Effective Date: The date on which the Customer accepts the Terms of Use.
This Data Processing Agreement (“DPA”) is entered into between:
DAO ADVERTISING LLP, a limited liability partnership registered in the United Kingdom, with its registered office at 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom (“DAO”, “Processor” or “we”); and the business customer accepting the Terms of Use (“Customer”, “Controller” or “you”).
DAO and the Customer are each a “Party” and together the “Parties”.
1.1. This DPA forms an integral, mandatory and legally binding part of the Terms of Use governing the Customer’s access to and use of DAO’s services, platforms, tools, technologies and related services (the “Services”).
1.2. By accepting the Terms of Use, creating an account, entering into a commercial relationship with DAO or using the Services, the Customer accepts and agrees to be bound by this DPA.
1.3. This DPA applies to the extent that DAO processes Personal Data on behalf of the Customer in connection with the Services.
1.4. In the event of a conflict between this DPA and the Terms of Use, this DPA shall prevail solely in relation to the processing of Personal Data.
1.5. This DPA is intended to satisfy the requirements applicable to processor agreements under Article 28 of the EU GDPR and Article 28 of the UK GDPR, where applicable.
For the purposes of this DPA:
“Applicable Data Protection Law” means all applicable data protection, privacy and electronic communications laws applicable to the Processing, including, where applicable:
(a) Regulation (EU) 2016/679 (“EU GDPR”);
(b) the UK General Data Protection Regulation (“UK GDPR”);
(c) the UK Data Protection Act 2018;
(d) applicable national implementing legislation;
(e) applicable laws relating to electronic marketing, cookies, tracking technologies and electronic communications; and
(f) any applicable amendments, successor legislation or binding regulatory requirements.
“Controller” means the entity which determines the purposes and means of the Processing of Personal Data.
“Processor” means the entity which processes Personal Data on behalf of the Controller.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“Personal Data” means any information relating to an identified or identifiable natural person processed under this DPA.
“Processing” means any operation performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, erasure or destruction.
“Security Incident” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
“Sub-processor” means any third party appointed by or on behalf of DAO to process Personal Data on behalf of the Customer.
“Supervisory Authority” means any competent data protection authority, including the ICO in the United Kingdom or a competent EU data protection authority.
3.1. The Parties acknowledge that their respective roles may differ depending on the relevant Processing activity.
3.2. DAO shall act as Processor where it processes Personal Data:
(a) on behalf of the Customer;
(b) in accordance with the Customer’s documented instructions;
(c) for the purposes specified in this DPA; and
(d) without independently determining the purposes of such Processing.
Examples may include:
processing push tokens on behalf of the Customer;
transmitting technical identifiers;
delivering push notifications;
processing campaign attribution data;
processing impression and click data;
providing tracking and reporting functionality;
hosting or technically processing data submitted by the Customer;
providing technical support relating to Customer-controlled data.
3.3. DAO shall act as an independent Controller where it determines the purposes and means of Processing for its own purposes, including:
(a) platform security;
(b) fraud prevention and detection;
(c) abuse prevention;
(d) protection of DAO’s systems, infrastructure and services;
(e) compliance with legal obligations;
(f) accounting, tax and financial recordkeeping;
(g) payment processing and reconciliation;
(h) establishment, exercise or defense of legal claims;
(i) internal business analytics; and
(j) improvement, monitoring and maintenance of DAO’s own services, to the extent permitted by Applicable Data Protection Law.
Such Processing is not governed by the Processor obligations in this DPA and shall be governed by DAO’s Privacy Policy and applicable law.
3.4. Nothing in this DPA shall be interpreted as requiring DAO to act as Processor where DAO independently determines the purposes and means of the relevant Processing.
4.1. The subject matter of the Processing is the provision of the Services, including advertising technology, publisher and webmaster services, push-notification delivery, tracking, attribution, reporting, analytics and related technical functionality.
