Royalada Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between Royalada LLC ("Royalada") and the customer, publisher, advertiser, or business partner that has entered into an agreement with Royalada for the provision of advertising, lead generation, or customer engagement services (the “Customer”) governing the use of Royalada’s services (the “Agreement”).
This DPA applies where and to the extent that Royalada processes Personal Data on behalf of the Customer in connection with the services, and such Personal Data is subject to the GDPR, the UK GDPR, the Swiss FADP, or a US State Privacy Law.
By entering into the Agreement, the Customer and Royalada also enter into this DPA, including the Standard Contractual Clauses incorporated in Section 12, which are executed by the parties’ acceptance of the Agreement. No additional signature is required, although the parties may also execute this DPA in writing on request.
Simply put: This document is part of your contract with Royalada. It sets the rules for how Royalada handles personal data on your behalf, and accepting the main contract automatically puts these rules — including the EU-approved transfer clauses — into force.
1. Definitions
“GDPR” means Regulation (EU) 2016/679; “UK GDPR” means the GDPR as incorporated into United Kingdom law; “FADP” means the Swiss Federal Act on Data Protection; “US State Privacy Laws” means the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and other applicable US state privacy laws; “Data Protection Laws” means all of the foregoing, as applicable.
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR. Under US State Privacy Laws, “Personal Data” includes “personal information”, “Controller” includes “business”, and “Processor” includes “service provider” or “processor” as defined there.
“Customer Personal Data” means Personal Data that Royalada processes on behalf of the Customer in connection with the services.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner’s Office.
“Subprocessor” means any third party engaged by Royalada to process Customer Personal Data.
Simply put: This section just fixes the meaning of the technical terms used below — most come directly from the GDPR.
2. Roles and Scope
2.1. As between the parties, the Customer is the Controller of Customer Personal Data and Royalada is a Processor acting on the Customer’s behalf. Where the Customer is itself a Processor for a third-party Controller, the Customer warrants that it is authorized to engage Royalada as a Subprocessor and this DPA applies mutatis mutandis, with Royalada acting as Subprocessor.
2.2. This DPA does not apply where Royalada acts as an independent Controller or Joint Controller (for example, for its own business operations, billing, security, fraud prevention, or the independent operation of its advertising services), as described in the Royalada Privacy Policy. Where the parties act as Joint Controllers for a specific activity, they will enter into a separate joint controller arrangement for that activity.
2.3. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I.
Simply put: For the data you give us to process for you, you are the owner and decision-maker; Royalada only acts on your instructions. Things Royalada does for itself (like its own billing or fraud prevention) are covered by the Royalada Privacy Policy instead.
3. Processing on Documented Instructions
3.1. Royalada will process Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to third countries, unless required to do so by law to which Royalada is subject; in such a case, Royalada will inform the Customer of that legal requirement before Processing, unless the law prohibits this.
3.2. The Agreement, this DPA, and the Customer’s configuration and use of the services (including campaign settings, consent configuration, and API calls) constitute the Customer’s complete documented instructions. Additional instructions require the parties’ written agreement.
3.3. Royalada will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
Simply put: Royalada only does with your data what you tell it to — through the contract, this DPA, and how you configure the service — and will warn you if an instruction looks illegal.
4. Customer Obligations
4.1. The Customer is responsible for: (a) the lawfulness of the Customer Personal Data and of its instructions; (b) providing all legally required privacy notices to Data Subjects; (c) obtaining and maintaining all legally required consents or other valid legal bases, including operating a suitable Consent Management Platform where required; and (d) making relevant consent and privacy signals (including IAB TCF and GPP signals and Global Privacy Control, where applicable) available to Royalada through supported mechanisms.
4.2. The Customer will not instruct Royalada to process sensitive or special categories of Personal Data, or Personal Data of children, unless expressly agreed in writing and permitted by Data Protection Laws.
Simply put: You must have the legal right to give us the data — proper notices, consents, and a working consent tool on your site. Don’t send us sensitive data or children’s data unless we’ve agreed to it in writing.
5. Confidentiality
Royalada ensures that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to personnel who need it to provide the services.
Simply put: Everyone at Royalada who touches your data is bound to keep it confidential, and only the people who need access get it.
6. Security
6.1. Royalada implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing. The current measures are described in Annex II.
