Terms of Service
Weavely Ltd — Terms of Service
Last updated: 11 June 2026
Agreement to These Terms
These Terms of Service (the "Terms") are a legally binding agreement between you, whether personally or on behalf of an entity ("you" or the "Customer"), and Weavely Ltd, a company registered in England and Wales under company number 16331589, whose registered office is at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom ("Weavely", "we", "us" or "our"). Our VAT number is GB345964955.
These Terms govern your access to and use of the website at https://www.weavely.io (the "Site") and our data pipeline platform, applications, APIs and related services (together, the "Services").
By creating an account, clicking to accept, or otherwise accessing or using the Services, you confirm that you have read, understood and agree to be bound by these Terms and by our Privacy Policy and the Data Processing Terms set out in Schedule 1. If you are entering into these Terms on behalf of an organisation, you confirm that you have authority to bind that organisation. If you do not agree to these Terms, you must not access or use the Services.
The Services are intended for business use by users who are at least 18 years old and are not directed at consumers or to children. By using the Services you confirm you are using them for purposes relating to your trade, business, craft or profession.
1. The Services
Weavely is a data pipeline platform built for marketing agencies and brands. The Services extract marketing and advertising data from third-party platforms (such as Google Ads, Meta, TikTok, Amazon Ads, LinkedIn, Google Analytics 4 and Google Search Console) and load it into a data warehouse that you own and control, principally Google BigQuery within your own Google Cloud project (your "Warehouse").
Data ownership and no lock-in. Because your marketing data is delivered into your own Warehouse, you own and retain control of that data and the historical data asset built within it. We do not hold your marketing data hostage in a proprietary store as a condition of continued payment. If your subscription ends for any reason, the data already loaded into your Warehouse remains yours and stays in your Warehouse; what stops is our ongoing delivery of new data into it. This commitment is a core part of what you are paying for and survives termination.
The Services are provided for your internal business purposes. They are not designed or certified for environments subject to sector-specific regimes such as HIPAA or comparable healthcare, financial or government data regimes, and you must not use the Services to process data subject to such regimes unless we have agreed otherwise in writing.
Those who access the Services from outside the United Kingdom do so on their own initiative and are responsible for compliance with local law to the extent it applies.
2. Accounts and Registration
To use most of the Services you must register for an account. You agree to provide accurate, current and complete information and to keep it up to date. You are responsible for safeguarding your account credentials and for all activity that occurs under your account. You must notify us promptly at help@weavely.io if you suspect any unauthorised use of your account.
You are responsible for the acts and omissions of your authorised users and for ensuring they comply with these Terms. We may suspend or terminate access if information you provide is untrue, inaccurate or incomplete, or where required to protect the security or integrity of the Services.
3. Connecting Third-Party Platforms and Your Warehouse
The Services work by connecting, at your instruction, to your accounts with third-party advertising and analytics platforms ("Source Platforms") and to your Warehouse. You authorise us to access those accounts via the credentials, OAuth tokens or other access you provide, solely in order to provide the Services.
You represent and warrant that you are entitled to grant us this access, that doing so does not breach your agreements with any Source Platform or Warehouse provider, and that you have all necessary rights and permissions in the underlying data. Your use of each Source Platform and your Warehouse is governed by your own agreement with the relevant provider, and we are not responsible for those services.
Dependency on third parties. Source Platforms and warehouse providers control their own APIs, data fields, rate limits and availability, and may change, deprecate or withdraw them at any time, in ways outside our control. We work to maintain and update our connectors promptly when this happens, but we do not warrant uninterrupted availability of any particular connector, field, or historical backfill, and we are not liable for changes, outages, throttling, data gaps or inaccuracies originating from a Source Platform or warehouse provider.
4. Fees, Billing and Renewal
Pricing model. We charge a flat fee per connected ad account or other billable unit set out in your plan or order, irrespective of data volume. We do not charge per row, per credit or per "flexpoint". Applicable taxes (including VAT where it applies) are added to the fees.
Standard plans (billed in arrears). Unless your order states otherwise, fees for standard plans are calculated based on your actual usage during each calendar month (for example, the number of connected accounts active during that month) and are charged at the end of that month.
