Effective Date: January 31, 2024
This BidsCube Data Processing Addendum (hereinafter ‘DPA’) supplements the BidsCube Terms of Use DSP and Publisher Terms of Use (hereinafter ‘Terms’), the agreement between you (hereinafter ‘Publisher’, ‘Advertiser’, ‘RTB Partner’, or ‘Customer’ or together as ‘Customers’, ‘you’, ‘your’) and BidsCube SP. Z.O.O (hereinafter ‘Company’, ‘BidsCube’, ‘we’, ‘us’ or ‘our’) and governs the processing of personal data provided to BidsCube in connection with the Services or of any personal data that BidsCube processes in connection with the performance of the Services, hereinafter referred to individually as a ‘Party’ or together as the ‘Parties’.
Unless otherwise defined in this DPA, all capitalised terms used in this DPA will have the meanings set forth in BidsCube’s Terms. This DPA shall remain in force until the termination of the Terms between you and us governing your use of the Services.
“Data Protection Laws and Regulations” means all laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, the United Kingdom, the United States and its states, applicable to the processing of personal data under the Terms as amended from time to time, such as the GDPR, UK Data Protection Laws, or other applicable laws and regulations.
“General Data Protection Regulation (GDPR)” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
“UK Data Protection Laws” means the Data Protection Act 2018 and the UK GDPR (retained version of the EU GDPR).
“EU Standard Contractual Clauses (EU SCCs)” means Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eurlex.europa.eu/eli/dec_impl/2021/914/oj.
“UK Addendum” means International Data Transfer Addendum to the EU Standard Contractual Clauses that have been issued by the Information Commissioner for Parties making Restricted Transfers in the meaning of the UK Data Protection Laws, as currently set out at https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf.
“controller”, “joint controller”, “processor”, “data subject”, “personal data”, and “processing” have the meanings given in Data Protection Laws and Regulations.
“End User Data” means personal data provided to BidsCube in connection with the Services or any personal data that BidsCube processes in connection with the performance of the Services.
“Services” means online advertising services, including AdTech solutions (the SSP, DSP) and White Label AdExchange, SSP and DSP solutions as described in the Terms.
“Sub-processor” means any entity which provides processing services to BidsCube in furtherance of BidsCube’s processing on behalf of the Customer.
“Public Authority” means a government agency or law enforcement authority, including judicial authorities.
“Supervisory Authority” means an independent public authority to be responsible for monitoring the application of the data protection legislation.
During the provision of Services, BidsCube and Customers may have different roles under Data Protection Laws and Regulations depending on the specific service BidsCube provides. Thus, certain provisions of this DPA are applicable only in specific cases, as described below. The Customer acknowledges and agrees that with regard to the processing of End User Data the Customer and the Company have the roles under Data Protection Laws and Regulations specified in this Section. This DPA shall apply accordingly to established roles and not apply to situations where we act as sole controllers in accordance with BidsCube’s Privacy Policy.
Where the Customer uses Supply Side Platform services, the Customer as a data exporter and the Company as a data importer are joint controllers in respect of End User Data. In this case, Sections 1, 2, 8 and 9 of this DPA and Schedules 1 and 4 of this DPA shall apply.
Where the Customer uses Demand Side Platform services, the Customer as a data importer and the Company as a data exporter are joint controllers in respect of End User Data. In this case, Sections 1, 2, 8 and 9 of this DPA and Schedules 2 and 4 of this DPA shall apply.
Where the Customer uses White Label AdExchange, White Label Supply Side Platform, White Label Demand Side Platform services, the Customer is a controller and a data exporter of End User Data, and the Company is a processor and a data importer in respect of End User Data. In this case, Sections 1 to 7 and 9 of this DPA and Schedules 3 and 4 of this DPA shall apply.
The Parties agree that this DPA and the Terms constitute your complete and final documented instructions regarding when we process End User Data on your behalf (hereinafter ‘Instructions’). Any additional or alternate instructions must be consistent with the terms and conditions of this DPA and the Terms.
