- Version
- 2.0.0
- Published
- Effective
These Data Protection Terms ("DPT") govern the processing of personal data between Adwirk GmbH ("we", "us"), operating the Realpush brand, and each Customer that uses the Services as an Advertiser or Publisher. Capitalised terms have the meaning given in the Definitions at https://realpush.net/legal/definitions or in clause 1.3.
Part A — General
1. Scope, order of precedence and definitions
1.1 The DPT form part of the Advertiser Terms or the Publisher & Supply Terms that the Customer has accepted, and of any Order Form. They apply to personal data that one party makes available to the other, or that we process, in the course of the Services.
1.2 If documents conflict on a data protection matter, the following order applies: (a) mandatory law; (b) data protection terms individually agreed in an Order Form; (c) the Standard Contractual Clauses, where they apply under clause 8; (d) these DPT; (e) the role terms and the policies they incorporate.
1.3 In the DPT:
- "Data Protection Law" means the GDPR, the laws of EU and EEA member states that supplement it or implement Directive 2002/58/EC (in Germany the TDDDG), and any other data protection law that applies to a party's processing.
- "controller", "processor", "personal data breach", "processing" and "data subject" have the meaning given in the GDPR.
- "Delivery Data" means personal data processed to request, auction, deliver, count and bill ads, as described in Annex 1, section A.
- "Conversion Data" means personal data in conversion events that an Advertiser sends to us, as described in Annex 1, section C.
- "Consent Signal" means information sent with an ad request that records a user's choices or the legal status of the request, including TCF and GPP strings and flags for content directed at children.
- "Sub-processor" means a processor we engage to process Conversion Data under Part C.
- "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
2. Allocation of roles
2.1 The parties' roles depend on the processing operation. They are:
| Processing operation | Our role | Customer's role | Applicable part |
|---|---|---|---|
| Delivery Data exchanged with a Publisher or Supply Partner (ad requests, impressions, clicks, Consent Signals) | Independent controller | Independent controller | Part B |
| Delivery Data in reports to an Advertiser | Independent controller | Independent controller | Part B |
| Data an Advertiser collects on its Destinations, including through trackers and redirects | Not involved | Controller | Part B, clause 6 |
| Conversion Data, stored, matched to clicks and shown to the Advertiser on its instructions | Processor | Controller | Part C |
| Conversion Data used for our own billing, optimisation and fraud prevention | Independent controller | Independent controller | Part B |
| Data about invalid traffic and investigations | Independent controller | Independent controller | Part B |
| Account, contact, billing and correspondence data about the Customer's staff | Controller | — | Privacy Notice |
| Push subscriptions collected on a Publisher's website | See Part E | See Part E | Part E |
2.2 We do not process Delivery Data on behalf of a Publisher or an Advertiser. Each party decides for itself, and is responsible for, the purposes and means of its own processing of Delivery Data.
2.3 The split for Conversion Data reflects that the same events serve the Advertiser's own measurement and our own billing and fraud prevention. Where we use Conversion Data for our own purposes, we do so as controller and only for the purposes listed in Annex 1, section A.
2.4 Our processing of personal data about the Customer's own staff is described in our Privacy Notice at https://realpush.net/legal/privacy. The Customer will make that notice available to the staff it appoints to use the Services.
3. Obligations of both parties
3.1 Each party complies with Data Protection Law in its own processing and is responsible for having a legal basis for it, for informing data subjects and for answering their requests.
3.2 Neither party will send the other, in ad requests, URLs, sub-IDs, click parameters, postbacks or any other field:
- special categories of personal data (Art. 9 GDPR) or data about criminal convictions;
- names, e-mail addresses (also hashed), phone numbers, postal addresses or account identifiers of end users;
- precise geolocation;
unless the parties have expressly agreed it in an Order Form and a legal basis exists.
3.3 Each party keeps personal data received from the other confidential and uses it only as permitted by the DPT.
3.4 Each party implements technical and organisational measures appropriate to the risk (Art. 32 GDPR). Our measures are described in Annex 2.
3.5 If a party becomes aware of a personal data breach affecting personal data it received from, or shared with, the other party, it informs the other party without undue delay with the information it has and that the other party needs to meet its own obligations, and updates it as more information becomes available.
3.6 If a data subject or an authority contacts a party about processing for which the other party is responsible, the party forwards the request to the other party within 5 Business Days, unless the law forbids it, and the parties give each other reasonable help to answer.