4.2. The Processing shall continue for the duration of:
(a) the Terms of Use;
(b) any applicable order, service arrangement or commercial relationship; and
(c) any additional period during which DAO is required or permitted to retain Personal Data under this DPA or Applicable Data Protection Law.
4.3. Following termination of the Services, DAO shall delete or return Personal Data in accordance with Section 14, unless retention is required by law or otherwise permitted under this DPA.
The Processing may include:
-fraud-related checks performed on behalf of the Customer;
-maintaining service functionality;
and other Processing reasonably necessary to provide the Services.
DAO shall not use Personal Data processed as Processor for unrelated purposes or for its own independent purposes, except where such Processing is expressly permitted under Section 3.3 or required by law.
6.1. DAO shall process Personal Data only:
(a) on documented instructions from the Customer;
(b) for the purposes specified in this DPA;
(c) as necessary to perform the Terms of Use and provide the Services; or
(d) where required by Applicable Data Protection Law.
6.2. The following shall constitute the Customer’s documented instructions:
(a) this DPA;
(b) the Terms of Use;
(c) applicable service descriptions and specifications;
(d) account and platform configuration;
(e) data fields submitted by the Customer;
(f) written instructions provided by email or through the platform; and
(g) the Customer’s use of the Services consistent with their intended functionality.
6.3. The Customer authorizes DAO to process Personal Data to the extent reasonably necessary to provide, secure, maintain and support the Services.
6.4. If DAO reasonably believes that an instruction infringes Applicable Data Protection Law, DAO shall inform the Customer without undue delay.
6.5. DAO shall not be required to comply with an instruction that would require it to violate Applicable Data Protection Law.
6.6. Where DAO is legally required to process Personal Data otherwise than on the Customer’s instructions, DAO shall, unless prohibited by law, inform the Customer of that legal requirement before carrying out the relevant Processing.
7. CUSTOMER’S RESPONSIBILITIES AND WARRANTIES
7.1. The Customer shall remain responsible for:
(a) determining the purposes and legal bases of Processing;
(b) ensuring the lawfulness of collecting and transferring Personal Data to DAO;
(c) providing legally compliant privacy notices;
(d) obtaining legally required consents;
(e) ensuring that its instructions are lawful; and
(f) complying with its obligations as Controller.
7.2. The Customer warrants that all Personal Data provided to DAO:
(a) has been collected lawfully;
(b) has been collected for specified and legitimate purposes;
(c) is adequate, relevant and limited to what is necessary;
(d) is accurate to the extent required; and
(e) may lawfully be disclosed to DAO for the relevant Services.
7.3. The Customer shall provide Data Subjects with all legally required information concerning:
the identity and contact details of the Controller; purposes of Processing; legal bases; categories of recipients; international transfers; retention periods; Data Subject rights; cookies and tracking technologies; advertising technologies; push notifications; and any other information required by Applicable Data Protection Law.
7.4. Where consent is required, the Customer shall ensure that consent:
(a) is freely given, specific, informed and unambiguous;
(b) is obtained through a clear affirmative action;
(c) is obtained before the relevant Processing begins;
(d) is not inferred from passive browsing, scrolling, closing a banner or continued website use;
(e) is properly recorded where required; and
(f) may be withdrawn as easily as it was provided.
7.5. The Customer warrants that any push tokens, subscription identifiers or related technical data provided to DAO have been collected from Data Subjects who have validly opted in to receive the relevant push notifications, where required by law.
The Customer shall not transmit push tokens obtained through deceptive consent mechanisms; pre-ticked consent boxes where prohibited; forced consent; bundled consent unrelated to the relevant service; purchased or scraped databases; or any other unlawful collection method.
7.6. The Customer shall not transmit to DAO:
or other sensitive data not necessary for the Services.
8.1. DAO shall ensure that persons authorized to process Personal Data:
(a) are bound by confidentiality obligations; or
(b) are subject to an appropriate statutory obligation of confidentiality.
8.2. DAO shall limit access to Personal Data to persons who require access for the performance of their duties.
8.3. DAO shall take reasonable steps to ensure that authorized persons process Personal Data only in accordance with this DPA and applicable instructions.
