Data Processing Agreement
Effective: ยท Version 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and ADPILOT AI LIMITED("Processor", operator of RepairAds). It applies whenever the Processor processes Personal Data on behalf of the Controller in connection with the RepairAds service.
1. Scope of processing (Art. 28(3) GDPR)
- Subject matter and purpose: operate managed Google Ads campaigns and microsites for repair shops, on the Controller's documented instructions only.
- Nature of processing: collection, storage, hosting, transmission, analysis, and deletion.
- Categories of data: shop contact details, employee names, emails and phone numbers, lead records (tracked calls, form submissions and the technical data needed to attribute them), and click and impression metrics.
- Categories of data subjects: shop staff and prospects contacting the shop.
- Duration: for the term of the subscription plus 30 days retention, unless deletion is requested earlier.
- The Processor processes Personal Data only on the Controller's instructions, does not process it for its own purposes, and informs the Controller if an instruction appears to infringe applicable data-protection law.
- Persons authorised by the Processor are bound by written confidentiality obligations that survive the end of their engagement.
- The Processor assists the Controller with security obligations (Art. 32), breach notification (Art. 33-34), impact assessments (Art. 35-36), and makes available the information needed to demonstrate compliance, including submitting to audits or inspections once per year on 30 days' written notice, or sooner following a confirmed breach.
2. Sub-processors
The Controller grants general written authorisation for the sub-processors listed below. The Processor imposes data-protection obligations on each sub-processor that are no less protective than this DPA and remains liable for their performance. The Processor will give the Controller at least 14 days' notice by email or in the dashboard before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds and, if the objection cannot be resolved, terminate the affected service without penalty.
| Name | Purpose | Location |
|---|---|---|
| Supabase | Auth, database, storage | EU (Frankfurt) |
| Cloudflare Workers | Application hosting | Global edge |
| Stripe | Payments & invoicing | US / EU (Ireland) |
| Resend | Transactional & marketing email | US |
| Twilio | WhatsApp Business API | US / EU (Ireland) |
| Google Ads | Campaign delivery in customer-authorised advertising accounts | US |
| Apify | Public data enrichment | EU (Czech Republic) |
| Instantly.ai | Cold outreach delivery | US |
| Microlink.io | Website screenshots for microsites | EU |
| Lovable AI Gateway (OpenAI, Anthropic, Google) | Ad copy & microsite content generation | US / EU |
3. Technical and organisational measures (Art. 32 GDPR)
- Encryption at rest (AES-256) and in transit (TLS 1.3).
- Row-level security on all tenant data with authenticated access only; tenant isolation enforced in the database, not only in the application.
- Least-privilege service accounts, role-based access control, and 2FA for admin roles.
- Secrets held in a managed secret store, never in source code; keys rotatable on demand.
- Full audit log of admin actions retained for 12 months; authentication and security logs for 12 months.
- Managed hosting with automated daily backups and point-in-time recovery, restore procedures tested by the platform provider.
- Data minimisation and defined retention windows, with automated or scheduled deletion at the end of each window.
- Pseudonymisation or aggregation of performance metrics wherever identification is not required.
- Change control: code review and automated checks before deploy; dependency and security scanning.
- Personnel bound by confidentiality; access removed on termination of engagement.
4. Data subject requests
The Processor will assist the Controller in responding to access, rectification, deletion, restriction, objection, and portability requests within 30 days, and will forward any request it receives directly from a data subject to the Controller without responding to it substantively. Requests: hello@repair-ads.com.
5. International transfers & SCC appendix
The Processor is established in Hong Kong SAR, which is not covered by an EU adequacy decision. Where Personal Data of EU or UK data subjects is transferred outside the EEA/UK, the parties incorporate the European Commission Standard Contractual Clauses (Implementing Decision 2021/914) by reference, and the UK International Data Transfer Addendum (version B1.0) for UK transfers. Where no adequacy decision applies, the clauses are deemed executed on acceptance of the Terms of Service, with:
- Module: module two (controller to processor) where the Controller is a controller; module three (processor to processor) where the Controller acts as a processor for its own customers.
- Clause 7 (docking): applies.
- Clause 9 (sub-processors): option 2, general written authorisation, 14 days' notice, as in section 2.
- Clause 11 (redress): the optional independent dispute-resolution body does not apply.
- Clause 17 (governing law): the law of Ireland.
- Clause 18(b) (forum): the courts of Ireland. For UK transfers, the Addendum's governing law and forum apply instead.
- Annex I: the parties, categories of data, data subjects, purpose, and duration as set out in section 1 above; the Processor is data importer, the Controller data exporter.
- Annex II: the technical and organisational measures in section 3 above.
- Annex III: the sub-processor table in section 2 above.
- Competent supervisory authority: the authority of the EEA member state in which the Controller, or its Art. 27 representative, is established.
The Processor has carried out a transfer impact assessment, has received no government access request for Controller data, and will challenge any unlawful request and notify the Controller where legally permitted. The Processor also complies with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486). Where the clauses and this DPA conflict, the clauses prevail.
6. Breach notification
The Processor will notify the Controller without undue delay and in any case within 48 hours of becoming aware of a personal-data breach affecting Controller data, with the nature of the breach, the categories and approximate volume of data and data subjects affected, likely consequences, and remedial measures taken.
7. Deletion
Upon termination, the Processor will delete or return all personal data within 30 days and certify deletion on request, subject to legal retention obligations (in particular accounting records, retained for 7 years).
8. Liability & order of precedence
This DPA forms part of the Terms of Service, and the liability limits in those terms apply to it, except where applicable data-protection law prohibits limitation. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service on matters of personal-data processing.