Data Processing Agreement (DPA)

This English translation is provided for convenience. In case of any discrepancy, the Romanian version prevails.

DATA PROCESSING AGREEMENT (DPA) – seenly.ad

Version 2026-07.3 · Effective date: 25 July 2026 (aligned with version 2026-07.3 of the Terms and Conditions)

This Data Processing Agreement ("DPA") forms an integral part of the seenly.ad Terms and Conditions and applies whenever NOVA MASTERCLASS MARKETING SRL ("seenly.ad", the "Processor") processes personal data on behalf of the Customer (the "Controller") through the use of the service. It is concluded in accordance with Art. 28 of Regulation (EU) 2016/679 ("GDPR").


1. ROLES OF THE PARTIES

The Customer is the Controller for the personal data it makes available to seenly.ad or that seenly.ad accesses on its behalf (data from advertising accounts, store orders, end-customer data). seenly.ad is the Processor and processes such data exclusively in accordance with the Controller's documented instructions. Where the Customer is itself a processor acting for a third party (e.g. an agency working for an advertiser), seenly.ad acts as a sub-processor.


2. SUBJECT MATTER, DURATION, NATURE AND PURPOSE OF PROCESSING

  • Subject matter: the provision of the SaaS service for PPC reporting, feed management and profit analysis.

  • Duration: for the entire term of the contract, plus statutory retention periods.

  • Nature: collection, storage, structuring, analysis, aggregation, display and, upon the Controller's instruction, transmission of data to connected platforms (e.g. uploading per-order profit to Google Ads).

  • Purpose: exclusively the provision of the service's functionalities to the Controller.


3. CATEGORIES OF DATA AND DATA SUBJECTS

Categories of data subjects: the Controller's representatives and users; the end customers of the Controller's store.

Categories of data: identification and contact data of users; transactional and order data; marketing identifiers (gclid, utm, fbclid); the end customer's email address (irreversibly transformed into a SHA-256 hash for LTV calculation, never stored in clear text). seenly.ad does not request and does not intentionally process special categories of data (Art. 9 GDPR).


4. OBLIGATIONS OF THE PROCESSOR

seenly.ad undertakes:

  1. to process the data only on the basis of the Controller's documented instructions (including this DPA and the use of the service), except for obligations imposed by EU or national law;

  2. to ensure that persons authorised to process the data are bound by an obligation of confidentiality;

  3. to implement the appropriate technical and organisational measures set out in Annex 2 (Art. 32 GDPR);

  4. to comply with the conditions for engaging sub-processors (Section 5);

  5. to assist the Controller, insofar as possible, in fulfilling its obligations regarding data subject requests (Art. 12–23) and security, notification and impact assessments (Art. 32–36);

  6. at the Controller's choice, to delete or return all data upon termination of the services and to delete existing copies, except where retention is required by law;

  7. to make available to the Controller the information necessary to demonstrate compliance with Art. 28 and to allow audits (Section 8).


5. SUB-PROCESSORS

The Controller grants a general authorisation for the engagement of sub-processors for the provision of the service. The up-to-date list is published on the Sub-processors page. The sub-processors performing artificial intelligence processing are OpenAI (feed optimisation, recommendations, agents) and Google (Gemini API, for the generation and editing of product images); the data transmitted to them is not used for model training. seenly.ad imposes on each sub-processor data protection obligations at least equivalent to those in this DPA. We will notify the Controller before adding or replacing a sub-processor, and the Controller may object on reasonable grounds related to data protection.


6. INTERNATIONAL TRANSFERS

We prioritise storage and processing within the European Economic Area (EEA). Where a sub-processor processes data outside the EEA (e.g. the USA), the transfer is based on a valid legal mechanism: an adequacy decision (e.g. the EU-US Data Privacy Framework) or Standard Contractual Clauses (SCCs) approved by the European Commission, with supplementary measures where necessary.


7. SECURITY INCIDENTS

seenly.ad will notify the Controller without undue delay (and, insofar as possible, within no more than 72 hours) after becoming aware of a personal data breach affecting the Controller's data, providing the available information necessary for the Controller to comply with its notification obligations.


8. AUDIT

Upon the Controller's written and reasonable request (no more than once per year, except where required by a supervisory authority), seenly.ad will make available the relevant compliance documentation and, where necessary, will allow an audit carried out by the Controller or by a mandated auditor, subject to confidentiality and the security of other customers.


9. DELETION / RETURN OF DATA

Upon termination of the service, the Controller may export the data in a structured format (CSV/JSON). Usage data is deleted 30 days after account closure; billing data is retained for 10 years in accordance with Romanian accounting legislation. Backups are overwritten in accordance with the normal backup cycle.


10. LIABILITY

Each party's liability in connection with this DPA is subject to the limitations and exclusions of liability set out in the seenly.ad Terms and Conditions, to the extent permitted by law.


Annex 1 — Details of processing

The subject matter, nature, purpose, duration, categories of data and of data subjects are those described in Sections 2 and 3 above.

Annex 2 — Technical and organisational measures

  • Encryption in transit (TLS 1.2+) and of sensitive data at rest (tokens, API keys, secrets — encrypted in the database).

  • Role-based access control (RBAC), multi-tenant isolation, 2FA authentication for administrative access.

  • Strong password hashing (bcrypt/argon2); the end customer's email address stored only as a SHA-256 hash.

  • Regular backups; logging and monitoring; the data minimisation principle.


For any question regarding this DPA or to sign a countersigned version, contact us at [email protected].