3.7 Each party cooperates with competent supervisory authorities. Where an authority asks a party about processing under the DPT, the other party provides the information it holds that is reasonably needed to answer.
Part B — Controller to controller
4. Purposes
4.1 We process Delivery Data and, as controller, Conversion Data only for the purposes listed in Annex 1, section A, and to comply with our legal obligations.
4.2 The Customer processes the Delivery Data it receives from us only for delivering, measuring, reporting on and billing its ads or inventory, preventing invalid traffic, and complying with its legal obligations, unless it has its own legal basis for another purpose and has informed data subjects of it.
5. Publisher duties
5.1 Transparency. The Publisher informs its users, in a privacy notice on each website or app that sends ad requests to us, that ads are delivered through third-party ad-tech providers, which data they receive, and how users can exercise their choices. It names us or the category of providers to which we belong.
5.2 Consent before device access. The Publisher obtains any consent required by § 25(1) TDDDG, Art. 5(3) of Directive 2002/58/EC or equivalent law before information is stored on or read from a user's device by its pages, by our tags or by tags it loads for us. Where such consent is required and has not been given, the Publisher does not send us data obtained from the device, and does not load our tags in a way that accesses the device.
5.3 Consent Signals. The Publisher, and each Supply Partner for the sources it aggregates:
- passes the Consent Signals generated for a request accurately and without alteration;
- sets the flag for content directed at children where it applies;
- does not create, copy or reuse a Consent Signal that the user did not generate for that request;
- ensures that requests made after a user withdraws consent reflect the withdrawal.
5.4 Evidence of consent. The Publisher keeps records that show the consent it relies on was obtained as required (Art. 7(1) GDPR), including the wording and design of the consent request and the time of the user's choice, for as long as Data Protection Law requires. On our reasonable request, it gives us the information we need to answer a data subject, an authority or a partner within a reasonable time.
5.5 Push subscriptions. A Publisher that collects push subscriptions used through the Services:
- asks for permission with a clear request that does not mislead users about what they are agreeing to, for example by disguising the permission prompt as a verification step or a video player control;
- tells users that the notifications will contain advertising;
- tells users how to unsubscribe;
- records where and when each subscription was collected.
5.6 Downstream sources. A Supply Partner ensures that the publishers and sources whose inventory it sends to us comply with clauses 5.1 to 5.5, and can show this on request.
6. Advertiser duties
6.1 Destinations. The Advertiser is the controller for personal data collected on its Destinations, including through trackers, redirects, pre-landers and landing pages used in its Campaigns, whether it operates them itself or through a Customer Agent. It provides a privacy notice there, obtains any consent required for storing or reading information on the user's device, and has a legal basis for its processing.
6.2 Conversion Data. The Advertiser sends us only the Conversion Data needed to attribute and bill conversions, has a legal basis to send it, and does not include data listed in clause 3.2.
6.3 Targeting inputs. If the Advertiser uploads IP addresses, ranges or other identifiers for targeting or exclusion, it has a legal basis to do so and does not upload data that identify individual end users unless agreed in an Order Form.
7. Our duties
7.1 We inform data subjects about our processing in our Privacy Notice.
7.2 We pass on Consent Signals we receive, as received, with the ad requests we send to bidders.
7.3 We keep Delivery Data only for the periods stated in our Privacy Notice.
7.4 We answer data subjects' requests that concern our processing.
8. International transfers
8.1 A party transfers personal data to a country outside the EEA that has no adequacy decision of the European Commission only if a safeguard under Article 46 GDPR or another lawful transfer mechanism applies.
8.2 To the extent that a transfer between the parties under the DPT requires it, the parties agree to the SCCs, which are incorporated by reference, with the following modules:
- Module One (controller to controller): transfers of Delivery Data or Conversion Data between us and a Customer acting as controller;
- Module Four (processor to controller): where we act as processor under Part C and return Conversion Data to an Advertiser established outside the EEA;
- Module Two (controller to processor): where we act as processor under Part C, the Advertiser is subject to the GDPR and we process the data outside the EEA.
For each module, the party sending the data is the data exporter, Annex 1 of the DPT completes Annex I of the SCCs, Annex 2 of the DPT completes Annex II, and Annex 3 of the DPT completes Annex III. The optional docking clause (Clause 7) applies. Clause 11 (redress) applies without the optional wording. For Clause 13, the competent supervisory authority is the one determined under that clause. For Clauses 17 and 18, the SCCs are governed by the law of, and disputes are resolved by the courts of, the EU member state determined in the role terms, or, if that is not an EU member state, Germany.
