Data Processing Agreement
Last updated: 26 July 2026
This agreement applies whenever you route another party's personal data (for example, your clients' Google Ads data) through AdsAudit. It also covers a direct advertiser auditing its own account. In both cases you are the controller and we are your processor.
Parties and structure
This Data Processing Agreement ("DPA") forms part of the Terms of Service between KlientBrain Ltd (company number 15306831, registered office 20 Wenlock Road, London, England, N1 7GU) ("Processor", "we"), and the customer ("Controller", "you"). It applies to our processing of personal data on your behalf in providing AdsAudit (the "Services").
1. Subject-matter and details of processing
- Subject-matter: provision of the AdsAudit audit and monitoring Services.
- Duration: for as long as you use the Services, plus the deletion/return period in clause 11.
- Nature and purpose: retrieving, storing, and analysing Google Ads account data to produce audits, scores, and reported issues, and (if subscribed) ongoing monitoring, at your instruction.
- Type of personal data: primarily advertising account configuration and performance data; any personal data it contains (for example, account user identifiers, names in account metadata). We do not require special-category data and ask you not to send it.
- Categories of data subjects: your personnel and your clients' personnel whose identifiers appear in the connected Google Ads accounts.
2. Processing only on your instructions
2.1 We process the personal data only on your documented instructions, including the instructions set out in the Terms and this DPA (which include the international transfers described in clause 9) and the configuration you choose in the app, unless required to do otherwise by law (in which case we will tell you, unless the law prohibits it).
2.2 We will inform you if, in our opinion, an instruction infringes UK data-protection law.
3. Confidentiality
3.1 We ensure that persons authorised to process the personal data are under an appropriate obligation of confidentiality. Access is restricted to those who need it to provide or support the Services (consistent with the Google API Limited Use commitment in our Privacy Policy).
4. Security
4.1 We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art and the nature of the data. These include, at least: multi-tenant isolation so one customer cannot access another's data; encryption in transit; access controls and authentication (via Clerk); read-only Google Ads access; storage of audit history in the EU (Supabase, eu-west-3 Paris); and logging.
5. Sub-processors
5.1 You give general written authorisation for us to engage the sub-processors listed below, each under a written contract imposing data-protection obligations no less protective than this DPA.
5.2 We will notify you of any intended addition or replacement of a sub-processor (for example by email or in-app notice), giving you a reasonable opportunity to object on reasonable data-protection grounds before the new sub-processor starts processing. If we cannot resolve a reasonable objection, you may terminate the affected Services.
5.3 We remain liable to you for a sub-processor's failure to meet its data-protection obligations.
6. Assisting with data-subject rights
6.1 Taking account of the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection).
6.2 If a data subject contacts us directly about data we process for you, we will refer them to you and tell you promptly.
7. Assisting with your compliance obligations
7.1 We will assist you in ensuring compliance with your obligations on security, personal-data breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to us.
8. Personal-data breach
8.1 We will notify you without undue delay after becoming aware of a personal-data breach affecting the data we process for you, and within 48 hours where feasible, with the information you need to meet your own notification duties.
9. International transfers
9.1 Audit history is stored in the EU (Supabase, eu-west-3 Paris). Some sub-processors operate outside the UK. Where personal data is transferred outside the UK, we ensure a valid transfer mechanism is in place (a UK data-bridge/adequacy destination, the IDTA, or the UK Addendum to the EU SCCs).
10. Audits and information
10.1 We will make available to you the information necessary to demonstrate compliance with our processor obligations and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits. We may satisfy this through third-party certifications or reports where available.
11. Return or deletion on termination
11.1 On the end of the Services, at your choice we will delete or return the personal data we process for you, and delete existing copies, within 60 days, unless UK law requires us to keep it. This aligns with the retention statement in our Privacy Policy.
12. Liability
12.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.
13. General
13.1 If there is a conflict between this DPA and the Terms on data protection, this DPA prevails.
13.2 This DPA is governed by the same law as the Terms (England and Wales).
Sub-processor list
Recipients are grouped by their data-protection role, because not all are sub-processors. We keep the recipient table in our Privacy Policy in sync with this list.
(i) Sub-processors (process customer data on our instructions)
| Sub-processor | Purpose | Personal data | Location / transfer basis |
|---|---|---|---|
| Cloudflare, Inc. | Application hosting and delivery (Workers/Pages), edge/CDN | App traffic, request data | Cloudflare DPA; UK transfer safeguard |
| Clerk, Inc. | Authentication and member identity | Member email, authentication data | Clerk DPA; UK transfer safeguard |
| Supabase, Inc. | Audit history and analytics storage; operational state, entitlements, job state | Audit history, change events, tenant/member/config/job state | EU region (eu-west-3, Paris) |
(ii) Independent (or joint) controllers, not our sub-processors
| Provider | Purpose | Personal data | Note |
|---|---|---|---|
| Google LLC / Google Ireland (Ads platform) | The Google Ads API is the data source you authorise; Google sign-in; PageSpeed Insights (free teaser) | Ads account data you authorise; site signals | Google is a controller of its own platform; we read data under your authorisation. Google DPA + SCCs/IDTA as applicable |
| Stripe, Inc. / Stripe Payments UK | Billing and payment processing | Billing contact, payment status (Stripe holds card data; we do not) | Stripe acts as an independent controller for payment/fraud data. Stripe DPA; PCI-DSS on Stripe |
(iii) Marketing (opted-in lead data only, never audit data)
| Provider | Purpose | Personal data | Note |
|---|---|---|---|
| Kit (ConvertKit) | Marketing email to opted-in leads (never audit data) | Lead email + source | Their DPA; consent basis |
| HubSpot, Inc. | Marketing/CRM for opted-in leads (never audit data) | Lead email + source | Their DPA; consent basis |
Your Google Ads data is never shared with Kit or HubSpot.