Enterprise plans (prepaid allowance). Enterprise plans are charged at the start of the applicable billing period for a committed bulk allowance, which you may then use at your discretion during that period in accordance with your order. Unless your order states otherwise, prepaid allowances do not roll over to a later period and prepaid fees are non-refundable except as required by law.
Payment. You agree to keep your payment and billing details current and you authorise us (and our payment processors) to charge your chosen payment method for all fees as they fall due, including on a recurring basis without requiring prior approval for each charge, until the relevant plan is cancelled. We accept the payment methods made available at checkout or stated in your order. All payments are in GBP unless your order specifies another currency.
Late payment. If undisputed fees are overdue, we may suspend the Services on reasonable notice and charge interest on overdue amounts at the statutory rate under the Late Payment of Commercial Debts (Interest) Act 1998. Suspension of delivery does not affect your ownership of data already in your Warehouse.
Price changes. We may change our fees. For changes affecting your plan, we will give you at least 30 days' notice before the change takes effect, and the change will apply from your next renewal or billing period. If you do not accept a price change, you may cancel before it takes effect.
5. Free Trial
We may offer a free trial to new users. Unless stated otherwise at sign-up, the trial lasts 30 days. At the end of the trial your account will convert to the paid plan you selected and billing will begin in accordance with section 4, unless you cancel before the trial ends. We may modify or withdraw trial offers at any time.
6. Cancellation, Suspension and Termination
Cancellation by you. You may cancel your subscription at any time from within your account or by emailing help@weavely.io. For standard plans, cancellation stops further data delivery and you will be billed for usage up to the effective date of cancellation. For enterprise plans, cancellation takes effect at the end of the prepaid period for which you have already been charged, and prepaid fees are non-refundable except as required by law.
Termination by us. We may suspend or terminate your access if you materially breach these Terms (including non-payment) and, where the breach is capable of remedy, fail to remedy it within 14 days of notice; if required by law; or to protect the security, integrity or lawful operation of the Services or other customers. Where practicable and lawful we will give you notice.
Effect of termination. On termination, your right to access the Services ends and we stop delivering new data into your Warehouse. Data already loaded into your Warehouse remains in your Warehouse and remains yours. We will handle any personal data we still hold as a processor in accordance with Schedule 1. Sections that by their nature should survive (including sections 1 (data ownership), 7, 9, 10, 11, 12, 13 and Schedule 1) survive termination.
7. Availability, Support and Changes
We aim to keep the Services available and reliable, including monitoring pipelines and retrying failed data fetches. Any specific service-level commitments (for example, target uptime or support response times) apply only where expressly set out in an order or a separate service-level agreement. In the absence of such a document, the Services are provided on a commercially reasonable-efforts basis.
We may need to carry out maintenance, and we may modify, improve or discontinue features of the Services. We will not be liable for unavailability during planned or emergency maintenance or for discontinuing a feature, provided that for changes that materially reduce core functionality of a paid plan we will give reasonable notice and you may cancel if the change has a material adverse effect on you.
8. Acceptable Use
You agree not to, and not to permit anyone else to:
use the Services in breach of any applicable law or regulation, or to infringe the rights of others;
upload or transmit malware, or interfere with, disrupt, probe or place an undue burden on the Services or their infrastructure;
attempt to gain unauthorised access to the Services, other customers' data, or any systems or networks connected to the Services;
reverse engineer, decompile or disassemble any part of the Services, except to the extent this restriction is prohibited by applicable law;
copy, resell, sublicense or make the Services available to any third party except as expressly permitted, or use the Services to build a competing product;
misrepresent your identity or your authority to connect a Source Platform or Warehouse, or provide data you do not have the right to provide; or
use the Services to process special category personal data, children's data, or data subject to sector-specific regimes, except as expressly agreed in writing.
We may investigate suspected breaches and take appropriate action, including suspension, and (where legally required) reporting to authorities.
9. Intellectual Property
Our IP. We and our licensors own all intellectual property rights in the Services, including the platform software, connectors, Site, designs, documentation and the Weavely name and logo (the "Marks"). Subject to these Terms, we grant you a non-exclusive, non-transferable, revocable licence to access and use the Services for your internal business purposes during your subscription. We reserve all rights not expressly granted.
