is scanned within six hours of the changed data being written, without depending on a human trigger. Landing-page URLs are not captured today: the Tag transmits no URL and the collection endpoint discards the field. No landing-page URL is captured: the Tag transmits the path component only, never the full URL or its query string, and the collection endpoint accepts no landing-URL field. If URL capture is ever introduced for a Property, the URL shall be minimised at ingestion to strip all query parameters except the click identifier before any storage. Where path storage is enabled for a Property, the path component is stored on the raw event only, capped at 256 characters and 8 segments; path segments matching identifier patterns (numeric sequences of 6 or more digits, email addresses, UUIDs, and hexadecimal or base64 token-like strings of 16 or more characters) are redacted at ingestion; a path is admitted to the aggregate layer (retention per Annex 4) only where observed across at least ten (10) distinct visitors, applying the same minimum-cluster discipline as Evidence Records, so that a path unique to fewer visitors expires with the raw event at 90 days. Landing-page paths are never included in Shared Threat Signals, Benchmark Data or the sampled examples within Evidence Records, and appear in a Claim Package only where the advertising platform’s dispute process requires them. The identifier-pattern set, caps and gates in this entry are minima: Kliksight may extend the patterns or tighten the caps and gates at any time under clause 9.2 without variation of this Agreement (such changes only ever reducing the data stored), and may not narrow or relax them except by signed variation under clause 21.2. User-agent strings are stored in full within raw event data for its 90-day life; only derived device attributes (browser family and major version, operating system family, device class) and rule outcomes persist beyond that class, and no user-agent string appears in any Evidence Record. No names, email addresses or form contents are collected.
Anonymity safeguards on aggregatesMinimum cluster size before any sampled example is stored; sample timestamps coarsened to the hour; suppression triggered by event-cluster size, on firing withholding the network operator’s name while retaining the autonomous system number; shared-layer emission gated by a minimum contributor threshold counting both distinct Properties and distinct customers; timing expressed as distribution parameters only, never raw event sequences.
Child-directed exclusion at derivationAt each derivation of Shared Threat Signals performed after a Property is declared or determined to be directed to children, and at any recomputation, records attributable to that Property are excluded from the derivation, including from the diversity counting in which site and tenant identifiers are used transiently and discarded. This entry speaks to derivations performed after the declaration or determination and asserts nothing about a signal written before it. The exclusion mechanism is deployed and its engagement logic is verifiable before acceptance opens: it has been read and exercised against constructed state, with the results recorded in the verification record. Upon the first flagged detection row arising for a Property declared or determined to be directed to children, the exclusion engages as described in this entry, and Kliksight shall verify that engagement against the live system within thirty (30) days of that first occurrence, recording the result in the same verification record.
Access control & tenant isolationLeast-privilege IAM per function; deployment via single sign-on with short-lived credentials (no static access keys); multi-factor authentication on administrative access to both the cloud console and the application’s own administrative interface (TOTP), including the permanent-erasure function; tenant isolation via opaque site keys resolved server-side; cross-tenant requests return not-found responses so resource existence cannot be probed; advertising-platform OAuth tokens held in a dedicated secrets manager, per customer per connection. Verification codes, where report verification is in operation, are generated with not less than 128 bits of entropy, are not enumerable and are exposed by no listing or search route; the verification surface is excluded from search-engine indexing, is rate limited, and returns only the attested figures and issuance particulars, no Customer Personal Data and no event-level record, in identical fields whether the response is rendered for a reader or returned as structured data; codes cease to verify on revocation instructed under clause 3.5 and on expiry of the record class from which the report was produced. Every rejection produced by the client-facing share surface, and by the verification surface, returns an identical HTTP 404 and an identical body (unknown, revoked, malformed, wrong-length, wrong-character-set, injection-shaped and empty tokens alike), so that a caller cannot learn whether a token exists, was revoked or was ever issued; transport-layer headers set by the content delivery network and the API gateway are not identical across all rejections, are outside Kliksight’s control and carry no token-derived information; one class of malformed request is refused by the content delivery network at its edge before reaching Kliksight infrastructure and differs in status and body, that difference being a function of the request URI alone and likewise carrying no token-derived information.
