How this addendum is executed: every MabrookTrack customer signs this exact text electronically in the dashboard, pre-filled with their legal details, before their workspace is unlocked. The signed PDF (with the acceptance record — signatory, timestamp, IP address and document hash) is emailed to the customer and stays available under Settings. Placeholders in square brackets are filled with the customer's details at signing. Customers whose procurement requires a countersigned copy through an e-signature service can request one from Settings.
Parties and Background
This Data Processing Addendum (the "DPA") is entered into between:
- VM MEDIA LLC, Sharjah Media City (SHAMS), Sharjah, United Arab Emirates, operating the "MabrookTrack" service (the "Processor"); and
- [Customer legal name], [Customer registered address], represented by [Customer contact name] ([Customer account email]), operating the online store at [Customer store URL] (the "Controller").
Effective date: [Date of acceptance]. Version: 2026-09-17.
This DPA forms part of, and is governed by, the MabrookTrack Terms of Service between the parties (the "Agreement"). It sets out the parties' obligations when the Processor processes Personal Data on behalf of the Controller through the Service. Where VM MEDIA LLC also provides advertising-management or other agency services to the Controller under a separate engagement, this DPA governs only the processing performed through the Service.
1. Definitions
Capitalised terms not defined here have the meaning given in the Agreement. In this DPA:
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its executive regulations ("UAE PDPL"), the Personal Data Protection Law of the Kingdom of Saudi Arabia issued by Royal Decree M/19 of 1443H as amended by Royal Decree M/148 of 1444H, its Implementing Regulations and the Regulation on Personal Data Transfer outside the Kingdom, each as issued by the Saudi Data and Artificial Intelligence Authority ("SDAIA") (together "KSA PDPL"), and any other data protection law applicable to a party.
- "Personal Data" means any information relating to an identified or identifiable natural person that the Processor processes on behalf of the Controller under the Agreement, as described in Annex A.
- "Data Subject" means the natural person to whom Personal Data relates, in particular the Controller's website visitors and customers.
- "Processing" means any operation performed on Personal Data, including collection, hashing, storage, matching, transmission, restriction and deletion.
- "Sub-Processor" means any third party engaged by the Processor to process Personal Data on the Controller's behalf (Annex C).
- "Advertising Platform" means an advertising service (such as TikTok, Meta, Snap or Google) to which the Controller instructs the Processor to transmit conversion signals through its account configuration.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- "Supervisory Authority" means the UAE Data Office, SDAIA, or any other authority competent for Data Protection Laws.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data outside the Kingdom of Saudi Arabia issued by SDAIA, in the version current on the Effective date (Annex D).
2. Roles of the Parties
- The Controller determines the purposes and means of processing the Personal Data of its own customers and website visitors. The Processor processes that Personal Data only on the Controller's documented instructions as set out in this DPA, the Agreement and the Controller's configuration of the Service.
- With respect to Personal Data the Processor collects in its own right — the Controller's account, billing and support data, and visitors of the Processor's own website — the Processor acts as an independent controller under its Privacy Policy. This DPA does not govern that data.
- Each Advertising Platform to which conversion signals are transmitted at the Controller's configuration acts as an independent controller of the data it receives, under its own terms and privacy policy. The Controller is responsible for its relationship with, the lawful basis for, and the transfer of Personal Data to, each Advertising Platform it configures.
- Nothing in this DPA makes the Processor a joint controller with the Controller or with any Advertising Platform.
3. Scope, Purpose and Instructions
- The subject-matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are described in Annex A.
- The Controller's documented instructions consist of this DPA, the Agreement, and the settings the Controller applies in the Service (including which store platforms are connected, which Advertising Platforms receive conversion signals, attribution windows and event filters). Further instructions must be given in writing and may be subject to a reasonable fee if they exceed the scope of the Service.
- The Processor shall inform the Controller without delay if, in its opinion, an instruction infringes Data Protection Laws. The Processor may then suspend the affected processing until the instruction is confirmed or amended.
