Data Processing Agreement

Last updated: February 7, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Lazy Ads (“Processor” or “we”) and the entity or person using our services (“Controller” or “you”) as set forth in our Terms of Service (the “Agreement”).

This DPA applies where and only to the extent that Lazy Ads processes Personal Data on behalf of the Controller in the course of providing the Service, and such Personal Data is subject to Data Protection Laws. This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and equivalent provisions in other applicable data protection legislation.

1. Definitions

In this DPA, the following terms have the following meanings:

  • “Personal Data” means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller through the Service.
  • “Data Protection Laws” means all applicable data protection and privacy legislation, including the GDPR, the UK GDPR, the California Consumer Privacy Act (CCPA), and any implementing or supplementary legislation.
  • “Data Subject” means the identified or identifiable natural person to whom the Personal Data relates.
  • “Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • “Processing” means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
  • “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
  • “Standard Contractual Clauses” (“SCCs”) means the standard contractual clauses approved by the European Commission for the transfer of Personal Data to processors established in third countries.

2. Scope and Purpose of Processing

2.1 Subject Matter

The Processor processes Personal Data on behalf of the Controller to provide the Lazy Ads AI-powered advertising management platform as described in the Agreement.

2.2 Nature and Purpose

The processing is carried out for the following purposes:

  • Providing and operating the Lazy Ads platform and services.
  • Managing advertising campaigns across connected platforms.
  • Generating AI-powered ad content and optimization recommendations.
  • Processing analytics and campaign performance data.
  • Processing payments and managing subscriptions.
  • Providing customer support and communications.

2.3 Types of Personal Data

The following categories of Personal Data may be processed:

  • Contact information (name, email address, phone number).
  • Account credentials (email, hashed passwords).
  • Business information (company name, industry, website URL).
  • Advertising account data (campaign metrics, audience parameters, ad content).
  • Payment information (billing address, payment method details via Stripe).
  • Usage data (platform interactions, feature usage, log data).
  • Device data (IP address, browser type, operating system).

2.4 Categories of Data Subjects

The Data Subjects may include:

  • The Controller's employees and authorized users.
  • The Controller's customers and prospects (as reflected in advertising audiences).
  • End users who interact with the Controller's advertisements.

2.5 Duration

The processing will continue for the duration of the Agreement and as specified in Section 10 (Data Deletion/Return) of this DPA.

3. Data Processor Obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. Where required by law, the Processor shall inform the Controller of that legal requirement before processing (unless the law prohibits such disclosure).
  • Ensure that all persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in Section 4.
  • Not engage another processor (Sub-processor) without the prior written authorization of the Controller, as detailed in Section 5.
  • Assist the Controller in fulfilling its obligations to respond to Data Subject requests, as detailed in Section 7.
  • Assist the Controller in ensuring compliance with security, breach notification, data protection impact assessments, and prior consultation obligations under applicable Data Protection Laws.
  • At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of services and delete existing copies, as detailed in Section 10.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor.

4. Security Measures

The Processor shall implement and maintain the following technical and organizational security measures:

  • Encryption: Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256).
  • Access Control: Role-based access control (RBAC) with the principle of least privilege. Multi-factor authentication (MFA) for all employee access to systems processing Personal Data.
  • Monitoring: Continuous monitoring and logging of access to systems processing Personal Data, with automated alerting for suspicious activity.
  • Infrastructure Security: Hosting on Google Cloud Platform with SOC 2 Type II and ISO 27001 certifications. Network segmentation, firewalls, and intrusion detection systems.
  • Data Backup: Regular encrypted backups with tested restoration procedures. Backups stored in geographically separate locations.
  • Incident Response: Documented incident response plan with defined roles, procedures, and escalation paths.
  • Employee Training: Regular data protection and security training for all employees who process Personal Data.
  • Vulnerability Management: Regular vulnerability assessments and penetration testing. Timely patching of known security vulnerabilities.

5. Sub-processors

5.1 Authorization

The Controller provides general written authorization for the Processor to engage Sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object to such changes within 30 days.

5.2 Current Sub-processors

The following Sub-processors are currently engaged in the processing of Personal Data:

Sub-processorPurposeLocation
Stripe, Inc.Payment processing, subscription management, fraud preventionUnited States
Google Cloud PlatformCloud infrastructure, data hosting, compute servicesUnited States (us-central1)
OpenRouterAI model inference for ad generation and optimization (anonymized data only)United States
ResendTransactional email delivery (notifications, alerts, communications)United States
PostHogProduct analytics, session recording, feature flagsUnited States (Cloud-hosted)

5.3 Sub-processor Obligations

The Processor shall ensure that each Sub-processor is bound by data protection obligations no less protective than those set out in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-processor's obligations.

6. International Data Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, the Processor shall ensure that such transfers are made in compliance with applicable Data Protection Laws and that appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs) as approved by the European Commission.
  • UK International Data Transfer Agreement or UK Addendum to the EU SCCs.
  • Transfer to countries recognized as providing adequate data protection.
  • Supplementary measures as required to address specific risks.

7. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests exercising their rights under Data Protection Laws, including:

  • Right of access to Personal Data.
  • Right to rectification of inaccurate Personal Data.
  • Right to erasure (“right to be forgotten”).
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.

If the Processor receives a request directly from a Data Subject, the Processor shall promptly notify the Controller and shall not respond to such request directly unless authorized to do so by the Controller or required by applicable law.

8. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. The notification shall include:

  • A description of the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned.
  • The name and contact details of the Processor's data protection contact point where more information can be obtained.
  • A description of the likely consequences of the Personal Data Breach.
  • A description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

The Processor shall cooperate fully with the Controller and take all reasonable commercial steps to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

9. Audits and Compliance

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA.

The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Such audits shall be subject to reasonable advance notice (minimum 30 days) and shall be conducted during normal business hours in a manner that does not unreasonably disrupt the Processor's operations.

The Controller shall bear its own costs for any audit. The Processor may charge reasonable fees for time spent assisting with an audit that exceeds one business day per calendar year.

10. Data Deletion and Return

Upon termination of the Agreement or upon the Controller's written request, the Processor shall, at the Controller's choice:

  • Return: Return all Personal Data to the Controller in a commonly used, machine-readable format (e.g., JSON or CSV).
  • Delete: Securely delete all Personal Data and existing copies, unless retention is required by applicable law.

The Processor shall complete the return or deletion of Personal Data within 30 days of the request. The Processor shall provide written certification of deletion upon the Controller's request.

Personal Data that is stored in backup systems shall be securely deleted within 90 days following the deletion from primary systems, or shall be isolated and protected from further processing until deletion is possible.

11. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement, except that nothing in this DPA or the Agreement shall limit either party's liability for breaches of Data Protection Laws that cannot be limited by contract.

12. Governing Law

This DPA shall be governed by and construed in accordance with the governing law provisions of the Agreement, except that where the GDPR applies, this DPA shall be governed by the law of the EU Member State in which the Controller is established.

13. Contact

For questions about this Data Processing Agreement or to request execution of a DPA tailored to your enterprise requirements, please contact us:

DPA Inquiries: dpa@lazyads.ai

General Privacy: privacy@lazyads.ai

Company: Lazy Ads

Website: https://lazyads.ai