Legal · Art. 28 GDPR

Data Processing Addendum

When your projects, campaigns, or audiences contain personal data, we process it on your documented instructions — you are the controller, we are the processor. This addendum is the Art. 28 GDPR contract that governs that relationship, with the same plain-words tickets as our Terms.

Effective September 15, 2026Version 1.0Processor Scalista GmbHForms part of the Terms of Service
  • Roles

    You control, we process

    For data inside your workspace and hosted campaigns, your instructions are the law — these terms write that down.

  • Security

    Art. 32 measures, documented

    Encryption in transit, workspace isolation, scoped access — detailed on our Security page and binding here.

  • Chain

    Sub-processors, listed & noticed

    The full register is below. Changes come with 30 days' notice and an objection right.

  • Exit

    Your data leaves with you

    Export anytime; on termination we delete within 30 days unless law says keep.

Scope & roles

  • This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Scalista GmbH (“Processor”) and the Customer (“Controller”) and applies to all personal data the Processor processes on the Controller's behalf in providing the Service.
  • It covers in particular: personal data contained in Customer Content (uploads, configs, copy), in hosted web campaigns, and in any audience interactions the Controller routes through the Service.
  • It does not cover processing for which Scalista is itself controller (accounts, billing, platform analytics) — that processing is described in the Privacy Policy.
  • Terms such as “personal data”, “processing” and “data subject” have the meanings of Art. 4 GDPR.

Details of processing (Annex I)

ItemDescription
Subject matterHosting, storage, processing and delivery of playable-ad projects and published campaigns
DurationTerm of the Terms of Service plus the 30-day deletion window
Nature & purposeStorage, media optimization, AI-assisted transformation at Controller's request, export bundling, web hosting and delivery
Categories of data subjectsController's staff and contractors; persons appearing in Customer Content; visitors of the Controller's hosted campaigns
Categories of personal dataContact and identification data in Customer Content; technical access data (IP, user agent) of campaign visitors in server logs; no special categories (Art. 9) are intended — the Controller must not submit them
FrequencyContinuous, as driven by the Controller's use of the Service

Processor obligations

  • Instructions. We process personal data only on the Controller's documented instructions — these are, primarily, your use of the product's features — unless EU or member-state law requires otherwise, in which case we inform you before processing (unless the law forbids it). We flag instructions we consider unlawful.
  • Confidentiality. Persons authorized to process the data are bound by confidentiality obligations.
  • Security (Art. 32). We implement appropriate technical and organizational measures, including encryption in transit, per-workspace isolation of assets, scoped credentials and access logging — as documented on the Security page, which is incorporated here as Annex II and updated as the state of the art evolves (never below the current protection level).
  • Assistance. Taking into account the nature of processing, we assist you with appropriate measures in fulfilling data-subject rights (Arts. 12–23) and your obligations under Arts. 32–36 GDPR.
  • Breach notice. We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information required by Art. 33(3) as it becomes available.
  • Deletion & return. Upon termination, we delete personal data processed on your behalf within 30 days (backups shortly thereafter), unless EU or member-state law requires storage. Self-service export is available before and during this window.
  • Audits. We make available the information necessary to demonstrate compliance with Art. 28 and allow audits — first satisfied through documentation and third-party attestations of our sub-processors; on-site audits require 30 days' notice, business hours, confidentiality, and no more than once per year unless a breach or supervisory authority demands more.

Sub-processors

  • The Controller grants general authorization (Art. 28(2)) for the sub-processors listed below. We impose data-protection obligations on each of them equivalent to this DPA and remain fully liable for their performance.
  • We announce intended additions or replacements at least 30 days in advance (in-app or by email). If you object on reasonable data-protection grounds and no solution is found, you may terminate the affected part of the Service with a pro-rata refund of prepaid fees.
Sub-processorFunctionLocationSafeguard
TursoDatabaseEUEU processing
Cloudflare R2Asset & export storage, campaign deliveryGlobal networkSCCs / EU-U.S. DPF
CloudinaryTransient media optimizationUSA / globalSCCs / EU-U.S. DPF
RailwayApplication hosting & logsUSASCCs / EU-U.S. DPF
OpenRouter / AnthropicAI processing at Controller's requestUSASCCs / EU-U.S. DPF · no-training API terms
SentryError monitoringUSASCCs / EU-U.S. DPF
Clerk / SvixAuthentication & related webhooks (workspace member data)USASCCs / EU-U.S. DPF
BrevoTransactional emailEUEU processing

International transfers

Transfers to third countries occur only as shown in the sub-processor register and rest on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (for certified recipients) or on Standard Contractual Clauses (2021/914, Module 3 where applicable) with supplementary measures. Copies are available on request.

Liability & order of precedence

  • Liability under this DPA is governed by the limitation-of-liability provisions of the Terms of Service, without prejudice to mandatory liability under Art. 82 GDPR.
  • In case of conflict regarding data protection, this DPA prevails over the Terms; mandatory provisions of the GDPR prevail over both.

Term & execution

This DPA takes effect automatically for every Customer upon acceptance of the Terms of Service and lasts as long as we process personal data on your behalf. It is concluded in electronic form; a countersigned copy for your vendor records is available via [email protected]. Austrian law and venue per the Terms apply.

Vendor review in progress?

We're happy to walk your DPO through this DPA, provide the signed copy, or answer security questionnaires.

Scalista GmbH · Vienna, Austria
Scalista GmbH
Spallartgasse 23/99
1140 Vienna, Austria
[email protected]
Data Processing Addendum — MyAdMaker