Your data. As between you and us, you own your marketing data, the data delivered into your Warehouse, and the configurations and client structures you create. You grant us a limited licence to access, copy, transmit and process that data only as necessary to provide, secure and improve the Services and as set out in Schedule 1.
Feedback. If you send us suggestions or feedback about the Services, you grant us a perpetual, royalty-free licence to use it without restriction or obligation to you. We do not, however, claim ownership of your underlying data or confidential information by virtue of feedback.
10. Confidentiality
Each party may receive confidential information of the other. The receiving party will use the other's confidential information only to perform under these Terms, protect it with reasonable care, and not disclose it except to personnel and advisers who need it and are under similar obligations. This does not apply to information that is public through no fault of the receiving party, independently developed, lawfully received from a third party, or required to be disclosed by law (with notice where permitted).
11. Warranties and Disclaimers
We warrant that we will provide the Services with reasonable skill and care. Except for that warranty and any rights you have under mandatory law that cannot be excluded, the Services are provided "as is" and "as available", and we disclaim all other warranties, whether express or implied, including implied terms as to satisfactory quality, fitness for a particular purpose and non-infringement, to the fullest extent permitted by law.
We do not warrant that the Services will be uninterrupted or error-free, that all data will be complete or accurate (in particular where it originates from or is affected by Source Platforms or warehouse providers), or that the Services will meet every requirement you may have. You are responsible for verifying outputs before relying on them for business decisions.
12. Limitation of Liability
Nothing excluded. Nothing in these Terms limits or excludes either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be limited or excluded by law.
Excluded losses. Subject to the paragraph above, neither party is liable to the other for any indirect or consequential loss, or for loss of profit, revenue, anticipated savings, goodwill, or business, in each case whether arising in contract, tort (including negligence) or otherwise.
Cap. Subject to the paragraphs above, each party's total aggregate liability arising out of or in connection with these Terms in any 12-month period is limited to the total fees paid or payable by you to us for the Services in the 12 months immediately before the event giving rise to the liability. The parties acknowledge this allocation of risk is reflected in the fees.
Your data is your responsibility. You are responsible for maintaining your own backups and for the configuration and security of your Warehouse and Source Platform accounts. While we take reasonable care, we are not liable for loss or corruption of data within your Warehouse or third-party accounts that is not caused by our breach of these Terms.
13. Indemnity
You will indemnify us against reasonable losses, damages and costs (including reasonable legal fees) arising from a third-party claim to the extent caused by your breach of section 3 (rights to connect and provide data), section 8 (acceptable use), or your infringement of a third party's rights through data you provide to the Services. We will notify you of the claim, allow you to control the defence (without settling in a way that admits liability on our part or imposes obligations on us without our consent), and provide reasonable cooperation at your expense.
14. Data Protection
We care about data protection and security. Our handling of personal data is governed by our Privacy Policy at https://www.weavely.io/legal/privacy-policy and by the Data Processing Terms in Schedule 1, which form part of these Terms. Where we process personal data on your behalf in providing the Services, you are the controller and we are the processor, and Schedule 1 applies.
The Services are operated from the United Kingdom, and we may use sub-processors located elsewhere. International transfers are addressed in Schedule 1. If you access the Services from a jurisdiction with different data protection requirements, you are responsible for your own compliance as controller.
15. Third-Party Services and Links
The Services interoperate with, and may contain links to, third-party services and content. We do not control and are not responsible for third-party services, including Source Platforms, your Warehouse provider, payment processors and any linked sites. Your use of them is at your own risk and subject to their terms.
16. Changes to These Terms
We may update these Terms from time to time. For changes that materially affect your rights or obligations, we will give you reasonable prior notice (for example, by email to the address on your account or by notice within the Services) before they take effect. Your continued use of the Services after the effective date constitutes acceptance. If you do not accept a material change, you may cancel before it takes effect. Minor or legally required changes may take effect on posting.
17. Governing Law and Disputes
These Terms and any dispute or claim arising out of or in connection with them (including non-contractual disputes) are governed by the laws of England and Wales. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Resolution. The parties will first try in good faith to resolve any dispute through senior representatives for at least 30 days. If they cannot, the courts of England and Wales have exclusive jurisdiction, except that either party may seek injunctive or other urgent relief, and may bring proceedings to protect its intellectual property or confidential information, in any court of competent jurisdiction. Nothing in this section deprives a customer who is a consumer of the protection of mandatory provisions of the law of their country of residence.
