GDPR & Data Processing Addendum
Last updated: July 20, 2026
This Data Processing Addendum (the "DPA") forms part of the Advertising Agreement, the Publisher Terms, and the Terms of Service (each an "Agreement") between TrafficSigma and the customer ("Customer"). It applies where TrafficSigma processes personal data on the Customer’s behalf in connection with the Services and is designed to meet Article 28 of the GDPR, the UK GDPR, and the Swiss revFADP.
A countersigned copy of this DPA is available on request. Where the Customer’s own data processing agreement is required instead, contact [email protected]. [THE CONTRACTING ENTITY, ITS REGISTERED DETAILS, AND ANY ARTICLE 27 EU/UK REPRESENTATIVE TO BE COMPLETED BEFORE EXECUTION.]
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR. "Data Protection Law" means the GDPR, the UK GDPR and the Data Protection Act 2018, the Swiss revFADP, and any other applicable data protection or privacy law. "SCCs" means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914; "UK Addendum" means the UK International Data Transfer Addendum issued by the ICO.
2. Roles of the parties
The parties acknowledge that their roles depend on the processing activity:
| Processing activity | Role of TrafficSigma |
|---|---|
| Delivery, optimization, and measurement of the Customer’s campaigns or inventory on the Customer’s instructions | Processor, with the Customer acting as Controller |
| Account administration, billing, KYC/AML, fraud prevention, platform security, and product improvement | Independent Controller, governed by the TrafficSigma Privacy Policy rather than by this DPA |
| Aggregated and de-identified statistics that do not identify a Data Subject | Not personal data processing under this DPA |
Each party is responsible for its own compliance with Data Protection Law in its role. The Customer warrants that it has a valid legal basis, and where required valid consent, for the personal data it makes available to TrafficSigma and for the processing it instructs.
3. Processing on documented instructions
TrafficSigma will process personal data only on the Customer’s documented instructions, which comprise the Agreement, this DPA, and the Customer’s use of the platform’s configuration options, unless processing is required by law to which TrafficSigma is subject - in which case TrafficSigma will inform the Customer of that requirement before processing, unless the law prohibits it. TrafficSigma will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
4. Confidentiality
TrafficSigma ensures that personnel authorized to process personal data are bound by an appropriate duty of confidentiality and are subject to access controls limiting access to what each role requires.
5. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, TrafficSigma implements appropriate technical and organizational measures under Article 32 GDPR, including:
- Encryption of personal data in transit over public networks, and encryption at rest where appropriate.
- Role-based access control, least-privilege provisioning, and multi-factor authentication for administrative access.
- Hashed credential storage and secret management.
- Network segmentation, logging, and monitoring for unauthorized access or anomalous activity.
- Secure development practices, dependency management, and change control.
- Backup, restoration testing, and business-continuity procedures.
- Periodic review of the measures, and of personnel security awareness.
The measures may be updated over time, provided the level of protection is not reduced. [ANY THIRD-PARTY CERTIFICATION OR AUDIT REPORT (E.G. ISO 27001, SOC 2) SHOULD ONLY BE REFERENCED HERE IF AND WHEN ACTUALLY HELD - NONE IS ASSERTED IN THIS DRAFT.]
6. Sub-processors
The Customer grants TrafficSigma general written authorization to engage sub-processors, subject to this Section. TrafficSigma imposes on each sub-processor data protection obligations no less protective than those in this DPA and remains fully liable to the Customer for its sub-processors’ performance.
The current list of sub-processors - covering categories such as cloud hosting and CDN, payment processing, fraud prevention, communications and support tooling, and analytics - is available on request from [email protected]. TrafficSigma will give the Customer at least 30 days’ notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period, in which case the parties will work in good faith towards a resolution; if none is found, the Customer may terminate the affected part of the Services without penalty.
7. Data subject rights
Taking into account the nature of the processing, TrafficSigma will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Chapter III GDPR. If TrafficSigma receives such a request directly in respect of Customer data, it will not respond substantively but will refer the Data Subject to the Customer and notify the Customer without undue delay.
8. Assistance with DPIAs and breach notification
TrafficSigma will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35-36 GDPR, taking into account the information available to it.
TrafficSigma will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer personal data, and will provide the information reasonably available to it - the nature of the breach, the categories and approximate volume of data and Data Subjects affected, the likely consequences, and the measures taken or proposed - to enable the Customer to meet its own notification obligations.
9. International transfers
Where processing under this DPA involves a transfer of personal data from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference and apply, with Module Two (Controller to Processor) or Module Three (Processor to Processor) as appropriate, the Customer as data exporter and TrafficSigma as data importer, the optional docking clause applying, Clause 9 Option 2 (general written authorization) with the notice period in Section 6, Clause 11 without the independent-dispute-resolution option, and Clause 17 and Clause 18 governed by and litigated in the jurisdiction identified in the Agreement. For UK transfers the UK Addendum applies to the SCCs; for Swiss transfers, references to the GDPR are read as references to the revFADP and the FDPIC is the competent authority.
10. Audits
TrafficSigma will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR. Where that information is insufficient, the Customer may, at its own cost, conduct an audit no more than once per twelve-month period (and additionally after a Personal Data Breach affecting the Customer), on at least 30 days’ written notice, during business hours, subject to confidentiality and to reasonable limits protecting the security and data of other customers. The Customer may use an independent auditor who is not a competitor of TrafficSigma.
11. Deletion and return of data
On termination or expiry of the Agreement, TrafficSigma will, at the Customer’s election, delete or return the personal data processed on the Customer’s behalf, and delete existing copies, unless retention is required by law. Data held in routine backups is deleted in line with the backup cycle. Aggregated and de-identified data that cannot be attributed to a Data Subject may be retained.
12. Details of processing (Annex I)
| Item | Detail |
|---|---|
| Subject matter | Provision of the TrafficSigma advertising network and related services |
| Duration | For the term of the Agreement, plus any legally required retention period |
| Nature and purpose | Campaign delivery, targeting configuration, optimization, measurement and reporting, quality and fraud control, and support |
| Categories of Data Subjects | The Customer’s personnel and authorized users; and, where applicable, end users of publisher inventory reached by the Customer’s campaigns |
| Categories of Personal Data | Contact and account identifiers of Customer personnel; and technical identifiers such as IP address, device and browser characteristics, coarse location derived from IP, timestamps, and interaction events |
| Special categories | None. The Customer must not instruct processing of special-category data, and targeting on sensitive attributes is prohibited by the Acceptable Use Policy |
| Frequency | Continuous, for the duration of active campaigns or monetization |
| Competent supervisory authority | [TO BE COMPLETED ONCE THE CONTRACTING ENTITY AND ITS ESTABLISHMENT OR ARTICLE 27 REPRESENTATIVE ARE CONFIRMED] |
13. Technical and organizational measures (Annex II)
Annex II of the SCCs consists of the measures described in Section 5 of this DPA, as updated from time to time.
14. Liability and precedence
The liability provisions of the Agreement apply to this DPA. In the event of a conflict, this DPA prevails over the Agreement in respect of the processing of personal data, and the SCCs prevail over this DPA in respect of transfers to which they apply.
15. Contact
To request a signed DPA, the sub-processor list, or details of transfer safeguards, email [email protected].