§ 1 Subject Matter & Duration
(1) The subject matter of this agreement is the processing of personal data by the Processor on behalf of the Controller in the context of use of the "CreativeRadar" service.
(2) The duration corresponds to the term of the main contract.
§ 2 Nature, Purpose & Data Subjects
Nature of processing: Collection, storage, analysis and provision of ad placements and associated metadata.
Purpose: Verification of real campaign visibility and quality assurance of ad creatives.
Data subjects: Users of the service on the Controller's side (e.g. employees, agency contacts).
Data categories: Account/contact data of users, technical usage and log data, captured ad creatives and their metadata.
§ 3 Instructions
The Processor shall process data exclusively on documented instructions from the Controller, unless required to process by EU or Member State law.
§ 4 Confidentiality
The Processor shall only engage persons to carry out processing who have been bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.
§ 5 Technical & Organisational Measures (TOMs)
The Processor shall implement the measures required under Art. 32 GDPR, in particular encryption (TLS, encryption at rest), role-based access control, logging, data minimisation, and availability and recovery concepts. The specific measures implemented will be made available to the Controller on request.
§ 6 Sub-processors
(1) The Controller authorises the engagement of sub-processors for technical operations, currently for EU hosting (Host Europe GmbH, Hürth).
(2) The Processor shall notify the Controller of any intended changes and grant the Controller the right to object. Equivalent data protection obligations shall be agreed with sub-processors.
§ 7 Assistance to the Controller
The Processor shall assist the Controller in fulfilling data subject rights (Art. 12–23 GDPR) and in relation to data protection impact assessments and notification obligations (Art. 32–36 GDPR).
§ 8 Third-country Transfers
Transfers to a third country shall only take place where an adequacy decision exists or appropriate safeguards (e.g. EU Standard Contractual Clauses) are in place.
§ 9 Deletion & Return
Upon completion of processing, the Processor shall – at the Controller's choice – delete or return all personal data, unless a statutory retention obligation exists.
§ 10 Evidence & Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance and shall enable audits within a reasonable scope.