8.3 If the SCCs are replaced or amended, the parties will use the new version for new transfers.
Part C — Processing on behalf of Advertisers (Article 28 GDPR)
9. Scope
9.1 Part C applies when we store Conversion Data, match it to clicks and show it to the Advertiser in reports or through the API, on the Advertiser's instructions. Annex 1, section C describes this processing.
9.2 Our use of the same data for our own purposes (clause 2.3) is governed by Part B.
10. Instructions
10.1 We process Conversion Data only on the Advertiser's documented instructions, including with regard to transfers to a third country, unless the law requires otherwise; in that case we inform the Advertiser before processing unless the law forbids it.
10.2 The DPT, the Advertiser's configuration of its postbacks and campaigns in the cabinet or API, and written or electronic instructions agreed later are the Advertiser's documented instructions.
10.3 We inform the Advertiser without undue delay if, in our opinion, an instruction infringes Data Protection Law. We may suspend that instruction until it is confirmed or changed.
11. Confidentiality
11.1 We ensure that persons authorised to process Conversion Data are bound by confidentiality or are under an appropriate statutory obligation of confidentiality.
12. Security
12.1 We implement the measures described in Annex 2. We may change them, provided that the overall level of protection is not reduced.
13. Sub-processors
13.1 The Advertiser authorises us to engage the Sub-processors listed in Annex 3.
13.2 We inform the Advertiser by e-mail or in the cabinet at least 30 days before we add or replace a Sub-processor. The Advertiser may object on reasonable grounds relating to data protection within that period. If we cannot resolve the objection, the Advertiser may terminate the affected Services with effect from the change, without a termination fee.
13.3 We impose on each Sub-processor, by contract, data protection obligations that give at least the protection required by Article 28(3) GDPR. We remain responsible to the Advertiser for the performance of each Sub-processor's obligations.
14. Assistance
14.1 Taking into account the nature of the processing and the information available to us, we assist the Advertiser:
- by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from data subjects under Chapter III GDPR;
- in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment and prior consultation).
14.2 If a data subject contacts us directly about Conversion Data, we forward the request to the Advertiser and do not answer it ourselves unless the Advertiser instructs us to.
15. Personal data breaches
15.1 We notify the Advertiser of a personal data breach affecting Conversion Data without undue delay, and in any case within 48 hours, after becoming aware of it.
15.2 The notice describes, as far as we know at that time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we do not have all the information at once, we provide it in phases without undue further delay.
16. Deletion and return
16.1 When the processing under Part C ends, we delete the Conversion Data, or return it and then delete it if the Advertiser asks for this before the end, within 30 days, unless the law requires us to keep it.
16.2 Data that we also hold as controller under Part B, such as records that support an invoice, are kept under Part B and our Privacy Notice.
17. Information and audits
17.1 We make available to the Advertiser the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, by the Advertiser or an auditor it mandates.
17.2 Audits are proportionate. We first answer written questions and provide documentation. An inspection on site or of our systems takes place only if that information is not sufficient, after a personal data breach affecting the Advertiser's data, or where a supervisory authority requires it.
17.3 An inspection is announced at least 30 days in advance, takes place during business hours without disrupting operations, does not give access to other customers' data or to security details whose disclosure would put the Services at risk, and is carried out by persons bound to confidentiality. It takes place at most once in any twelve-month period unless one of the reasons in clause 17.2 for an inspection arises again. Each party bears its own costs, unless the audit shows a material breach of Part C by us.
18. Duration
18.1 Part C applies for as long as we process Conversion Data for the Advertiser, and its obligations continue until the data are deleted or returned.
Part D — Final provisions
19. Liability
19.1 Each party's liability toward data subjects is governed by Article 82 GDPR and cannot be limited by the DPT.
19.2 Between the parties, liability under the DPT is governed by the liability clause of the role terms. Where a party has paid full compensation to a data subject under Article 82(4) GDPR, it may claim back from the other party the part of the compensation corresponding to that party's responsibility (Article 82(5)).
19.3 Administrative fines are borne by the party on which they are imposed, to the extent the law does not allow them to be shifted.
20. Term and survival
20.1 The DPT apply for as long as either party processes personal data received under the role terms. Obligations that by their nature continue, including confidentiality, deletion, cooperation and liability, survive the end of the role terms.
21. Changes
21.1 We may change the DPT to reflect changes in the law, in guidance of supervisory authorities or in the Services. We publish each version in the Legal Hub with a version number.
