This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement (the “Agreement”) between ADVIGATOR S.R.L., Via Martiri Triestini 9, 20148 Milan, Italy, VAT IT12112650960 (“Advigator”, “Processor”) and the customer identified in the Agreement (“Customer”, “Controller”).
It applies whenever Advigator processes Personal Data on the Customer’s behalf and sets out the parties’ obligations under Article 28(3) GDPR. No signature is required for this DPA to apply; Advigator will provide a countersigned execution copy on request to legal@advigator.com.
1. Definitions
“Applicable Data Protection Law” means, as applicable: Regulation (EU) 2016/679 (“GDPR”) and EU member state implementing laws, including Italian Legislative Decree 196/2003 as amended; the UK GDPR and the Data Protection Act 2018 (“UK Data Protection Law”); the Swiss Federal Act on Data Protection (“FADP”); the US state privacy laws listed in Annex IV; and the Indian Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (“DPDP Act”).
“Customer Personal Data” means Personal Data contained in Customer Data that Advigator processes on the Customer’s behalf under the Agreement.
“EU SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
“Personal Data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR.
“Sub-processor” means a third party engaged by Advigator to process Customer Personal Data.
2. Roles and scope
2.1 The Customer is the controller and Advigator is the processor of Customer Personal Data. Where the Customer is itself a processor acting for its own clients — for example an advertising agency managing accounts for brands — Advigator is a sub-processor, and the Customer warrants that it has the authority from the relevant controller to appoint Advigator on these terms.
2.2 Advigator is a separate and independent controller for Personal Data it processes to run its own business: account registration and administration, authentication, billing, security monitoring, support administration, product analytics and marketing. Access to Customer Personal Data within support tickets or security investigations solely to provide the Customer’s service remains subject to this DPA. Roles depend on the purpose of the processing, not solely on the field or system used. Independent-controller processing is described in the Privacy Policy and is outside the scope of this DPA.
2.3 Neither party sells Customer Personal Data or shares it for cross-context behavioural advertising, as those terms are defined in US state privacy law.
3. Processing instructions
3.1 Advigator will process Customer Personal Data only on documented instructions from the Customer, which consist of the Agreement, this DPA, the configuration and automation settings the Customer makes in the Services, and any further written instruction the parties agree.
3.2 Advigator will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so by law.
3.3 If Advigator is required by EU, member state or other applicable law to process Customer Personal Data beyond the Customer’s instructions, it will inform the Customer of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
3.4 Advigator will not use Customer Personal Data to train generally available machine learning models and requires the same of its AI Sub-processors. See the AI Transparency Notice.
4. Confidentiality
Advigator ensures that persons authorised to process Customer Personal Data are bound by an appropriate statutory or contractual duty of confidentiality, are informed of their data protection and security obligations, and are granted access strictly on a need-to-know basis.
5. Security
5.1 Advigator implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.
5.2 Advigator may update those measures provided the level of security is not materially decreased.
6. Sub-processors
6.1 General authorisation. The Customer gives Advigator general written authorisation to engage Sub-processors. The current list is published at advigator.com/legal/subprocessors and forms Annex III to this DPA.
6.2 Notice of changes. Advigator will give at least 30 days’ prior notice of the addition or replacement of a Sub-processor, by email to the Customer’s designated legal/privacy contact, or account administrator if none is designated, and by updating that page. Subscription to public updates is optional and does not replace this contractual notice.
6.3 Objection. The Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period. The parties will discuss the objection in good faith. If Advigator cannot offer a reasonable alternative within 30 days, the Customer may terminate the affected Service without penalty and receive a refund of prepaid fees for the unused portion of the term.
6.4 Flow-down and responsibility. Advigator imposes on each Sub-processor data protection obligations no less protective than those in this DPA and remains fully liable to the Customer for the Sub-processor’s performance.
7. Data subject rights
7.1 Taking into account the nature of the processing, Advigator will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Applicable Data Protection Law.
7.2 If Advigator receives a request directly from a data subject relating to Customer Personal Data, it will not respond to the substance of the request but will, without undue delay, forward it to the Customer and confirm that it has done so.
7.3 The Services provide functions to search, export and delete Customer Data, which the Customer can use to answer many requests itself. Where they are not sufficient, Advigator will assist directly at no charge for reasonable volumes; requests should be sent to legal@advigator.com.
