Data Processing Addendum
For customers of the Adferry platform in the United States. Incorporated into the Terms of Service.
1. Definitions and roles
"Privacy Laws" means the U.S. federal and state laws that apply to the processing of personal information under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations, and the comprehensive privacy laws of other states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others as they take effect). "Platform Data" means personal information of end users processed through the Platform on the Customer's behalf. "Personal information", "sell", "share", "service provider", "processor", "controller", "business" and "consumer" have the meanings given in the applicable Privacy Law.
For Platform Data, the Customer is the business or controller and Adferry is its service provider or processor. Where the Customer itself acts as a service provider for another business, the Customer warrants that it is authorised to engage Adferry and that its instructions are consistent with that business's instructions. For account and user data of the Customer's personnel, Adferry acts on its own behalf under the Privacy Policy.
2. Details of processing (Annex A)
| Item | Detail |
|---|---|
| Business purpose | Serving, measuring and reporting video and CTV ads on the Customer's inventory or campaigns |
| Duration | The term of the Customer's agreement plus the deletion period in Section 11 |
| Nature of processing | Ad decisioning, delivery, measurement, invalid-traffic filtering, frequency capping, per-request logging, computing invoices from measured impressions |
| Categories of personal information | Identifiers (IP address; advertising identifier where present and not opted out); device and network information (user agent, device and OS, app bundle or domain); approximate geolocation; internet activity (ad request and event data: request, bid, render, beacon, completion, error); consent and opt-out signals passed on the request |
| Consumers | End users of the Customer's apps, sites and CTV channels |
| Sensitive personal information | None intended. The Customer must not configure the Platform to process sensitive personal information, or personal information of consumers known to be under 16, without prior written agreement |
| Frequency | Continuous, on each ad request |
3. Processing on instructions; customer obligations
Adferry processes Platform Data only to provide the services and only on the Customer's documented instructions, which are: this DPA, the Terms, the Customer's configuration in the console and API, and the consent and opt-out signals carried on each request. Adferry will inform the Customer if it believes an instruction violates Privacy Laws and may suspend the affected processing until the instruction is confirmed or changed.
Customer obligations. The Customer warrants that: it has provided consumers with the notices required by Privacy Laws, including notice at collection; it honours consumer opt-out requests and preference signals and passes accurate, current opt-out signals on each request; it will not instruct Adferry to process sensitive personal information or information of consumers under 16 without prior written agreement; and its instructions comply with Privacy Laws. The Customer will indemnify Adferry for claims arising from a breach of this paragraph, subject to the limitations in the Terms.
4. Service-provider and processor commitments
Adferry certifies that it understands the restrictions in this Section and will comply with them. Adferry will not: (a) sell or share Platform Data; (b) retain, use or disclose Platform Data for any purpose other than the business purposes specified in the Terms and this DPA, including any commercial purpose other than providing the services; (c) retain, use or disclose Platform Data outside the direct business relationship with the Customer; or (d) combine Platform Data with personal information it receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by Privacy Laws for the services. Adferry will comply with applicable Privacy Laws and provide the same level of privacy protection they require of service providers and processors; will notify the Customer if it determines it can no longer meet these obligations; and grants the Customer the right, on reasonable notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Platform Data. Adferry does not operate its own demand and does not use Platform Data to build profiles for its own purposes. Where Adferry uses de-identified or aggregated data derived from Platform Data to operate and improve the Platform, it takes reasonable measures to ensure the data cannot be associated with a consumer or household, publicly commits not to re-identify it except to test the effectiveness of de-identification, and contractually requires any recipient to do the same.
5. Confidentiality of personnel
Adferry ensures that persons authorised to process Platform Data are bound by confidentiality obligations, receive appropriate training, and access only the data necessary for their role.
6. Security measures (Annex B)
Adferry implements and maintains reasonable security procedures and practices appropriate to the nature of the information, including at minimum: encryption in transit (TLS) on all endpoints; network isolation of production data stores; role-based access control scoped per account; individual authentication for staff with production access and periodic access review; logical separation of customer data by account in storage and query paths; logging of administrative actions and of every platform decision; change-safety controls that revert harmful configuration changes; invalid-traffic filtering; secure development and vulnerability management practices; and backup and business-continuity procedures. The current description is on the Security page and may be updated provided the overall level of security is not reduced. Adferry does not currently hold a third-party security certification and does not represent that it does.
7. Subprocessors
The Customer authorises Adferry to engage the subprocessors listed at adferry.co/subprocessors. Adferry will give at least 30 days' prior notice of additions or replacements by updating that page and notifying the Customer's account contact. The Customer may object in writing within that period on reasonable privacy grounds; the parties will discuss in good faith, and if no resolution is found within 30 days either party may terminate the affected service without penalty. Adferry binds each subprocessor by written contract to obligations no less protective than this DPA and remains responsible for their performance.
8. Consumer requests
Adferry will, taking into account the nature of the processing, assist the Customer with reasonable technical and organisational measures to respond to verifiable consumer requests (to know, access, delete, correct, or opt out). If Adferry receives a request directly, it will not respond on the merits except to refer the consumer to the Customer where it can identify the Customer, and will notify the Customer promptly. Adferry will comply with a Customer instruction to honour a consumer's opt-out or deletion request received by the Customer.
9. Security incidents
Adferry will notify the Customer without unreasonable delay, and in any event within 48 hours, after confirming a security incident involving unauthorised access to Platform Data, providing the information reasonably available at the time and updating as the investigation proceeds. Adferry will cooperate with the Customer's own notification obligations under state breach-notification laws and will not notify regulators or consumers on the Customer's behalf unless required by law or agreed.
10. Assistance, records and audits
Adferry will provide the information reasonably necessary to demonstrate compliance with this DPA, and reasonable assistance with the Customer's risk assessments where Privacy Laws require them. Once per 12 months, on 30 days' written notice and subject to confidentiality, the Customer (or an independent auditor it mandates, not a competitor of Adferry) may assess Adferry's compliance by written questionnaire and review of relevant documentation; an on-site assessment may be agreed where a regulator requires it or after a security incident affecting the Customer, during business hours and without disrupting operations. The Customer bears its own assessment costs and reimburses Adferry's reasonable costs for on-site assessments beyond the first in any 12-month period.
11. Return and deletion
Raw request-level Platform Data is retained for up to 90 days, after which only aggregates remain for reporting and billing. Within 30 days after termination of the services Adferry will delete remaining Platform Data, or, if the Customer requests in writing before termination, first export it in a commonly used format, and will certify deletion in writing on request. Adferry may retain data required by law or for invoicing for the period required, protected under this DPA until deleted.
12. Data outside the United States
The Platform is offered to customers in the United States, and this DPA is written for U.S. Privacy Laws. Processing of personal data that is subject to the data protection laws of the European Economic Area, the United Kingdom or Switzerland is outside the scope of the services unless the parties agree to it in writing. If they do, the parties will execute an addendum for that data before processing begins, including the transfer mechanism required by those laws, and that addendum will prevail over this DPA for the data it covers.
13. Liability and precedence
Privacy contact at Adferry: our contact page. Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except to the extent Privacy Laws do not permit such limits. If this DPA conflicts with the Terms or an Order Form on a privacy matter, this DPA prevails. This DPA is governed by the same law as the Terms.