Network & application securityWeb application firewall attached to the production API stage, with managed core rule set and rate limiting; firewall logs record all evaluated requests to a dedicated bucket with 90-day expiry, credential-bearing headers redacted and client IP addresses retained in the clear (the firewall service provides no hashing facility); strict input validation; Origin/Referer validation on event collection.
Logging & monitoringNo personal information is written to application logs, enforced by an allowlist logging function. Audit logging comprises cloud-provider management-event logging (multi-region), delivered to a dedicated bucket with 400-day expiry, versioning and a bucket policy denying deletion, and log-file integrity validation, together with the firewall logs described above. Security monitoring comprises a cloud-provider intrusion-detection service and a configuration-monitoring service, both operated, together with alerting on defined incident classes built on the management-event log stream. No data-plane event log is retained and no security information and event management system is operated or represented: individual object and item reads are not recorded as an audit record, although the intrusion-detection service analyses object-storage data-plane events for threat detection without retaining a queryable log. Operational and integrity alarms are operated on the processing pipeline itself, covering processing failures, dead-letter queue arrivals, cryptographic key rotation failure and overdue rotation, orphaned key material, failure of the allowlist scan, and staleness of the geolocation data, these being pipeline integrity controls, distinct from security monitoring of the log streams.
Availability & backupsPoint-in-time recovery enabled on all primary datastores with a 35-day recovery window is the sole backup mechanism operated: no separate backup copies are created, so no backup can outlive that window by construction, consistent with clause 15.5; deletion protection on datastores; re-deletion after any restoration.
Environment & change managementInfrastructure defined and deployed as code under version control; single production environment; deployments through version-controlled infrastructure code and short-lived credentialed sessions.
Consent enforcementCollection is consent-gated and fails closed at both ends: absent an affirmative consent signal from the Property’s consent mechanism the Tag does not fire, and the collection endpoint independently rejects any event whose consent field is absent or not affirmative, with every rejection identical in HTTP status and body to the response for an unknown site key; transport-layer headers set by the content delivery network and the API gateway vary between responses, are outside Kliksight’s control and carry no key- or consent-derived information, so that consent state cannot be used to probe key validity; consent state and purpose are recorded on every accepted event. After consent, and only on the heartbeat path, the Tag stores a single session-scoped marker in browser sessionStorage (a key naming the Property’s public site key, with the value "1", containing no visitor, user or device identifier), solely to suppress duplicate transmission within a session; it is cleared when the session ends. Where a click identifier is present, the Tag sends the visit and writes nothing to storage; no other value is written to the terminal equipment by the Tag in any case.
PersonnelThe Services are presently delivered by a sole operator, bound to confidentiality and maintaining data protection awareness under the documented personnel policy, and holding all access; there are no other personnel. Before any further person is granted access: a written confidentiality undertaking, access limited to what that person needs to deliver the Services, and a completed and recorded data protection briefing, each as that policy requires.
Incident responseDocumented incident-handling procedure supporting the 72-hour notification in clause 12, informed by the operational and integrity alarms described in the logging entry.
Anonymisation governanceDocumented derivation methodology for Aggregated Data and Shared Threat Signals; the thresholds and suppression parameters referred to in clause 4.4 reviewed periodically against singling-out, linkability and inference risks; adversarial re-identification testing has been performed against production data under controlled conditions, with results recorded and used solely to assess and strengthen the thresholds, suppression parameters and safeguards in this Annex, and is repeated at production volume before material derived from Evidence Records circulates externally at volume, whenever a derived-data class is added, and whenever a threshold or suppression parameter is changed.
Sub-operator managementDue diligence before appointment; written contracts per clause 10.3; periodic review of Sub-operator terms and certifications.

