Skip to content

Legal

Data Processing Agreement

Last updated: 28 August 2026

This agreement covers how Ad Titan processes personal data on your behalf as your data processor: our obligations, the security measures we apply, the sub-processors we use, and how international transfers are handled. It's built to support your GDPR, UK GDPR, and CCPA compliance.

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of, and is subject to, the agreement between you ("Customer", "Controller") and MAK Technologies Inc, operator of Ad Titan ("Ad Titan", "Processor", "we"), governing your use of the Ad Titan service (the "Terms"). It applies whenever we process Personal Data on your behalf in providing the service.

For the Personal Data processed under the service, you are the Controller (or a processor acting for your own controllers), and we are your Processor. We process Personal Data only to provide the service, and only on your documented instructions, which you give through how you configure and use the product and through the Terms.

Where terms are capitalised but not defined here, they carry the meaning given in the Terms or in Applicable Data Protection Laws (including the EU GDPR, the UK GDPR, and the California Consumer Privacy Act as amended).

2. Our obligations as processor

As your Processor, we will:

  • Process Personal Data only on your documented instructions, including for international transfers, unless the law requires us to act (and if it does, we will tell you, unless the law forbids it).
  • Make sure the people we authorise to process Personal Data are bound by confidentiality.
  • Put in place, and keep, appropriate technical and organisational security measures (see Annex 3).
  • Follow the conditions below before we bring on a sub-processor.
  • Help you respond to data-subject requests and meet your own obligations around security, breach notification, and data-protection impact assessments, taking into account the nature of the processing.
  • Tell you without undue delay once we become aware of a Personal Data breach affecting your data, with the information you reasonably need to meet your own obligations.
  • At your choice, delete or return the Personal Data at the end of the service and delete any copies, unless the law requires us to keep it.
  • Give you the information reasonably needed to show we are meeting this DPA, and allow for and contribute to audits, as described below.

3. Sub-processors

You give us general authorisation to use sub-processors to help deliver the service. Our current sub-processors, and what each one does, are listed on our Sub-processors page. We hold each of them to data-protection obligations that are at least as protective as those in this DPA, and we stay responsible for their work.

We will give you reasonable notice before we add or replace a sub-processor, so you have a chance to object on reasonable data-protection grounds. If you object and we can't reasonably work around it, you can stop using the affected feature or end the agreement as described in the Terms.

4. International transfers

We may process Personal Data in countries other than where you are, including the United States. Where a transfer falls under Applicable Data Protection Laws, we use a lawful transfer mechanism such as the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), or another approved safeguard, along with any extra measures required.

5. Data-subject rights

The service gives you tools to access, correct, export, and delete much of the data in your workspace. Where you can't handle a data-subject request yourself, we will help you, taking into account the nature of the processing and the information available to us.

6. Audits

With reasonable prior written notice, and no more than once a year (unless a supervisory authority requires it, or there has been a breach), we will give you the information needed to show we are meeting this DPA and cooperate with audits, subject to confidentiality and to not compromising other customers' security. Send requests to support@getadtitan.com.

7. California (CCPA)

Where the CCPA applies, we act as a "service provider". We don't sell or share Personal Data, and we don't keep, use, or disclose it for anything other than performing the service (or as the CCPA otherwise permits). We understand these restrictions and will follow them.

8. Liability and term

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA takes effect when you accept the Terms and lasts for as long as we process Personal Data on your behalf.

9. Annex 1: Details of the processing

  • Subject matter: our provision of the Ad Titan paid-media management service.
  • Duration: the term of the Terms, until the data is deleted or returned.
  • Nature and purpose: monitoring, analysing, and reporting on your connected advertising accounts, and, with your approval, optimising them.
  • Categories of data: account and contact details of your users; advertising-account data pulled from your Google Ads and Meta connections (campaign structure, budgets, and performance metrics), which may incidentally contain Personal Data such as search terms; and any content you enter into the product.
  • Categories of data subjects: your personnel and authorised users, and, incidentally, individuals whose data appears within your advertising accounts.

10. Annex 2: Sub-processors

The current list of sub-processors, with the purpose and location of each, lives on our Sub-processors page and forms part of this DPA.

11. Annex 3: Technical and organisational measures

We keep security measures appropriate to the risk, including:

  • Encryption of data in transit (TLS), and encryption at rest where our infrastructure supports it.
  • Official OAuth for every ad-platform connection, so we never see or store your ad-platform passwords, and the service stays read-only until you approve a change.
  • Role-based, least-privilege access to our systems, limited to the people who need it.
  • Tenant isolation, so each customer's data stays scoped to their own workspace.
  • Network and application security controls, logging, and monitoring for failures and anomalies.
  • Regular backups and a documented way to restore service.
  • Confidentiality obligations for staff, and a process for responding to security incidents.

12. Contact

Questions about this DPA, or want a signed copy? Email support@getadtitan.com. You can also read our Privacy Policy and Terms of Service.