Data Processing Agreement
Last updated:
This Data Processing Agreement ("DPA") forms part of the Terms of Service between S.O. SIRIUSONE TECH LIMITED (registration no. HE 447061, Cyprus) ("SiriusOne", "we") and the customer agreeing to it ("Customer") for the provision of Adlensa (the "Services").
This DPA applies automatically to all Customers whose use of the Services involves Processing of Personal Data subject to Applicable Data Protection Law. No signature is required. Enterprise customers may execute a standalone version, which prevails to the extent of conflict.
1. Definitions
"Applicable Data Protection Law" means all laws applicable to the Processing of Personal Data under this DPA, including the EU GDPR (Regulation 2016/679), the UK Data Protection Act 2018 and UK GDPR, the Swiss FADP, and any other applicable privacy legislation.
"Controller", "Processor", "Data Subject", "Personal Data", and "Processing" have the meanings given in the GDPR. "Customer Data" means Personal Data that Customer submits to the Services or that we Process on Customer's behalf. "Sub-processor" means a third party we engage to Process Customer Data. "SCCs" means the EU Standard Contractual Clauses in Implementing Decision (EU) 2021/914. "Security Incident" means a breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
2. Roles and scope
2.1 Roles. As between the parties, Customer is the Controller of Customer Data and SiriusOne is the Processor. Where Customer is itself a Processor for a third-party Controller, SiriusOne is a Sub-processor.
2.2 Details of Processing are set out in Schedule 1.
2.3 Independent Controller activities. SiriusOne acts as an independent Controller — not a Processor — with respect to: (a) account registration and identity data; (b) billing information; (c) service usage analytics; and (d) the advertising data Adlensa collects from publicly available sources about companies' advertising activity. This last category is data we gather ourselves (via our data provider's API) about businesses' public advertising; it is not submitted by Customer and is not Customer Data under this DPA. We Process it for our own legitimate business purposes in accordance with our Privacy Policy. This section does not limit our Processor obligations for actual Customer Data.
3. Customer obligations
Customer shall: comply with its obligations under Applicable Data Protection Law, including having a lawful basis and giving required notices/obtaining consents; ensure the accuracy, quality and legality of Customer Data; and not submit special categories of Personal Data (GDPR Article 9) unless expressly agreed in writing.
4. Our processing obligations
4.1 Instructions. We Process Customer Data only on Customer's documented instructions (the Agreement and this DPA being the complete instructions), unless required by law. If we believe an instruction infringes Applicable Data Protection Law, we will notify Customer. We do not use Customer Data to train, fine-tune, or improve machine-learning or AI models.
4.2 Confidentiality. Personnel authorized to Process Customer Data are bound by confidentiality obligations, and access is limited to those who need it to provide the Services.
4.3 Security. We implement appropriate technical and organizational measures meeting GDPR Article 32, described in Schedule 2. We may update them provided the overall level of protection is not materially decreased.
4.4 Data Subject requests. Taking into account the nature of Processing, we assist Customer in responding to Data Subject rights requests. If we receive a request directly, we forward it to Customer.
4.5 Assistance. We assist Customer with GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of Processing and information available to us.
5. Sub-processors
5.1 Authorization. Customer gives general written authorization for us to engage Sub-processors. The current list is in Schedule 3.
5.2 Obligations. We impose data protection obligations on each Sub-processor no less protective than this DPA by written contract, and remain liable for their performance.
5.3 Change notice. We notify Customer at least 30 days before adding or replacing a Sub-processor. Customers may subscribe to notifications by emailing privacy@adlensa.com.
5.4 Objection. Customer may object in writing on reasonable data-protection grounds; the parties discuss in good faith, and if unresolved Customer may terminate the affected Services without penalty.
6. International transfers
6.1 The Services are operated from the EU (Cyprus). Where Processing involves a transfer of Customer Data outside the EEA/UK/Switzerland to a country without an adequacy decision (a "Restricted Transfer"), the parties rely on the SCCs (Schedule 4), supplemented as required.
6.2 Modules. Module Two (Controller→Processor) applies where Customer is a Controller; Module Three (Processor→Processor) where Customer is a Processor.
6.3 UK / Swiss. The UK International Data Transfer Addendum (version B1.0) and Swiss FADP adaptations apply to transfers subject to UK/Swiss law respectively.
6.4 Alternative mechanisms. If a transfer mechanism is invalidated, the parties cooperate in good faith to implement a suitable alternative.
7. Security incident notification
7.1 We notify Customer without undue delay (and in any case within 72 hours of becoming aware) of a Security Incident affecting Customer Data, to the account email on record.
7.2 Notification includes, to the extent available: nature of the incident, categories and approximate number of Data Subjects/records affected, likely consequences, our contact point, and measures taken/proposed.