6.2. Royalada may update the measures in Annex II from time to time, provided the updates do not materially reduce the overall level of protection.
Simply put: Royalada protects your data with concrete security measures (encryption, access controls, logging — listed in Annex II) and may improve them over time, but never weaken them.
7. Personal Data Breach
7.1. Royalada will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2. The notification will, to the extent then known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Royalada will provide updates as further information becomes available and will reasonably cooperate with the Customer’s own notification obligations.
7.3. Royalada’s notification of a Personal Data Breach is not an acknowledgement of fault or liability.
Simply put: If your data is involved in a breach, Royalada tells you within 48 hours with the facts it has, keeps you updated, and helps you meet your own 72-hour reporting duty to regulators.
8. Subprocessors
8.1. The Customer grants Royalada a general written authorization to engage Subprocessors, subject to this Section. The Subprocessors currently engaged are listed in the Royalada Service Provider and Subprocessor List available at [URL to subprocessors list] (the “Subprocessor List”).
8.2. Royalada will update the Subprocessor List and give the Customer at least 15 days’ prior notice before a new or replacement Subprocessor begins Processing Customer Personal Data (via the Subprocessor List, email, or an in-service notice). The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection in good faith, the Customer may terminate the affected service without penalty as its sole remedy. Where a replacement is reasonably necessary on an urgent basis to maintain the security, availability, or continuity of the services, Royalada may engage the replacement Subprocessor immediately and will notify the Customer as soon as reasonably practicable, in which case the Customer retains the objection and termination rights above. The removal of a Subprocessor does not require prior notice.
8.3. Royalada will impose on each Subprocessor, by written contract, data protection obligations that are materially no less protective than those in this DPA, including with respect to international transfers, and remains fully liable to the Customer for the performance of each Subprocessor’s obligations.
Simply put: Royalada may use vetted helper companies. The full list is public, you get 15 days’ notice before a new one touches your data (immediately followed by notice in emergencies) and can object, and Royalada stays responsible for what its helpers do.
9. Data Subject Requests
9.1. Taking into account the nature of the Processing, Royalada will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection, and opt-outs under US State Privacy Laws).
9.2. If a Data Subject contacts Royalada directly regarding Customer Personal Data, Royalada will not respond substantively except to direct the Data Subject to the Customer, unless required by law, and will promptly inform the Customer of the request.
Simply put: If a person asks to see or delete their data, that request belongs to you — Royalada gives you the tools and information to answer it and forwards any requests it receives directly.
10. Assistance with Compliance
Taking into account the nature of the Processing and the information available to it, Royalada will provide reasonable assistance to the Customer with: (a) the security of Processing; (b) Personal Data Breach notifications to Supervisory Authorities and Data Subjects; (c) data protection impact assessments; and (d) prior consultations with Supervisory Authorities.
Simply put: Where the law requires you to do a risk assessment, report a breach, or consult a regulator, Royalada gives you the information and help you reasonably need.
11. Return and Deletion
11.1. Upon termination or expiry of the services, Royalada will, at the Customer’s choice, delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires further storage. Absent a choice, Royalada will delete Customer Personal Data within 90 days of termination.
11.2. Customer Personal Data in backup systems is deleted or overwritten within 90 days of deletion from active systems, and remains protected by the measures in Annex II until then.
11.3. Royalada may retain records that it must keep under applicable law (for example, consent, suppression, and accounting records), which remain protected under this DPA and are deleted when the legal retention period ends.
Simply put: When you leave, you choose: get your data back or have it deleted. Either way it is gone from active systems and backups within about 90 days, except records the law forces Royalada to keep.
12. International Transfers
12.1. Royalada operates a central processing platform located in Serbia, provided by a licensed platform technology provider identified in the Subprocessor List, and stores Customer Personal Data regionally after processing (EEA data in EEA data centers, US data in US data centers), as further described in Annex I.B.
