What Is the GDPR?
The General Data Protection Regulation (GDPR) is a European Union privacy regulation that establishes rules for collecting, processing, storing, and protecting the personal information of individuals in the European Union. The GDPR may apply to websites and businesses regardless of where they are located when they attract visitors from the EU or process personal data relating to individuals in the EU.
The GDPR requires organizations to provide appropriate information about their data processing activities and support applicable rights of individuals concerning their personal information. It also establishes requirements relating to data security and personal data breaches. The regulation was adopted in April 2016 and became applicable in May 2018 following a two-year transition period.
This Data Processing Agreement, referred to as the “DPA,” “Data Processing Agreement,” or “Agreement,” is entered into between the Client and Adosiz. It forms an integral part of the Adosiz Tracker Terms and Conditions and is subject to those Terms and Conditions. The Agreement is effective from 25 May 2018.
Scope of the Agreement
This DPA applies when European Union data protection legislation applies to the processing of Personal Data under the Agreement. This includes circumstances where processing takes place in connection with the activities of an establishment of either Party within the European Economic Area or where Personal Data relates to Data Subjects located within the EEA and the processing involves offering goods or services to them or monitoring their behavior within the EEA.
The Client and Adosiz are collectively referred to as the “Parties” and individually as a “Party.” Capitalized terms that are not specifically defined in this DPA have the meanings assigned to them in the Terms and Conditions. If there is a conflict between this DPA and the Terms and Conditions, this DPA will prevail.
Definitions
Controller
“Controller” or “Data Controller” means the entity that determines the purposes and methods for processing Personal Data.
Processor
“Processor” or “Data Processor” means an entity that processes Personal Data on behalf of the Data Controller.
Data Subject
“Data Subject” means the individual to whom Personal Data relates, including End Users.
End User
“End User” means an individual who uses an internet-connected service. This may include a visitor to a website, a mobile application user, an IoT device user, or an individual visiting an advertising or campaign webpage.
GDPR
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council concerning the protection of individuals with regard to the processing of Personal Data and the free movement of such data, including the regulation that repealed Directive 95/46/EC.
Personal Data
“Personal Data” means information relating to an identified or identifiable individual as defined under Article 4.1 of the GDPR.
Processing
“Processing” means any operation or series of operations performed on Personal Data, whether carried out automatically or manually. Processing may include collecting, recording, organizing, storing, adapting, altering, retrieving, consulting, using, disclosing, transmitting, disseminating, making available, aligning, combining, blocking, erasing, or destroying Personal Data. The terms “Process,” “Processes,” and “Processed” will be interpreted accordingly.
Sub-Processor
“Sub-Processor” means a Data Processor engaged by the Processor to process Personal Data.
Services
“Services” means the services provided by Adosiz through the Adosiz Tracker Platform in accordance with the applicable Terms and Conditions.
Processing of Personal Data
Under this DPA, the Client may act as the Data Controller or Data Processor depending on the circumstances. Adosiz may act as the Client’s Processor or Sub-Processor, as applicable. The provisions of this Agreement apply to the processing relationship between the Parties concerning Personal Data.
The Client engages Adosiz to collect, process, and use Personal Data on the Client’s behalf within the scope of the Services. Adosiz will process Personal Data only on behalf of the Client and according to the Client’s instructions.
Processing will be performed in accordance with this DPA, the applicable Terms and Conditions, the features and limitations of the Services, and other reasonable instructions provided by the Client where those instructions are consistent with the Terms and Conditions.
Adosiz is not required to follow instructions that it determines would violate applicable laws. Processing outside the scope of this DPA requires a prior written agreement between the Client and Adosiz together with additional processing instructions from the Client.
Purpose of Processing
Adosiz uses Personal Data to provide the Services in accordance with the applicable Terms and Conditions. This includes providing tracking services, serving interest-based advertising, measuring advertising campaign effectiveness, and providing advertising reports.
At the Client’s request, Adosiz may combine Personal Data from different sources where necessary to improve the Services or integrate the Services with external platforms. Such processing is performed on behalf of the Client and for purposes connected with the Client’s interests.