4. Obligations of the Processor
The Processor shall:
- process Personal Data only on the Controller's documented instructions, unless required to do otherwise by law — in which case it shall inform the Controller of that requirement before processing, unless the law prohibits it;
- not sell, rent, license or otherwise commercialise Personal Data, not use it for its own marketing or for the benefit of any other customer, and not combine it with Personal Data of other customers, except in aggregated and anonymised form that no longer relates to an identifiable person (e.g. service-wide match-rate statistics);
- ensure that every person authorised to process Personal Data is bound by a contractual or statutory duty of confidentiality and has received appropriate data-protection training;
- implement and maintain the technical and organisational measures set out in Annex B, and not materially reduce the overall level of protection during the term;
- engage Sub-Processors only in accordance with Clause 7;
- assist the Controller, taking into account the nature of the processing, in responding to Data Subject requests in accordance with Clause 8;
- assist the Controller in meeting its obligations regarding security, Personal Data Breach notification, data protection impact assessments and prior consultation with a Supervisory Authority, taking into account the information available to the Processor;
- maintain a record of its processing activities on behalf of the Controller as required by the UAE PDPL and the KSA PDPL, and make the relevant extract available to the Controller on request;
- designate a privacy contact (Clause 17.4) responsible for this DPA and for cooperation with the Controller and, through the Controller, with any Supervisory Authority;
- make available to the Controller the information necessary to demonstrate compliance with this DPA and allow for audits in accordance with Clause 11;
- at the Controller's choice, delete or return all Personal Data at the end of the Service in accordance with Clause 12; and
- promptly notify the Controller if it receives a legally binding request for disclosure of Personal Data from a public authority, unless prohibited by law, and disclose only the minimum required.
5. Obligations of the Controller
The Controller shall:
- ensure that it has a valid legal basis under Data Protection Laws — and, where required, the Data Subject's consent — to collect the Personal Data, to have it processed through the Service, and to have conversion signals transmitted to each Advertising Platform it configures;
- provide its Data Subjects with a privacy notice that accurately describes the processing performed through the Service, including server-side conversion tracking, hashing of identifiers and onward transmission to Advertising Platforms, and implement any cookie or tracking consent mechanism required by Data Protection Laws;
- where Data Subjects are located in the Kingdom of Saudi Arabia, comply with the KSA PDPL requirements applicable to a controller, including the rules on consent for advertising and marketing purposes, and any registration or notification obligation with SDAIA that applies to the Controller's activities;
- not instruct the Processor to process Personal Data in breach of Data Protection Laws, and not submit through the Service any sensitive or special-category Personal Data (including health, genetic, biometric, religious, credit or criminal data) or the Personal Data of children, without the Processor's prior written agreement;
- keep its account credentials confidential, keep its business and contact details in the Service accurate, and ensure that only authorised persons access its workspace;
- comply with the terms of each Advertising Platform it configures, including their conversion-API terms and data-use policies; and
- be responsible for any notification to a Supervisory Authority or to Data Subjects that Data Protection Laws require the Controller to make, including notification of a Personal Data Breach to SDAIA within 72 hours where the KSA PDPL applies.
6. Security of Processing
- The Processor shall implement the technical and organisational measures set out in Annex B, which the parties agree are appropriate to the risk having regard to the state of the art, the nature of the Personal Data (predominantly one-way hashed identifiers) and the purposes of processing.
- Directly identifying identifiers (email address, phone number, first and last name) are converted to SHA-256 hashes at the edge before storage. Raw values of these identifiers are not persisted in the Processor's database.
- The Processor may update Annex B from time to time to reflect technical progress, provided the overall level of protection is not reduced. Material changes will be reflected in a new version of this DPA.
7. Sub-Processors
- The Controller gives the Processor general authorisation to engage the Sub-Processors listed in Annex C. The current list is also published at https://mabrooktrack.com/subprocessors.
- The Processor shall impose on each Sub-Processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to the Controller for the performance of each Sub-Processor.
- The Processor shall notify the Controller — by email to the Controller's account email and by updating the published list — at least 30 days before the intended addition or replacement of a Sub-Processor. Within that period the Controller may object on reasonable, documented data-protection grounds. The parties shall work in good faith to resolve the objection; if no resolution is found before the change takes effect, the Controller may terminate the affected part of the Service without penalty.