8. Personal data breach
8.1 Advigator will notify the Customer without undue delay and in any case within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where information is not available at once, it will be provided in phases without undue delay.
8.3 Advigator will take reasonable steps to contain and remediate the breach, will document the facts, and will cooperate with the Customer in its own notifications to supervisory authorities and data subjects. Advigator’s notification is not an acknowledgement of fault or liability.
8.4 The Customer is responsible for notifying its supervisory authority and affected data subjects where required. Where the Customer’s own regulator imposes a shorter deadline — including the six-hour reporting requirement of the Indian CERT-In Directions of 28 April 2022 — Advigator will use reasonable efforts to provide the information the Customer needs within that deadline, and the Customer should identify any such requirement promptly. This does not limit either party’s own direct reporting duties under applicable law. An initial notice need not await completion of an investigation.
9. Assistance with impact assessments
Taking into account the nature of processing and the information available to it, Advigator will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, with risk assessments required under US state privacy law, and with assessments of the use of automated decision-making technology. Supporting information may be requested under clause 11, subject to appropriate confidentiality. We will identify the scope and availability of current evidence, rather than represent that a certification or assessment exists when it does not.
10. Deletion and return
10.1 On termination or expiry of the Agreement, at the Customer’s choice Advigator will return Customer Personal Data and delete remaining copies, or delete it without return, in accordance with the Data Retention and Deletion Policy, following the exit and transition period set out in clause 12 of the Agreement.
10.2 During the transition and subsequent retrieval period the Customer may export Customer Data using the export functions of the Services. On written request made during either period, Advigator will return Customer Personal Data in a structured, commonly used, machine-readable format.
10.3 Advigator may retain Customer Personal Data to the extent required by law, in which case it will continue to protect it under this DPA, restrict processing to the purpose of the legal requirement, and delete it when the requirement ends.
10.4 Advigator will certify deletion in writing on request.
11. Audits and information
11.1 Advigator will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including its security documentation and any penetration test summaries, third-party certifications or attestation reports it holds. Advigator holds none of the latter at the date of this DPA, as stated in the Security Overview.
11.2 The Customer may audit Advigator’s compliance with this DPA. Audits will be carried out at the Customer’s expense, no more than once in any 12-month period (unless required by a supervisory authority or following a personal data breach), on at least 30 days’ prior written notice, during normal business hours, under confidentiality obligations, and in a manner that does not unreasonably disrupt Advigator’s operations or compromise the security or confidentiality of other customers’ data. The parties may use an up-to-date independent report to address the request where it adequately covers the relevant controls. This does not exclude further inspection reasonably necessary to demonstrate compliance, or restrict supervisory authorities’ powers. Urgent legally required reviews are not subject to the ordinary notice period.
11.3 Advigator will respond to reasonable security questionnaires from the Customer’s procurement or security function once per year and in connection with a renewal.
12. International transfers
12.1 Locations. Advigator is established in Italy. Production hosting and database backups are in the United States; other processing locations are described in the sub-processor register. No EU-only or India-only residency is included unless expressly agreed in writing and technically available. Residency does not by itself describe every location of remote access or ancillary processing.
12.2 Actual transfer relationships. An EEA Customer’s appointment of Advigator in Italy is not, by itself, a transfer to a third-country importer. Advigator is responsible for arranging lawful onward transfers to its non-EEA Sub-processors. Applicable transfer instruments must identify the actual exporting and importing legal entities, processing, countries and safeguards; merely naming the Customer and Advigator in this DPA does not execute an agreement with a third-party recipient.
12.3 Safeguards. Before a restricted transfer, Advigator will establish a valid mechanism under applicable law. This may be an applicable adequacy decision (including an active, in-scope Data Privacy Framework certification) or appropriate safeguards such as the EU SCCs, where their conditions of use are met. For onward transfers by Advigator as processor to a non-EEA Sub-processor, the processor-to-processor module is ordinarily relevant; independent-controller transfers are assessed separately. Required SCC annexes and selections are completed in the agreement with the actual recipient. The parties will execute any additional instrument necessary for a restricted transfer between them before that transfer begins.