12.2. EEA transfers. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision (including Serbia and the United States), the parties hereby enter into the SCCs, Module Two (controller to processor), which are incorporated into this DPA by reference, with the Customer as data exporter and Royalada as data importer, completed as follows:
- Clause 7 (docking clause): included;
- Clause 9(a): Option 2 (general written authorization), with the notice period and urgent-replacement mechanism in Section 8.2;
- Clause 11(a): the optional independent dispute resolution body is not selected;
- Clause 13 / Annex I.C: the competent Supervisory Authority is determined per Clause 13 and Annex I.C;
- Clause 17: Option 1 — the SCCs are governed by the law of Ireland;
- Clause 18(b): disputes are resolved before the courts of Ireland;
- Annexes I, II and III of the SCCs are populated by Annexes I, II and III of this DPA.
12.3. UK transfers. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK Addendum, completed as set out in Annex IV.
12.4. Swiss transfers. For transfers subject to the FADP, the SCCs apply with the adaptations customary for Switzerland: references to the GDPR are read as references to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, the governing law and forum under Clauses 17 and 18 may be Switzerland, and Data Subjects in Switzerland may enforce their rights in Switzerland.
12.5. In the event of any conflict between this DPA and the SCCs, the SCCs prevail. If a competent authority or court holds that a transfer mechanism relied upon is invalid, the parties will cooperate in good faith to implement a lawful alternative, and Royalada may suspend the affected transfer until then.
12.6. Royalada will, on request, make available to the Customer its transfer impact assessment for Serbia and information reasonably necessary for the Customer’s own transfer assessments.
Simply put: Your data is processed in Serbia and then stored in the region it belongs to. Because Serbia and the US are outside the EU’s “safe list”, this DPA has the EU’s official transfer contract (the SCCs) built in — accepting the DPA signs them. UK and Swiss versions are covered too.
13. US State Privacy Laws — Service Provider Terms
Where US State Privacy Laws apply to Customer Personal Data, Royalada acts as a “service provider” or “processor” and: (a) will not sell or share Customer Personal Data; (b) will not retain, use, or disclose it for any purpose other than providing the services (including not for cross-context behavioral advertising), except as permitted by those laws; (c) will not combine it with Personal Data from other sources except as permitted for service providers; (d) will comply with applicable obligations and provide the same level of protection as required of the Customer; (e) will notify the Customer if it can no longer meet these obligations, in which case the Customer may take reasonable steps to stop and remediate unauthorized use; and (f) grants the Customer the rights of assessment and remediation required by those laws, exercised through Section 14 (Audits).
Simply put: For US privacy laws (like California’s), Royalada is your “service provider”: it never sells your data, uses it only to run your service, and tells you if it can’t keep those promises.
14. Audits
14.1. Royalada will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
14.2. The parties agree that audits will first be satisfied, where reasonably sufficient, by Royalada providing existing documentation, certifications, or third-party audit reports. On-site or remote inspections require at least 30 days’ notice, occur at most once per 12 months (except after a Personal Data Breach or where required by a Supervisory Authority), take place during business hours, must not unreasonably disrupt operations, and are subject to confidentiality. Each party bears its own costs.
14.3. Nothing in this Section limits the audit rights mandated by Clause 8.9 of the SCCs where the SCCs apply.
Simply put: You can check that Royalada keeps its promises — normally by reviewing reports and documentation, and if needed by a real audit once a year with notice.
15. Liability
Each party’s liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Agreement, except where such limitations are not permitted by Data Protection Laws or the SCCs. Nothing in this Section limits a Data Subject’s rights under the SCCs.
Simply put: The liability caps from your main contract also apply here, except where the law or the SCCs say they can’t.
16. Term, Precedence, and General
16.1. This DPA takes effect on the effective date of the Agreement and remains in force as long as Royalada processes Customer Personal Data, notwithstanding termination of the Agreement.
16.2. In case of conflict: the SCCs prevail over this DPA, and this DPA prevails over the Agreement with respect to the Processing of Personal Data.
16.3. Royalada may update this DPA to reflect changes in Data Protection Laws or the services, provided updates do not materially reduce the protection of Customer Personal Data; material changes will be notified to the Customer.
16.4. Contact for all data protection matters under this DPA: [email protected]; Data Protection Officer / privacy reports: [email protected].
Simply put: These rules apply for as long as we hold your data, they win over the main contract on privacy questions, and the EU transfer clauses win over everything.
