1. Parties and precedence
The client is the controller and Astro Digital SL is the processor for data processed to provide Far on the client’s behalf. This DPA forms part of the service agreement. In matters of data protection, it takes precedence over conflicting general terms.
2. Subject matter, duration, nature and purpose
The processing arrangement lasts for the duration of the service and any subsequent deletion or return of data. It includes receiving data from Google Ads, validating, organising, storing, querying, aggregating, analysing and displaying it, generating reports and deleting it. Its purpose is to provide the client with reporting, performance checks, budget pacing, queries and decision records.
3. Documented instructions
Astro Digital will process data only in accordance with the client’s documented instructions, including these terms, project settings and authorised actions within the product, unless required by law. If an instruction infringes applicable rules, Astro Digital will inform the client and may suspend that instruction while it is clarified.
4. Data subjects and data categories
- Data subjects: the client’s authorised users and professional contacts. Far is not designed to import individual lead or purchaser data.
- Data: identity and work email address, roles, access and support records, business context, account identifiers and metadata, advertising entity names and aggregated metrics.
- Special categories of personal data and criminal offence data: neither authorised nor required.
5. Astro Digital’s obligations
- Ensure that authorised persons are bound by confidentiality.
- Apply the technical and organisational measures set out in the annex.
- Provide reasonable assistance with rights, impact assessments, consultations and compliance with Articles 32 to 36 of the GDPR.
- Maintain sufficient information to demonstrate compliance and allow proportionate audits, subject to confidentiality and prior coordination.
- Delete or return the project’s operational data when the service ends, unless retention is required by law. Google authorisations reused by other projects are managed separately and may be explicitly revoked.
6. Security
Measures include access controls by project and role, MFA for administration, encryption in transit, encryption of OAuth credentials, managed secrets, activity logs, monitoring, backups, restoration testing, secure development, data minimisation and separation between clients. Google Ads is queried through a reporting connector with no write operations.
7. Subprocessors and transfers
The client grants general authorisation for the subprocessors published in the list maintained by Astro Digital. Material changes will be communicated with reasonable advance notice, and the client may raise a justified objection. Astro Digital will impose equivalent contractual obligations and remain responsible for its obligations. International transfers will use a valid mechanism under the GDPR.
8. Incidents and breaches
Astro Digital will notify the client without undue delay when it confirms a breach affecting the client’s data. The operational target is an initial notification within 24 hours of that confirmation; this target does not replace the client’s legal obligations. As information becomes available, Astro Digital will provide the nature, scope, consequences, measures and a coordination contact.
9. Requests from data subjects and authorities
If Astro Digital receives a request concerning data controlled by the client, it will forward the request without responding on its merits unless instructed or legally required to do so. Any exceptional additional assistance may be agreed according to its scope.
10. Instructions annex
- Controller
- The client identified in the account or service order
- Processor
- Astro Digital SL, B67340463
- Service
- Far, paid-media analysis and reporting
- Duration
- The service term and technical deletion period
- Contact
- hola@somosastro.com