18. General
Entire agreement. These Terms, together with the Privacy Policy, Schedule 1 and any order, are the entire agreement between the parties on their subject matter and supersede prior discussions. Where there is a conflict, a signed order prevails over the body of these Terms, which prevails over Schedule 1 except on data protection matters, where Schedule 1 prevails.
Assignment. You may not assign or transfer these Terms without our consent. We may assign them to an affiliate or in connection with a merger, acquisition or sale of assets, on notice to you.
Subcontracting. We may use subcontractors and sub-processors to help provide the Services, and remain responsible for their performance.
Force majeure. Neither party is liable for failure or delay caused by events beyond its reasonable control.
Waiver and severance. A failure to enforce a term is not a waiver of it. If any term is found unlawful or unenforceable, it is severed and the remaining terms continue in force.
No partnership. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship between the parties.
Third parties. Except as expressly stated, a person who is not a party has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce these Terms.
Notices and electronic communications. You consent to receiving communications from us electronically, and agree that electronic agreements, notices and records satisfy any legal requirement that such communications be in writing. Legal notices to us should be sent to help@weavely.io and to our registered office.
19. Contact Us
Questions about these Terms or the Services can be sent to:
Weavely Ltd 71-75 Shelton Street Covent Garden London WC2H 9JQ United Kingdom Email: help@weavely.io
Schedule 1 – Data Processing Terms
These Data Processing Terms ("DPA") apply where, in providing the Services, Weavely processes personal data on the Customer's behalf. They form part of the Terms. Terms used here have the meaning given in the UK GDPR and the Data Protection Act 2018, and, where the EU GDPR applies, in the EU GDPR (together, "Data Protection Law").
1. Roles
For personal data contained in the marketing data processed through the Services, the Customer is the controller (or a processor acting for its own customers) and Weavely is the processor (or sub-processor). Each party will comply with its obligations under Data Protection Law.
2. Scope and instructions
Weavely will process personal data only on the Customer's documented instructions, including those set out in the Terms and given through configuration of the Services, except where required by law (in which case Weavely will, where lawful, inform the Customer). The subject matter, duration, nature, purpose, types of personal data and categories of data subjects are described in Annex A.
The Customer is responsible for ensuring it has a lawful basis to provide the personal data to Weavely and to instruct the processing, and that its instructions do not put Weavely in breach of Data Protection Law.
3. Confidentiality and staff
Weavely will ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations and have received appropriate data protection training.
4. Security
Taking account of the state of the art, costs of implementation and the nature, scope, context and purposes of processing, Weavely will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as relevant, encryption in transit, access controls, network security, logging and monitoring, and regular testing of measures.
5. Sub-processors
The Customer gives general authorisation for Weavely to engage sub-processors to help provide the Services. Current sub-processors include cloud and infrastructure providers (for example, Google Cloud) and the payment and operational tools we use to run the Services; a current list is available on request. Weavely will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for their performance. Weavely will give the Customer notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on reasonable data protection grounds.
6. Data subject requests and assistance
Taking into account the nature of the processing, Weavely will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights, and will assist the Customer in ensuring compliance with its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to Weavely.
7. Personal data breach
Weavely will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf, and will provide information reasonably available to it to help the Customer meet its own notification obligations.
8. International transfers
Weavely will not transfer personal data to a country outside the UK or, where the EU GDPR applies, the EEA, unless it has taken steps to ensure the transfer complies with Data Protection Law. Where required, the parties will rely on an adequacy decision, the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses (which are incorporated by reference and completed by reference to Annex A), together with any supplementary measures needed. This addresses transfers relevant to the Customer's US, EU, German and other international operations.
9. Return and deletion
On the Customer's request, and in any event on termination of the Services, Weavely will delete personal data it holds as processor, except (a) personal data already delivered into the Customer's own Warehouse, which remains under the Customer's control and is the Customer's responsibility, and (b) data Weavely is required to retain by law. Deletion will take place within a reasonable period taking account of routine backup cycles.
