AdServeKit

Data Processing Addendum

This addendum applies whenever you use AdServeKit to process personal data you are responsible for — most obviously the visitors to a website you have installed the tag on, and the customers you invoice through it. It forms part of the Terms and takes precedence over them on the subject of data protection.

1. Who is who

For the data collected from your websites and the customers you bill, you are the controller and AdServeKit is the processor. You decide what to measure, on which sites, and what to record about the people you invoice. We carry that out and do nothing else with it.

For your own account — your email address, your sessions, the security log of your administrative actions — the operator of this deployment is the controller, because that data exists to run the service itself rather than at your instruction. The Privacy Policy covers it.

The operator’s legal identity, place of establishment and the law governing this addendum are those stated by whoever runs this deployment. AdServeKit is self-hosted software, so those details belong to the deployment rather than to the product; ask through the support page if they have not been given to you.

2. Subject matter, duration and scope

Subject matter: providing ad delivery, website measurement, SEO reporting, marketplace listing and invoicing, as described in the Terms.

Duration: for as long as your account exists, plus the retention periods in clause 7.

Categories of data subject: visitors to your websites; the people you invoice; the members you invite into your workspace.

Categories of personal data: for visitors, a browser-generated identifier and a derived country, page and referrer, device, browser and operating system family, and the events you choose to send — the source address is used to derive a country and a keyed hash and is then discarded rather than stored. For the people you invoice, the name, address, email address and tax identifiers you enter. For workspace members, their email address and display name.

No special categories. The platform is not designed to process data revealing health, beliefs, ethnicity, sexual orientation, or any other special category, and you must not use it to. There is no facility for uploading such data and no lawful basis on which we would process it.

3. Our instructions

We process this data only on your documented instructions, which are: the configuration you set in the dashboard, the tag you install, and the API calls you make. We do not sell it, do not use it to build profiles, do not use it to train models, and do not use one customer’s data to serve another.

Measurement identifiers are separated per website by construction, not by policy: an identifier is replaced on arrival with a hash keyed to a secret and mixed with the website it came from, so the same visitor produces a different value on every publisher’s site and the two cannot be joined.

If an instruction of yours appeared to require us to break applicable data protection law, we would tell you rather than carry it out.

4. Confidentiality and people

Access is limited to those who need it to run the service, under a duty of confidentiality. Administrative access is role-restricted and every administrative action is written to an append-only audit log that records who did what and when.

5. Security

The measures in place include: transport encryption; passwords stored only as Argon2id hashes; session tokens stored only as hashes and revocable individually or in bulk; OAuth refresh tokens encrypted at rest; source addresses reduced to a keyed hash rather than stored; tenant isolation enforced on every read and write rather than by convention; CSRF protection and origin checking on every state-changing request; advertiser-supplied creative code confined to an opaque-origin sandbox with a restrictive content security policy; and rate limiting and admission control on the paths that cost real resources.

Because this is self-hosted software, the operator is responsible for the infrastructure it runs on — patching, backups, network boundaries and physical security. What that operator has done is a fair question to ask them before you rely on it.

6. Sub-processors

A deployment necessarily involves a small number of third parties, named in the Privacy Policy: the network provider in front of the service, the transactional email provider, and the identity providers you choose to connect. We will tell you before adding another in a way that affects your data, and you may object.

Which specific providers a deployment uses is the operator’s choice, so the current list is the one on the Privacy Policy of the deployment you are actually using, not a list held by the software.

7. Deletion and return

You can export your reporting data at any time from the dashboard. Deleting your account removes your websites, campaigns, creatives, placements, measurement configuration, connections, audits, marketplace properties and listings, and the files you uploaded — the bytes as well as the records that named them.

Three things are deliberately kept, and you should know which. Raw event data ages out on a retention period the operator configures, while the aggregated daily figures behind your reports are kept longer, so a report does not vanish when the events it was built from expire. Finalised invoices and their payment records stay with the workspace, because an issuer generally has a statutory duty to keep them. And the security audit log is append-only by design: it is what makes a compromise investigable, which is only true if it cannot be edited on request.

8. Helping you meet your own obligations

Requests from individuals. Most of what a visitor might ask about is not identifiable to them by the time we hold it: the identifier is replaced with a per-site keyed hash and the source address is discarded, so we usually cannot single out one person’s rows on request — which is a limit worth knowing rather than a promise. For the customers you invoice and the members of your workspace, the data is yours to read, correct and remove from the dashboard directly.

Breach notification. If we become aware of a personal data breach affecting your data we will tell you without undue delay, with what we know: what happened, which categories and roughly how many records are involved, the likely consequences, and what is being done. Notifying your own regulator and the people affected remains your decision to make.

Assessments and audits. We will give you the information you reasonably need for a data protection impact assessment, and on reasonable notice will answer an audit — in the first instance through documentation, because this is self-hosted software whose operator, not its author, holds the infrastructure being asked about.

9. International transfers

Where your data is processed depends on where the operator runs this deployment and which providers they have chosen. If that involves a transfer out of your jurisdiction, the lawful basis for it — standard contractual clauses or an adequacy decision — is the operator’s to put in place and to show you. Ask them where the service is hosted before assuming.

10. Contact

Data protection questions, requests and breach notifications go to the address on the support page. Please say that the request concerns data protection so it is routed accordingly.