Legal
Data Processing Addendum
Draft — pending legal review
1. Scope and roles
This Addendum applies where either party processes personal data on the other's behalf under our services agreement. For enquiry and partner records we act as controller. For data in a bid request we act as an independent controller or as a processor, depending on the role recorded in the signed agreement. Where we act as processor, the partner is the controller and this Addendum governs our processing.
2. Instructions and purpose limitation
We process personal data only to provide the services, to bill and reconcile them, to prevent fraud and invalid traffic, and to meet a legal obligation. We do not sell partner data, build audience segments of our own from it, or use it to train models. If an instruction appears to breach applicable data protection law we tell the partner rather than carry it out.
3. Security measures
We apply the technical and organisational measures described in our data protection measures page, including named individual accounts, multi-factor authentication on production access, least-privilege data access, encryption of data in transit, encrypted devices and logged administrative actions.
4. Sub-processors
The partner authorises the sub-processors listed on our sub-processors page. We impose equivalent obligations on each, remain liable for their performance, and notify partners in writing before one is added or replaced so an objection can be raised.
5. Data subject requests and assistance
We assist the partner in answering access, correction, erasure, restriction, portability and objection requests, and forward any request we receive directly rather than answering it ourselves where the partner is the controller. We assist with data protection impact assessments and with regulator enquiries relating to the processing under this Addendum.
6. Personal data breach
We notify the partner without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting its data, with what we know at the time, the categories and approximate volume affected, the steps taken and the contact for follow-up. We update the partner as the investigation develops.
7. International transfers
For transfers of personal data out of the EEA, the European Commission's Standard Contractual Clauses (Decision 2021/914) are incorporated into this Addendum, with Module Two applying controller to processor and Module Three processor to processor. For the UK, the ICO International Data Transfer Addendum applies to those Clauses. For Switzerland, the Clauses apply with the FDPIC amendments. A transfer risk assessment is available on request.
8. Audit
On reasonable notice, and no more than once a year unless a regulator or a breach requires otherwise, we answer a written security questionnaire and provide the records needed to demonstrate compliance with this Addendum. We claim no external certification or audit report; where a partner requires one we say so plainly.
9. Return and deletion
On termination we delete or return personal data processed on the partner's behalf, and delete existing copies unless a law requires us to keep them. Deletion is confirmed in writing on request.
10. Schedule 1 — details of processing
Subject matter: the provision of programmatic supply and demand connection services over OpenRTB.
Duration: the term of the services agreement, plus the retention periods stated in our privacy policy.
Nature and purpose: receiving, enriching, filtering, routing and logging bid requests and responses; reporting, billing reconciliation, fraud and ad quality controls; partner correspondence and support.
Categories of data subject: end users of a publisher's app or website, and business contacts at partner companies.
Categories of personal data:
- Pseudonymous identifiers: mobile advertising IDs, publisher-supplied IDs and session identifiers.
- Device and connection data: IP address, user agent, device model, OS, carrier.
- Approximate location derived from IP or supplied at reduced precision.
- Context: app bundle ID or page domain, content category, placement and format.
- Consent and privacy signals: TCF strings, GPP strings, US Privacy strings, Global Privacy Control and COPPA flags.
- Auction metadata: timestamps, bid prices, win and loss notices, and creative IDs.
- Business contact data: name, business email, company, country, role and message content.
Special category data: none is requested. We do not knowingly process special category data or children's data, and we honour COPPA and equivalent signals.
Frequency: continuous, for the duration of live traffic.
11. Signing this Addendum
To countersign this Addendum, or to have us review your own, write to contact@omniad.ai. We sign a partner's DPA where its terms match how we actually operate.
