AskMyAds legal
Data processing agreement
This public template sets out the GDPR processor terms AskMyAds offers when a business customer uses the service to process personal data on its behalf.
Effective 29 July 2026
1. Template status and parties
This page is a contract template, not a signed agreement merely because it is viewed. The customer identified in an accepted order or execution copy is the “Customer”; OrcDev (Uros Miric), trading as AskMyAds, is “AskMyAds.” To execute this DPA, send the Customer’s legal name, address, registration jurisdiction and privacy contact to AskMyAds privacy support. The completed copy will identify the parties, effective date and current subprocessor schedule.
Once accepted in writing by both parties, this DPA forms part of the agreement governing the Customer’s use of AskMyAds. “Personal Data,” “Controller,” “Processor,” “Data Subject,” “Processing,” and “Supervisory Authority” have the meanings given by the GDPR.
2. Roles, scope, and instructions
For Customer Personal Data submitted to or collected by AskMyAds through the Customer’s connected Google Ads account and workspace, the Customer is the Controller and AskMyAds is the Processor. AskMyAds processes that data only to provide, secure, support and maintain the contracted service, and on the Customer’s documented instructions in the service agreement, configured features and support requests.
AskMyAds may process account, Google identity sign-in and profile, billing, security, fraud-prevention and legal-compliance data as an independent Controller where it determines the purposes and means of that processing. That processing is governed by the privacy policy, not by the processor terms in this DPA.
The Customer is responsible for its instructions, notices, lawful basis, and authority to connect each Google Ads account. AskMyAds will promptly tell the Customer if, in its opinion, an instruction infringes applicable data-protection law, unless law prohibits that notice. AskMyAds will not sell Customer Personal Data or use it for general advertising or general-purpose model training.
3. AskMyAds’ duties
- Process Customer Personal Data only on documented instructions, including for transfers, unless applicable law requires otherwise; where permitted, AskMyAds will notify the Customer before that legally required processing.
- Ensure people authorized to process Customer Personal Data are bound by confidentiality and receive access only as necessary.
- Maintain appropriate technical and organizational measures proportionate to the risk, as summarized in Annex B.
- Taking account of the nature of processing, reasonably assist the Customer with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultations.
- Notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and provide available information reasonably needed for the Customer’s response.
- Make information necessary to demonstrate compliance with these processor duties available as described in section 6.
4. Subprocessors and transfers
The Customer gives general written authorization for the subprocessors identified in the completed Annex C. Before execution, AskMyAds will provide the current legal entity, processing function and processing location for each subprocessor. AskMyAds will impose materially equivalent data-protection duties on each subprocessor and remains responsible for its subprocessor’s performance of those duties.
AskMyAds will give reasonable advance notice of an intended subprocessor addition or replacement. The Customer may object on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected feature.
Where a restricted international transfer requires a safeguard, AskMyAds will use a lawful transfer mechanism, including the applicable European Commission standard contractual clauses where appropriate, and supplementary measures warranted by the transfer risk. The Commission publishes the official standard contractual clause materials.
5. Return and deletion
During the agreement, the Customer may request a structured export where the service supports it. On termination or a verified request, AskMyAds will, at the Customer’s choice, return or delete Customer Personal Data and delete existing copies unless applicable law requires limited retention. Backup remnants remain isolated from ordinary use until secure rotation and are subject to the deletion instruction if restored.
Product-specific timing, Google authorization revocation and verified request steps are described on the data deletion page.
6. Compliance information and audits
AskMyAds will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. AskMyAds may satisfy a request first with current policies, security summaries, certifications or an independent audit report where those materials address the requested control.
If that information is not sufficient, the Customer or an independent auditor bound by confidentiality may conduct a proportionate audit or inspection of the relevant processing. Except after a personal-data breach or where a Supervisory Authority requires otherwise, the Customer will give reasonable advance notice, avoid disrupting the service, and conduct no more than one audit in a 12-month period. An audit must not expose another customer’s data, security secrets, or systems outside the processing covered by this DPA.
Each party bears its own ordinary audit costs. If an audit identifies material non-compliance by AskMyAds, AskMyAds will promptly remediate it and reimburse the Customer’s reasonable external audit cost. These limits do not restrict the Customer’s rights or AskMyAds’ obligations where applicable data-protection law requires broader access.
Annex A - Processing details
- Subject and duration: operation of the Customer’s AskMyAds workspace for the agreement’s term, plus the limited deletion and retention period described above.
- Nature and purpose: read-only Google Ads connection and account discovery; collection of authorized advertising configuration and performance data; deterministic scans, findings and reports; support; and Customer-approved service features.
- Data subjects: Customer personnel and users; advertising audiences, searchers, leads or customers whose information may appear incidentally in authorized Google Ads data; and people represented in content the Customer submits.
- Data categories: workspace and user identifiers; Google Ads account, campaign, targeting, creative, conversion and performance data; search terms; support content; and derived findings and reports. Google Ads OAuth credentials are processed only to provide the authorized Ads connection and are subject to the security controls below.
- Sensitive data: the service is not designed for special-category or criminal-offence data. The Customer must not intentionally submit it. Search terms or advertising content may incidentally contain personal data, so the Customer should minimize its collection and access.
Annex B - Security measures
- Encrypted transport and authenticated, per-record encryption of stored Google Ads OAuth refresh tokens, with key material separated from the database.
- Workspace-scoped authorization and data queries, least-privilege service access, session controls and abuse-rate limiting.
- No persistence of Google identity access, ID or refresh tokens, or short-lived Google Ads access tokens, and no rendering of OAuth credentials to the browser, product analytics or AI inference providers.
- AI narrative requests use Vercel AI Gateway controls that restrict routing to inference providers covered for zero data retention and no prompt training; an ineligible route is not used.
- Data minimization, bounded payloads, retention controls, revocable public report links, dependency management and incident-response procedures.
- Restricted production access, confidentiality obligations, encrypted backup isolation and secure deletion through rotation.
Annex C - Execution schedule
The signed copy will list the Customer’s identity and contact, AskMyAds’ contact, the competent Supervisory Authority where applicable, and each current subprocessor’s legal name, location and task. AskMyAds’ current service categories include application hosting and AI request routing through Vercel AI Gateway, managed database, transactional email and - only when the relevant feature is enabled - limited processing by the inference provider selected for the configured Claude model.
This template is based on the processor duties in Article 28 GDPR. It does not replace the parties’ assessment of their roles, transfer rules or sector-specific requirements. Contact support@askmyads.ai for the completed execution schedule or a requested amendment.