12.4 UK and Switzerland. Transfers subject to UK law require a valid UK mechanism, such as adequacy or the UK Addendum/IDTA, with applicable tables completed for the actual transfer. For Swiss transfers, safeguards must address the FADP, the Swiss competent authority and Swiss data subjects’ rights. These provisions do not deem uncompleted transfer instruments executed.
12.5 Assessment and disclosure requests. Advigator will assess destination-country law and practice where required, adopt necessary supplementary measures, and review material changes. On request, it will provide relevant safeguards and assessment information, with proportionate redactions to protect confidential information and other customers. Where safeguards cannot be maintained, affected transfers must be suspended or otherwise made lawful; SCCs alone do not guarantee legality following invalidation of an adequacy decision.
Advigator will review legally binding government requests, disclose only what it is legally required to disclose and notify the Customer unless legally prohibited. It will assess available grounds to challenge unlawful or disproportionate requests and seek permission to notify where appropriate. These obligations do not promise a successful challenge or disclosure contrary to law.
13. Order of precedence and liability
This DPA prevails over any conflicting term of the Agreement in respect of the processing of Personal Data. Where the EU SCCs conflict with this DPA, the SCCs prevail. Each party’s liability under this DPA is subject to the limitations and exclusions in clause 10 of the Agreement, including the enhanced cap for breaches of this DPA. Nothing in this DPA limits a data subject’s rights under Applicable Data Protection Law.
Annex I — Description of the processing
A. Parties to this DPA. Customer: the contracting customer, acting as controller (or as processor for its own clients). Processor: ADVIGATOR S.R.L., providing the Services described in the Agreement. Contact for both: as stated in the Agreement; for Advigator, legal@advigator.com.
B. Description of the processing.
| Categories of data subjects | The Customer’s personnel and contractors who are Authorised Users of the Services; the personnel of the Customer’s own clients where the Customer is an agency; individuals named in the Customer’s advertising accounts held with an Advertising Platform. |
| Categories of personal data | Identification and contact data (name, business email address, business role); customer-directed user and access records (excluding authentication data processed independently by Advigator under clause 2.2); connection data (IP address, browser and device information, timestamps); activity and audit data (actions taken in the Services, changes made to advertising accounts, and the user who made them); advertising account identifiers linked to a named person; any personal data the Customer includes in free-text fields such as campaign names, product titles, keywords or notes. |
| Special category data | None. The Acceptable Use Policy prohibits the submission of special category data as defined in Article 9 GDPR and of sensitive personal data as defined under applicable US state privacy law. If prohibited data is identified, the parties will cooperate to restrict access and arrange lawful removal; this does not remove Advigator’s applicable security or incident-response duties. |
| Children’s data | None. The Services are not directed to children and the Customer must not submit the personal data of children. |
| Nature and purpose of processing | Hosting, storage, retrieval, structuring, analysis and transmission of Customer Data in order to provide the Services: connecting to Advertising Platforms on the Customer’s authorisation, importing campaign structures and performance reports, computing bid, budget and targeting recommendations, applying automated changes the Customer has configured, generating analytics and reports, retaining a change history, and providing support. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Duration of processing | For the term of the Agreement plus the exit and transition period and the retention periods set out in the Data Retention and Deletion Policy. |
| Sub-processor processing | As set out in Annex III; subject matter, nature and duration are as described above, limited to what each Sub-processor needs for its stated role. |
C. Supervisory authority. The Italian Garante supervises Advigator’s Italian establishment, without limiting other competent authorities’ powers. Transfer instruments identify the competent authority according to their own rules and the actual exporter.
Note on the nature of advertising data. Most of the data Advigator processes from Advertising Platforms — impressions, clicks, spend, orders, aggregated search terms, bids and budgets — is commercial performance data relating to products and campaigns, not to identified or identifiable individuals. The personal data in scope is principally the account, authentication, connection and audit data described above. This DPA applies to that personal data.
Annex II — Technical and organisational measures
The Security Measures Schedule forms this Annex. It is the single contractual source for these measures; the Security Overview is a summary. Detailed architecture, test evidence and questionnaires are supplied only under appropriate confidentiality. A roadmap, assessment template or planned control is not a representation that the control is implemented.
Annex III — Sub-processors
The current list of Sub-processors, their roles, locations and transfer mechanisms, is published and maintained at advigator.com/legal/subprocessors and is incorporated into this DPA. Changes are notified under clause 6.2.