Adosiz may also process Personal Data for fraud prevention, bot detection, rating, analytics, viewability, and advertising security services. Adosiz may process information derived from Personal Data in aggregated and non-identifiable forms for testing, development, quality control, and operation of the Services.
Categories of Personal Data
Depending on the Services used by the Client, Adosiz may process information including IP addresses, language information, session-based browsing behavior, header information, device type and model, operating system, wireless carrier information, geographical location, cookies, advertising identifiers, non-precise device location based on an IP address, device specifications, user interest information, and other information received from the Client or relevant third-party service providers.
The Client authorizes Adosiz to store and use cookies or pixel tags on End Users’ devices on behalf of the Client when necessary to provide the Services. Additional information regarding End User data collected or used through the Services may be provided through the applicable End User Privacy Policy.
Restricted Personal Data
The Client must not provide Adosiz with information that directly identifies an individual, including names, addresses, telephone numbers, or email addresses.
The Client must also not provide information relating to children or special categories of Personal Data described under Article 9 of the GDPR unless the Parties expressly agree otherwise in writing and such processing is permitted under applicable law. This type of information is not necessary for the normal use of Adosiz Services.
Client Responsibilities
The Client remains responsible for ensuring that its use of the Services complies with applicable laws and regulations, including the GDPR where applicable.
Where required by law, the Client must provide Data Subjects with appropriate information concerning the processing of their Personal Data in connection with the Services. The Client must also obtain and document consent where consent is legally required.
The Client must also provide End Users with clear information concerning cookies and other tracking technologies used through the Services where required by applicable law. This information should explain the purpose of the cookies or technologies, the type of information collected, and the available choices for managing or disabling them.
Where legally required, the Client must provide appropriate notice, consent, and choice mechanisms that comply with applicable laws and regulations, including the GDPR.
Lawfulness of Processing
The Client retains responsibility for ensuring that the processing of Personal Data is lawful. The Client confirms that it is legally permitted to engage Adosiz to process Personal Data on its behalf and that it has provided all required notices and obtained all necessary consents from Data Subjects where applicable.
The Client also confirms that the processing described in this DPA is permitted under the laws applicable to the Client and its use of the Services.
Rights of Data Subjects
If Adosiz receives a request from a Data Subject relating to access, correction, amendment, deletion, or objection to the processing of Personal Data, Adosiz will notify the Client by email.
Adosiz will not respond substantively to such a request without the Client’s prior written consent, except where necessary to confirm that the request relates to the Client.
Where the Client handles a Data Subject request, Adosiz will provide commercially reasonable cooperation and assistance to the extent required by applicable law and legally permitted.
Adosiz reserves the right to charge additional fees for cooperation and assistance provided in connection with Data Subject requests under this DPA.
Adosiz Personnel
Adosiz will ensure that personnel involved in processing Personal Data understand the confidential nature of such information and receive appropriate training concerning their responsibilities.
Personnel with access to Personal Data will be subject to confidentiality obligations. These obligations will continue after the termination of their employment or engagement with Adosiz.
Access to Personal Data will be restricted to personnel who require access to perform their responsibilities under the Terms and Conditions and this DPA.
Security
Adosiz will implement the measures required under Article 32 of the GDPR in accordance with Article 28(3)(c), where applicable.
Adosiz will maintain appropriate technical and organizational measures designed to ensure that processing meets applicable GDPR requirements and protects the rights and freedoms of Data Subjects.
Adosiz will maintain appropriate contractual obligations for personnel involved in processing Personal Data, including obligations concerning confidentiality, data protection, and information security.
Adosiz will ensure that relevant personnel are appropriately informed and trained regarding the confidential nature of Personal Data and are subject to written confidentiality obligations. Such obligations will continue after employment or other engagement ends.
Audit Rights
Where applicable law requires the Client to monitor the appropriate processing of Personal Data, the Client may request an audit of Adosiz to assess compliance with applicable law, this DPA, and the Client’s lawful instructions.
The audit may also cover relevant Adosiz Sub-Processors where necessary and legally permitted.
Adosiz may provide copies or summaries of relevant third-party audits or certifications issued by independent auditors where appropriate. Where an audit is legally required and cannot be satisfied through such documentation, the Client may conduct an on-site audit itself or through an independent third-party contractor at the Client’s expense.
