Skip to main contentSkip to navigationSkip to search

Data Processing Agreement

Article 28 GDPR processor terms — plain English summary first, then the binding clauses.

Last updated: May 3, 2026

When you sign up as an advertiser or partner, you (the “Controller”) instruct RateAds (“Processor”) to process personal data on your behalf. This DPA sets the rules. By clicking “I agree” in the advertiser flow you bind your organization to this DPA.

Plain-English summary

We process personal data only on your written instructions (i.e. your campaign settings).

We use sub-processors. The list is on our Privacy Policy. We give you 30 days' notice before adding a new one.

We tell you about a data breach affecting your data within 72 hours of discovery.

When you stop using the service, we delete or return all data within 30 days. Backups are purged within 90 days.

You may audit our security practices once per year on reasonable notice.

1. Subject matter and scope

Subject. We process data for you so we can run the RateAds platform.

Duration. While your advertiser account is active, plus the return or deletion period in § 8.

Nature and purpose. We host your creatives, serve ads, count clicks, build reports, and answer support questions.

Data subjects. People who use RateAds and touch your campaigns.

Categories of data. Random session IDs, click counts, country-level location, and grouped demographics. We do not process special-category data under this DPA.

2. Processor obligations

RateAds will:

  • Process data only on the Controller's written instructions. That includes transfers to other countries.
  • Make sure our staff are bound to keep your data confidential.
  • Use the security measures GDPR Art. 32 calls for. We encrypt data on the wire and at rest. We log access. We review controls each year.
  • Help you answer data-subject requests under GDPR Arts. 12–22.
  • Help you with DPIAs under Art. 35 and with prior consultations under Art. 36, where we have the info.
  • Delete or return all data when our contract ends, unless law tells us to keep it.

3. Sub-processors

The Controller authorises RateAds to engage the sub-processors listed at /privacy#subprocessors. RateAds will inform the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object for good cause; if RateAds cannot accommodate the objection, the Controller may terminate the affected service.

RateAds remains liable for the acts and omissions of its sub-processors as if they were its own.

4. International transfers

When data of EU, UK, or Swiss users moves outside those areas, we use the EU Standard Contractual Clauses (Module 2 or 3, 2021/914) and the UK addendum.

We do a Transfer Impact Assessment when the law says to.

5. Personal-data breach notification

RateAds will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach. The notification will include, where available:

  • The nature of the breach and approximate number of records.
  • The likely consequences.
  • The measures taken or proposed to address it.
  • Contact details of our security team.

6. Audit

The Controller may, on reasonable notice (at least 14 days) and at its own cost, conduct one audit per calendar year. The audit may take the form of an independent third-party report (SOC 2 / ISO 27001) where one is available.

7. Assistance with data-subject rights

RateAds will, to the extent legally permitted, promptly forward to the Controller any data-subject request RateAds receives regarding the Controller's data, and assist the Controller in answering it within the statutory time limit.

8. Return / deletion on termination

Within 30 days of termination, RateAds will, at the Controller's choice, delete or return all personal data processed on the Controller's behalf. Backups will be purged within 90 days.

9. Contact

Privacy Team

Email: privacy@rateads.us

Address: 363 Tipperary Loop, Delaware, Ohio 43015, USA

Effective version: 2026-05-03.