21.2 Material changes require notice to the Customer and, where the role terms or the law require it, the Customer's acceptance. They apply only from their effective date. A Customer's continued use of the Services is not acceptance of a material change.
21.3 Changes to the list of Sub-processors follow clause 13.2.
22. Governing law
22.1 The DPT are governed by the law that governs the role terms, except that the SCCs are governed as stated in clause 8.2.
Part E — Joint collection of push subscriptions
23. Joint responsibility
23.1 Where a Publisher collects push subscriptions on its website that are used to deliver ads through the Services, the Publisher and we are jointly responsible for the collection of the subscription and its transmission to us. Each party is solely responsible for its processing after that.
23.2 The Publisher:
- provides the information required by Articles 13 and 26(2) GDPR to users at the point of subscription, including that ads will be delivered through us;
- obtains the user's consent to receive notifications as described in clause 5.5.
23.3 We:
- make the essence of this arrangement available in our Privacy Notice;
- process subscriptions only to deliver notifications, count deliveries and clicks, prevent invalid traffic and honour unsubscribes;
- answer data subjects' requests that concern subscriptions we hold.
23.4 A data subject may exercise its rights against either party. A party that receives a request that the other party must answer forwards it under clause 3.6.
Annex 1 — Description of the processing
A. Controller-to-controller: Delivery Data and our own use of Conversion Data
| Item | Description |
|---|---|
| Data subjects | End users who request, see or click ads delivered through the Services |
| Categories of data | IP address; browser user agent; device type, operating system and version, browser, language; country derived from the IP address or supplied; domain, page URL or app identifier; referring page; publisher, placement and sub-source identifiers; identifiers assigned by the Supply Partner; request, auction, impression and click identifiers; time; bid and price data; Consent Signals; conversion click identifier, time, type and value |
| Special categories | None (clause 3.2) |
| Our purposes | Running auctions; selecting and delivering ads; frequency limiting; counting Billable Events; reporting; billing; detecting and preventing invalid traffic and fraud; establishing, exercising or defending legal claims; complying with legal obligations |
| Customer's purposes | Clause 4.2 |
| Nature of processing | Collection from ad requests and browsers, transmission to bidders, storage, aggregation, analysis, deletion |
| Recipients | DSPs, exchanges and advertisers' platforms that may bid; Advertisers (reports); our processors in Annex 3 and our other infrastructure providers |
| Frequency | Continuous, for the term of the role terms |
| Retention by us | Event-level data: 13 months; fraud signals: 3 years; data supporting invoices: statutory periods; data under legal hold: until the matter is closed |
B. Push subscriptions
| Item | Description |
|---|---|
| Data subjects | Users who subscribed to browser notifications on a Publisher's website |
| Categories of data | Push endpoint address and keys; subscription time; browser, operating system, language, country; website of subscription; delivery and click history |
| Purposes | Delivering notifications; counting deliveries and clicks; preventing invalid traffic; honouring unsubscribes |
| Retention by us | Until unsubscribe or invalid endpoint, then 30 days |
C. Processing on behalf of Advertisers (Part C)
| Item | Description |
|---|---|
| Subject matter | Storage, attribution and reporting of the Advertiser's conversion events |
| Duration | Term of the Advertiser Terms, then until deletion under clause 16 |
| Nature and purpose | Receiving postbacks, matching them to clicks, storing them, showing them in the cabinet and API |
| Data subjects | End users who clicked an Advertiser's ad and converted |
| Categories of data | Click identifier; conversion time, type and value; campaign and sub-identifiers; other fields the Advertiser configures (clause 6.2) |
| Special categories | None |
| Sub-processors | Annex 3 |
D. Contact points
| Party | Contact |
|---|---|
| Us | [email protected] |
| Customer | The privacy contact the Customer gives in its Account, or failing that the Account's main e-mail address |
Annex 2 — Technical and organisational measures
1. Measures for all brands
1.1 Encryption in transit. Our websites and payment pages are served over HTTPS (TLS).
1.2 Least privilege. Access to personal data is limited to staff and service providers who need it for their tasks.
2. Cabinet and ad delivery platform
2.1 The cabinet and ad delivery software is provided by a third-party software vendor as our processor. Its technical and organisational measures are those agreed in our data processing agreement with it.
Annex 3 — Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Content delivery, TLS termination, edge routing | United States and other countries of its network |
| DataWeb Global Group B.V. (Advanced Hosting) | Hosting of our servers | Netherlands |
| a third-party software vendor | Cabinet and ad delivery platform | not yet confirmed by the provider |