Annex IV — United States state privacy law terms
1. Scope. This Annex applies where Advigator processes personal information subject to the California Consumer Privacy Act as amended (“CCPA”), or to the comprehensive privacy laws of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia or any other US state law of similar effect (together, “US State Privacy Laws”).
2. Roles. The Customer is the “business” or “controller” and Advigator is the “service provider” or “processor” as those terms are defined in the applicable law.
3. Advigator’s undertakings. Advigator will:
(a) process personal information only for the limited and specified business purposes set out in the Agreement and this DPA, and only on the Customer’s documented instructions;
(b) not sell or share personal information, as “sell” and “share” are defined in the CCPA;
(c) not retain, use or disclose personal information for any purpose other than the business purposes specified, including not for a commercial purpose other than those specified, and not outside the direct business relationship with the Customer, except as permitted by law;
(d) not combine personal information received from the Customer with personal information received from or on behalf of another person, or collected from its own interaction with a consumer, except as permitted by the CCPA regulations;
(e) comply with the obligations applicable to it under US State Privacy Laws and provide the same level of privacy protection as those laws require of the Customer;
(f) notify the Customer promptly, and in any event within five business days, if it determines that it can no longer meet its obligations under US State Privacy Laws;
(g) grant the Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information; and
(h) assist the Customer in responding to verifiable consumer requests, including requests to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information.
4. Automated decision-making technology. Where the Customer uses the Services in a manner that constitutes automated decision-making technology under the CCPA regulations, Advigator will provide the information the Customer reasonably requires about the logic and the intended output of the relevant functionality, and will assist with the Customer’s pre-use notice, opt-out and access obligations. The Services are designed to support advertising optimisation and are not intended to be used to make decisions that produce legal or similarly significant effects concerning a consumer, including decisions about financial or lending services, housing, education, employment or healthcare. The Customer must not use the Services for such decisions.
5. Cybersecurity audits and risk assessments. Advigator will cooperate with the Customer’s obligations to conduct risk assessments and cybersecurity audits under the CCPA regulations by providing the documentation described in clause 11 of this DPA.
6. Certification. Advigator certifies that it understands the restrictions in this Annex and will comply with them. It will notify the Customer if it can no longer meet them. Neither party will attempt to re-identify de-identified personal information except as permitted by applicable law.
Annex V — India Digital Personal Data Protection Act terms
1. Scope. This Annex applies where Advigator processes digital personal data of Data Principals located in India on behalf of the Customer, and is subject to the DPDP Act. Statutory provisions and Rules apply according to their respective commencement dates and territorial scope. Nothing here treats all provisions as already in force; express contractual safeguards apply independently of later statutory commencement.
2. Roles. The Customer is the Data Fiduciary and Advigator is a Data Processor engaged under a valid contract, as required by section 8(2) of the DPDP Act.
3. Advigator’s undertakings. Advigator will:
(a) process personal data only under the Customer’s instructions and only for the purposes of the Agreement;
(b) implement reasonable security safeguards as required by section 8(5) of the DPDP Act and Rule 6 of the Digital Personal Data Protection Rules, 2025, as described in Annex II;
(c) notify the Customer of a personal data breach within the timescale in clause 8 of this DPA so that the Customer can meet its obligation to notify the Data Protection Board of India and affected Data Principals;
(d) assist the Customer in responding to requests from Data Principals to access, correct, complete, update or erase their personal data and to nominate another person;
(e) erase personal data on the Customer’s instruction and on termination, in accordance with clause 10 of this DPA, and retain logs and data only for the periods stated in the Data Retention and Deletion Policy; and
(f) not engage a Sub-processor except under clause 6 of this DPA.
4. Customer responsibilities. The Customer is responsible for giving notice to and obtaining consent from Data Principals, or for establishing another lawful ground, for publishing the contact details of its Data Protection Officer or of the person able to answer questions about processing, and for responding to Data Principal grievances.
5. Significant Data Fiduciary. If the Customer is designated a Significant Data Fiduciary, Advigator will provide reasonable assistance with the Customer’s annual data protection impact assessment and independent audit, on the terms in clauses 9 and 11 of this DPA.
6. Advigator’s own contact point. Questions about Advigator’s processing of personal data of individuals in India may be sent to legal@advigator.com. Advigator will acknowledge within 72 hours and respond substantively within 30 days.