- Advertising Platforms are not Sub-Processors. They receive data only because and to the extent the Controller configures them in the Service.
8. Data Subject Rights
- The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests to exercise Data Subject rights (access, correction, erasure, restriction, portability, objection, withdrawal of consent) within the time limits set by Data Protection Laws.
- If the Processor receives such a request directly from a Data Subject, it shall forward the request to the Controller within two business days and shall not respond to the Data Subject except on the Controller's documented instructions, other than to confirm that the request has been forwarded.
- On the Controller's written instruction the Processor shall locate the records associated with a hashed identifier supplied by the Controller and delete or export them within 15 days. The Processor cannot identify a Data Subject from the hashed values it holds without the Controller providing the original identifier.
9. Personal Data Breach
- The Processor shall notify the Controller without undue delay, and in any event within 24 hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data. Notification will be sent to the Controller's account email and, where a phone number is on file, by telephone or messaging.
- The initial notification shall describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information not available at the time of the initial notification shall be provided in phases without undue delay.
- The Processor shall cooperate with the Controller, take reasonable steps to contain and remediate the breach, preserve relevant logs, and provide the information the Controller reasonably needs to meet its own notification duties towards Supervisory Authorities and Data Subjects.
- The Processor shall not notify a Supervisory Authority or Data Subjects of a Personal Data Breach on the Controller's behalf unless instructed by the Controller in writing or required by law. Notification of a breach is not an acknowledgement of fault or liability.
10. International Transfers and Data Location
- The Controller's Personal Data is stored in a managed PostgreSQL database operated by Supabase, Inc. in the AWS Asia-Pacific (Mumbai, ap-south-1) region, India. Event ingestion runs on Cloudflare's global edge network (transient processing only). The dashboard and marketing site are hosted by Vercel, Inc. with server functions pinned to the Mumbai region. Transactional email is sent via Resend, Inc. (USA).
- The Controller acknowledges and, by accepting this DPA, instructs the transfer of Personal Data to the locations in Clause 10.1 and Annex C. A deployment inside the GCC is not part of the standard Service; a Controller with a residency requirement must raise it before onboarding so the parties can agree a dedicated deployment.
- Where the transfer of Personal Data of Data Subjects in the Kingdom of Saudi Arabia outside the Kingdom requires a safeguard under the KSA PDPL, the parties agree that the Standard Contractual Clauses issued by SDAIA (controller-to-processor) are incorporated into this DPA in accordance with Annex D, with the Controller as data exporter and the Processor as data importer, and with Annexes A, B and C serving as the appendices to those clauses. In case of conflict, the Standard Contractual Clauses prevail over this DPA for the transfer they govern.
- Where the UAE PDPL applies, the parties rely on this DPA and the contractual safeguards it contains as the appropriate safeguard for transfers to jurisdictions without an adequacy decision, together with the other lawful transfer mechanisms available under the UAE PDPL (including the Data Subject's explicit consent obtained by the Controller and the necessity of the transfer for the performance of the contract).
- The Processor shall make available to the Controller, on request, a transfer risk assessment covering the destination countries, the safeguards applied and the level of protection provided, to support the Controller's own assessment.
- The Processor applies data minimisation to every transfer: identifiers are hashed before storage and transmission, raw IP addresses are retained for no more than 30 days, and no device fingerprinting is performed.
- The Processor shall promptly inform the Controller if it becomes aware that the laws of a destination country prevent it from complying with this DPA, and the Controller may then suspend the affected transfer or terminate the affected part of the Service.
11. Audits and Compliance Information
- The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security assessments and tenant-isolation tests.
- The Controller may audit the Processor's compliance with this DPA no more than once in any 12-month period, and additionally following a Personal Data Breach affecting the Controller's Personal Data or on the reasonable request of a Supervisory Authority. An audit starts with a written questionnaire; an on-site or remote inspection may follow only where the written response and available third-party reports are insufficient, on at least 30 days' notice, during business hours, without unreasonable disruption, and subject to confidentiality obligations. Each party bears its own costs.