The processing of End User Data on your behalf in connection with Services is described in Schedule 3 of this DPA. We reserve the right to update the description of processing from time to time to reflect new functionality which is part of the Services.
Within the scope of the DPA and Terms and your use of the Services, when you act as a data controller and we act as a data processor, you will be solely responsible for complying with all requirements that apply to you under the Data Protection Laws and Regulations. You represent and warrant that you will be solely responsible for:
(i) the accuracy, quality, integrity, confidentiality and security of collected End User Data;
(ii) complying with all necessary transparency, lawfulness, fairness and other requirements under Data Protection Laws and Regulations for the collection and use of personal data by establishing and maintaining the procedure for the exercise of the rights of the data subjects whose personal data are processed on behalf of the Customer; providing us only with data that has been lawfully and validly obtained and ensuring that such data will be relevant and proportionate to the respective uses; ensuring compliance with the provisions of this DPA and Terms by your personnel or by any third-party accessing or using End User Data on your behalf; and
(iii) ensuring that your Instructions to us regarding the processing of End User Data comply with the Data Protection Laws and Regulations, including complying with principles of data minimisation, purpose and storage limitation.
With regard to the processing of End User Data, we shall:
(i) process End User Data using appropriate technical and organisational security measures and in compliance with the Instructions received from the Customer subject to Section 3 of this DPA;
(ii) inform the Customer if, in our opinion, the Customer’s Instructions may be in violation of the provisions of the Data Protection Laws and Regulations;
(iii) inform the Customer if we cannot comply with its obligations under this DPA, in which case the Customer may terminate the agreement or take any other reasonable actions, including suspending data processing operations;
(iv) follow the Customer’s instructions regarding the collection of End User Data, in case we are obtaining End User Data from data subjects on behalf of the Customer under Terms;
(v) take reasonable steps to ensure that any employee/contractor to whom we authorise access to End User Data on our behalf comply with respective provisions of the Terms and this DPA.
Upon becoming aware, we shall inform you of any legally binding request for disclosure of End User Data by a Public Authority, unless we are otherwise forbidden by law to inform the Customer, for instance, to preserve the confidentiality of investigation by a Public Authority. We will inform the Customer if it becomes aware of any notice, inquiry, or investigation by a Supervisory Authority with respect to the processing of End User Data under this DPA conducted between you and us.
We shall implement and maintain appropriate technical and organisational measures to protect End User Data from personal data breaches (hereinafter ‘Security Incidents’) in accordance with our security standards set out in Schedule 4 of this DPA. You acknowledge that security measures are subject to technical progress so that we may modify or update Schedule 4 of this DPA at our sole discretion, provided that such modification or update does not result in a material degradation in the security measures offered by Schedule 4 of this DPA.
Upon becoming aware of a Security Incident, we shall:
(i) notify you without undue delay after we become aware of the Security Incident;
(ii) provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by you; and
(iii) promptly take reasonable steps to contain and investigate any Security Incident so that you can notify competent authorities and/or affected Data Subjects of the Security Incident. Our notification of or response to a Security Incident shall not be construed as an acknowledgement by us of any fault or liability regarding the Security Incident.
We will not access, use, or disclose to any third party any End User Data, except, in each case, as necessary to maintain or provide the Services or as necessary to comply with contractual and legal obligations or binding order of a public body (such as a subpoena or court order). We shall ensure that any employee/contractor whom we authorize to access End User Data on our behalf is subject to appropriate confidentiality contractual or statutory duty obligations with respect to End User Data.
Upon termination or expiration of the Terms concluded between you and us, we shall delete all End User Data in our possession or control, except that this requirement shall not apply to the extent we are required by applicable law or respective contractual obligations to retain some or all of End User Data.
We agree to provide reasonable assistance to the Customer, when acting as a data processor, regarding:
(i) any request from a data subject in respect of access to or the rectification, erasure, restriction, portability, blocking or deletion of End User Data that we process on behalf of the Customer. In the event that a data subject sends such a request directly to us, Section 7 of this DPA shall apply;
(ii) the investigation of Security Incident and communication of necessary notifications regarding such Security Incident subject to Section 6.4 of this DPA;
(iii) preparation of data protection impact assessments and, where necessary, consultation of the Customer with the Supervisory Authority under Articles 35 and 36 of the GDPR.
