Data Processing Agreement
Effective: 14 August 2026 · Version 2026-08-14
This Data Processing Agreement (“DPA”) forms part of the Terms of Use between you (the “Customer”, acting as responsible party/controller) and Prebo Digital (Pty) Ltd (acting as operator/processor) where we process personal information on your behalf to provide the Adsynth platform (“Service”). It is designed to meet the requirements of POPIA (South Africa) and, where applicable, the GDPR.
1. Roles and scope
For Customer Data you submit or connect, you are the responsible party/controller and we are the operator/processor. We process personal information only on your documented instructions (including as set out in the Terms and this DPA), and for the purpose of providing and supporting the Service.
2. Our obligations
- Process personal information only on your instructions and as permitted by law.
- Ensure persons authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational security measures (encryption in transit, encryption of stored credentials at rest, access controls, rate limiting).
- Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal-information breach affecting your data.
- On termination, delete or return Customer Data, subject to retention required by law.
3. Subprocessors
You authorise us to engage the subprocessors below to help deliver the Service. Each is bound by data-protection terms consistent with this DPA. We will give notice of intended changes and you may object on reasonable data-protection grounds.
| Subprocessor | Purpose | Data | Location | Safeguards |
|---|---|---|---|---|
| Railway Corp | API, PostgreSQL database, and background-worker hosting | Account, campaign, chat, and application data | USA | DPA / contractual safeguards; encryption at rest and in transit |
| Vercel Inc | Web application hosting, CDN, and serverless delivery | Application requests, logs, and user sessions | USA / EU edge | DPA; SCCs; SOC 2 |
| Anthropic PBC | AI model inference and agent routing | Prompts, relevant account context, and generated output | USA | Commercial DPA; API data not used for model training under applicable terms |
| OpenAI, L.L.C. | AI model inference and fallback model routing | Prompts, relevant account context, and generated output | USA | DPA; SCCs; API data controls; API inputs and outputs excluded from model training under OpenAI's API data usage terms |
| PayPal Holdings, Inc. | Subscription billing and payment processing (default checkout) | Name, email, billing address, and transaction metadata | USA / global | DPA; SCCs; PCI DSS |
| Paddle.com Market Ltd | Merchant of record, subscription billing, and tax handling (optional) | Name, email, billing address, and transaction metadata | Ireland / USA | DPA; SCCs; PCI DSS |
| Stripe Inc | Legacy/fallback payment processing | Name, email, and payment metadata | USA | DPA; SCCs; PCI DSS |
| Google LLC (Workspace) | Business email, support, and internal collaboration | Support communications and business records | Global | Google Workspace DPA and contractual transfer safeguards |
Customer-authorised advertising and commerce platforms
The following services are connected only when a customer authorises the integration. For the customer’s platform data, the customer remains the responsible party/controller and the platform provider processes data under its own terms. Disconnecting an integration removes the local credential; some providers may also require revocation in the provider account.
| Platform | Purpose | Data | Location |
|---|---|---|---|
| Google LLC | Google Ads, GA4, Search Console, Merchant Center, and YouTube APIs | Data authorised through the customer’s Google OAuth scopes | USA / EU / global |
| Meta Platforms Inc | Meta Ads API | Authorised ad-account structure, audiences, and performance data | USA |
| Microsoft Corporation | Microsoft Advertising and LinkedIn Ads APIs | Authorised campaign, lead, and performance data | USA / EU |
| TikTok / ByteDance | TikTok Ads API | Authorised campaign and performance data | USA / Singapore |
| Reddit Inc | Reddit Ads API | Authorised campaign and performance data | USA |
| Shopify Inc | Shopify store integration | Authorised store, catalogue, and commerce metadata | Canada / USA / global |
| X Corp | X Ads API | Authorised campaign and performance data | USA |
| Apple Inc | Apple Search Ads API | Authorised campaign and performance data | USA / global |
| Canva Pty Ltd | Canva design integration | Authorised design metadata and exports | Australia / USA / global |
4. International transfers
Where personal information is transferred outside South Africa or the EEA/UK, we rely on lawful transfer mechanisms (such as standard contractual clauses) and the safeguards described in our Privacy Policy.
5. Audits and requests
We will make available information reasonably necessary to demonstrate compliance with this DPA. To request a counter-signed copy of this DPA, or to discuss audit arrangements, contact info@prebodigital.co.za.