10. Audit
Weavely will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, no more than once per year except where required by a supervisory authority or following a breach, on reasonable notice, during business hours, subject to confidentiality, and in a manner that does not unreasonably disrupt Weavely's operations or compromise other customers' data.
Annex A – Processing Details
Subject matter | Provision of the Weavely data pipeline Services, extracting marketing data from Source Platforms and loading it into the Customer's Warehouse. |
Duration | For the term of the subscription and as set out in clause 9 of this DPA. |
Nature and purpose | Collection, retrieval, transmission, structuring and loading of marketing and advertising data for the Customer's reporting and analytics purposes. |
Types of personal data | Business contact details of the Customer's users; and any personal data incidentally contained in marketing/advertising platform data the Customer chooses to connect (for example, identifiers within campaign or analytics data). The Customer controls what data is connected. |
Categories of data subjects | The Customer's personnel and authorised users; and individuals whose data may appear within connected marketing data sources. |
Annex 12 – Data Processing Agreement ("DPA")
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer") and Weavely Ltd ("Weavely") for the Customer's use of the Weavely service (the "Agreement"), and is incorporated into Weavely's Terms of Service. It applies whenever the UK GDPR or EU GDPR applies to the Customer's use of the service. By accepting the Terms of Service, the Customer agrees to this DPA.
1. Background
1.1 The purpose of this DPA is to fulfil the requirements of a written agreement pursuant to Article 28 of the GDPR.
2. Definitions
2.1 "Data Protection Laws" means the UK GDPR, the EU GDPR (Regulation (EU) 2016/679), the UK Data Protection Act 2018, the CCPA, and any other applicable data protection or privacy laws.
2.2 "EU SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, or any successor version.
2.3 "UK Addendum" means the UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
2.4 "Personal Data" means the personal data that Weavely processes on behalf of the Customer pursuant to the Agreement, as described in Appendix A.
2.5 "Subprocessor" means any third party engaged by Weavely to process Personal Data under this DPA.
2.6 The terms "controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in the GDPR.
3. Roles and Processing Instructions
3.1 As between the parties, the Customer is the controller of the Personal Data and Weavely is the processor. The Customer complies with its obligations as controller, and Weavely complies with its obligations as processor under this DPA, Data Protection Laws and the Customer's written instructions.
3.2 This DPA, together with the Agreement and the Customer's use and configuration of the service, constitutes the Customer's documented instructions for the processing of Personal Data, as further detailed in Appendix A.
3.3 Weavely shall process Personal Data only on those instructions, unless required to do otherwise by law, in which case Weavely shall inform the Customer of that requirement before processing (unless the law prohibits it).
3.4 If Weavely believes an instruction infringes Data Protection Laws, it shall promptly inform the Customer.
4. Confidentiality
4.1 Weavely shall ensure that all persons authorised to process Personal Data are bound by an obligation of confidentiality and process Personal Data only as set out in this DPA.
4.2 Weavely shall ensure that access to Personal Data is limited to those personnel who need it to provide the service.
5. Security
5.1 Weavely shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, including as appropriate the measures referred to in Article 32 of the GDPR. Weavely's measures are described in Appendix B.
6. Personal Data Breach
6.1 Weavely shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Personal Data, and in any event no later than 72 hours after becoming aware where the breach falls under Article 33 of the GDPR. The notification shall describe what happened, the data involved, the measures taken, and a contact point, and shall provide sufficient information to enable the Customer to meet its own notification obligations under Data Protection Laws.
6.2 Weavely shall cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation and remediation of the breach.
7. Data Subject Rights
7.1 Taking into account the nature of the processing, Weavely shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to data subject requests. For marketing data processed via the service, that data resides in the Customer's own BigQuery instance under the Customer's control, so the Customer can action access, rectification and erasure requests directly; Weavely shall assist where a request relates to Weavely-held data or configuration.
7.2 If a data subject request is made directly to Weavely, Weavely shall inform the Customer without undue delay and shall not respond except on the Customer's instructions or as required by law.
8. Data Protection Impact Assessments
Weavely shall provide the Customer with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and the information available to Weavely.
9. Subprocessors
9.1 The Customer grants Weavely general authorisation to engage Subprocessors. Weavely shall ensure each Subprocessor is bound by data-protection obligations no less protective than those in this DPA, and remains fully liable for each Subprocessor's performance.
