DATA PROCESSING AGREEMENT
Last updated: August 11, 2026
01. PARTIES AND ROLES
This Data Processing Agreement ("DPA") forms part of the Terms of Service between ProtectPPC ("Processor") and the customer using the Service ("Controller"). It governs the processing of personal data carried out by the Processor on behalf of the Controller within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR").
The Controller determines the purposes and means of processing; the Processor processes personal data solely on the Controller's documented instructions as expressed through the configuration of the Service.
02. SUBJECT MATTER, DURATION, NATURE AND PURPOSE
Subject matter: Personal data of visitors to the Controller's websites collected by the ProtectPPC tracking script and pixel.
Categories of data: IP addresses, device and browser information (user agent, fingerprint), approximate geolocation derived from the IP address, and behavioral signals (time on page, scrolling, interaction flags).
Categories of data subjects: Visitors to the Controller's websites, in particular visitors arriving through paid advertising campaigns.
Nature and purpose: Automated analysis of clicks to detect and block fraudulent advertising traffic (bots, click farms, competitor clicks), including synchronization of blocked IP addresses to the Controller's advertising platform accounts.
Duration: For the term of the Controller's use of the Service, subject to the retention periods in Section 05.
03. PROCESSOR OBLIGATIONS
The Processor shall:
- process personal data only on documented instructions from the Controller, including with regard to transfers to third countries;
- ensure that persons authorised to process the data have committed themselves to confidentiality;
- implement appropriate technical and organisational measures (Section 06);
- respect the conditions for engaging sub-processors (Section 04);
- taking into account the nature of the processing, assist the Controller in responding to data subject requests (access, erasure, objection, and others under Chapter III GDPR);
- assist the Controller in ensuring compliance with Articles 32–36 GDPR, including notification of personal data breaches without undue delay;
- at the Controller's choice, delete or return all personal data after the end of the provision of services, unless EU or member state law requires storage;
- make available all information necessary to demonstrate compliance and allow for and contribute to audits conducted by the Controller or an auditor mandated by the Controller.
04. SUB-PROCESSORS
The Controller grants general authorisation to engage the following sub-processors. The Processor will inform the Controller of intended changes, giving the Controller the opportunity to object:
- IPQualityScore (USA): IP reputation lookups — transfers safeguarded by EU Standard Contractual Clauses
- MaxMind: IP geolocation via a locally hosted database (no personal data transmitted)
- Hosting provider: Infrastructure hosting of the Service and its databases
- Sentry: Error monitoring (may incidentally process request metadata)
- Google Ads API: Synchronization of excluded IP addresses to the Controller's own advertising account
05. RETENTION
- Click records (including IP addresses): deleted automatically after 90 days
- IP reputation records: deleted automatically 90 days after the address was last seen (unless an active exclusion still references it)
- IP exclusions: expire automatically after the Controller-configured TTL (default 14 days)
06. SECURITY MEASURES
- Encryption in transit (TLS) for all data collection and dashboard access
- Encryption at rest for OAuth tokens and credentials
- Tenant isolation — each customer's data is scoped to their projects
- Role-based access control and two-factor authentication for accounts
- Automated retention enforcement and daily encrypted backups
- Audit logging of account and configuration changes
07. CONTROLLER OBLIGATIONS
The Controller warrants that it has a valid legal basis for the processing of visitor data and that its own privacy policy discloses the use of a click-fraud detection service, including the collection of IP addresses and device information for fraud prevention purposes (legitimate interest, Art. 6(1)(f) GDPR).
08. CONTACT
Questions about this DPA and data protection requests: [email protected]