Skip to main content
Enterprise Data Processing Agreement

Data Processing Agreement

Our Data Processing Agreement (DPA) is designed to align with GDPR Article 28 for enterprise customers and provides transparent documentation of our data handling practices.

GDPR Article 28 Compliance
Overview

Enterprise-grade data protection

Our Data Processing Agreement provides the legal framework required for GDPR compliance when Adverizeo acts as a data processor for your organization.

GDPR Article 28 Aligned

Designed to meet EU requirements for data processor relationships

EU Data Residency

Personal data hosted within the European Union (Netherlands, via Railway)

Data Encryption

Data encrypted in transit and at rest

Audit Rights

Full audit and inspection rights for data controllers
Roles

Understanding data roles

Clear definition of responsibilities between data controllers and data processors under GDPR.

You (Data Controller)

As the data controller, you determine the purposes and means of processing personal data and remain responsible for GDPR compliance.

Your responsibilities

  • Determine lawful basis for processing
  • Obtain necessary consents from data subjects
  • Handle data subject rights requests
  • Conduct Data Protection Impact Assessments
  • Maintain records of processing activities

Adverizeo (Data Processor)

As the data processor, Adverizeo processes personal data on your behalf according to your documented instructions and this DPA.

Our responsibilities

  • Process data only as instructed by you
  • Implement appropriate security measures
  • Assist with data subject rights requests
  • Report data breaches within 72 hours
  • Delete or return data upon contract termination
Purposes

Processing purposes & data types

Detailed breakdown of how and why we process personal data on your behalf.

Security

Technical & organizational measures

Comprehensive security safeguards to protect personal data as required by GDPR Article 32.

Technical Safeguards

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • End-to-end encrypted API communications
  • Automated security monitoring and alerts

Organizational Safeguards

  • Role-based access controls (RBAC)
  • Principle of least privilege access
  • Regular security training for all staff
  • Incident response procedures and protocols

Physical Safeguards

  • Infrastructure hosted within the European Union (EU West region, via Railway)
  • Physical and environmental security managed by our hosting provider
  • Automated database backups

Compliance Safeguards

  • GDPR-focused development and review practices
  • Encrypted data storage and transmission
  • Access limited to authorized team members
Sub-processors

Sub-processors & third parties

All sub-processors are GDPR compliant with signed Data Processing Agreements.

Category

Payment Processing

Sub-processor

Stripe, Inc.

Location

Ireland (EU)

Purpose

Payment processing, PCI-DSS compliant

Category

Cloud Infrastructure

Sub-processor

Railway Corporation

Location

Netherlands (EU)

Purpose

Hosting and infrastructure services

Category

File Storage

Sub-processor

Amazon Web Services (AWS)

Location

EU (Frankfurt/Ireland)

Purpose

User-uploaded file storage (S3)

Category

Email Communications

Sub-processor

Mailgun (Sinch)

Location

EU

Purpose

Transactional email delivery

Category

AI Processing

Sub-processor

OpenAI OpCo, LLC

Location

United States (Standard Contractual Clauses)

Purpose

AI-powered content generation and natural language processing

Category

AI Processing

Sub-processor

Anthropic, PBC

Location

United States (Standard Contractual Clauses)

Purpose

AI-powered content generation and natural language processing

Sub-processor Changes

We will notify you at least 30 days in advance of any changes to our sub-processors. You have the right to object to new sub-processors and terminate the agreement if concerns cannot be resolved.

Get started

Execute your DPA

Ready to formalize our data processing relationship? Download the DPA or contact our team for enterprise agreements.

Standard DPA

Request our standard Data Processing Agreement for use with your Adverizeo subscription.

Request the Standard DPA

Sent by email; no signature required for standard terms.

Enterprise DPA

Custom Data Processing Agreement with enterprise-specific terms, liability coverage, and dedicated support.

Request Enterprise DPA

Custom terms, enhanced SLAs, and dedicated legal support included.

Legal & Compliance Team

Questions about our DPA or need custom contract terms? Our legal team is ready to assist.

legal@adverizeo.com

Typical response within 2 business days for enterprise inquiries.