Data Processing Agreement
Updated 2026-08-17
This agreement describes how AdDecide processes Customer Content and uploaded data on your instructions as a processor, including the subprocessors we may use to deliver the service. A signed copy is available on request for paid workspaces.
Roles
Customer is controller for Customer Content and ingest. AdDecide is processor and processes only on documented instructions to provide the SaaS.
Security
We apply reasonable technical and organizational measures. We engage subprocessors only as needed to provide the SaaS. Material changes are listed in this agreement and, where required, notified to customers.
Breach, delete, audit
We will notify of personal-data breaches without undue delay as required by applicable law. On termination we delete or return Customer data per retention rules (invoice legal hold excepted). Audits available on reasonable request.
No default model training
Secondary use of Customer Content for model training is Off by default and requires separate consent plus counsel approval.
Subprocessors (Phase 1)
Hosting / VPS for application and database, including Postgres backups.
Cloudflare tunnel when used for public HTTPS.
Email delivery provider for transactional mail.
Paddle (merchant of record / PSP) for card payments when billing is configured.
Changes to subprocessors
This list may change; material changes will be reflected here and, where required, notified to customers.
Last updated 2026-08-17. Questions: [email protected]. This document is not legal advice.