9.2 A current list of Subprocessors is available at https://weavely.io/legal/subprocessor-list (or another location notified by Weavely from time to time).
9.3 Weavely shall give the Customer reasonable advance notice of the addition or replacement of a Subprocessor. The Customer may object on reasonable data-protection grounds within ten (10) days; the parties shall then negotiate in good faith, and failing resolution either party may terminate the affected service on thirty (30) days' notice.
10. International Data Transfers
10.1 The Customer determines the storage region of its BigQuery instance and may keep EU data within the EU (for example by provisioning datasets in europe-west3, Frankfurt).
10.2 Weavely is established in the United Kingdom, which benefits from a European Commission adequacy decision. Certain subprocessors are located outside the UK/EEA, including in the United States. Where a transfer of Personal Data requires an additional safeguard under Data Protection Laws:
10.2.1 for Personal Data subject to the EU GDPR, the EU SCCs (Module Two: controller to processor) are incorporated by reference and completed as set out in Appendix C; and
10.2.2 for Personal Data subject to the UK GDPR, the EU SCCs as amended by the UK Addendum are incorporated by reference and completed as set out in Appendix C.
10.3 The Customer authorises Weavely to conclude the applicable SCCs and UK Addendum on the Customer's behalf where required for an onward transfer to a Subprocessor.
11. CCPA
11.1 Where Personal Data is subject to the CCPA, "controller" means "business" and "processor" means "service provider". Weavely acts as a service provider and shall not sell or share Personal Data, nor retain, use or disclose it for any purpose other than performing the service.
12. Audit
12.1 Weavely shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits by the Customer or an auditor mandated by the Customer (not a competitor of Weavely), on reasonable prior notice, during business hours, and subject to confidentiality undertakings. Where Weavely holds relevant third-party certifications or audit reports, it may satisfy this obligation by providing them; the parties acknowledge Weavely does not currently hold such certifications.
12.2 The Customer shall not exercise its audit rights more than once in any twelve (12) month period, except where required by a supervisory authority or following a personal data breach.
13. Retention, Return and Deletion
13.1 Marketing data processed via the service resides in the Customer's own BigQuery instance and remains under the Customer's control at all times; the Customer may export or delete it directly.
13.2 On termination or expiry of the Agreement, Weavely shall, at the Customer's choice, delete or return any Personal Data held within Weavely-controlled systems, and delete existing copies, unless storage is required by law. Weavely shall confirm completion on the Customer's written request.
14. Government Access
14.1 Weavely shall only comply with binding orders of governmental authorities as required by Data Protection Laws. Where subject to such an order, Weavely shall, to the extent legally permitted, give the Customer reasonable notice, disclose only what is required, and seek confidential treatment of any information disclosed.
15. Term, Precedence and Governing Law
15.1 This DPA applies for as long as Weavely processes Personal Data for the Customer.
15.2 In the event of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails. In the event of conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail for the relevant transfer.
15.3 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, without depriving a data subject of rights available under Data Protection Laws.
Appendix A — Details of Processing
Weavely processes two distinct categories of Personal Data on behalf of the Customer:
Category A — Marketing data (pass-through). Marketing and advertising data ingested into the Customer's own BigQuery instance. Weavely does not retain this data in its own systems beyond what is necessary to deliver the service; it flows through to the Customer-controlled warehouse.
Category B — Account and operational data (Weavely-held). Data Weavely holds in its own systems to operate the service, including user account details, authentication/login data, and logs.
Category A — Marketing data (pass-through) | Category B — Account / operational data | |
|---|---|---|
Subject matter & purpose | Ingestion, transfer, structuring and making available of marketing/advertising data within the Customer's BigQuery instance, for reporting and analytics. | Provision, administration, security and support of the service, including authentication, access control and logging. |
Categories of data subjects | End users / individuals in the Customer's connected marketing sources (e.g. website visitors, ad audiences, leads, contacts). | The Customer's authorised users (e.g. employees / staff who access the service). |
Categories of Personal Data | Online identifiers, cookie/device identifiers, IP addresses, contact details, and campaign interaction data, as present in the connected sources. | Names, email addresses, authentication credentials/identifiers, and log data (e.g. IP address, access timestamps, activity logs). |
Processing activities | Collection from sources via API; secure transmission to the Customer's BigQuery; transformation, structuring and aggregation; temporary caching with encryption at rest. | Account creation and management; authentication; logging and monitoring; access for support purposes; storage; deletion. |
Location of processing | The Customer's chosen BigQuery region. | Weavely's own Google Cloud Platform project (europe-west2, London, UK). |
Retention | Remains in the Customer's BigQuery under the Customer's control; not retained by Weavely beyond delivery needs. | For the term of the Agreement and a reasonable period thereafter, then deleted or returned per Section 13. |
Special category data: None intended. The Customer shall not route special category data through the service without prior written agreement.
