Legal & trust
Data Processing Addendum
The terms that govern FrescoAds processing Customer Personal Data on behalf of enterprise customers.
How and when this DPA applies
This Data Processing Addendum forms part of the agreement between the customer and FrescoAds. It applies only where FrescoAds processes Customer Personal Data on the customer's behalf as a processor, service provider or comparable role under applicable data-protection law.
FrescoAds acts as controller for its own account administration, business communications, security and website operations as described in the Privacy Policy. Those controller activities are outside this DPA.
Roles and definitions
The customer determines the purpose and means of processing Customer Personal Data and acts as controller, or as processor for another controller. FrescoAds acts as processor to the customer. Customer Personal Data means personal data contained in Customer Content or Connected Content that FrescoAds processes to provide the Services.
- Applicable Data Protection Law includes privacy and data-protection law directly applicable to the processing.
- Data Subject means the identified or identifiable person to whom Customer Personal Data relates.
- Personal Data Breach means a confirmed breach of FrescoAds security affecting Customer Personal Data.
- Sub-processor means a third party appointed by FrescoAds to process Customer Personal Data.
Documented instructions
FrescoAds will process Customer Personal Data only to provide, secure and support the Services according to the agreement, the customer's workspace configuration and other documented instructions, unless applicable law requires otherwise. If FrescoAds reasonably believes an instruction violates applicable law, it will notify the customer where permitted.
Confidentiality and personnel
FrescoAds limits access to personnel who require it to perform their responsibilities. Personnel with access to Customer Personal Data are subject to confidentiality obligations and receive security and privacy guidance appropriate to their role.
Security measures
FrescoAds maintains technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Measures are reviewed according to risk and may be updated without materially reducing overall protection.
- Role-based access, least privilege and administrative access review.
- Encryption in transit and encryption at rest where supported by the applicable service.
- Logical separation of customer workspaces and controlled production environments.
- Security logging, monitoring, vulnerability handling and incident response.
- Business continuity, backup management and recovery procedures.
- Vendor diligence and contractual data-protection obligations.
Data-subject requests
Taking into account the nature of processing, FrescoAds will provide reasonable and technically feasible assistance for the customer to respond to requests from Data Subjects. If FrescoAds receives a request relating to Customer Personal Data, it will direct the person to the relevant customer unless law requires a different response.
Security incidents
FrescoAds will notify the customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data. The notice will include available information reasonably required for the customer to meet applicable notification duties. Notification does not constitute an admission of fault or liability.
Sub-processing
The customer provides general authorization for FrescoAds to use the sub-processors identified for the customer’s deployment. FrescoAds will impose data-protection obligations on each sub-processor appropriate to the service and remain responsible for the sub-processor’s performance to the extent required by this DPA.
- FrescoAds will notify the customer of material additions or replacements through the notice process in the applicable agreement.
- The customer may object on reasonable data-protection grounds within the contractual notice period.
- If no reasonable alternative is available, the parties will follow the remedy stated in the applicable agreement.
International transfers
Where processing involves a restricted international transfer, the parties will use a valid transfer mechanism required by applicable law. For transfers subject to the EU GDPR, the applicable modules of the European Commission Standard Contractual Clauses are incorporated by reference. UK-restricted transfers use the UK Addendum where required. The applicable Order Form or transfer notice identifies the relevant exporter, importer and processing details.
Assistance and compliance evidence
FrescoAds will provide information reasonably necessary to demonstrate compliance with this DPA and assist with data-protection impact assessments and regulator consultations where the processing requires it. Independent reports or certifications, when available and relevant, may be provided under confidentiality as the primary compliance evidence.
Audit process
If available compliance information is not sufficient, the customer may request an audit relating to Customer Personal Data no more than once per year, unless required by law or following a confirmed incident. Audits require reasonable advance notice, an agreed scope, confidentiality, minimal disruption and use of an independent qualified auditor. The customer is responsible for its audit costs unless the audit identifies a material breach by FrescoAds.
Return and deletion
At termination, FrescoAds will delete or return Customer Personal Data according to the customer's documented choice and the agreement. Limited copies may remain in protected backups until the normal deletion cycle completes, or where law requires retention. Retained data remains protected and is not used for another purpose.
Customer responsibilities
The customer is responsible for the lawfulness of Customer Personal Data and its instructions, providing required notices, obtaining required permissions, configuring authorized users, approving model providers and determining whether the Services are appropriate for the data submitted.
- Do not submit payment-card data, government identifiers, medical data, biometric data, account passwords or data about children unless a written agreement expressly permits it.
- Maintain appropriate backups of source materials and exported campaign assets.
- Review workspace people, connected applications and provider settings regularly.
Annex 1 · Processing details
Annex 2 · Contact and precedence
Privacy and DPA notices may be sent through the Contact page. If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls. If applicable Standard Contractual Clauses conflict with this DPA, those clauses control for the relevant transfer.
Next step
Need an enterprise review?
Talk with FrescoAds about privacy, procurement, security and governance requirements.
Contact FrescoAds