Legal documents

Data Processing Agreement

Privacy policy, terms & conditions, and data processing agreement of Adbrains.

Version: June 2026

This Data Processing Agreement ("DPA") applies to the processing of personal data by Adbrains B.V. ("Processor") on behalf of the Client ("Controller") in connection with the services agreement.

Article 1, Definitions

  • GDPR: Regulation (EU) 2016/679 (General Data Protection Regulation)
  • Personal Data: any information relating to an identified or identifiable natural person
  • Processing: any operation performed on personal data within the meaning of the GDPR
  • Breach: a personal data breach within the meaning of Art. 4(12) GDPR

Article 2, Purpose & nature of the processing

The Processor processes personal data solely for the purpose of:

  • Managing and optimising Google Ads campaigns on behalf of the Controller
  • Forwarding conversion data to Google Ads and, where applicable, Meta
  • Generating campaign reports and AI analyses
  • Providing the client portal and dashboard

Categories of data subjects: website visitors and customers of the Controller.

Categories of personal data: IP addresses, click identifiers (GCLID, fbclid), email addresses, conversion data.

Article 3, Processor obligations

The Processor undertakes to:

  • Process personal data solely in accordance with the Controller's written instructions
  • Maintain confidentiality of personal data towards third parties
  • Implement appropriate technical and organisational security measures (Art. 32 GDPR)
  • Not engage sub-processors without the Controller's prior consent
  • Cooperate with data subject rights requests

Article 4, Sub-processors

The Controller consents to the engagement of the following sub-processors:

  • Google LLC, Google Ads API, Google Analytics, Google Cloud
  • Anthropic, PBC, Claude AI API (anonymised campaign data)
  • Hosting providers, server infrastructure (EU-based)

The Processor informs the Controller of changes to sub-processors. The Controller has the right to object.

Article 5, Security (Art. 32 GDPR)

The Processor implements and maintains appropriate technical and organisational measures:

  • Encryption of personal data at rest and in transit (AES-256, TLS 1.2+)
  • Two-factor authentication for system access
  • Pseudonymisation of analytical data where possible
  • Regular security testing and access reviews
  • Incident recovery procedures

Article 6, Data breaches & incidents

In the event of a personal data breach, the Processor informs the Controller as soon as possible and no later than 72 hours after discovery. The notification includes: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken.

Article 7, Transfers outside the EEA

The Processor does not transfer personal data to countries outside the EEA unless necessary (e.g. Google/Anthropic in the US) and compliant with Art. 46 GDPR via the European Commission's Standard Contractual Clauses (SCCs).

Article 8, Rights of data subjects

The Processor assists the Controller in handling data subject requests (access, rectification, erasure, etc.) within a timeframe that enables the Controller to meet the statutory 30-day deadline.

Article 9, Audit & control

The Processor enables the Controller to carry out audits, or have them carried out by an independent third party, subject to at least 30 days' notice and a confidentiality obligation.

Article 10, Deletion & return

Upon termination of the agreement, the Processor deletes all personal data within 90 days, unless a statutory retention obligation applies. Upon request, the Processor provides written confirmation of deletion.

Article 11, Governing law

This Data Processing Agreement is governed by Dutch law. Disputes are submitted to the competent court in Rotterdam.