ANNEX 3: APPROVED SUB-OPERATORS AND RESERVED CATEGORIES

Approved Sub-operators at the Acceptance Date

Sub-operatorProcessing / roleLocation(s)
Amazon Web Services, Inc.Cloud hosting, storage, compute, messaging and backup infrastructure for the ServicesUnited States (region us-east-1, N. Virginia)

Processing locations (clause 14.1)

Customer Personal Data is stored and processed in the United States (AWS region us-east-1) for all storage and regional processing; content-delivery edge termination for the Tag occurs at edge locations within the configured price class (North America, Europe and Israel), with no storage of event content at edge. Kliksight personnel access the systems remotely from South Africa for administration and support; no Customer Personal Data is stored at rest in South Africa. The transfer safeguards in clause 14 and Annex 5 address both jurisdictions.

Reserved categories (appointment is a notice event under clause 10.2)

Reserved categoryConditions
AI service provider for report narrative generationMay receive anonymous Aggregated Data only; no Customer Personal Data; no use of Customer content for model training; bound by clause 16.
Content delivery network / edge providerTag delivery and ingestion edge only; transient processing at edge locations within the configured price class (North America, Europe and Israel), terminating requests at the nearest edge; no storage of event content at edge; all storage and regional processing in us-east-1.

Excluded from this Annex

Paddle (payment and merchant-of-record services) is not a Sub-operator: it processes the Customer's payment and tax data as an independent responsible party / controller under its own terms, outside the scope of this Agreement, and is disclosed in Kliksight's privacy policy.

Zoho (business email) processes Kliksight's own account, support and business correspondence, in respect of which Kliksight acts as a responsible party / controller in its own right; it does not process Customer Personal Data and is therefore not a Sub-operator. It is disclosed in Kliksight's privacy policy.

ANNEX 4: RETENTION SCHEDULE

The field enumerations in this Annex are completed and kept current from the schema extract produced by the standing allowlist scan described in Annex 2 (covering raw event data, Evidence Records and the provider object corpus). The extract produced by that scan is published as the Schedule to this Annex with each numbered version of this Agreement; the Schedule published with the version the Customer accepts is the Schedule to this Agreement, forms part of it, and is retained by Kliksight with that version and produced on request. Where this Agreement is executed by signature, the extract produced at the Acceptance Date is appended on execution instead, and no signature shall be taken without it. Once appended, where this Annex and the Schedule differ, the Schedule (as the scan of the live system) prevails for field composition, and clause 1.3 continues to govern protections. For the 58 records created before the retention-anchoring control was deployed, the recorded creation time is the most recent processing run rather than first creation, with observed drift between 0.35 and 3.32 days against a two-year period; these records are retained undisturbed as a documented disclosure, and the anchoring statements in this Annex apply to records created on or after that deployment.

Record classRetentionEnd-of-life action
Raw event data: salted-hashed IP (per-site derivation), /24 prefix (IPv4), user-agent string and generalised device attributes, click identifier, consent state and purpose, derived country/ASN, timestamp, landing-page path (where enabled; query parameters stripped except the click identifier, ingestion redaction and length cap per Annex 2), conversion event type (where enabled; occurrence fact and timestamp only)90 days from ingestionAutomatic deletion
Advertising-platform provider responses (object storage)Up to 730 days (claim-supporting and billing-reconciliation evidence). These objects contain no click identifiers, IP-derived values, user-agent data or other personal data from creation; the class is listed for completeness of the retention and deletion picture, and clause 15 applies to it only to the extent personal data is ever presentLifecycle expiry; purged earlier on Customer Removal
Perimeter firewall logs (dedicated log bucket)90 days. Client IP address in the clear; request metadata with credential-bearing headers redacted; all evaluated requests loggedLifecycle expiry
Ingestion processing queue (transient)Event payload including the raw IP address, pending derivation: main queue up to 4 days; dead-letter queue up to 14 daysAutomatic expiry
Detections and statistical aggregates (including per-landing-page aggregates only where the minimum-visitor gate in Annex 2 is satisfied)Account-level and monthly rows: 2 years from first creation; campaign- and ad-group-level daily rows: 120 days from first creation. Periods are anchored at first creation; reprocessing a period does not reset themAutomatic deletion on expiry
Evidence Records: cluster-level findings only (detection period, platform, ASN and ASN organisation, country, datacenter classification, rules triggered, event counts, first and last observed, campaign targeting context, weighting and flag status), plus not more than approximately five sampled examples per cluster, each limited to hour-coarsened timestamp, ASN, country and rule. Evidence Records contain no click identifiers, no IP addresses or IP hashes, and no user-agent strings.2 years from first creation (anchored; reprocessing does not reset the period)Automatic deletion on expiry; see clauses 15.2(c) and 15.3
Claim Packages (compiled on demand from raw event data within its 90-day life)Platform dispute window + 60 days or, if later, 60 days after final resolution of the related claimDeletion; purged on Customer Removal
Backups (all classes)35-day rotation cycleExpiry by rotation; re-deletion after restoration

ANNEX 5: CROSS-BORDER TRANSFER MECHANISMS

1. EU Standard Contractual Clauses (Decision (EU) 2021/914)

The SCCs are incorporated by reference and completed as follows: Module Two applies in the Controller Configuration (Customer as data exporter/controller; Kliksight as data importer/processor); Module Three applies in the Processor Configuration (Customer as data exporter/processor; Kliksight as data importer/sub-processor). Clause 7 (docking) is included; Clause 9(a): Option 2 (general written authorisation, 30 days' notice); Clause 11(a): the independent dispute resolution option is not selected; Clause 17: Option 1, laws of Ireland; Clause 18(b): courts of Ireland. Annex I of the SCCs is completed by the Parties block and Annex 1 of this Agreement; Annex II of the SCCs by Annex 2 of this Agreement; Annex III of the SCCs by Annex 3 of this Agreement. The competent supervisory authority is determined under Clause 13.

