1. Scope and order of precedence
This DPA forms part of the GuardPPC Terms of Service and applies only to the extent GuardPPC processes personal data on a customer’s behalf while providing the service. If there is a conflict between this DPA and the Terms on processor obligations, this DPA controls for that subject matter.
This page summarizes GuardPPC’s standard processor commitments. Enterprise customers that need execution-ready contracting language or transfer addenda should contact GuardPPC directly.
2. Roles of the parties and customer instructions
As between the parties, the customer is the controller or business for customer data submitted to GuardPPC, and GuardPPC acts as a processor or service provider when handling that data to operate the service.
- Documented instructions. GuardPPC processes personal data only to provide the contracted service, maintain security, deliver support, and comply with lawful instructions or legal obligations.
- Customer responsibilities. The customer is responsible for establishing a lawful basis for processing, providing required notices, and obtaining any consents needed for the use of GuardPPC tracking, analysis, and fraud-response workflows.
- Independent controller data. GuardPPC remains the controller for account administration, billing, support relationship data, website analytics, and other information we collect directly to run our business.
3. Subject matter, duration, and categories of data
The subject matter of the processing is GuardPPC’s provision of click-fraud detection, traffic-quality analytics, session evidence, rule execution, exclusion synchronization, reporting, and customer support. Processing continues for the duration of the customer’s use of the relevant services and any limited post-termination period needed for secure deletion, return, or legal retention.
- Categories of data subjects. Website visitors, ad clickers, leads, customers, prospects, and authorized users whose data is included in campaign, website, or support workflows.
- Categories of personal data. IP addresses, click timestamps, landing pages, referrers, campaign identifiers, browser and device information, user-agent strings, network and location indicators, session activity, exclusion events, and related support or account metadata.
- Sensitive data. GuardPPC is not designed for special-category or highly sensitive personal data. Customers should not submit such data unless GuardPPC has expressly agreed in writing to support that use case.
4. Processing limits and permitted use
GuardPPC processes customer data only to the extent reasonably necessary to provide and secure the service, investigate incidents, prevent abuse, support the customer, and meet legal obligations. We do not sell customer personal data or process it for unrelated advertising purposes.
- Core service operations. Storage, analysis, scoring, reporting, alerting, replay, automation, exclusion syncing, and troubleshooting required to operate GuardPPC.
- Service protection. Logging, abuse prevention, vulnerability response, and system monitoring needed to preserve the confidentiality, integrity, and availability of the service.
- Improvement data. GuardPPC may derive aggregated or de-identified statistics from customer usage for service improvement, provided those statistics do not identify the customer or any natural person.
5. Subprocessors
GuardPPC may engage subprocessors to provide infrastructure, hosting, analytics, communications, support, security, or payment services that help us deliver the platform. GuardPPC remains responsible for its subprocessors to the extent required by applicable law and our contract with the customer.
- Contractual controls. Each subprocessor that handles customer personal data must be bound by written terms that require appropriate confidentiality, security, and data-protection measures.
- Changes to subprocessors. GuardPPC may update its subprocessor list from time to time. Customers with a reasonable, data-protection-based objection to a new subprocessor may contact us to discuss alternatives.
- Access minimization. Subprocessors receive only the access needed for their assigned function and may not use customer data for unrelated purposes.
6. Security and security incidents
GuardPPC implements technical and organizational measures appropriate to the nature of the data and the risks presented by our service, including measures designed to control access, protect data in transit, log privileged activity, and reduce the likelihood of unauthorized disclosure or misuse.
- Confidentiality controls. Access to customer data is limited to authorized personnel and subprocessors with a need to know and who are bound by confidentiality obligations.
- Security incident notice. If GuardPPC confirms a security incident affecting customer personal data, we will notify the affected customer without undue delay and provide information reasonably available to help the customer assess impact and response steps.
- Evolving safeguards. GuardPPC may update security controls over time as technology, threat conditions, and service architecture evolve, provided those changes do not materially reduce the overall level of protection for the purchased service.
Additional operational detail is available on our Data Security page.
7. Audits, documentation, and assistance
GuardPPC will provide reasonable information needed for customers to assess our compliance with this DPA, subject to confidentiality obligations, proportionality, and the protection of other customers and system security.
- Security documentation. Upon reasonable request, GuardPPC may provide summaries of relevant controls, questionnaire responses, or other compliance information appropriate to the customer relationship.
- Data subject requests. Taking into account the nature of the processing, GuardPPC will reasonably assist customers in responding to access, deletion, correction, portability, or objection requests when the customer cannot do so independently through the service.
- Regulatory cooperation. Where required by applicable law and reasonably necessary, GuardPPC will help customers with data protection impact assessments, regulator inquiries, or related documentation tied to GuardPPC processing.
8. International transfers
GuardPPC and its subprocessors may process customer personal data in countries outside the one in which the data was collected. When cross-border transfer restrictions apply, GuardPPC will rely on an appropriate transfer mechanism, such as standard contractual clauses or another legally recognized safeguard.
- Transfer safeguards. GuardPPC will implement contractual, technical, and organizational measures appropriate to the nature of the transfer and applicable law.
- Government requests. Where legally permitted, GuardPPC will review and appropriately respond to government or regulatory disclosure requests involving customer personal data.
9. Return, deletion, and retention
Upon termination or expiration of the relevant service, GuardPPC will delete or return customer personal data in accordance with the customer’s instructions, the service functionality, and applicable law. Residual copies may remain temporarily in secured backups until overwritten in the ordinary course.
GuardPPC may retain limited data where retention is required for security, fraud prevention, legal compliance, dispute resolution, or enforcement of our agreements, in which case the data will remain protected and processed only for those purposes.
10. Miscellaneous and contact
Except as modified by this DPA, the GuardPPC Terms of Service remain in effect. This DPA is governed by the governing-law provisions in the Terms unless applicable data protection law requires a different result.
For DPA execution requests, subprocessor questions, transfer mechanism documentation, or enterprise privacy reviews, contact hello@guardppc.com.