Data Processing Addendum
Last updated: October 7, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between SPO.expert — Roman Sarychev, Lisbon, Portugal ("SPO.expert") and the client using the Service (the "Client"). It applies whenever SPO.expert processes personal data on the Client's behalf while providing the Service, and it is accepted together with the Terms. Clients whose procurement requires a signature may countersign this same text; request a copy from [email protected].
1. Definitions
"Personal data," "processing," "controller," "processor," "sub-processor," "data subject," "supervisory authority" and "personal data breach" have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where applicable, the UK GDPR. "Client Personal Data" means personal data that SPO.expert processes on the Client's behalf under the Terms. "Service" has the meaning given in the Terms.
2. Roles and Scope
For Client Personal Data, the Client is the controller and SPO.expert is the processor. The Service is designed so that the measurement tag carries no personal data; Client Personal Data is therefore expected to be limited to the account details of the people the Client authorizes to use the dashboard, and to any personal data the Client includes in the tag's parameters contrary to the Terms. Annex 1 describes the processing.
3. SPO.expert's Obligations
SPO.expert will:
- process Client Personal Data only on the Client's documented instructions — the Terms, this DPA and the Client's use of the Service — unless required to do otherwise by law, in which case SPO.expert informs the Client before processing where the law permits;
- ensure that the people authorized to process Client Personal Data are bound by confidentiality;
- implement the technical and organizational measures in Annex 2 and keep them appropriate to the risk;
- engage sub-processors only as set out in section 5;
- assist the Client, by appropriate measures and insofar as possible, in responding to data subjects' requests to exercise their rights;
- assist the Client in meeting its obligations on security, personal data breaches, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to SPO.expert;
- delete or return Client Personal Data at the end of the Service as set out in section 9;
- make available the information necessary to demonstrate compliance with this DPA and allow audits as set out in section 8;
- inform the Client promptly if, in SPO.expert's opinion, an instruction infringes data protection law.
4. The Client's Obligations
The Client is responsible for the lawfulness of the processing it instructs — including having a legal basis for it and giving data subjects the notices the law requires — for ensuring that its instructions comply with law, and for not including personal data, device identifiers or user identifiers in the tag's parameters, as the Terms provide.
5. Sub-processors
The Client gives SPO.expert general authorization to engage sub-processors. The current sub-processors are listed in the Privacy Policy (section 7): Hetzner Online GmbH (hosting and backups, Germany), Cloudflare, Inc. (network security), OpenAI (AI analyst) and Google (Google Workspace, email). SPO.expert imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains responsible to the Client for their performance.
SPO.expert will announce any intended addition or replacement at least 30 days in advance by updating that list and emailing the Client's account holders. The Client may object within that period on reasonable, documented data protection grounds; if the parties cannot resolve the objection in good faith, the Client may terminate the affected part of the Service without penalty.
6. International Transfers
SPO.expert hosts Client Personal Data in the European Union (Germany). Where a sub-processor processes data outside the EU/EEA, the transfer relies on an adequacy decision of the European Commission — including the EU–U.S. Data Privacy Framework where the sub-processor is certified — or on the Standard Contractual Clauses incorporated into the sub-processor's data processing terms.
7. Personal Data Breach
SPO.expert will notify the Client without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Client Personal Data. The notification contains the information reasonably available at the time — the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — and is supplemented as further information becomes available. SPO.expert will cooperate with the Client in the Client's own notifications to supervisory authorities and data subjects.
8. Audits
On the Client's request, no more than once in any 12 months, SPO.expert will answer a reasonable written security and data protection questionnaire and provide relevant documentation. Where a supervisory authority requires it, or following a personal data breach affecting the Client, the Client — or an independent auditor bound by confidentiality — may audit SPO.expert's relevant systems on at least 30 days' notice, during business hours, without disrupting the Service and at the Client's cost; the parties agree the scope in advance.
9. Deletion and Return
At the end of the Service, SPO.expert deletes Client Personal Data within 90 days, unless the signed agreement provides otherwise or the law requires retention. On the Client's written request made before deletion, SPO.expert first returns the Client's data in a machine-readable format (CSV exports of the Client's reports are available in the dashboard at any time). Encrypted backups are overwritten in the ordinary backup cycle within 12 months and are restored only to recover the Service.
10. Data Subject Requests
If SPO.expert receives a request from a data subject concerning Client Personal Data, it forwards the request to the Client within 5 business days and does not respond to it except on the Client's instructions, unless the law requires otherwise.
11. Liability and Precedence
Each party's liability under this DPA is subject to the limitations in the Terms, to the extent the law allows. Each party is responsible for its own compliance with data protection law. For data protection matters this DPA prevails over the Terms; where the Standard Contractual Clauses apply, they prevail over this DPA.
12. Term
This DPA applies for as long as SPO.expert processes Client Personal Data and, for the obligations in sections 7 to 10, until deletion is complete.
Annex 1 — Details of the Processing
- Subject matter: provision of the SPO.expert supply path verification Service to the Client.
- Duration: the term of the Service, plus the deletion period in section 9.
- Nature and purpose: hosting, storage, analysis and display of the data the Client sends through the measurement tag; running the Client's dashboard accounts; generating reports and AI analyst answers for the Client.
- Categories of data subjects: the Client's employees and contractors authorized to use the dashboard. End users of the Client's advertising are not intended to be data subjects: the tag carries no personal data about them.
- Categories of personal data: account data of authorized users — name, work email address, role, company — and technical sign-in data (session cookies, short-lived sign-in attempt counters). No special categories of data.
- Retention: the term of the Service and up to 90 days after; web server logs up to 14 days, application logs replaced at each deployment; encrypted backups up to 12 months.
Annex 2 — Technical and Organizational Measures
- Data minimization by design: the tag accepts a fixed list of impression parameters and discards everything else; no cookies, device or user identifiers; no request headers recorded on any domain; no IP addresses recorded for the tag domain; truncated IP addresses only on the website, dashboard and API domains, deleted within 14 days; logs are never included in backups.
- Encryption in transit: TLS on all connections, HSTS, TLS 1.2 or higher enforced at the network edge.
- Hosting and network security: dedicated server in a Hetzner data center in Germany; all domains behind Cloudflare (web application firewall, rate limiting, DDoS protection); host firewall allowing only web and administrative ports; administrative access by SSH key only, root login disabled, brute-force protection.
- Isolation: the tag endpoint is served from its own domain and cannot reach the dashboard, the API or administrative functions; services run in separate containers on an internal network; no database, cache or queue is exposed to the Internet.
- Access control: role-based access in the dashboard and the administrative console; session cookies with HttpOnly and Secure flags; CSRF protection; per-address and per-account sign-in rate limits; administrative access limited to two people.
- Backups and recovery: hourly encrypted backups to a separate Hetzner storage location in Germany; weekly automated restore test; retention of 12 months.
- Monitoring: metrics and alerting on availability, errors and traffic anomalies; external uptime monitoring; operating-system security updates applied automatically.
- Sub-processor control: data processing terms with every sub-processor; list published in the Privacy Policy; 30 days' notice of changes.
- Incident response: breach notification to the Client within 48 hours (section 7); post-incident review recorded in the engineering journal.