If a Supervisory Authority requires an audit of the data processing facilities from which we process End User Data to ascertain or monitor Customer’s compliance with Data Protection Laws and Regulations, we will cooperate with such audit. The Customer is responsible for all costs and fees related to such audit, including all reasonable costs and fees for any and all time we expend for any such audit, in addition to the rates for services performed by us.
The Customer may, prior to the commencement of processing and at regular intervals thereafter, audit the technical and organisational measures taken by us. If the Customer is the controller with respect to the personal data processed by us on its behalf, upon reasonable and timely advance agreement, during regular business hours and without interruption to our business operations, we may provide the Customer with all information necessary to demonstrate compliance with its obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer with respect to such processing.
We shall, upon a Customer’s written request and within a reasonable period, provide the Customer with all information necessary for such audit, to the extent that such information is within our control and we are not precluded from disclosing it by applicable law, a duty of confidentiality, or any other obligation owed to a third party.
In the event that a data subject contacts us with regard to the exercise of their rights under the Data Protection Laws and Regulations (in particular, requests for access to, rectification or deletion of End User Data) when acting as a data processor, we will use all reasonable efforts to forward such requests to you. If we are legally required to respond to such a request, we shall immediately notify you and provide you with a copy of the request unless we are legally prohibited from doing so.
This Section shall apply only with respect to the processing of personal data carried out in the context of the provision of the services by the Company to the Customer when the Parties act as the joint controllers.
In accordance with Article 26 of the GDPR, the Parties hereby determine their responsibilities for compliance with their obligations under the GDPR.
When processing personal data as joint controllers under Section 8 of this DPA, each Party agrees that it shall:
(i) comply with requirements arising to its role under the Data Protection Laws and Regulations;
(ii) maintain a record of the processing activities under its responsibility;
(iii) implement appropriate technical and organizational measures as defined in Schedule 4 of this DPA to protect the personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access;
(iv) take all the measures necessary to address the Security Incident relating to the personal data it processes (if any), mitigate its effects, prevent further Security Incidents, notify the other Party about the Security Incident, and, when required, notify the competent supervisory authority(ies) and the data subjects;
(v) cooperate with the preparation of the data protection impact assessments where required;
(vi) handle data subject’s requests it receives, in particular, the requests relating to the exercise of data subject’s rights under the Data Protection Laws and Regulations;
(vii) provide the other Party with reasonable assistance in complying with any data subject access request;
(viii) notify the other Party about the receipt of the data subject request in respect of personal data processing by the other Party covered by this DPA;
(ix) when one Party receives a request from a data subject regarding his or her personal data that is processed by the other Party, it should redirect the request to the other Party. The redirecting Party should explain to the data subject how he or she can exercise his or her rights with the other Party;
(x) not disclose or release any personal data in response to a data subject request without prior consulting the other Party where necessary;
(xi) notify the other Party without undue delay on becoming aware of any breach of the provisions of the GDPR;
(xii) designate a contact point through which the Parties can be contacted in respect of queries or complaints in relation to issues covered by this DPA or any other data protection issues.
When processing personal data as joint controllers under Section 8 of this DPA, the Company shall:
(i) comply with all obligations listed in subsection 8.1.;
(ii) be responsible for the creation and publication of the Company’s Privacy Policy and additional policies;
(iii) process the personal data only for the purposes defined in its Privacy Policy, additional policies, and other internal information security policies;
(iv) inform the Company’s contact point in respect of queries or complaints in relation to issues covered by this DPA or any other data protection issues;
(v) comply with other obligations established by the GDPR.
