Last updated: September 2026
Roles
For data we process on your instructions — such as campaign audiences, CRM exports and analytics data — you are the controller and we act as a processor or service provider. For our own business records, such as prospect enquiries and invoices, we act as the controller.
Scope and instructions
We process client data only to deliver the services set out in the proposal, to report on them, and where required by law. We do not sell client data, and we do not use it to train models or to benefit other clients.
Security practices
- Access granted on a least-privilege basis and reviewed when staff or scope changes
- Multi-factor authentication required on platform and email accounts we control
- Data transferred over encrypted connections and kept in approved tools only
- Access to your platforms revoked at the end of an engagement
No system is completely secure. These are the controls we operate today; they are not an independent certification of our security posture.
Subprocessors
| Category | Providers | Purpose |
|---|---|---|
| Advertising platforms | Google, Meta, LinkedIn, TikTok | Campaign delivery and measurement |
| Analytics | Google Analytics 4, Google Tag Manager | Website and campaign measurement |
| Website hosting | Lovable hosting infrastructure | Serving this website and its forms |
| Client systems | Your CRM, ESP and reporting tools | Only where you grant us access |
We will tell clients in advance before adding a subprocessor that handles their personal data.
Data subject requests
If you receive an access, correction or deletion request relating to data we process for you, we will assist you in responding within a reasonable timeframe. Individuals can also contact us directly and we will route the request to the relevant client.
Retention and deletion
Client data is retained for the duration of the engagement and for up to 90 days afterwards to support handover, then deleted from our systems except where we must keep records for accounting or legal reasons. Deletion can be requested sooner in writing.
Incidents
If we become aware of a security incident affecting client data we process, we will notify the affected client without undue delay with the facts known at the time, and support their investigation.
Contact
For data protection questions or to request a signed agreement:
A & J Custom Graphics & Signs842 Saratoga Road, Burnt Hills, NY 12027
Phone: (518) 399-9291
Email: hello@ajdigital.com
This summary is app-owned content describing our current practices. It is not a certification, an audit result or a substitute for a signed data processing agreement — we are happy to execute your own DPA on request.