This Data Processing Addendum (“DPA”) forms part of the Master Advertising Services Agreement (“Agreement”) between:
BlockchainAds Labs LLC (“Blockchain-Ads”),
and
Advertiser (“Customer”).
This DPA governs the processing of Personal Data in connection with Customer’s use of Blockchain-Ads’ advertising technology, analytics, and related services.
Applicable Data Protection Laws: Means all privacy and data protection regulations that apply to the Parties, including GDPR, UK GDPR, CCPA/CPRA, LGPA, PDPA, and similar global standards.
Personal Data: Any information relating to an identifiable or identified individual, as defined under Applicable Laws.
For clarity, most data processed by Blockchain-Ads is pseudonymous and aggregated.
Pseudonymous Data: Data that cannot identify an individual without additional information.
Processing: Any operation performed on Personal Data, including collection, storage, transmission, pseudonymization, or deletion.
Services: The advertising, analytics, targeting, optimization, measurement, and related technology provided by Blockchain-Ads.
Subprocessor: Any third party appointed by Blockchain-Ads to process Personal Data on its behalf.
Customer as Controller
Customer acts as the Data Controller for Personal Data collected through its digital properties and shared with Blockchain-Ads.
Blockchain-Ads as Processor
Blockchain-Ads acts as a Data Processor, processing Personal Data solely for the purposes of providing the Services.
Processor Instructions
Blockchain-Ads will process Personal Data only:
(a) in accordance with Customer’s documented instructions;
(b) as necessary to perform the Services;
(c) as required by law.
Blockchain-Ads will promptly notify Customer if any instruction violates Applicable Laws.
Types of Data Processed
Purposes of Processing
No Sensitive Data
Blockchain-Ads does not process health, biometric, financial, or other sensitive categories.
Blockchain-Ads shall:
Confidentiality
Ensure personnel with access to Personal Data are bound by confidentiality obligations.
Security Controls
Implement technical and organizational measures appropriate for pseudonymous advertising data, including:
Assistance
Assist Customer with:
Compliance
Process data in accordance with Applicable Data Protection Laws.
Authorized Subprocessors
Customer grants general authorization for Blockchain-Ads to engage Subprocessors (e.g., cloud infrastructure, SSPs, analytics partners, fraud detection vendors).
Subprocessor Obligations
Blockchain-Ads ensures Subprocessors are bound by contractual commitments consistent with this DPA.
Subprocessor List
Blockchain-Ads will maintain an updated list available upon request.
Blockchain-Ads may transfer Personal Data globally as required to perform the Services.
Such transfers are safeguarded through:
Blockchain-Ads will assist Customer in fulfilling rights requests including:
Requests will be executed based on Customer’s written instructions.
In the event of a confirmed security incident involving Personal Data, Blockchain-Ads will:
(a) promptly notify Customer without undue delay;
(b) provide details as information becomes available;
(c) cooperate in remediation and regulatory notices.
Customer may request summaries of security certifications, SOC reports, penetration tests, and technical documentation.
If required by law, Customer may conduct an audit, subject to reasonable notice, confidentiality, and minimization of disruption.
Upon termination or expiration of the Agreement:
Blockchain-Ads qualifies as a Service Provider. It shall not:
Customer certifies that any Personal Information disclosed is necessary for permitted business purposes.
Liability under this DPA is governed by the limitation of liability clause in the Master Advertising Services Agreement.
If any term of this DPA conflicts with the MSA, this DPA prevails regarding data protection matters.
This DPA becomes effective upon signature of the MSA or the applicable Order Form.
Access is limited to qualified advertisers.