When processing personal data as joint controllers under Section 8 of this DPA, the Customer shall:
(i) comply with all obligations listed in subsection 8.1.;
(ii) provide the Company with evidence of the data subject’s consent collection when required;
(iii) be responsible for the creation and publication of the Customer’s Privacy Policy and additional policies;
(iv) process the personal data only for the purposes defined in its Privacy Policy, additional policies, and other internal information security policies;
(v) inform the Customer’s contact point in respect of queries or complaints in relation to issues covered by this DPA or any other data protection issues
(vi) comply with other obligations established by the GDPR.
The Parties established their contact points as follows:
Parties agree that when the processing of End User Data on behalf of the Customer in connection with Services constitutes a transfer under Data Protection Laws and Regulations and appropriate safeguards are required, such processing will be subject to the Standard Contractual Clauses and/or UK Addendum which are deemed to be incorporated into and form part of this DPA as further described in subsections 9.2 and 9.3 of this DPA. If and to the extent the EU SCCs and/or UK Addendum, as applicable, conflict with any provision of the DPA, the EU SCCs and UK Addendum shall prevail to the extent of such conflict.
When the processing of End User Data on behalf of the Customer in connection with Services does not constitute a transfer under Chapter V of the GDPR, the Standard Contractual Clauses and/or UK Addendum are used to impose obligations on the data processor under Article 28 of the GDPR and employ additional data protection safeguards during data transmission between controllers to the extent that such clauses are not in conflict with the Data Protection Laws and Regulations.
When the processing of End User Data, including when the Company processes End User Data on behalf of the Customer in connection with Services, constitutes a “transfer” under the GDPR and in other cases under this DPA, Standard Contractual Clauses shall apply. When you act as a controller, and we act as a controller (together as joint controllers), Module One of the EU SCCs shall apply, and when you act as a controller, and we act as a processor, Module Two of the EU SCCs shall apply.
For the purpose of the EU SCCs, when the Company and the Customer act as joint controllers, including the case when we obtain data from the Customer under Supply Side Platform services, we are a “data importer”, and the Customer is a “data exporter”; when we transfer data to the Customer under Demand Side Platform services we are a “data exporter”, and the Customer is a “data importer”. When the Customer acts as a data controller, and the Company acts as a data processor under White Label AdExchange, White Label Supply Side Platform, White Label Demand Side Platform services, we are a “data importer”, and the Customer is a “data exporter”. The relevant provisions contained in the EU SCCs are incorporated by reference and are an integral part of this DPA. Clauses and annexes of the EU SCCs deemed to be completed are as follows:
(i) in Clause 7, the optional docking clause shall not apply;
(ii) in Clause 9, Option 2 (the General Written Authorisation) shall apply. For the purpose of Clause 9(a), the time period for informing of data exporter shall be 1 month;
(iii) in Clause 11, the optional provision shall not apply;
(iv) in Clause 13, where the Customer acts as a data exporter, a particular option shall apply depending on the specific case, and where the Company acts as a data exporter, Option 1 shall apply;
(v) in Clause 17, Option 1 shall apply. The EU SCCs shall be governed by the law of the Republic of Poland;
(vi) in Clause 18(b), disputes shall be resolved by the courts of the Republic of Poland;
(vii) Annex I of the EU SCCs is deemed completed with the information set out in Schedules 1, 2 and 3 of this DPA, depending on the specific case;
(viii) Annex II of the EU SCCs is deemed completed with the information set out in Schedule 4 of this DPA.
When the processing of End User Data on behalf of the Customer in connection with Services constitutes a “restricted transfer” under UK Data Protection Laws and in other cases under this DPA, the UK Addendum shall apply. When you act as a controller, and we act as a controller (together as joint controllers), Module One of the EU SCCs shall apply, and when you act as a controller, and we act as a processor, Module Two of the EU SCCs shall apply, as completed in subsection 9.2 of this DPA.
