Data Processing Agreement
Last updated: July 15, 2026
1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between influio s.r.o., ID No. 22238697, with its registered office at Varšavská 715/36, Vinohrady, 120 00 Praha, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague under file no. C 412818 ("Processor", "we", "us"), and the organization that has accepted this DPA when registering for or using the Admazing platform at app.getadmazing.com ("Controller", "you").
This DPA forms part of and is incorporated into our Terms of Service (the "Agreement"). By accepting the Agreement, you accept this DPA. Where this DPA conflicts with the Agreement, this DPA prevails in respect of the processing of Customer Personal Data.
This DPA is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and governs our processing of Customer Personal Data on your behalf.
2. Definitions
"Customer Personal Data" means personal data that we process on your behalf in providing the Service, as described in Annex 1. Terms such as "personal data", "processing", "controller", "processor", "data subject", "sub-processor", and "personal data breach" have the meanings given to them in the GDPR.
3. Roles of the Parties
You are the controller and we are the processor in respect of Customer Personal Data. You are responsible for establishing a legal basis for the processing, for the accuracy and lawfulness of the Customer Personal Data you provide or make accessible to us, and for complying with your own obligations as a controller.
We are a separate and independent controller in respect of the account and usage data described in our Privacy Policy (for example, the email address you register with, billing data, and security logs). That processing is governed by the Privacy Policy, not by this DPA.
4. Processing on Documented Instructions
We will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which we are subject. In such a case, we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Agreement, this DPA, and your use of the Service's features constitute your complete documented instructions. If we consider that an instruction infringes the GDPR or other data protection law, we will inform you without undue delay.
5. Confidentiality
We ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Customer Personal Data is limited to personnel who require it in order to provide, maintain, or support the Service.
6. Security of Processing
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. Our measures in force as at the date of this DPA are described in Annex 2. We may update these measures over time, provided that the level of security is not materially reduced.
7. Sub-Processors
You give us general written authorization to engage sub-processors for the provision of the Service. A current list of our sub-processors is maintained at app.getadmazing.com/subprocessors, and forms Annex 3 to this DPA.
We will give you notice by email or in-app notification of any intended addition or replacement of a sub-processor at least thirty (30) days before that sub-processor begins processing Customer Personal Data. You may object to the change on reasonable data protection grounds within that period by writing to admin@getadmazing.com. If we cannot accommodate your objection, you may terminate your subscription without penalty and receive a pro-rata refund of prepaid fees for the remainder of the billing period.
Where we engage a sub-processor, we impose on it data protection obligations that are no less protective than those set out in this DPA by way of a written contract. We remain fully liable to you for the performance of that sub-processor's obligations.
8. Assistance with Data Subject Rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.
The Service provides functionality that allows you to access, correct, export, and delete Customer Personal Data directly. Where a request cannot be fulfilled through that functionality, we will provide reasonable assistance on request. If we receive a request directly from a data subject in relation to Customer Personal Data, we will not respond to it substantively but will refer the data subject to you without undue delay.
9. Assistance with Security, Breaches, and Impact Assessments
Taking into account the nature of the processing and the information available to us, we will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known to us, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. We will provide further information as it becomes available. It is your responsibility as controller to notify the supervisory authority and, where required, affected data subjects.
10. Deletion and Return of Data
At your choice, we will delete or return all Customer Personal Data to you after the end of the provision of the Service, and delete existing copies, unless Union or Member State law requires storage of that data.
You may export Customer Personal Data at any time during your subscription using the Service's export functionality. Unless you request return or deletion within thirty (30) days of termination, we will delete or anonymize Customer Personal Data in accordance with the retention periods set out in our Privacy Policy. Data contained in routine backups is deleted on the backup cycle described in Annex 2.
11. Audits and Information
We will make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you.
You may exercise this right no more than once in any twelve (12) month period, on at least thirty (30) days' prior written notice, during our normal business hours, and without unreasonably disrupting our operations. Any auditor must be bound by confidentiality obligations. You bear your own costs and our reasonable costs of assisting with an audit. This limitation does not apply where an audit is required by a supervisory authority or follows a personal data breach affecting Customer Personal Data.
