01Parties and scope
This Data Processing Agreement (“DPA”) forms part of the agreement between Staromeda OÜ, a company registered in Estonia (“Processor” or “AdCrime”), and the customer identified in the execution block (“Controller” or “Customer”) under AdCrime's Terms of Service (the “Agreement”).
It applies whenever AdCrime processes personal data on the Customer's behalf in the course of providing the service, and it is intended to satisfy Article 28(3) of Regulation (EU) 2016/679 (“GDPR”). Where the Customer is established in the United Kingdom, references to the GDPR include the UK GDPR and the Data Protection Act 2018.
If this DPA conflicts with the Agreement on a matter of data protection, this DPA prevails.
02Definitions
“Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, “Supervisory Authority” and “Personal Data Breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data that AdCrime processes on the Customer's behalf under the Agreement, as described in Annex I. “Sub-processor” means any third party engaged by AdCrime to process Customer Personal Data.
03Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I. The Customer instructs AdCrime to process Customer Personal Data only as necessary to provide the service described in the Agreement, to comply with the Customer's further written instructions, and as required by law.
The Customer acknowledges that the core output of the service - evidence about publicly displayed advertisements and the publicly reachable pages they lead to - is not Customer Personal Data. AdCrime is the controller of that evidence corpus and of the Customer's own account data (see the privacy policy). This DPA governs the Customer Personal Data listed in Annex I.
04Controller obligations
The Customer warrants that it has a lawful basis for the processing it instructs, that its instructions comply with applicable law, and that it has given any notices and obtained any consents required for AdCrime to process Customer Personal Data as described in Annex I. The Customer is responsible for the accuracy and legality of the scan inputs and account details it provides.
05Processor obligations
AdCrime shall:
- Instructions. Process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do so by EU or Member State law, in which case AdCrime informs the Customer of that requirement before processing unless the law prohibits it. AdCrime will inform the Customer if, in its opinion, an instruction infringes the GDPR.
- Confidentiality. Ensure that every person authorised to process Customer Personal Data is bound by a duty of confidentiality.
- Security. Implement the technical and organisational measures in Annex II, and keep them appropriate to the risk in line with Article 32 GDPR.
- Sub-processors. Engage Sub-processors only under the conditions in section 6.
- Data Subject requests. Taking into account the nature of the processing, assist the Customer with appropriate technical and organisational measures in responding to Data Subject requests under Chapter III GDPR. AdCrime forwards to the Customer, without responding itself, any such request it receives that relates to Customer Personal Data.
- Compliance assistance. Assist the Customer in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to AdCrime.
- Deletion and return. At the Customer's choice, delete or return all Customer Personal Data at the end of the provision of the service, and delete existing copies within 30 days, unless EU or Member State law requires storage of the Personal Data. Billing records are retained for the period required by Estonian accounting law.
- Information and audit. Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable written notice of at least 30 days, no more than once in any twelve-month period unless a Supervisory Authority requires otherwise or a Personal Data Breach has occurred, and subject to reasonable confidentiality undertakings. AdCrime may first satisfy an audit request with written answers and existing documentation.
06Sub-processors
The Customer gives general written authorisation for AdCrime to engage the Sub-processors listed in Annex III. AdCrime imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations.
AdCrime gives the Customer at least 30 days' notice by email before adding or replacing a Sub-processor that will process Customer Personal Data. The Customer may object in writing on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the remaining term.
07International transfers
Customer Personal Data is stored in the European Union. Where AdCrime or a Sub-processor transfers Customer Personal Data to a country outside the European Economic Area that is not covered by an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), the EU-US Data Privacy Framework where the recipient is certified, or another transfer mechanism valid under Chapter V GDPR. For UK Customers, the UK International Data Transfer Addendum applies to the Standard Contractual Clauses.
08Personal Data Breach
AdCrime notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice describes, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available. AdCrime provides reasonable cooperation to the Customer in its own notifications to Supervisory Authorities and Data Subjects.
09Liability
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Agreement. Nothing in this DPA limits either party's liability to Data Subjects or Supervisory Authorities under Article 82 GDPR.
10Term, governing law and precedence
This DPA takes effect on the date in the execution block and remains in force for as long as AdCrime processes Customer Personal Data under the Agreement. It is governed by the laws of the Republic of Estonia, and the courts of Estonia have jurisdiction, without prejudice to the rights of Data Subjects and Supervisory Authorities under the GDPR.
AdCrime may update Annex II and Annex III to reflect improvements to its security measures or changes to its Sub-processors in accordance with section 6; other changes to this DPA require written agreement of both parties.
11Annex I - Details of processing
- Subject matter: provision of the AdCrime affiliate brand-bidding detection service to the Customer.
- Duration: the term of the Agreement, plus the deletion period in section 5.
- Nature and purpose: creating and administering the Customer's user accounts; authenticating users; delivering scan results, reports and notifications by email; billing; providing support.
- Types of Personal Data: names, work email addresses, job titles where provided, authentication data (hashed credentials, session identifiers), IP addresses and browser metadata in request logs, billing contact details, and the content of support correspondence.
- Categories of Data Subjects: the Customer's employees, contractors and agents who use the service or correspond with AdCrime.
- Special categories of data: none. The Customer shall not submit special category data to the service.
12Annex II - Technical and organisational measures
- Encryption: TLS for all data in transit, with HTTP Strict Transport Security enforced; encryption at rest on the database and storage platform.
- Access control: production access limited to the founder; managed authentication with server-side sessions for customers; edge-level protection of all authenticated routes; administrative actions on customer accounts recorded in an audit log.
- Tenant isolation: scan results are scoped to the commissioning account. Aggregated cross-brand intelligence shares counts only, never customer identities.
- Application hardening: framing denied, MIME sniffing disabled, restrictive referrer and permissions policies, dependency updates applied on a regular cadence.
- Payment data: processed exclusively by Stripe; card numbers are never transmitted to or stored by AdCrime.
- Data minimisation: the service requires only a name, a work email and the brand details to be monitored. No tracking script is installed on the Customer's properties and no access to the Customer's analytics, advertising or affiliate network accounts is requested or held.
- Incident response: a documented process for containment, assessment and Customer notification within the period in section 8.
- Deletion: account deletion on request, with removal of Customer Personal Data within 30 days subject to statutory retention.
- Personnel: everyone with access to Customer Personal Data is bound by confidentiality obligations.
AdCrime holds no third-party certification (such as SOC 2 or ISO 27001) at the date of this DPA and does not represent otherwise.
13Annex III - Sub-processors
| Sub-processor | Purpose | Location and safeguard |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | EU data region; SCCs for any support access from outside the EEA |
| Vercel, Inc. | Application hosting and content delivery | Global edge network; SCCs / EU-US DPF |
| Stripe | Payment processing and subscription billing | EU (Stripe Payments Europe) / US; SCCs / EU-US DPF |
| Google (Workspace) | Email correspondence and report delivery | EU / US; SCCs / EU-US DPF |
Scanning infrastructure providers used to run public search queries and load public pages do not receive Customer Personal Data and are therefore not Sub-processors under this DPA.
14Execution
To put this DPA in force, email mario@adcrime.com with the Customer's legal name, registered address, registration number and the email address on the AdCrime account. AdCrime returns a countersigned copy of this text, with the execution block completed, within two business days. The DPA is effective on the date of countersignature.
Execution block
Customer: ____________________ (legal name, registered address, registration number)
Signed for the Customer: ____________________ Date: ____________
Signed for Staromeda OÜ: ____________________ Date: ____________
Need your own DPA template reviewed instead? Send it to mario@adcrime.com. - Staromeda OÜ, Estonia, EU.