Scope & roles
- This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Scalista GmbH (“Processor”) and the Customer (“Controller”) and applies to all personal data the Processor processes on the Controller's behalf in providing the Service.
- It covers in particular: personal data contained in Customer Content (uploads, configs, copy), in hosted web campaigns, and in any audience interactions the Controller routes through the Service.
- It does not cover processing for which Scalista is itself controller (accounts, billing, platform analytics) — that processing is described in the Privacy Policy.
- Terms such as “personal data”, “processing” and “data subject” have the meanings of Art. 4 GDPR.
Details of processing (Annex I)
| Item | Description |
|---|---|
| Subject matter | Hosting, storage, processing and delivery of playable-ad projects and published campaigns |
| Duration | Term of the Terms of Service plus the 30-day deletion window |
| Nature & purpose | Storage, media optimization, AI-assisted transformation at Controller's request, export bundling, web hosting and delivery |
| Categories of data subjects | Controller's staff and contractors; persons appearing in Customer Content; visitors of the Controller's hosted campaigns |
| Categories of personal data | Contact and identification data in Customer Content; technical access data (IP, user agent) of campaign visitors in server logs; no special categories (Art. 9) are intended — the Controller must not submit them |
| Frequency | Continuous, as driven by the Controller's use of the Service |
Processor obligations
- Instructions. We process personal data only on the Controller's documented instructions — these are, primarily, your use of the product's features — unless EU or member-state law requires otherwise, in which case we inform you before processing (unless the law forbids it). We flag instructions we consider unlawful.
- Confidentiality. Persons authorized to process the data are bound by confidentiality obligations.
- Security (Art. 32). We implement appropriate technical and organizational measures, including encryption in transit, per-workspace isolation of assets, scoped credentials and access logging — as documented on the Security page, which is incorporated here as Annex II and updated as the state of the art evolves (never below the current protection level).
- Assistance. Taking into account the nature of processing, we assist you with appropriate measures in fulfilling data-subject rights (Arts. 12–23) and your obligations under Arts. 32–36 GDPR.
- Breach notice. We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information required by Art. 33(3) as it becomes available.
- Deletion & return. Upon termination, we delete personal data processed on your behalf within 30 days (backups shortly thereafter), unless EU or member-state law requires storage. Self-service export is available before and during this window.
- Audits. We make available the information necessary to demonstrate compliance with Art. 28 and allow audits — first satisfied through documentation and third-party attestations of our sub-processors; on-site audits require 30 days' notice, business hours, confidentiality, and no more than once per year unless a breach or supervisory authority demands more.
Sub-processors
- The Controller grants general authorization (Art. 28(2)) for the sub-processors listed below. We impose data-protection obligations on each of them equivalent to this DPA and remain fully liable for their performance.
- We announce intended additions or replacements at least 30 days in advance (in-app or by email). If you object on reasonable data-protection grounds and no solution is found, you may terminate the affected part of the Service with a pro-rata refund of prepaid fees.
| Sub-processor | Function | Location | Safeguard |
|---|---|---|---|
| Turso | Database | EU | EU processing |
| Cloudflare R2 | Asset & export storage, campaign delivery | Global network | SCCs / EU-U.S. DPF |
| Cloudinary | Transient media optimization | USA / global | SCCs / EU-U.S. DPF |
| Railway | Application hosting & logs | USA | SCCs / EU-U.S. DPF |
| OpenRouter / Anthropic | AI processing at Controller's request | USA | SCCs / EU-U.S. DPF · no-training API terms |
| Sentry | Error monitoring | USA | SCCs / EU-U.S. DPF |
| Clerk / Svix | Authentication & related webhooks (workspace member data) | USA | SCCs / EU-U.S. DPF |
| Brevo | Transactional email | EU | EU processing |
International transfers
Transfers to third countries occur only as shown in the sub-processor register and rest on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (for certified recipients) or on Standard Contractual Clauses (2021/914, Module 3 where applicable) with supplementary measures. Copies are available on request.
Liability & order of precedence
- Liability under this DPA is governed by the limitation-of-liability provisions of the Terms of Service, without prejudice to mandatory liability under Art. 82 GDPR.
- In case of conflict regarding data protection, this DPA prevails over the Terms; mandatory provisions of the GDPR prevail over both.
Term & execution
This DPA takes effect automatically for every Customer upon acceptance of the Terms of Service and lasts as long as we process personal data on your behalf. It is concluded in electronic form; a countersigned copy for your vendor records is available via [email protected]. Austrian law and venue per the Terms apply.
Vendor review in progress?
We're happy to walk your DPO through this DPA, provide the signed copy, or answer security questionnaires.