12. International Transfers
We store and process Customer Personal Data within the European Union. Where a transfer of Customer Personal Data to a third country is necessary — in particular to the advertising and payment providers identified in Annex 3 — that transfer is made under an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework where the recipient is certified under it, or under Standard Contractual Clauses adopted by the European Commission, together with any supplementary measures required following a transfer impact assessment.
13. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits either party's liability to data subjects or to a supervisory authority under Article 82 of the GDPR.
14. Term and Termination
This DPA takes effect when you accept the Agreement and remains in force for as long as we process Customer Personal Data on your behalf. Clauses that by their nature should survive termination — including Sections 5, 10, 11, and 13 — survive termination of this DPA.
15. Changes to This DPA
We may update this DPA to reflect changes in law, in the Service, or in our processing practices. We will notify you of material changes by email or in-app notification at least thirty (30) days before they take effect. If you do not agree to the updated DPA, you may terminate your subscription before the effective date.
16. Governing Law
This DPA is governed by the laws of the Czech Republic, and disputes are subject to the jurisdiction set out in the Agreement, without prejudice to any mandatory provisions of applicable data protection law.
Annex 1 — Description of the Processing
Subject matter. Provision of the Admazing advertising management platform, which enables you to create, deploy, and monitor advertising campaigns on third-party advertising platforms, to manage product catalogs, and to generate ad creatives.
Duration. For the term of your subscription, plus the retention periods set out in the Privacy Policy.
Nature and purpose. Collection, storage, structuring, retrieval, use, transmission to advertising platforms, and erasure of Customer Personal Data, for the purpose of providing the Service to you.
Categories of data subjects.
- Your personnel and other individuals you authorize to use the Service on your behalf
- Individuals whose personal data is contained within the advertising accounts, campaigns, product catalogs, or creative assets that you connect to or upload into the Service
Types of personal data.
- Identification and contact data of your authorized users — email address, organization membership, role and access scope
- Advertising platform data — ad account identifiers and names, currency settings, page and pixel identifiers, platform user identifiers, and access tokens issued to your connected accounts
- Campaign data — campaign names, budgets, targeting countries, deployment status, and aggregate performance metrics such as impressions, clicks, spend, conversions, and return on ad spend
- Content data — product catalog data, brand assets, ad copy, and rendered ad creatives that you upload or generate, insofar as these contain personal data
- AI assistant conversations — the messages your users compose in the in-app assistant, insofar as these contain personal data
Special categories of data. The Service is not intended for the processing of special categories of personal data within the meaning of Article 9 of the GDPR, and you must not upload such data into the Service.
Annex 2 — Technical and Organizational Measures
- Encryption in transit. All communication with the Service and with third-party APIs uses HTTPS/TLS.
- Encryption at rest. Advertising platform access tokens are encrypted at rest using AES-256-GCM. Databases and object storage are encrypted at rest by our infrastructure provider.
- Authentication. Sessions are held in HttpOnly, Secure cookies that cannot be read by client-side scripts. Passwords are stored only as salted hashes.
- Integrity of platform callbacks. Inbound webhook callbacks from advertising platforms are verified using HMAC-SHA256 signatures with timing-safe comparison.
- Secret management. Application secrets and API credentials are held server-side only and are never exposed to the browser.
- Access control. Access to production systems is restricted to authorized personnel on a need-to-know basis. Within the Service, access to your data is scoped to your organization, and you control which of your users may access which brands.
- Data residency. Customer Personal Data is stored and processed within the European Union.
- Backups. Database backups are retained for 7 days and are then automatically deleted.
- Logging and monitoring. Infrastructure logs used for security monitoring and debugging are retained for up to 30 days. Application logs record request context and do not systematically record IP addresses.
- Deletion and anonymization. On disconnection of an advertising account or on an erasure request, identifying data is anonymized immediately, with only non-attributable aggregate metrics retained.
Annex 3 — Sub-Processors
The sub-processors we engage, the purpose for which each processes Customer Personal Data, and the region in which each processes it, are set out in our sub-processor list at app.getadmazing.com/subprocessors, which is incorporated into this DPA and maintained in accordance with Section 7.
Contact
For any question relating to this DPA, contact us at: