Data processing terms
The processing scope and contractual safeguards for customer personal data.
Last updated
When these terms apply
These terms are available for incorporation into a customer agreement between the identified Ads Lighthouse operator and the customer. This page alone does not establish an executed data processing agreement. Before processing customer personal data under this arrangement, the agreement must identify the parties and confirm the provider list, processing locations and applicable transfer safeguards.
Once incorporated, these terms govern personal data processed on the customer's behalf and take precedence over conflicting general service terms on that subject. The customer is the controller, or a processor authorised by its client; Ads Lighthouse acts as processor or subprocessor accordingly. Independently controlled account administration is described in the Privacy policy.
Processing details
The agreed scope must match the features the customer activates.
- Subject matter and purpose: provide configured advertising monitoring, project records, optional live Google reporting, alerts and related technical support.
- Nature: receiving, transmitting, storing, organising, retrieving and deleting project information; querying optional connected services on request.
- Duration: the service relationship and the agreed return or deletion period, including any protected copies lawfully retained afterwards.
- Data subjects: authorised business users, customer staff and clients, and individuals whose personal information appears in submitted project material or observed public advertisements.
- Data categories: business identifiers, contact information, domains, queries, URLs, observed ad content, timestamps, technical records, connection metadata and authorisation credentials. Live Google report responses are transmitted to answer requests rather than ingested into historical report storage.
- Excluded data: special-category data, criminal-offence records and children's information are not intended inputs and must not be submitted without a separate assessed arrangement.
Instructions and confidentiality
Ads Lighthouse will process customer personal data only on documented lawful instructions, including the customer agreement and authorised feature configuration, unless applicable law requires otherwise. It will inform the customer of a legally required departure unless prohibited, and raise an instruction it believes infringes applicable data protection law.
The customer is responsible for the lawful collection and disclosure of its inputs, necessary notices and permissions, and the authority to instruct processing for its clients. People authorised to handle customer personal data must be bound by appropriate confidentiality obligations.
Security measures
Ads Lighthouse will maintain technical and organisational measures appropriate to the processing risks. The current application includes password hashing, encrypted connector credentials, session expiry, server-side authorisation checks and administrative request protections. Deployment measures include encrypted transport and encrypted backup files.
The agreement's security annex should confirm access-management procedures, operational responsibilities, backup retention and recovery arrangements. These terms make no claim of an ISO certification, SOC report, guaranteed recovery time or absolute protection against an incident.
Subprocessors and transfers
The customer must authorise the applicable named subprocessors in the incorporated agreement or its provider schedule. Where general authorisation is used, Ads Lighthouse will notify the customer of intended additions or replacements and allow an opportunity to object before the change takes effect, using the notice and objection procedure agreed by the parties.
Each subprocessor must be subject to data protection obligations appropriate to its work and consistent with the incorporated agreement. Ads Lighthouse remains responsible for its subprocessor obligations. A restricted international transfer requires an applicable lawful mechanism and any necessary supplementary safeguards; these terms alone do not execute standard contractual clauses.
Requests, incidents and assistance
Taking account of the processing and information available, Ads Lighthouse will provide appropriate assistance with data subject requests, security obligations, impact assessments and supervisory consultations concerning the service. A request received directly about customer-controlled data will be referred to the customer unless the law requires a different response.
Ads Lighthouse will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data. Information may be supplied in stages as facts become available and will address the nature, likely consequences and response measures known at the time. The customer remains responsible for its own regulator and data subject notifications.
Information and audits
Ads Lighthouse will make available information reasonably needed to demonstrate its processor obligations and allow and contribute to audits required by applicable law. The parties may agree practical arrangements protecting confidentiality, other customers and service operation, without preventing a legally required audit or supervisory access.
Return and deletion
At the end of the processing services, Ads Lighthouse will return or delete customer personal data at the customer's choice, and delete existing copies unless applicable law requires retention. The customer agreement must specify the request process, export format, completion period and treatment of backups. Data lawfully retained remains protected and restricted to the permitted purpose.
Project deletion is not a substitute for agreeing account-wide return and deletion requirements. Contact us to arrange the applicable data processing agreement before relying on a particular retention period or regulatory requirement.