In the event of any conflict between the SCCs and this Agreement, the SCCs prevail.

2. UK transfers

Where the UK GDPR applies, the UK International Data Transfer Addendum to the EU SCCs (version B1.0) is incorporated: Tables 1 to 3 are completed by the Parties block and Annexes 1 to 3 of this Agreement; Table 4: the Importer may end the Addendum as set out in section 19 when the ICO issues a revised Approved Addendum. Alternatively, where the Parties elect, the IDTA applies completed on materially equivalent terms.

3. Future mechanisms

Per clause 14.4, if the European Commission adopts SCCs for importers subject to Article 3(2) GDPR, or an adequacy decision covering the relevant transfer becomes applicable, the Parties will migrate to that mechanism in good faith without renegotiating commercial terms.

4. South Africa (POPIA section 72)

Transfers of personal information from South Africa are made under section 72(1)(a) of POPIA on the basis that each recipient is bound by a legally enforceable instrument providing an adequate level of protection that effectively upholds principles for reasonable processing substantially similar to the conditions in POPIA, including provisions substantially similar to section 72 relating to onward transfer. For transfers to Sub-operators, that instrument is the written agreement required by clause 10.3: in the case of AWS, its executed data processing addendum, which incorporates standard contractual clauses and onward-transfer restrictions; and Kliksight retains executed copies or records of those agreements as evidence of this assessment. As between the Parties, this Agreement (including Annex 2) is the relevant instrument.

ANNEX 6: US STATE PRIVACY ADDENDUM (CCPA/CPRA SERVICE-PROVIDER TERMS)

This Annex applies to the extent Customer Personal Data includes personal information of consumers protected by the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA") or by the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon or other US states ("US State Privacy Laws"). Capitalised terms in this Annex bear the meanings given in the CCPA.

1. Roles and business purpose. The Customer (or its client) is the Business; Kliksight is a Service Provider (or, under other US State Privacy Laws, a processor). Kliksight processes personal information for the following Business Purposes only: helping to ensure security and integrity; detecting security incidents; and protecting against malicious, deceptive, fraudulent, or illegal activity, namely the detection, measurement, evidencing and dispute of invalid traffic and invalid click activity, together with the auditing of ad interactions to the extent inherent in that purpose, and short-term transient use strictly necessary to deliver the Services.

2. Restrictions. Kliksight shall not: (a) sell or share personal information; (b) retain, use or disclose personal information for any purpose other than the Business Purposes above, or outside the direct business relationship between the Parties; or (c) combine personal information received from or on behalf of the Customer with personal information received from another person, except that the Parties acknowledge that combining information across Businesses is permitted, and is hereby instructed, to the extent necessary to detect data security incidents and to protect against malicious, deceptive, fraudulent, or illegal activity, as expressly permitted by Cal. Code Regs. tit. 11, § 7050(a)(4), being the mechanism by which the Shared Threat Signals in clause 4 operate. Benchmark Data is derived and displayed exclusively from deidentified and aggregate consumer information (sections 1798.140(m) and 1798.140(b) CCPA) in accordance with clauses 4A and 16, and no personal information is retained, used or disclosed to perform services on behalf of another person (§ 7050(a)(3)); Claim Outcome Intelligence contains no personal information (clause 4B). Kliksight does not combine personal information for, and shall not be engaged to provide, cross-context behavioural advertising (§ 7050(b)).

3. Compliance and oversight. Kliksight certifies that it understands and will comply with the restrictions in this Annex; shall notify the Customer if it determines it can no longer meet its obligations under the CCPA; and grants the Customer the right, upon reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information, exercised through the audit mechanism in clause 18.

4. Consumer requests. Clause 11 (identification not possible) applies to consumer requests. Where identification is possible, Kliksight shall assist the Customer in responding to verifiable consumer requests, including requests to delete, correct and know, by the means described in clauses 11 and 15.

5. Deidentified data. Data qualifying as deidentified under section 1798.140(m) CCPA is processed subject to clause 16 (no re-identification), which the Parties adopt as the public commitment and contractual obligation required by that section.

6. Subcontractors. Kliksight shall engage Sub-operators under written contracts imposing the restrictions of this Annex, per clause 10.3.