For the purpose of the UK Addendum, when the Company and the Customer act as joint controllers, including the case when we obtain data from the Customer under Supply Side Platform services, we are a “data importer”, and the Customer is a “data exporter”; when we transfer data to the Customer under Demand Side Platform services we are a “data exporter”, and the Customer is a “data importer”. When the Customer acts as a data controller and the Company acts as a data processor under White Label AdExchange, White Label Supply Side Platform, White Label Demand Side Platform services, we are a “data importer”, and the Customer is a “data exporter”. The relevant provisions contained in the UK Addendum are incorporated by reference and are an integral part of this DPA. Tables in the UK Addendum deemed to be completed as follows:
(i) Table 1 in Part 1 is deemed completed with the information set out in Schedules 1, 2 and 3 of this DPA. When the Company acts as a data importer, the official registration number of the importer is 0000867869, and the official registration number of the exporter is contained in the Customer’s account, if any.
When the Company acts as a data exporter, the official registration number of the importer is contained in the Customer’s account (if any), and the official registration number of the exporter is 0000867869;
(ii) Table 2 in Part 1 is deemed completed accordingly with the information set out in subsection 9.2 of this DPA;
(iii) Table 3 in Part 1 is deemed completed with the information set out in Schedules 1, 2 and 3 of this DPA, depending on the specific case;
(iv) in Table 4 in Part 1, neither party may end this Addendum as set out in Section 19 of the UK Addendum.
Data exporter
Name: You, «Publisher», «Customer»
Address: the relevant information is contained in the Customer’s account.
Contact person’s name, position and contact details: the relevant information is contained in the Customer’s account.
Signature and date: By entering into the Terms, the data exporter is deemed to have signed the EU SCCs incorporated herein, including their Annexes, as of the effective date of the Terms.
Role: controller
Data importer
Name: BidsCube SP. Z.O.O
Address: str.Odrzanska 6A /6, Wroclaw, Lower, Silesian Voivodeship, Poland 50-113
Contact person’s name, position and contact details: Dmytro Chebakov, support@bidscube.com
Signature and date: By entering into the Terms, the data importer is deemed to have signed the EU SCCs incorporated herein, including their Annexes, as of the effective date of the Terms.
Role: controller
In accordance with Clause 13, competent supervisory authority under these Clauses is determined depending on what version of Clause 13(a) applies to the data exporter.
Data exporter
Name: BidsCube SP. Z.O.O
Address: str.Odrzanska 6A /6, Wroclaw, Lower, Silesian Voivodeship, Poland 50-113
Contact person’s name, position and contact details: Dmytro Chebakov, support@bidscube.com
Signature and date: By entering into the Terms, the data importer is deemed to have signed the EU SCCs incorporated herein, including their Annexes, as of the effective date of the Terms.
Role: controller
Data importer
Name: You, «Advertiser», «Customer»
Address: the relevant information is contained in the Customer’s account.
Contact person’s name, position and contact details: the relevant information is contained in the Customer’s account.
Signature and date: By entering into the Terms, the data exporter is deemed to have signed the EU SCCs incorporated herein, including their Annexes, as of the effective date of the Terms.
Role: controller
In accordance with Clause 13, the competent supervisory authority under these Clauses is Urząd Ochrony Danych Osobowych (Polish Personal Data Protection Office).
Data exporter
Name: You, «Customer»
Address: the relevant information is contained in the Customer’s account.
Contact person’s name, position and contact details: the relevant information is contained in the Customer’s account.
Signature and date: By entering into the Terms, the data exporter is deemed to have signed the EU SCCs incorporated herein, including their Annexes, as of the effective date of the Terms.
Role: controller
Data importer
Name: BidsCube SP. Z.O.O
Address: str.Odrzanska 6A /6, Wroclaw, Lower, Silesian Voivodeship, Poland 50-113
Contact person’s name, position and contact details: Dmytro Chebakov, support@bidscube.com
Signature and date: By entering into the Terms, the data importer is deemed to have signed the EU SCCs incorporated herein, including their Annexes, as of the effective date of the Terms.
Role: controller
In accordance with Clause 13, competent supervisory authority under these Clauses is determined depending on what version of Clause 13(a) applies to the data exporter.
Your request will be received in a few minutes and our team will get in touch with you as soon as possible!
In the meantime, you can read the latest articles on our AdTech Blog!
Your request will be received in a few minutes and our team will get in touch with you as soon as possible!
In the meantime, you can read the latest articles on our AdTech Blog!