9.1. DAO shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk of Processing.
9.2. Such measures shall include, where appropriate:
(a) access control and least-privilege principles;
(b) authentication and authorization controls;
(c) encryption of data in transit;
(d) encryption or equivalent protection at rest where appropriate;
(e) pseudonymization, hashing or truncation of technical identifiers where feasible;
(f) logging and monitoring;
(g) network security;
(h) vulnerability management;
(i) malware and intrusion protection;
(j) backup and recovery procedures;
(k) business continuity measures;
(l) incident response procedures;
(m) personnel confidentiality measures;
(n) secure deletion procedures; and
(o) periodic review of security measures.
9.3. The applicable technical and organizational measures are further described in Annex 2.
9.4. DAO may modify its security measures from time to time, provided that such modifications do not materially reduce the overall level of protection appropriate to the Processing.
10.1. The Customer provides DAO with a general written authorization to engage Sub-processors for the Processing of Personal Data where reasonably necessary to provide the Services. This authorization is granted subject to the conditions of this Section 10.
10.2. Sub-processors may include providers of:
10.3. DAO shall inform the Customer of any intended addition or replacement of Sub-processors by:
(a) updating a publicly available Sub-processor list;
(b) publishing a notice on the platform;
(c) sending an email notification; or
(d) another reasonable written communication method.
10.4. The Customer may object to the appointment of a new Sub-processor on reasonable data protection grounds by notifying DAO within fourteen (14) days after receiving notice of the relevant change. If the Customer fails to object within the Objection Period, the Customer shall be deemed to have fully and unconditionally authorized and approved the appointment of the new Sub-processor.
10.5. Any objection must identify the specific data protection concern and explain why the proposed Sub-processor may materially affect the protection of Personal Data.
10.6. DAO shall use commercially reasonable efforts to address the objection. If DAO cannot reasonably resolve the objection, the Parties shall discuss an alternative solution in good faith.
10.7. If no commercially reasonable solution is available, either Party may terminate the affected Services upon written notice, without affecting unrelated Services.
10.8. DAO shall ensure that each Sub-processor is bound by written obligations requiring the Sub-processor to provide an appropriate level of data protection and security substantially equivalent to the obligations applicable to DAO under this DPA.
10.9. DAO shall remain responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law. The sub-processing framework reflects the Article 28 requirement for prior specific or general written authorization, notice of changes and an opportunity to object.
11.1. Taking into account the nature of the Processing, DAO shall provide reasonable technical and organizational assistance to the Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
11.2. Such assistance may include, where technically feasible:
and providing relevant technical information.
11.3. The Customer shall remain responsible for:
(a) verifying the identity of the requesting Data Subject;
(b) determining whether the request is legally valid;
(c) responding to the Data Subject; and
(d) communicating the final response.
11.4. DAO shall not respond directly to Data Subjects except:
(a) on the Customer’s documented instructions;
(b) where required by law; or
(c) where DAO acts as an independent Controller.
11.5. The Customer shall reimburse DAO for reasonable costs incurred in responding to excessive, manifestly unfounded or technically disproportionate requests, to the extent permitted by law.
12.1. DAO shall notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Personal Data processed on behalf of the Customer.
12.2. DAO shall take reasonable measures to contain, investigate and mitigate the Security Incident.
The Customer shall reasonably cooperate with DAO in investigating and mitigating a Security Incident.
12.3 The Customer shall be responsible for determining whether notification to a Supervisory Authority or Data Subjects is required, unless DAO is independently required to notify an authority under Applicable Data Protection Law.
13.1. The Customer acknowledges that Personal Data may be processed or accessed outside the United Kingdom or the European Economic Area.
13.2. DAO may transfer Personal Data to countries outside the UK or EEA where reasonably necessary to provide the Services, provided that an appropriate lawful transfer mechanism is implemented where required.
