Data Processing Agreement

Last updated: July 28, 2026

1. Introduction and Scope

This Data Processing Agreement ("DPA") forms part of the PerfoAds Terms of Service between PerfoAds ("we", "us", the "Processor") and the customer using the Service ("you", the "Controller"). It applies whenever we process personal data on your behalf that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or similar data protection laws.

For such processing, you act as the data controller and we act as your data processor within the meaning of Article 28 GDPR. This DPA takes effect automatically when you create an account and connect a Google Ads or Merchant Center account; no signature is required. A countersigned copy is available on request at privacy@perfoads.com.

2. Subject Matter, Duration, Nature and Purpose

  • Subject matter: processing of advertising account data and related personal data required to provide the PerfoAds service (audits, monitoring, optimization and reporting for Google Ads and Merchant Center accounts).
  • Duration: the term of your account, plus the deletion period described in Section 7.
  • Nature of processing: collection via Google APIs (with your OAuth authorization), storage, structuring, analysis (including AI-assisted analysis), display back to you, and, only when you approve a change, transmission of updates to Google on your instruction.
  • Purpose: providing the Service as described in the Terms of Service. We do not use your data for advertising, do not sell it, and do not use it to train general-purpose AI models.

3. Categories of Data and Data Subjects

  • Categories of personal data: account holder identification data (name, email address), Google account email addresses, OAuth tokens, advertising performance and configuration data that may contain personal data (for example search terms or ad text), billing metadata, and support communications.
  • Special categories: none are required by the Service, and you agree not to submit any.
  • Data subjects: you and your staff, and, to the extent present inside advertising data, end users who interacted with your advertising.

4. Our Obligations as Processor

  • We process personal data only on your documented instructions, which are: the Terms of Service, this DPA, and the actions you take in the product (running audits, enabling monitoring, approving changes). We will inform you if we believe an instruction violates data protection law.
  • All personnel authorized to process personal data are bound by confidentiality obligations.
  • We implement appropriate technical and organizational measures (Section 8).
  • Taking into account the nature of processing, we assist you in responding to data subject requests (access, rectification, erasure, portability, objection). Requests reaching us directly are forwarded to you without undue delay.
  • We assist you with your obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments) insofar as they relate to our processing.
  • We notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data, with the information reasonably required for your own notification duties.
  • We make available the information necessary to demonstrate compliance with this DPA and, at your reasonable request and cost, allow for and contribute to audits (in the first instance by providing documentation and completed security questionnaires).

5. Subprocessors

You grant us general authorization to engage the subprocessors listed below. We impose data protection obligations on each subprocessor that are materially equivalent to this DPA, and we remain fully liable to you for their performance.

SubprocessorPurposeLocation
Anthropic PBCAI analysis and recommendation generation (Claude). Data processed in real time, not retained for model training.USA
Supabase Inc.Primary database hosting (PostgreSQL) with encryption at rest.USA (AWS us-east-1)
Render Services Inc.Application hosting and background job infrastructure.USA (Oregon)
Stripe Inc.Payment processing. Receives billing data only, never Google Ads data.USA
Firecrawl (Mendable AI)Landing page content extraction and screenshots for CRO analysis. Processed in real time, not retained.USA
Google LLC (Sheets API)Optional, user-initiated export of performance data into a spreadsheet the customer owns.USA / EU
DataForSEOKeyword and search-results enrichment. Receives search queries only, never account identifiers.USA
Tidio LLCLive chat support (loaded only with consent). May receive data the customer chooses to share in chat.USA / EU

Changes: we will update this page and notify account holders by email at least 14 days before adding or replacing a subprocessor. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected part of the Service.

6. International Transfers

Where personal data originating in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, Module Two: controller to processor), which are incorporated into this DPA by reference, together with the UK Addendum where applicable. Our US subprocessors either certify under the EU-US Data Privacy Framework or are bound by Standard Contractual Clauses in our agreements with them.

7. Retention and Deletion

  • Advertising data and audit reports are retained while your account is active, so you can reference past audits and track changes over time. Disconnecting a specific Google Ads client removes it from active syncing; previously generated audit reports remain available in your account.
  • Upon deletion of your account, or upon your written request to privacy@perfoads.com, we delete all personal data processed on your behalf, including audit reports, within 30 days, unless retention is required by law (for example billing records).
  • Inactive OAuth connections are deleted automatically after 90 days; revoking access in your Google account settings invalidates our tokens immediately.

8. Security Measures

  • OAuth refresh and access tokens encrypted at rest with AES-256-GCM; databases encrypted at rest by our hosting subprocessors.
  • All data in transit protected with TLS.
  • Access to production systems restricted to authorized personnel with least-privilege access controls.
  • Account-ownership verification before any change is applied to a connected advertising account, with a mandatory preview and approval step and a 30-day rollback window.
  • Logging and monitoring of production systems; automated cleanup of stale data (Section 7).

9. Google API Data

Data received via Google APIs is additionally handled in accordance with the Google API Services User Data Policy (including the Limited Use requirements) and the Google Ads API Terms of Service.

10. Contact

Privacy questions and data subject requests: privacy@perfoads.com. General support: contact@perfoads.com. See also our Privacy Policy and Terms of Service.