Annex I — Description of Processing and Transfer
A. List of Parties
| Data exporter | Data importer | |
|---|---|---|
| Name | The Customer, as identified in the Agreement | Royalada LLC |
| Address | As set out in the Agreement | [Registered Address] |
| Contact | As set out in the Agreement | [email protected] / [email protected] |
| Role | Controller | Processor |
| Signature and date | Executed by acceptance of the Agreement | Executed by acceptance of the Agreement |
B. Description of Transfer
| Item | Description |
|---|---|
| Categories of Data Subjects | Visitors of the Customer’s websites, applications, and digital properties; leads submitting forms; recipients of the Customer’s communications (email, SMS, push, messaging applications); end users interacting with advertisements delivered through the services |
| Categories of Personal Data | Online and technical identifiers (IP address, session and visitor identifiers, push identifiers); device and browser information; page URL, referrer, and interaction/event data; campaign and attribution parameters; consent and privacy preference signals (including IAB TCF/GPP strings); lead form submissions (e.g., name, email address, phone number, company, country/region, preferences); communication contact details, subscription status, and engagement data; fraud prevention and traffic quality signals |
| Sensitive data | None intended. The Customer must not submit special categories of data (see Section 4.2) |
| Frequency of transfer | Continuous, for the duration of the services |
| Nature and purpose of Processing | Collection, receipt, storage, organization, analysis, transmission, and deletion of Personal Data as necessary to provide advertising delivery and measurement, lead generation, customer engagement and communications, reporting, security, and fraud prevention services, as configured by the Customer |
| Duration of Processing / retention | For the duration of the Agreement, plus the deletion periods in Section 11; category-level retention periods are set out in the Royalada Privacy Policy (“Data Retention”) |
| Transfers to (sub-)processors | Central processing in Serbia (platform technology provider identified in the Subprocessor List); regional storage (EEA data in EEA data centers; US data in US data centers); other Subprocessors as listed in the Subprocessor List, for the purposes stated there |
C. Competent Supervisory Authority
The Supervisory Authority of the EU Member State in which the data exporter is established or, where the exporter is not established in the EU, of the Member State where its EU representative is located or where the relevant Data Subjects are located, determined in accordance with Clause 13 of the SCCs.
Simply put: This annex is the “who, what, and where” form the EU transfer clauses require: whose data, which data, why, for how long, and which regulator oversees it.
Annex II — Technical and Organizational Measures
- Encryption of Personal Data in transit (TLS) and at rest; fields designated as directly identifying (PII) are encrypted at rest with restricted key access
- Access controls and role-based permissions; access limited to personnel with a need to know
- Authentication and authorization procedures for all systems processing Personal Data
- Audit logging of access to Personal Data; manual access to decrypted Personal Data requires authorization and is logged
- Segregation and isolation of Customer data
- Regional data storage (EEA data in EEA data centers; US data in US data centers) after central processing
- Monitoring, logging, and security review procedures; invalid traffic and abuse detection
- Backup and recovery measures; backups purged within 90 days of deletion from active systems
- Contractual confidentiality obligations for staff and contractors
- Security and data protection requirements imposed on Subprocessors by written contract
- Data minimization and retention limits per the Royalada Privacy Policy; deletion or anonymization at end of retention
- Measures to assist the Customer with Data Subject requests (export, correction, deletion, and consent-state handling, including immediate deletion of consent-gated identifiers on withdrawal)
Simply put: The concrete security promises: encryption, strict and logged access, separated customer data, regional storage, short-lived backups, and vetted helpers under contract.
Annex III — Subprocessor List
The authorized Subprocessors, including their role, location, data processed, and transfer mechanism, are listed in the Royalada Service Provider and Subprocessor List, available at [URL to subprocessors list], as updated in accordance with Section 8.
Simply put: The live list of helper companies lives at a public link, so it’s always current — changes are announced 30 days in advance.
Annex IV — UK Addendum
For transfers subject to the UK GDPR, the UK Addendum applies with its tables completed as follows:
- Table 1 (Parties): as set out in Annex I.A
- Table 2 (Selected SCCs): the SCCs as incorporated in Section 12.2, including its selected modules and options
- Table 3 (Appendix Information): Annexes I, II, and III of this DPA
- Table 4 (Ending the Addendum): neither party may end the Addendum as set out in Section 19 of the Addendum
Simply put: The UK has its own add-on form to the EU clauses; this fills it in using the same information, so UK data is covered the same way.