13.3. The Customer authorizes DAO to use international hosting, infrastructure, payment, anti-fraud and technical service providers where legally permitted.
14.1. If DAO receives a legally binding request from a public authority for disclosure of Personal Data processed on behalf of the Customer, DAO shall, where legally permitted:
(a) notify the Customer;
(b) provide relevant details of the request; and
(c) reasonably cooperate with the Customer’s efforts to challenge or limit the disclosure.
14.2. DAO shall disclose only the minimum amount of Personal Data legally required.
14.3. DAO shall not be required to notify the Customer where prohibited by law or where notification would prejudice an investigation or other legally protected interest.
15.1. DAO shall make available to the Customer information reasonably necessary to demonstrate compliance with DAO’s obligations under this DPA and Article 28 GDPR, where applicable. Such information may include relevant policies; security descriptions; summaries of technical and organizational measures; compliance documentation; audit summaries; certifications, where available; Sub-processor information; and responses to reasonable compliance questionnaires.
15.2. The Customer may conduct an audit or inspection where:
(a) required by Applicable Data Protection Law;
(b) DAO has experienced a confirmed Security Incident materially affecting the Customer’s Personal Data; or
(c) the Customer reasonably demonstrates a material and specific compliance concern.
15.3. Any audit shall:
(a) be requested with at least 30 days’ prior written notice, except in the case of a Security Incident or legal requirement;
(b) take place during normal business hours;
(c) be conducted in a manner that does not unreasonably disrupt DAO’s business;
(d) be limited to Processing relevant to the Customer;
(e) be subject to confidentiality obligations;
(f) not provide access to other customers’ data;
(g) not expose security-sensitive information or trade secrets; and
(h) be conducted at the Customer’s cost.
15.4. The Customer shall first use available audit reports, certifications, questionnaires and other documentation before requesting an on-site audit.
15.5. DAO may satisfy an audit request by providing an independent third-party audit report or equivalent compliance documentation where such documentation reasonably demonstrates compliance.
16.1. DAO shall retain Personal Data for the duration necessary to provide the Services and for any additional period required or permitted by:
(a) Applicable Data Protection Law;
(b) tax or accounting obligations;
(c) fraud prevention requirements;
(d) security and operational requirements;
(e) dispute resolution; or
(f) establishment, exercise or defense of legal claims.
16.2. Upon termination of the Services, the Customer may request either:
(a) return of Personal Data in a reasonably usable format; or
(b) deletion of Personal Data.
16.3. Unless otherwise required by law, DAO shall comply with the Customer’s choice within a reasonable period.
16.4. DAO may retain copies of Personal Data where required by law or where necessary for:
legal claims; accounting; tax; fraud prevention; security; regulatory compliance; or other legitimate legal purposes.
16.5. Any retained Personal Data shall remain subject to the confidentiality and security obligations of this DPA and shall not be processed for unrelated purposes.
16.6. DAO may anonymize or aggregate Personal Data instead of deleting it where the resulting data no longer constitutes Personal Data.
17.1. DAO shall maintain records and documentation reasonably necessary to demonstrate compliance with its obligations under this DPA.
17.2. DAO shall reasonably cooperate with the Customer in responding to legitimate requests from Supervisory Authorities relating to Processing performed under this DPA.
17.3. The Customer shall promptly notify DAO of:
(a) any restriction on Processing;
(b) any withdrawal of consent materially affecting the Services;
(c) any Data Subject request requiring DAO’s assistance;
(d) any regulatory investigation concerning the relevant Processing; or
(e) any suspected unlawful Processing involving DAO.
18.1. The Customer shall be responsible for any claims, losses, penalties, costs or liabilities arising from:
(a) unlawful collection of Personal Data;
(b) failure to obtain required consent;
(c) unlawful push-notification practices;
(d) unlawful transfer of Personal Data to DAO;
(e) inaccurate or unlawful instructions;
(f) failure to provide required privacy notices; or
(g) transmission of prohibited or excessive data.
