Last Updated: July 27, 2026
Download / Print PDFThis Data Processing Agreement ("DPA") forms part of the Terms of Service between Adtool ApS ("Adtool", "we", "us", "Processor") and the customer ("Customer", "you", "Controller") using Adtool.io services.
By using Adtool.io, you automatically agree to this DPA. You may download or print this document for your records.
In the context of this DPA:
If you use Adtool to manage advertising for your own clients (e.g., as an agency or freelancer), you act as Controller or, where you process your clients' Personal Data on their behalf, as their Processor, in which case Adtool acts as your sub-processor. You warrant that you have the authorizations and agreements with your clients necessary to engage Adtool and to give the instructions in this DPA, and you remain responsible for compliance with Data Protection Laws in your relationship with your clients.
The terms of this DPA are the data protection terms on which Adtool acts, including where Adtool acts as a sub-processor. Where the Customer's agreement with its own client imposes obligations more onerous than those set out in this DPA, the Customer must notify Adtool in writing in advance, and Adtool is not bound by those obligations unless it has expressly agreed to them in writing.
Adtool processes Personal Data solely to provide the Services. The details of the processing, its subject matter, duration, nature and purpose, the types of Personal Data, and the categories of data subjects, are set out in Annex I.
This DPA, the Terms of Service, and the Customer's use of the Services' features constitute the Customer's complete and documented instructions to Adtool regarding the Processing of Personal Data. Additional instructions require prior written agreement between the parties.
Adtool agrees to:
You agree to:
You grant Adtool general authorization to engage the sub-processors identified in Annex III (which incorporates the current list published at https://adtool.io/subprocessors) to assist in providing the Services. Adtool reviews each sub-processor's data protection practices and enters into a data processing agreement with each of them before any processing begins.
We maintain the current list of authorized sub-processors at https://adtool.io/subprocessors (incorporated into this DPA by Annex III). We will update that list at least 14 days before a new sub-processor begins processing Personal Data; publication of the updated list constitutes notice of the change, and you are responsible for checking the page. You may object on reasonable data-protection grounds within 14 days of the update. If we cannot reasonably accommodate your objection, you may terminate your account. Your continued use of the Services after the 14-day period without objection constitutes acceptance of the new sub-processor.
Where Adtool engages a sub-processor, Adtool will impose data protection obligations on that sub-processor that are no less protective than those set out in this DPA, by way of a written contract. Adtool remains fully liable to you for any acts or omissions of its sub-processors that result in a breach of this DPA.
Personal Data is stored in the United States (Supabase) and processed by sub-processors in the US and EU, as listed in Annex III. Where Personal Data is transferred from the EU/EEA to the United States, Adtool relies on the following safeguards:
In the event of a Security Incident, a Personal Data Breach as defined in Section 1, affecting your data, Adtool will notify you without undue delay and, where feasible, not later than 72 hours after becoming aware of the incident.
The notification will include, to the extent known:
• A description of the nature of the incident
• Categories and approximate number of data subjects affected
• Likely consequences of the incident
• Measures taken or proposed to address the incident
Adtool will cooperate with you and provide reasonable assistance in investigating the incident and meeting your notification obligations to supervisory authorities and data subjects.
Adtool will assist you in responding to requests from data subjects exercising their rights under Data Protection Laws, including:
• Right of access
• Right to rectification
• Right to erasure
• Right to restriction of processing
• Right to data portability
• Right to object
If Adtool receives a request directly from a data subject, we will promptly forward it to you unless legally prohibited from doing so.
Upon termination of your account, your data is kept intact for 90 days, unless you request earlier deletion, so that you can export or request the return of your Personal Data, or reactivate your account. At the end of this 90-day window, Adtool will delete your Personal Data, except where Adtool is required to retain data it holds as an independent controller (for example, billing records under the Danish Bookkeeping Act).
If you request deletion of your account and data, deletion will be carried out within 90 days of your request, or within such shorter period as you reasonably require to meet your own obligations under Data Protection Laws. Adtool will delete your Personal Data from its production systems, including cached data derived from connected platforms such as Meta, and will procure the deletion of Personal Data processed on Adtool's behalf by the sub-processors listed in Annex III. Once deleted, your data cannot be restored and your account cannot be reactivated. Database backups are retained for 7 days on a rolling basis, so data deleted from our production systems is removed from any remaining backups within 7 days of deletion. Creative assets in file storage are not included in database backups; they are deleted at the same time as the rest of your data and are not retained in any backup. Unsubscribing from marketing communications is not a request to delete your account or data.
To request data deletion, contact: support@adtool.io
Each party's liability under this DPA is subject to, and counts towards, the limitations of liability set forth in the Terms of Service. Nothing in this DPA increases or creates liability beyond the cap stated in the Terms of Service.
This DPA remains in effect for as long as Adtool processes Personal Data on your behalf. This DPA survives termination of your Adtool account until Adtool has deleted or returned all Personal Data in accordance with Section 9 (Data Retention and Deletion).
This DPA is governed by Danish law. Any disputes arising from this DPA shall be resolved by the competent courts of Denmark.
For questions about this Data Processing Agreement:
Adtool ApS
Vallensbækvej 63, 2625 Vallensbæk, Denmark
CVR: 45752577
Email: hello@adtool.io
To exercise data protection rights or request deletion, contact support@adtool.io (see Section 9).
Acceptance: By using Adtool.io services, you confirm that you have read, understood, and agree to this Data Processing Agreement.
Subject matter: The provision of the Services, Adtool's advertising workflow platform, to the Customer.
Duration: The duration of the Customer's use of the Services, plus the retention period set out in Section 9.
Nature and purpose of processing: Processing necessary to provide the Services, currently including:
Categories of data subjects:
Types of Personal Data:
• Tenant Isolation: Application-level tenant isolation enforced on every API route, backed by database row-level security (RLS) policies
• Infrastructure: Data stored on Supabase servers (US), with transfers safeguarded by Standard Contractual Clauses (see Section 6)
• Token Security: OAuth tokens are protected by infrastructure-level encryption at rest, strict access controls, and audit-logged administrative access; field-level token encryption is on our security roadmap
• Monitoring: Regular security monitoring and updates
Adtool's current authorized sub-processors, including each sub-processor's purpose, location, and the transfer safeguard applying to it, are listed at https://adtool.io/subprocessors. That list forms part of this DPA. Changes to the list are handled as described in Section 5.2; publication on that page constitutes notice of changes.
Note on integrations: The Meta integration operates on the Customer's own ad accounts and business assets, under the Customer's own agreements with Meta Platforms Ireland Ltd (or the Meta entity applicable to the Customer). Meta is therefore not engaged by Adtool as a sub-processor; Adtool accesses the Customer's Meta assets on the Customer's behalf using the Customer's authorization. The Google Drive integration, and, once launched, the Microsoft OneDrive integration, likewise operates on the Customer's own account; in that context Google or Microsoft acts as the Customer's processor, not as Adtool's sub-processor for file contents. Analytics and marketing tags managed via Google Tag Manager, on our website and in the platform, operate in Adtool's own capacity as controller, are consent-based, and are described in our Privacy Policy; they do not involve sub-processing of Customer Personal Data under this DPA.
Download / Print PDF