- The Processor may satisfy an audit request by providing relevant certifications or independent audit reports where available.
12. Return and Deletion of Personal Data
- On termination or expiry of the Agreement, the Processor shall, at the Controller's choice made within 14 days, return the Personal Data in a machine-readable export or delete it, and shall delete all remaining copies within 30 days, unless applicable law requires further retention. On request the Processor shall confirm deletion in writing.
- Aggregated, anonymised statistics that no longer relate to an identifiable person may be retained.
- Data held in encrypted backups is deleted through the backup rotation of the relevant Sub-Processor and is not restored except to recover from a system failure.
13. Liability
- Each party is liable for the damage it causes by processing in breach of this DPA or Data Protection Laws. The Processor is liable for damage caused by processing only where it has not complied with obligations of Data Protection Laws specifically directed to processors, or where it has acted outside or contrary to the Controller's lawful instructions.
- Each party's aggregate liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent that Data Protection Laws do not allow such limitation.
14. Term and Termination
- This DPA takes effect on the Effective date and continues for as long as the Processor processes Personal Data on behalf of the Controller under the Agreement.
- Obligations that by their nature are intended to survive — including confidentiality, deletion, cooperation with Supervisory Authorities and liability — survive termination of the Agreement.
15. Governing Law and Disputes
- This DPA is governed by the federal laws of the United Arab Emirates, consistent with the Agreement. Any dispute arising out of or in connection with this DPA that is not resolved amicably within 30 days shall be submitted to the exclusive jurisdiction of the Courts of the Dubai International Financial Centre (DIFC Courts), to which the parties expressly opt in.
- Nothing in this DPA limits the mandatory application of the KSA PDPL to the processing of Personal Data of Data Subjects in the Kingdom of Saudi Arabia, the mandatory application of the UAE PDPL, or the powers of any Supervisory Authority. In the event of a conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails.
16. Electronic Execution and Evidence
- This DPA is executed electronically. The Controller accepts it through the Service by (a) confirming its legal details, (b) typing the full name of its authorised representative as signature, and (c) confirming acceptance. The Processor records the acceptance together with the date and time, the accepting user's account email, the IP address and browser from which acceptance was made, the version of this DPA and a SHA-256 hash of the exact text accepted (the "Acceptance Record").
- The parties agree that this method constitutes a valid and binding electronic signature and electronic record under UAE Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services and the Electronic Transactions Law of the Kingdom of Saudi Arabia (Royal Decree M/18 of 1428H), and that the Acceptance Record is admissible evidence of the parties' agreement.
- The Processor's signature is applied electronically by its authorised signatory upon the Controller's acceptance. A PDF copy of the executed DPA, including the Acceptance Record, is made available to the Controller in the Service and sent to the Controller's account email. Either party may request a countersigned copy through an external electronic-signature service.
- The Controller represents that the person accepting this DPA is authorised to bind the Controller.
17. General
- Order of precedence: (a) the Standard Contractual Clauses for the transfers they govern, (b) this DPA, (c) the Agreement.
- If any provision of this DPA is held invalid, the remaining provisions remain in force and the invalid provision shall be replaced by a valid provision that comes closest to its purpose.
- The Processor may amend this DPA by publishing a new version and requiring the Controller's re-acceptance in the Service; the Controller will be notified by email at least 30 days in advance unless the change is required by law or is purely favourable to the Controller. Until re-acceptance, the version last accepted by the Controller continues to apply.
- Privacy contact of the Processor: privacy@mabrooktrack.com (general: hello@mabrooktrack.com, +971 58 543 9796). Notices to the Controller are sent to the Controller's account email.
- Each party bears its own costs of complying with this DPA unless expressly stated otherwise.
- This DPA is drafted in English. Any Arabic or other translation is provided for convenience only; in case of conflict the English version prevails to the maximum extent permitted by applicable law.