SCHEDULE TO ANNEX 4: FIELD COMPOSITION EXTRACT

Generated: 2026-08-12 19:30:13Z. Source: the live system, read directly.

This Schedule records the field composition of the record classes it covers, as read from the live system at the generation timestamp it bears. Record counts and observed value ranges are observations at that timestamp and are not warranted to persist: the record classes turn over under the retention periods in this Annex 4, and a count taken over an expiring population is superseded by design. The obligations in this Annex 4 are the retention periods and the end-of-life actions it states, and those obligations do not vary with record volume. Each numbered version of the Agreement publishes the Schedule current at that version, frozen at the Acceptance Date.

Drift between this Schedule and the live system is reported through the standing allowlist scan described in Annex 2. No drift tolerance is adopted and none is stated.

provider_objects

Source: s3://apistack-providerdatabucketa00598c1-lrrzaehawf6w/provider/

Records read: 219

Annex 4 describes this class by exclusion rather than by enumeration, so no field-by-field disclosure comparison applies to it.

pathoccurrencestypein allowlistenumerated in Annex 1/4
.account_id219stryesn/a
.breakdowns219containeryesn/a
.breakdowns.campaign219containeryesn/a
.breakdowns.campaign.currency219none/stryesn/a
.breakdowns.campaign.dimension219stryesn/a
.breakdowns.campaign.rows219containeryesn/a
.breakdowns.campaign.rows[].clicks20intyesn/a
.breakdowns.campaign.rows[].invalid_clicks18intyesn/a
.breakdowns.campaign.rows[].key20stryesn/a
.breakdowns.campaign.rows[].label20stryesn/a
.breakdowns.campaign.rows[].spend_minor20intyesn/a
.breakdowns.campaign.status219stryesn/a
.breakdowns.device219containeryesn/a
.breakdowns.device.currency219none/stryesn/a
.breakdowns.device.dimension219stryesn/a
.breakdowns.device.rows219containeryesn/a
.breakdowns.device.rows[].clicks2intyesn/a
.breakdowns.device.rows[].invalid_clicks2nullyesn/a
.breakdowns.device.rows[].key2stryesn/a
.breakdowns.device.rows[].label2stryesn/a
.breakdowns.device.rows[].spend_minor2intyesn/a
.breakdowns.device.status219stryesn/a
.breakdowns.geo219containeryesn/a
.breakdowns.geo.currency219none/stryesn/a
.breakdowns.geo.dimension219stryesn/a
.breakdowns.geo.rows219containeryesn/a
.breakdowns.geo.rows[].clicks2intyesn/a
.breakdowns.geo.rows[].invalid_clicks2nullyesn/a
.breakdowns.geo.rows[].key2stryesn/a
.breakdowns.geo.rows[].label2stryesn/a
.breakdowns.geo.rows[].spend_minor2intyesn/a
.breakdowns.geo.status219stryesn/a
.credits219containeryesn/a
.credits.as_of219int/noneyesn/a
.credits.credit_count219int/noneyesn/a
.credits.credited_minor219int/noneyesn/a
.credits.currency219none/stryesn/a
.credits.status219stryesn/a
.derived_detection_targeting219containeryesn/a
.derived_detection_targeting.location_setting31stryesn/a
.derived_detection_targeting.metro_radius31nullyesn/a
.derived_detection_targeting.target_countries31containeryesn/a
.derived_detection_targeting.target_countries[]31stryesn/a
.fetched_at219intyesn/a
.invalid_clicks219containeryesn/a
.invalid_clicks.currency219none/stryesn/a
.invalid_clicks.invalid_click_cost_minor219nullyesn/a
.invalid_clicks.invalid_clicks219int/noneyesn/a
.invalid_clicks.status219stryesn/a
.period219containeryesn/a
.period.period_start219stryesn/a
.period.period_type219stryesn/a
.platform219stryesn/a
.provider219stryesn/a
.spend219containeryesn/a
.spend.clicks219int/noneyesn/a
.spend.currency219none/stryesn/a
.spend.impressions219int/noneyesn/a
.spend.spend_minor219int/noneyesn/a
.spend.status219stryesn/a
.targeting219containeryesn/a
.targeting.campaigns219containeryesn/a
.targeting.campaigns[].campaign_id37stryesn/a
.targeting.campaigns[].campaign_name37stryesn/a
.targeting.campaigns[].location_setting37stryesn/a
.targeting.campaigns[].metro_radius37nullyesn/a
.targeting.campaigns[].target_countries37containeryesn/a
.targeting.campaigns[].target_countries[]37stryesn/a
.targeting.status219stryesn/a

raw_events

Source: dynamodb://kliksight-raw-events

Records read: 13 across 1 page(s)

Counting method: scan paginated to exhaustion. Count 13, ScannedCount 13, across 1 page(s), LastEvaluatedKey absent on the final page: True.