18.2. DAO shall be responsible for its Processing obligations under this DPA to the extent required by Applicable Data Protection Law.
18.3. Nothing in this DPA shall exclude or limit liability that cannot lawfully be excluded or limited under Applicable Data Protection Law.
18.4. Subject to mandatory law, liability under this DPA shall be subject to the liability provisions of the Terms of Use.
19.1. This DPA shall remain effective for as long as DAO processes Personal Data on behalf of the Customer.
19.2. Termination of the Terms of Use shall automatically terminate this DPA, except to the extent that Processing continues under Section 16.
19.3. The provisions that regulate following matters shall survive termination: confidentiality; security; deletion and retention; audit rights; liability; dispute resolution; and any provisions which by their nature are intended to survive.
This DPA shall be governed by the governing law and dispute resolution provisions specified in the Terms of Use.
If the Terms of Use do not specify such provisions, this DPA shall be governed by the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction, subject to mandatory provisions of Applicable Data Protection Law.
21.1. This DPA constitutes the entire agreement between the Parties concerning the Processing of Personal Data as Processor in connection with the Services.
21.2. This DPA may be accepted electronically and shall be legally binding in electronic form.
21.3. DAO may update this DPA where reasonably necessary to reflect: changes in Applicable Data Protection Law; regulatory guidance; changes in the Services; changes in technology; or changes to DAO’s Sub-processors or security framework. Where an update materially affects the Customer’s rights or obligations, DAO shall provide reasonable notice where required by law.
21.4. If any provision is invalid or unenforceable, the remaining provisions shall remain in full force and effect.
PROCESSING DETAILS
Processing of Personal Data in connection with DAO’s advertising technology, publisher/webmaster, push-notification, tracking, analytics, attribution and related Services.
For the duration of the Terms of Use and any additional retention period required or permitted under this DPA.
collection;
receipt;
recording;
organization;
storage;
retrieval;
consultation;
use;
transmission;
matching;
attribution;
analysis;
reporting;
restriction;
deletion;
anonymization;
and technical support.
delivery of push notifications;
campaign management;
advertising attribution;
impression and click measurement;
performance reporting;
technical service provision;
platform operation;
troubleshooting;
fraud prevention on behalf of the Customer;
and related Services.
visitors to Customer websites;
users subscribing to push notifications;
end users interacting with advertising content;
users interacting with Customer digital properties;
Customer employees and representatives;
advertisers;
publishers;
webmasters;
and authorized platform users.
IP addresses;
hashed or truncated IP addresses;
push tokens;
cookie identifiers;
device identifiers;
browser and operating system data;
country and approximate location;
click and impression data;
subscription status;
timestamps;
referral URLs;
account information;
contact details;
and technical logs.
No special categories of Personal Data are intended to be processed.
Technical and Organizational Measures
DAO shall maintain measures appropriate to the risks of the Processing, including:
role-based access;
least-privilege access;
access restriction based on business need;
account management procedures;
authentication controls.
encryption in transit;
appropriate encryption at rest;
pseudonymization or hashing where feasible;
secure transmission mechanisms;
controlled access to infrastructure.
network security;
vulnerability management;
monitoring;
logging;
malware protection;
intrusion detection;
security updates.
backup procedures;
recovery mechanisms;
business continuity measures;
service monitoring;
incident response procedures.
confidentiality obligations for authorized personnel;
access limitation;
security awareness;
appropriate internal policies.
incident identification;
escalation procedures;
containment;
investigation;
remediation;
notification procedures.
deletion procedures;
anonymization where appropriate;
retention controls;
backup deletion cycles;
restriction of retained data.
allocation of security responsibilities;
internal access controls;
periodic review of security measures;
vendor/Sub-processor management;
compliance monitoring.
Authorised Sub-processor Categories
The Customer authorizes DAO to engage Sub-processors in the following categories:
Other technical providers reasonably necessary to provide the Services.
DAO shall maintain or make available an up-to-date list of material Sub-processors where required by Applicable Data Protection Law.