Annex A — Details of the Processing
| Item | Description |
|---|---|
| Subject-matter | Server-side conversion tracking and marketing attribution for the Controller's online store: capturing e-commerce events, matching them to advertising clicks, and forwarding conversion signals to the Advertising Platforms configured by the Controller. |
| Duration | The term of the Agreement, plus the deletion period in Clause 12. |
| Nature and purpose | Collection at the edge, one-way hashing, identity matching, deduplication, attribution, storage, reporting to the Controller, and transmission of conversion signals to Advertising Platforms — to measure and optimise the Controller's advertising performance. |
| Categories of Data Subjects | Visitors of the Controller's website or store, and customers who place orders with the Controller. |
| Types of Personal Data | SHA-256 hashes of email address, phone number, first name, last name and customer ID; advertising click identifiers (ttclid, fbclid / fbc / fbp, ScCid, gclid); a first-party random visitor and session identifier; IP address (retained max. 30 days) and user agent; event metadata (event type, timestamp, order ID, order value, currency, product IDs, payment method, shipping and tax amounts); UTM parameters, page URL and referrer. No device fingerprinting. |
| Sensitive data | None. Sensitive or special-category Personal Data and children's data must not be submitted through the Service (Clause 5.4). |
| Frequency | Continuous, in real time or near real time as events occur. |
| Retention | Raw IP addresses: 30 days. Store webhook logs (identifiers redacted at receipt): 90 days. Event, click and conversion records: for the term of the Agreement, up to 25 months, for attribution and reporting. Hashed identity links: for the term of the Agreement. All of the above deleted within 30 days of termination (Clause 12). Executed legal documents and Acceptance Records: term of the Agreement plus 7 years, as evidence. |
Annex B — Technical and Organisational Measures
The Processor maintains the following measures. They may be updated in accordance with Clause 6.3.
Data minimisation and pseudonymisation
- Email, phone, first name, last name and customer ID are normalised and converted to one-way SHA-256 hashes on the Cloudflare edge worker before storage or transmission. Raw values are not written to the database.
- Store webhooks (Salla, Zid, Shopify, custom) are stripped of names, contact details, addresses and IP addresses before the webhook log is stored.
- Raw IP addresses are removed from event records after 30 days by an automated retention job; a salted hash is kept for fraud and deduplication purposes.
- No device fingerprinting; visitor identifiers are random first-party values.
Encryption
- TLS 1.2 or higher for all data in transit between browsers, edge workers, the database, the dashboard and Advertising Platforms; HTTP Strict Transport Security with preload on all domains.
- AES-256 encryption at rest for the managed PostgreSQL database and its backups.
- Advertising Platform and store API tokens are stored encrypted with AES-256-GCM under a key held outside the database.
Access control and tenant isolation
- Row-Level Security policies in the database enforce that every workspace can read only its own data; anonymous roles hold no table privileges. Isolation is verified by recurring cross-tenant penetration tests.
- Production access is limited to named, authorised engineers on a least-privilege basis, with multi-factor authentication on infrastructure and administrative accounts and audit logging of administrative actions.
- Customer users authenticate with individual accounts; agency users see only workspaces assigned to their agency. Sensitive on-screen values can be masked in the dashboard.
- Ingestion endpoints are protected by per-workspace keys, domain allow-lists, signature verification for store webhooks, per-IP rate limiting and Cloudflare DDoS protection.
Operations, monitoring and resilience
- Automated health checks run hourly across tracking, store connections, advertising synchronisation and conversion delivery, with alerting to the operations team.
- Daily automated encrypted backups by the database provider; point-in-time recovery where enabled; documented restore procedure.
- Change management through version control and reviewed deployments; secrets are never stored in source code; security headers and content-security policies on all web properties.
- Regular security reviews, including authorisation and RLS audits, with findings tracked to closure.
Organisational measures
- Confidentiality undertakings and data-protection awareness for all personnel with access to Personal Data.
- Documented incident-response procedure with a 24-hour customer-notification target (Clause 9) and an internal breach log.
- Record of processing activities and a public Sub-Processor list with 30-day change notice.
- Vendor due diligence and written data-processing terms with every Sub-Processor.
- Automated retention and deletion jobs; workspace deletion purges all associated records.