DescribeTable ItemCount, a cached estimate and NOT the count of record: 13 (differs from the scanned count by 0).

pathoccurrencestypein allowlistenumerated in Annex 1/4
.account_id13stryesNO
.asn13intyesyes
.asn_org13stryesyes
.automation_declared13stryesNO
.click_id_ambiguous13boolyesNO
.consent_purpose13stryesyes
.consent_state13stryesyes
.country13stryesyes
.device_class13stryesyes
.expires_at13intyesNO
.fbclid13nullyesyes
.gclid13stryesyes
.ip_hash13stryesyes
.ip_hash_version13intyesNO
.ip_prefix13stryesyes
.is_datacenter13boolyesyes
.li_fat_id13nullyesyes
.msclkid13nullyesyes
.os_family13stryesyes
.platform13stryesyes
.sk13stryesNO
.ts13intyesyes
.ttclid13nullyesyes
.ua13stryesyes
.ua_family13stryesyes
.ua_major13intyesyes
.webview_app13nullyesyes

6 path(s) in this class are not enumerated in Annex 1 or Annex 4: .account_id, .automation_declared, .click_id_ambiguous, .expires_at, .ip_hash_version, .sk

evidence_records

Source: dynamodb://kliksight-detections

Records read: 14 across 1 page(s)

Counting method: scan paginated to exhaustion. Count 14, ScannedCount 14, across 1 page(s), LastEvaluatedKey absent on the final page: True.

DescribeTable ItemCount, a cached estimate and NOT the count of record: 14 (differs from the scanned count by 0).

pathoccurrencestypein allowlistenumerated in Annex 1/4
.account_id14stryesNO
.agency_id14stryesNO
.agency_sk14stryesNO
.asn14intyesyes
.asn_org14nullyesyes
.asn_org_suppressed14boolyesNO
.contribution_eligible14boolyesNO
.country14stryesyes
.created_at14intyesNO
.expires_at14intyesNO
.first_seen_at14intyesyes
.flagged14boolyesyes
.hit_count14intyesyes
.is_datacenter14boolyesyes
.is_test14boolyesNO
.last_seen_at14intyesyes
.pattern14stryesNO
.period_start14stryesyes
.period_type14stryesyes
.platform14stryesyes
.rules14nullyesyes
.rules_not_evaluated14containeryesNO
.rules_not_evaluated[].id16stryesNO
.rules_not_evaluated[].reason16stryesNO
.sample_events14nullyesyes
.samples_suppressed_reason14stryesNO
.sk14stryesNO
.targeting14containeryesyes
.targeting.location_setting14stryesyes
.targeting.metro_radius14nullyesyes
.targeting.target_countries14containeryesyes
.targeting.target_countries[]14stryesyes
.weight14nullyesyes

14 path(s) in this class are not enumerated in Annex 1 or Annex 4: .account_id, .agency_id, .agency_sk, .asn_org_suppressed, .contribution_eligible, .created_at, .expires_at, .is_test, .pattern, .rules_not_evaluated, .rules_not_evaluated[].id, .rules_not_evaluated[].reason, .samples_suppressed_reason, .sk

Summary of fields present but not enumerated in the annexes

raw_events: 6 - .account_id, .automation_declared, .click_id_ambiguous, .expires_at, .ip_hash_version, .sk

evidence_records: 14 - .account_id, .agency_id, .agency_sk, .asn_org_suppressed, .contribution_eligible, .created_at, .expires_at, .is_test, .pattern, .rules_not_evaluated, .rules_not_evaluated[].id, .rules_not_evaluated[].reason, .samples_suppressed_reason, .sk

Limits of this extract

It reports what exists at the moment of generation. A record class whose rows are short-lived can be absent from a run and present an hour later; the DEDUPE# rows in the raw-event table carry a short TTL and are one such shape.

The "enumerated in Annex 1/4" column is a transcription of the annex prose into a field set, held in ANNEX_DISCLOSED in the scan source. It is a reading of the contract, not an output of the system, and should be re-read whenever the annexes change.

It records field COMPOSITION. It does not assess whether a disclosed field's contents are what the annex says they are.