AdsynthLegal & TrustBack to Adsynth

Policies

Clear guidance on how Adsynth operates, protects data, and supports customers.

Privacy PolicyTerms of UseAcceptable UseCookie PolicyData ProcessingSecurityAI DisclosureRefundsLegal RequestsAffiliate & Partners

Need help?

Questions about a policy or your data are welcome.

Contact privacy
Data ProcessingAll policies
Privacy PolicyTerms of UseAcceptable UseCookie PolicyData ProcessingSecurityAI DisclosureRefundsLegal RequestsAffiliate & Partners

Data Processing Agreement

Effective: 14 August 2026 · Version 2026-08-14

This Data Processing Agreement (“DPA”) forms part of the Terms of Use between you (the “Customer”, acting as responsible party/controller) and Prebo Digital (Pty) Ltd (acting as operator/processor) where we process personal information on your behalf to provide the Adsynth platform (“Service”). It is designed to meet the requirements of POPIA (South Africa) and, where applicable, the GDPR.

1. Roles and scope

For Customer Data you submit or connect, you are the responsible party/controller and we are the operator/processor. We process personal information only on your documented instructions (including as set out in the Terms and this DPA), and for the purpose of providing and supporting the Service.

2. Our obligations

  • Process personal information only on your instructions and as permitted by law.
  • Ensure persons authorised to process are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (encryption in transit, encryption of stored credentials at rest, access controls, rate limiting).
  • Assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations.
  • Notify you without undue delay after becoming aware of a personal-information breach affecting your data.
  • On termination, delete or return Customer Data, subject to retention required by law.

3. Subprocessors

You authorise us to engage the subprocessors below to help deliver the Service. Each is bound by data-protection terms consistent with this DPA. We will give notice of intended changes and you may object on reasonable data-protection grounds.

SubprocessorPurposeDataLocationSafeguards
Railway CorpAPI, PostgreSQL database, and background-worker hostingAccount, campaign, chat, and application dataUSADPA / contractual safeguards; encryption at rest and in transit
Vercel IncWeb application hosting, CDN, and serverless deliveryApplication requests, logs, and user sessionsUSA / EU edgeDPA; SCCs; SOC 2
Anthropic PBCAI model inference and agent routingPrompts, relevant account context, and generated outputUSACommercial DPA; API data not used for model training under applicable terms
OpenAI, L.L.C.AI model inference and fallback model routingPrompts, relevant account context, and generated outputUSADPA; SCCs; API data controls; API inputs and outputs excluded from model training under OpenAI's API data usage terms
PayPal Holdings, Inc.Subscription billing and payment processing (default checkout)Name, email, billing address, and transaction metadataUSA / globalDPA; SCCs; PCI DSS
Paddle.com Market LtdMerchant of record, subscription billing, and tax handling (optional)Name, email, billing address, and transaction metadataIreland / USADPA; SCCs; PCI DSS
Stripe IncLegacy/fallback payment processingName, email, and payment metadataUSADPA; SCCs; PCI DSS
Google LLC (Workspace)Business email, support, and internal collaborationSupport communications and business recordsGlobalGoogle Workspace DPA and contractual transfer safeguards

Customer-authorised advertising and commerce platforms

The following services are connected only when a customer authorises the integration. For the customer’s platform data, the customer remains the responsible party/controller and the platform provider processes data under its own terms. Disconnecting an integration removes the local credential; some providers may also require revocation in the provider account.

PlatformPurposeDataLocation
Google LLCGoogle Ads, GA4, Search Console, Merchant Center, and YouTube APIsData authorised through the customer’s Google OAuth scopesUSA / EU / global
Meta Platforms IncMeta Ads APIAuthorised ad-account structure, audiences, and performance dataUSA
Microsoft CorporationMicrosoft Advertising and LinkedIn Ads APIsAuthorised campaign, lead, and performance dataUSA / EU
TikTok / ByteDanceTikTok Ads APIAuthorised campaign and performance dataUSA / Singapore
Reddit IncReddit Ads APIAuthorised campaign and performance dataUSA
Shopify IncShopify store integrationAuthorised store, catalogue, and commerce metadataCanada / USA / global
X CorpX Ads APIAuthorised campaign and performance dataUSA
Apple IncApple Search Ads APIAuthorised campaign and performance dataUSA / global
Canva Pty LtdCanva design integrationAuthorised design metadata and exportsAustralia / USA / global

4. International transfers

Where personal information is transferred outside South Africa or the EEA/UK, we rely on lawful transfer mechanisms (such as standard contractual clauses) and the safeguards described in our Privacy Policy.

5. Audits and requests

We will make available information reasonably necessary to demonstrate compliance with this DPA. To request a counter-signed copy of this DPA, or to discuss audit arrangements, contact info@prebodigital.co.za.

Adsynth

Prebo Digital (Pty) Ltd

Office Park Block A, Unit 17 · Van Hoof Street Willowbrook, Ruimsig · Johannesburg, 1709 · South Africa

info@adssynth.com087 292 2101