Annex C — Authorised Sub-Processors
The Processor engages the following Sub-Processors to process Personal Data on the Controller's behalf. The current list is published at https://mabrooktrack.com/subprocessors.
| Sub-Processor | Purpose | Personal Data | Location |
|---|---|---|---|
| Cloudflare (Cloudflare, Inc.) | Edge compute (Workers) for event ingestion and hashing, CDN, DDoS protection, DNS | Event payloads in transit (identifiers are hashed here before storage), click IDs, IP address, user agent | Global edge network; GCC requests served from regional points of presence. Transient processing only — no durable storage of personal data |
| Supabase (Supabase, Inc.) | Managed PostgreSQL database, authentication, file storage | Hashed identifiers, click IDs, event and conversion records, IP address (max. 30 days), account data, executed legal documents | AWS Asia-Pacific (Mumbai, ap-south-1), India |
| Vercel (Vercel, Inc.) | Hosting of the marketing site (mabrooktrack.com) and the dashboard (app.mabrooktrack.com) | Web request logs, application metadata | USA (serverless functions pinned to the Mumbai region), global edge |
| Resend (Resend, Inc.) | Transactional email (account notifications, password resets, legal-document copies) | Account holder email address, message content | USA |
Onward recipients — independent controllers, enabled only by the Controller's configuration (not Sub-Processors):
| Advertising Platform | Purpose | Data transmitted |
|---|---|---|
| TikTok (TikTok Pte. Ltd.) | Events API — conversion matching for the Controller's TikTok ads | Hashed email / phone / name, ttclid, IP, user agent, event metadata |
| Meta (Meta Platforms, Inc.) | Conversions API — conversion matching for the Controller's Meta ads | Hashed email / phone / name, fbc / fbp, IP, user agent, event metadata |
| Snap (Snap Inc.) | Conversions API — conversion matching for the Controller's Snapchat ads | Hashed email / phone, ScCid, IP, user agent, event metadata |
| Google (Google LLC) | Google Ads API / Enhanced Conversions for the Controller's Google ads | Hashed email / phone, gclid, event metadata |
Annex D — Transfer Safeguards
D.1 Kingdom of Saudi Arabia — SDAIA Standard Contractual Clauses
- For Personal Data of Data Subjects in the Kingdom of Saudi Arabia, the Standard Contractual Clauses for the transfer of personal data outside the Kingdom issued by SDAIA under the Regulation on Personal Data Transfer outside the Kingdom, controller-to-processor module, in the version published by SDAIA and current on the Effective date, are incorporated into this DPA by reference and form an integral part of it.
- For the purposes of the Standard Contractual Clauses: the Controller is the data exporter; the Processor is the data importer; Annex A of this DPA is the description of the transfer; Annex B is the description of the technical and organisational measures; Annex C is the list of sub-processors; the competent Supervisory Authority is SDAIA.
- The parties shall not modify the text of the Standard Contractual Clauses. Where the Standard Contractual Clauses are updated by SDAIA, the Processor shall publish an updated version of this DPA in accordance with Clause 17.3.
D.2 United Arab Emirates
- For Personal Data of Data Subjects in the United Arab Emirates, this DPA (including Annexes A to C) constitutes the contractual safeguard for transfers outside the UAE to jurisdictions without an adequacy decision, as contemplated by the UAE PDPL.
- Should the UAE Data Office adopt standard contractual clauses or another mandatory instrument for such transfers, the Processor shall incorporate it into a new version of this DPA.
D.3 Transfer risk assessment
The Processor maintains a transfer risk assessment covering India (database hosting) and the United States (dashboard hosting and email), considering the nature of the data (predominantly hashed identifiers), the safeguards in Annex B, and the legal environment of each destination. The assessment is available to the Controller on request (Clause 10.5).
Signatures
This DPA is executed electronically in the MabrookTrack dashboard (Clause 16). The executed copy carries the Acceptance Record of both parties.
Integrity: SHA-256 of this template text (version 2026-09-17, canonical form, placeholders unfilled):
991d13936a5a6fcd74a5ea9a758f45d2a9c34a3d97d754183d06e80564b0b7d0
Each executed copy prints its own document hash and this template hash on the last page.