7.3 We cooperate with Customer and provide information reasonably required for Customer's own notification obligations.
7.4 We maintain a record of Security Incidents.
7.5 These obligations do not apply to incidents caused by Customer's own actions, and notification is not an admission of fault.
8. Audit
We make available, on reasonable request, information about our security practices (Schedule 2). Where we hold independent certifications or audit reports, we make them available to Enterprise customers, along with reasonable audit rights, subject to confidentiality.
9. Data return and deletion
9.1 Customer may export Customer Data via the product/API during the term.
9.2 On termination, we delete or return Customer Data. Account-level data is retained for legitimate business purposes (tax, fraud, reactivation) unless Customer requests deletion, in which case we delete within 30 days of the request.
9.3 We may retain data where required by law, isolated and protected, and delete it once the obligation expires.
10. Records; data protection contact
10.1 We maintain records of Processing activities per GDPR Article 30(2).
10.2 As a Cyprus (EU) company, we are established in the EU. For data protection inquiries: privacy@adlensa.com.
11. Liability
Each party's liability under this DPA is subject to the limitations in the Agreement, except for liability that cannot be limited under applicable law (fraud, death/personal injury by negligence, etc.).
12. General
12.1 Precedence. This DPA prevails over the Agreement regarding Processing of Customer Data; the SCCs prevail over this DPA in case of conflict.
12.2 Governing law. This DPA is governed by the laws of the Republic of Cyprus, except where Applicable Data Protection Law or the SCCs require otherwise.
12.3 Amendments. We may update this DPA to reflect legal changes; material changes are published at least 30 days before taking effect.
Schedule 1Details of Processing
- Subject matter: Processing of Customer Data in connection with providing Adlensa (account management, running competitor scans on Customer's instruction, usage logging, billing, support).
- Duration: For the term of the Agreement plus the period until Customer Data is deleted or returned per Section 9.
- Nature and purpose: Receiving Customer's requests to scan competitors; running those scans against publicly available advertising data via our data provider; storing and presenting results to Customer; logging usage for billing, rate limiting, and abuse prevention; processing payments via a third-party processor; providing support.
- Categories of Data Subjects: Customer's employees, agents, or contractors who use the Services; individuals whose Personal Data may incidentally appear in inputs Customer provides.
- Types of Personal Data: Account holder contact information (name, email); IP addresses and access logs; account identifiers; billing/payment information (via payment Sub-processor); usage, access, and error logs; support correspondence. Note: advertising data about companies collected from public sources is not Customer Data (see Section 2.3).
- Special categories: None. Customer shall not submit Article 9 data unless agreed in writing.
- Frequency: Continuous, as Customer uses the Services.
Schedule 2Technical and Organizational Security Measures
- Encryption. Data in transit encrypted with TLS 1.2+; data at rest encrypted with AES-256 or equivalent.
- Network security. Production runs in a cloud environment with private network segmentation and access controls; databases not exposed to the public internet.
- Access control. Least-privilege access to production; multi-factor authentication for administrative access; role-based access; unique API keys where applicable.
- Logging & monitoring. Audit logs of administrative and key activity; anomaly monitoring; security logs retained in protected storage.
- Data minimization & retention. Data minimization by default; scheduled purging of transient data; account data retained for legitimate purposes and deleted within 30 days of a deletion request.
- Personnel security. Confidentiality obligations for all personnel with access; access limited to those who need it.
- Incident response. Documented procedures covering identification, containment, eradication, recovery, and notification.
- Business continuity. Automated backups; documented recovery procedures.
- Vulnerability management. Dependencies monitored for known vulnerabilities; security patches applied promptly by severity.
- Sub-processor security. Sub-processors assessed for data protection posture and bound by written agreements.
Schedule 3Authorized Sub-processors
Current Sub-processors that Process Customer Data include providers of:
- Cloud infrastructure / hosting
- Payment processing — Stripe
- Transactional & marketing email — Resend
- Publicly-available advertising data collection (API) — SearchApi
- Product/website analytics — Google (Analytics), subject to consent
- Advertising measurement — Google Ads, Meta, subject to consent
- Customer support / chat — Chatling
An up-to-date list is maintained and Customers may subscribe to change notifications (Section 5). Internal tools that do not Process Customer Data (code repositories, internal messaging) are not Sub-processors.
Schedule 4International transfer mechanisms
The EU SCCs (Implementing Decision (EU) 2021/914) are incorporated by reference, with: Module Two (Controller→Processor) or Module Three (Processor→Processor) as applicable; general written authorization for Sub-processors (Clause 9, Option 2, 30-day notice); governing law and forum of Cyprus (as the data exporter's establishment is in Cyprus); UK Addendum and Swiss adaptations for those jurisdictions. Supplementary measures: encryption in transit and at rest, role-based access with MFA, and rejection of unlawful government/law-enforcement data requests.