Data Processing Agreement

Effective: ยท Version 1.0

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and ADPILOT AI LIMITED("Processor", operator of RepairAds). It applies whenever the Processor processes Personal Data on behalf of the Controller in connection with the RepairAds service.

1. Scope of processing (Art. 28(3) GDPR)

2. Sub-processors

The Controller grants general written authorisation for the sub-processors listed below. The Processor imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains liable for their performance. The Processor will give the Controller at least 14 days' notice by email or in the dashboard before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and, if the objection cannot be resolved, terminate the affected service without penalty.

Authorized sub-processors, their purpose and location
NamePurposeLocation
SupabaseAuth, database, storageEU (Frankfurt)
Cloudflare WorkersApplication hostingGlobal edge
StripePayments & invoicingUS / EU (Ireland)
ResendTransactional & marketing emailUS
TwilioWhatsApp Business APIUS / EU (Ireland)
Google AdsCampaign delivery in customer-authorised advertising accountsUS
ApifyPublic data enrichmentEU (Czech Republic)
Instantly.aiCold outreach deliveryUS
Microlink.ioWebsite screenshots for micrositesEU
Lovable AI Gateway (OpenAI, Anthropic, Google)Ad copy & microsite content generationUS / EU

3. Technical and organisational measures (Art. 32 GDPR)

4. Data subject requests

The Processor will assist the Controller in responding to access, rectification, deletion, restriction, objection, and portability requests within 30 days, and will forward any request it receives directly from a data subject to the Controller without responding to it substantively. Requests: hello@repair-ads.com.

5. International transfers & SCC appendix

The Processor is established in Hong Kong SAR, which is not covered by an EU adequacy decision. Where Personal Data of EU or UK data subjects is transferred outside the EEA/UK, the parties incorporate the European Commission Standard Contractual Clauses (Implementing Decision 2021/914) by reference, and the UK International Data Transfer Addendum (version B1.0) for UK transfers. Where no adequacy decision applies, the clauses are deemed executed on acceptance of the Terms of Service, with:

The Processor has carried out a transfer impact assessment, has received no government access request for Controller data, and will challenge any unlawful request and notify the Controller where legally permitted. The Processor also complies with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486). Where the clauses and this DPA conflict, the clauses prevail.

6. Breach notification

The Processor will notify the Controller without undue delay and in any case within 48 hours of becoming aware of a personal-data breach affecting Controller data, with the nature of the breach, the categories and approximate volume of data and data subjects affected, likely consequences, and remedial measures taken.

7. Deletion

Upon termination, the Processor will delete or return all personal data within 30 days and certify deletion on request, subject to legal retention obligations (in particular accounting records, retained for 7 years).

8. Liability & order of precedence

This DPA forms part of the Terms of Service, and the liability limits in those terms apply to it, except where applicable data-protection law prohibits limitation. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service on matters of personal-data processing.