Legal

Data Processing Agreement

This Data Processing Agreement (the “DPA”) forms part of the agreement between you (“Controller”) and ADPILOT AI LIMITED, operating as ADmetric AI (“Processor”), governing the processing of personal data under EU-GDPR and UK-GDPR.

Effective date: 1 June 2026 · Version 1.2

1. Subject matter and duration

The Processor processes personal data only to provide the ADmetric AI service for the duration of the underlying subscription agreement and any wind-down period not exceeding 30 days.

2. Nature and purpose of processing

Storage, retrieval, aggregation and analysis of advertising spend, budget allocations, billing records, and account-holder identifiers strictly to operate the budget management, treasury and intelligence features chosen by the Controller.

3. Categories of data subjects

  • Controller's employees, contractors and authorised users of the workspace
  • Account-holder contacts at connected ad networks
  • Recipients of invoices issued from the workspace

4. Categories of personal data

  • Identification data: name, business email, role, workspace membership
  • Authentication data: hashed credentials, MFA factors, session metadata
  • Billing data: company name, billing address, VAT/tax ID, invoice line items
  • Connector metadata: OAuth tokens (encrypted), account IDs, spend records

5. Processor obligations

The Processor will: (a) process personal data only on documented instructions from the Controller; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures described in our Security overview; (d) assist the Controller with data-subject requests and DPIAs; (e) notify the Controller of personal-data breaches without undue delay and within 72 hours; (f) make available all information necessary to demonstrate compliance and allow for audits, including SOC 2 reports under NDA.

6. Subprocessors

The Controller grants general authorisation for the Processor to engage the subprocessors listed at /legal/subprocessors. We will notify the Controller of intended changes at least 30 days in advance and the Controller may object on reasonable grounds.

7. International transfers

Where personal data is transferred outside the EEA or UK to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (Controller to Processor), and the UK International Data Transfer Addendum, as updated from time to time.

8. Security measures

AES-256 at rest, TLS 1.3 in transit, hardware-backed key custody, least-privilege access with mandatory MFA for production, immutable audit log, encrypted backups across two regions with point-in-time recovery, formal incident-response runbook, annual penetration testing by an independent firm.

9. Return and deletion of data

On termination, the Controller may export workspace data in machine-readable form for 30 days. The Processor will then delete or anonymise personal data within 60 days, except where retention is required by law (e.g. accounting records).

10. Liability

Liability under this DPA is governed by the underlying subscription agreement.

11. Signing

This DPA is auto-accepted by both parties on creation of the workspace. A counter-signed PDF version is available on request from legal@admetricai.app.