Audits must be scheduled with Adosiz in writing at least 30 days in advance and may generally occur no more than once per year. Auditors must comply with applicable confidentiality requirements and must take reasonable measures to protect Adosiz systems, information, and the Personal Data of other clients.
The Client will bear the costs associated with its audit and will be responsible for damage or disruption caused by its audit activities. Audit results must be kept confidential and used only for the purposes permitted under this DPA and applicable law.
Security Breach Management and Notification
If Adosiz becomes aware of an accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access involving Personal Data processed, stored, or transmitted through Adosiz equipment or facilities, Adosiz will treat the event as a Security Breach.
Upon becoming aware of a Security Breach, Adosiz will promptly notify the Client, investigate the incident, provide relevant information concerning the incident, and take commercially reasonable steps to mitigate its effects and minimize resulting damage.
Sub-Processing and International Data Transfers
The Client authorizes Adosiz to appoint Sub-Processors when necessary to provide the Services. Adosiz may continue to use Sub-Processors already engaged in accordance with this DPA.
The original DPA identifies Amazon Web Services Inc. for cloud hosting services, Freshworks Inc. for help desk services, Datadog Inc. for analytical services, Loggly Inc. for analytical services, and CoreOS Inc. for IT services.
Adosiz may appoint additional Sub-Processors and will provide notice concerning new Sub-Processors and the processing activities they will perform.
If the Client has reasonable grounds for objecting to a proposed Sub-Processor, the Client may provide written notice within seven days of receiving the applicable notice. Adosiz will consider reasonable objections and take appropriate steps to address them. Where an objection cannot reasonably be resolved, either Party may terminate the affected Services as provided in the Agreement.
Adosiz may integrate the Client’s Services with external service providers where necessary to provide the Services on behalf of the Client. Such providers may act as Sub-Processors. A complete list of Sub-Processors may be requested from Adosiz in writing.
Where necessary to provide the Services, Adosiz may engage Sub-Processors located outside the European Economic Area, provided that appropriate safeguards and legally recognized international data transfer mechanisms are used.
Term and Data Retention
This DPA automatically supplements the agreement between the Client and Adosiz when the Client creates an Adosiz account.
Subject to the applicable provisions of this Agreement, Adosiz may retain Personal Data for 741 days from the date of collection on behalf of the Client. The stated purposes include fraud prevention, advertising security, reporting, complaint handling, and chargeback handling.
Personal Data may be deleted from Adosiz servers after the applicable retention period or earlier upon the Client’s written request. If the Client requests deletion during the term of the Agreement, the deleted data may no longer be available to the Client and may not be recoverable.
Termination and Data Deletion
This DPA remains effective for the duration of the Services agreement between the Client and Adosiz. The DPA may terminate when the Client deletes its Adosiz account and the underlying Services agreement expires.
Following termination, the Client instructs Adosiz to delete Personal Data subject to this DPA, including End User Data, from Adosiz systems and existing copies.
The original DPA provides for deletion within one month after expiration. During this period, the Client may request retrieval of applicable data. Any retrieval request must be submitted within the applicable one-month period, and the method of retrieval will be agreed between Adosiz and the Client.
After the applicable period expires, Adosiz will no longer be responsible for storing, exporting, or retrieving the relevant data.
Data Protection Contact
For questions or inquiries concerning this Data Processing Agreement, you may contact the Adosiz Data Protection Officer at dpo@Adosiz.com.
Indemnification and Limitation of Liability
The Client agrees to indemnify and hold harmless Adosiz, including its officers, directors, employees, contractors, and agents, against claims, liabilities, administrative fines, lawsuits, investigations, settlements, penalties, damages, losses, costs, expenses, and reasonable legal fees arising from claims or proceedings brought by Data Subjects, legal persons, or supervisory authorities under applicable data protection laws in connection with the processing of Personal Data on behalf of the Client through the Services.
The liability of each Party remains subject to the exclusions and limitations established under the applicable Terms and Conditions.
Governing Law
This DPA is governed by and interpreted in accordance with the laws of India.
Any choice-of-law provision that would result in the application of the laws of another jurisdiction will not apply where excluded under this Agreement.