Appearance
Data Processing Agreement
Status: template. This DPA reflects how Adsidian actually processes data, but it has not yet completed legal-counsel review. To execute a signed copy (or to ask questions), contact [email protected].
This Data Processing Agreement ("DPA") forms part of the agreement between Adsidian ("Processor") and the customer identified in the applicable order or account ("Customer", "Controller") and governs Adsidian's processing of personal data on the Customer's behalf.
1. Roles and scope
Customer is the controller (GDPR) / business (CCPA) of Customer Data; Adsidian is the processor / service provider. "Customer Data" means personal data Adsidian processes on Customer's behalf, including CRM contact records synced from Customer's systems and website-visitor event data collected by Prism on Customer's (or Customer's clients') websites.
2. Processing instructions
Adsidian processes Customer Data only: (a) to provide the services described in the documentation (campaign management, tracking, attribution, CRM sync, AI-assisted operations); (b) per Customer's configuration (consent settings, retention windows, connected platforms); and (c) as required by law. Adsidian does not sell Customer Data and does not retain, use, or disclose it for any purpose other than providing the services (CCPA §1798.140 service-provider commitments).
3. Subprocessors
Customer authorizes the subprocessors listed at Subprocessors. Adsidian will update that page at least 15 days before adding a subprocessor that processes Customer Data; Customer may object on reasonable data-protection grounds. Adsidian remains responsible for its subprocessors' performance.
4. Confidentiality and security
Adsidian applies the technical and organizational measures described in the platform documentation, including: TLS in transit and encryption at rest; client-side SHA-256 hashing of visitor contact identifiers; row-level multi-tenant isolation; cryptographic verification of inbound CRM webhooks; secret masking; scheduled data-retention purges; and least-privilege access limited to personnel who need it. Personnel with access are bound by confidentiality obligations.
5. Data subject requests
Adsidian provides consent enforcement, deletion, and export tooling, and assists Customer in fulfilling access, deletion, correction, and opt-out requests within the GDPR one-month / CCPA 45-day windows. Requests received directly by Adsidian that concern Customer Data are forwarded to Customer.
6. Personal data breach
Adsidian will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably required for Customer's own notification obligations.
7. International transfers
Customer Data is processed in the United States. For personal data originating in the EEA, UK, or Switzerland, the parties rely on the EU Standard Contractual Clauses (module 2, controller-to-processor), incorporated by reference, and on subprocessors' SCCs and/or Data Privacy Framework participation.
8. Retention and deletion
Adsidian retains Customer Data per the configured retention schedule (defaults: Prism raw events 13 months; CRM-mirror records purged within 180 days of disappearing from the source CRM; webhook logs 90 days; AI assistant conversations 12 months). On termination, Adsidian deletes Customer Data within 30 days, except aggregate de-identified statistics and records required by law.
9. Audit
Adsidian will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits of its infrastructure providers, no more than once annually.