Legal

Data Processing Agreement

How we process personal data on your behalf — roles, security, sub-processing, and international transfers.

Last Updated:
September 21, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service, Master Services Agreement, or other agreement governing the Service (“Agreement”) between Ad Spend Technologies, Inc. and Customer. It applies when we process Personal Data on Customer's behalf and takes effect with the applicable Agreement. Mandatory transfer clauses prevail within their scope, followed by this DPA for processing Personal Data, then the Agreement.

“Applicable Data Protection Laws” means privacy and data-protection laws applicable to the processing, including, where applicable, the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss FADP, CCPA as amended, and other applicable US state privacy laws. Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Special Categories have their GDPR meanings; Business, Service Provider, Sell, Share, and Consumer have their CCPA meanings, with equivalent terms construed accordingly.

“Customer Personal Data” is Personal Data contained in Customer Data processed on Customer's behalf. “Subprocessor” is a third party engaged to process that data for us. “SCCs” means the clauses and addenda identified in the International Data Transfer Annex. Other capitalized terms have the meanings in the Agreement.

Customer acts as Controller or Business, or as Processor for an underlying Controller; we act as Processor, Service Provider, or Subprocessor accordingly. Our independent processing of account, billing, and website information is governed by the Privacy Policy.

We process Customer Personal Data only on documented lawful instructions to provide, maintain, secure, and support Customer's Service, execute authorized workflows and purchased services, and comply with law. Instructions include the Agreement, applicable Orders, and authorized configuration and use. We inform Customer where legally permitted if processing is required by law outside its instructions, and if in our opinion an instruction infringes applicable data-protection law.

Customer is responsible for lawful instructions, required notices and consents, authority from underlying clients, and its right to provide the data. Customer must not intentionally provide Special Categories or similarly sensitive data except as expressly agreed. We do not undertake general monitoring of Customer's legal compliance, but this does not excuse knowingly unauthorized processing.

We bind authorized personnel to confidentiality, maintain the measures in Annex 2, maintain legally required records, and provide reasonable assistance with data-subject requests, security obligations, breach notifications, impact assessments, and prior consultations, taking into account the processing and information available to us. Non-routine assistance may be charged reasonably to the extent permitted by law and the Agreement.

We process Customer Personal Data only for the specified Service and permitted business purposes, not outside the direct business relationship or for independent purposes. We do not Sell or Share it, combine it with other personal information except as permitted by applicable law, use it to serve another customer, or use it to train generalized AI models or authorize providers to do so. We certify our understanding of these restrictions.

Permitted de-identified operational telemetry may improve reliability and performance, but no aggregation or de-identification permission overrides the Agreement's confidentiality restrictions, platform requirements, or restrictions on cross-customer use. We do not attempt re-identification except as legally permitted for testing de-identification safeguards.

Where required by applicable US privacy law, Customer may take reasonable and appropriate steps to verify that we use data consistently with its obligations and, upon notice, to stop and remediate unauthorized use. We will notify Customer if we determine we can no longer meet applicable processor or service-provider obligations. Audit arrangements below do not reduce those rights.

Customer provides general written authorization to engage subprocessors. We maintain a current register of their identities, purposes, and processing locations, available through https://theadspend.com/legal/subprocessors and on request to support@theadspend.com.

We impose appropriate written confidentiality and data-protection obligations no less protective than this DPA and remain responsible for subprocessors as required by law and this Agreement. We provide advance notice of additions or replacements, allowing at least 15 days for reasonable, documented data-protection objections before the new processing, unless applicable law requires a different procedure.

If an objection cannot be reasonably resolved, Customer may terminate only the affected Service. Prepaid fees for the unperformed affected Service after termination will be refunded and future fees for that portion released; properly accrued fees remain payable. This right does not permit unrelated Services or commitments to be cancelled.

We promptly route requests concerning Customer Personal Data to Customer where legally permitted and respond only on its instructions or as required by law. We provide reasonable assistance through available tools and information.

We notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and provide reasonably available information and updates to assist Customer's obligations. Notice is not an admission of fault. We take reasonable mitigation and remediation steps. Customer must maintain current notice and security contacts.

Restricted transfers are governed by the International Data Transfer Annex, incorporating applicable EU SCCs, the UK Addendum, and Swiss adjustments. Its annex details are supplied by Annexes 1 and 2 here and the subprocessor register. Mandatory rights under those instruments prevail over contrary contractual terms.

We make reasonably necessary compliance information available on written request, ordinarily no more than once in 12 months unless a regulator, applicable law, or a Personal Data Breach requires more. Available security documentation and any completed independent reports are used first.

Where an on-site audit is necessary, it is ordinarily subject to 30 days' notice, business hours, confidentiality, a reasonable scope, and measures protecting other customers and competitively sensitive information. Customer ordinarily bears its reasonable audit costs, subject to mandatory law. These arrangements must not prevent an audit or disclosure required by law or the SCCs.

When the relevant processing ends, we delete Customer Personal Data unless Customer requests return of available data within 30 days after termination, in which case we return it and delete remaining active copies. We process deletion without undue delay through applicable deletion procedures, subject to mandatory requirements and permitted retention.

Retention is limited to what law requires or permits for establishing, exercising, or defending legal claims. Retained copies remain protected, with access and use limited to that purpose. Routine backups are isolated from ordinary use and expire in the ordinary course; if restored, relevant deletion instructions are reapplied. De-identified operational telemetry is excluded only to the extent law and applicable platform policies permit.

Google user data subject to Limited Use, including derivatives and aggregates, is processed subject to the Google API Services User Data Policy. This includes restrictions on human review, advertising uses, transfers, and explicit prior user consent for applicable merger, acquisition, or asset-sale transfers. General instructions, a services Order, or a data-license clause cannot override those requirements.

Liability between the parties under this DPA is part of, not additional to, the aggregate liability under the governing Agreement and is subject to its exclusions and limits only to the extent legally permitted. Nothing limits non-waivable data-subject rights, regulatory powers, or liability under mandatory transfer clauses to the extent such limitation is prohibited.

The Agreement's law and dispute provisions apply except where data-protection law or transfer clauses require otherwise. Changes to this DPA may reflect legal or operational developments but may not materially diminish existing protections. No update retroactively expands data use or removes an accrued right.

ItemDescription
Customer roleController/Business, or Processor for an underlying Controller
Our roleProcessor/Service Provider or Subprocessor, as applicable
Subject matterProvision of authorized software and professional or managed business, marketing, advertising, analytics, and implementation services
DurationTerm of the relevant Service plus permitted return, deletion, and retention periods
Nature and purposesAuthorized collection, retrieval, hosting, organization, analysis, output generation, communication, and creation, modification, publication, transmission, or deletion of records; maintenance, security, and support
Data subjectsCustomer personnel, Authorized Users, client personnel, contacts, correspondents, customers, prospects, and others whose information is included in authorized accounts or content
Data categoriesIdentifiers and business contacts; account records; campaign, audience, measurement and configuration data; content and associated metadata submitted or authorized for supported features; prompts, outputs, usage and security records, as authorized
Sensitive dataNot intended or requested; Customer must not intentionally provide it unless expressly agreed
FrequencyAs directed by authorized use, configuration, and services scope
SubprocessorsAs identified in the current register and applicable notices

We maintain a security program appropriate to the risk, including encryption of Customer Personal Data in transit and at rest; role-based and least-privilege access; unique credentials and administrative multi-factor authentication; network and application safeguards; secure development and vulnerability management; access logging and monitoring; backup and recovery measures; personnel confidentiality and security awareness; vendor diligence and contractual controls; periodic security testing; and documented incident-response procedures.

Measures may evolve without materially reducing the overall protections applicable to Customer Personal Data. Nothing here guarantees prevention of every incident.

The current register is incorporated by reference and available through https://theadspend.com/legal/subprocessors. Requests and questions may be sent to support@theadspend.com.