AI-assisted features. Certain optional AI features submit account- and campaign-level data to third-party AI providers to generate outputs. These features are not designed to process end-user personal data, and the Customer shall not submit end-user personal data to them.
Other Weavely-held processing. Billing contact details are processed via the Customer's payment provider, and notification/report emails are sent via Weavely's email delivery subprocessor, as listed at https://weavely.io/legal/subprocessor-list.
Appendix B — Technical and Organisational Measures
These measures reflect Weavely's architecture, in which the Customer's marketing data resides in the Customer's own Google Cloud project rather than Weavely's.
Data ownership and residency: Marketing data lands in datasets inside the Customer's own Google Cloud project, inheriting the Customer's IAM, residency, encryption configuration and audit logging. The Customer can revoke Weavely's access at any time from its own Google Cloud console.
Encryption in transit: All traffic between the Customer's browser, Weavely's connectors and APIs, the ad platforms and the warehouse is encrypted with TLS 1.2 or higher; legacy protocols are disabled.
Encryption at rest — warehouse: Data in the Customer's BigQuery is encrypted at rest by Google Cloud using AES-256 by default, and supports customer-managed encryption keys (CMEK) configured by the Customer in Cloud KMS.
Encryption at rest — Weavely side: The limited operational data Weavely holds (account settings, connector configuration, pipeline metadata) is encrypted at rest by its cloud provider.
Credentials and secrets: OAuth tokens and service-account credentials are stored in a dedicated secrets manager, never in source code or configuration files; each integration requests the minimum scope needed; the Customer can rotate or revoke any connection from its dashboard.
Access control — Customer: Role-based access to scope who can configure connectors, run pipelines and manage billing; multi-factor authentication available.
Access control — Weavely staff: Least-privilege basis. Because marketing data resides in the Customer's BigQuery, Weavely staff have no standing access to it; access to a Customer project is granted only with the Customer's authorisation for a specific support purpose.
Data use: Weavely does not sell, rent or share Customer data and does not use it to train machine-learning models.
Application security: Code changes are reviewed by a second engineer before reaching production; open-source dependencies are monitored for known vulnerabilities and patched on a prioritised basis; production, staging and development environments are separated, and real customer data is not used in development.
Monitoring and incident response: Production systems are monitored for availability, errors and anomalous activity, with an internal incident-response process.
Subprocessor management: Maintenance of a subprocessor list and flow-down of data-protection obligations.
Appendix C — International Transfer Details (EU SCCs / UK Addendum)
This Appendix completes the EU SCCs (Module Two: controller to processor) and the UK Addendum referred to in Section 10.
Data exporter | The Customer (controller). |
Data importer | Weavely Ltd (processor), United Kingdom. |
Categories of data / data subjects | As set out in Appendix A. |
Frequency of transfer | Continuous, for the duration of the service. |
Sub-processors | As listed at https://weavely.io/legal/subprocessor-list. Core infrastructure is Google Cloud (europe-west2, London). Some subprocessors are located outside the UK/EEA (including in the USA); transfers to them are made under the EU SCCs and/or UK Addendum, or another valid Article 46 mechanism. |
Competent Supervisory Authority (EU SCCs) | The supervisory authority of the EU Member State in which the Customer is established. |
SCC optional clauses | Clause 7 (docking) applies; Clause 11 (independent dispute resolution) does not apply; Clause 17 governing law and Clause 18 forum: as per the data exporter's Member State (EU SCCs) and England and Wales (UK Addendum). |
Weavely Ltd · 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom · help@weavely.io
Own your marketing data. Scale without limits.