Last updated 29 September 2026
Data Processing Agreement
This DPA applies automatically to every Customer that accepts the Terms. If you need a countersigned copy, email eczenn@gmail.com.
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Karina 2710 EOOD (“Processor”) and the Customer (“Controller”). It applies to personal data in Customer Data that we process on the Customer’s behalf, and meets the requirements of Article 28 of the GDPR and the UK GDPR.
Terms such as “personal data”, “processing” and “personal data breach” have the meaning the GDPR gives them.
2. Details of the processing
| Item | Description |
|---|---|
| Subject matter | Providing the Roaswise service under the Terms |
| Duration | The term of the Customer's subscription, plus the deletion periods in section 9 |
| Nature and purpose | Storing, syncing and analysing advertising data; running the AI Agent; generating creative assets; applying changes to the Customer's Meta ad accounts; support |
| Data subjects | The Customer's staff and members; the Customer's contacts and invitees; people who appear in content the Customer uploads or connects |
| Categories of data | Names, email addresses, roles and activity of members; Meta user IDs and access tokens; ad account and campaign data; images, text and other content the Customer provides |
| Special categories | None intended. The Customer will not upload special category data (GDPR Art. 9) unless it is strictly needed and lawful. |
3. Processing on instructions
We process personal data only on the Customer’s documented instructions, which are the Terms, this DPA and the Customer’s use and configuration of the service, unless the law requires otherwise. In that case we will tell the Customer first, unless the law forbids it. We will tell the Customer if we believe an instruction breaks data protection law.
4. Confidentiality
Everyone we authorise to process the personal data is bound by confidentiality obligations.
5. Security
We maintain technical and organisational measures appropriate to the risk (GDPR Art. 32), including:
- encryption in transit (TLS) and encryption of access tokens at rest, with the key kept apart from backups;
- strict separation of each brand’s data, enforced on every request;
- role-based access control, and a full audit log of changes;
- hashed passwords and protected sessions (HttpOnly cookies, CSRF protection);
- encrypted nightly backups with a tested restore procedure;
- access for our own staff limited to what is needed to run and support the service.
6. Subprocessors
The Customer authorises us to use the subprocessors on our Subprocessors page. We bind each by written contract to data protection obligations at least as protective as this DPA, and remain responsible for them.
We will announce a new or replacement subprocessor on that page, and by email to Owners, at least 30 days before it starts processing. The Customer may object on reasonable data protection grounds within that period; if we cannot address the objection, the Customer may terminate the affected service before the change takes effect.
7. International transfers
Where we or a subprocessor transfer personal data outside the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is covered by the EU-U.S. Data Privacy Framework or by the European Commission’s Standard Contractual Clauses (Module 2 or 3, with the UK Addendum where relevant), which are incorporated here by reference.
8. Assistance
Taking into account the nature of the processing, we will help the Customer respond to requests from data subjects, including through the export and deletion features in the service, and with security, data protection impact assessments and consultations with authorities. We will pass on to the Customer any request we receive directly from its data subjects.
9. Personal data breaches
We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. We will give the information the Customer reasonably needs to meet its own notification duties, and take steps to contain the breach.
10. Return and deletion
An Owner can export a brand’s data at any time. When a brand is deleted, or the subscription ends, its data is erased after a 30-day restore period. Copies in encrypted backups are erased as the backups expire, within 60 days. We keep data longer only where the law requires it.
11. Information and audits
We will make available the information needed to demonstrate compliance with this DPA. Where that is not enough, the Customer may carry out an audit, at most once a year, on 30 days’ notice, during business hours, at its own cost, and under confidentiality.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Terms. If this DPA conflicts with the Terms, this DPA prevails; if the Standard Contractual Clauses apply and conflict with this DPA, they prevail. Questions: eczenn@gmail.com.