Data Processing Agreement
(annex to the Terms and Conditions—a personal data processing agreement under Article 28 of Regulation (EU) 2016/679, the "GDPR")
ThriveAds s.r.o., with its registered office at Na Folimance 2155/15, 120 00 Prague 2 – Vinohrady, Czech Republic, Company ID No. 22485236, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, File No. 417297 (the "processor")
and
the client under the agreement for the provision of services entered into pursuant to the processor's Terms and Conditions (the "controller")
enter into this Data Processing Agreement. This Data Processing Agreement becomes part of the contractual relationship upon formation of an agreement for the provision of services whose performance involves the processing of personal data.
1. Subject matter, nature, and purpose of processing
- The processor provides the controller with performance marketing services, particularly the management of advertising campaigns on Meta (Facebook and Instagram) and Google, email marketing, lead generation, work with the controller's CRM system, audits, and related consulting. In providing those services, the processor has access to and processes personal data controlled by the client.
- Purpose of processing: exclusively to provide the agreed services, including the setup, management, optimization, and evaluation of advertising campaigns and measurement; the preparation and distribution of email campaigns; the management of contacts and inquiries; and work in the CRM system. The processor must not process the data for its own purposes. If it does so, it will be considered a controller in relation to that processing and will bear all resulting obligations.
- Nature of processing: accessing data in the controller's advertising, analytics, email marketing, and CRM systems; viewing, sorting, and analyzing data; creating and managing audiences and segments; sending communications on the controller's instructions; and collecting and passing inquiries to the controller.
- Duration of processing: for the duration of the agreement for the provision of services.
2. Types of personal data and categories of data subjects
- Types of data: identification and contact data (first name, last name, email address, phone number, and, where applicable, address); social media profiles and identifiers; data about purchasing and customer behavior and order history; the content of communications and inquiries (leads from forms); technical identifiers and cookies; and data contained in audiences, segments, and measurement systems used by advertising and email marketing tools, such as Meta Pixel, Conversions API, Google Ads, CRM systems, and email marketing tools.
- Categories of data subjects: the controller's customers and prospective customers, recipients of its commercial communications, people who submit inquiries (leads), visitors to its website and social media profiles, and users who interact with its advertising.
- Special categories of personal data under Article 9 GDPR are not subject to processing. The controller undertakes not to make such data available to the processor.
3. Controller's instructions
- The processor processes personal data only on the controller's documented instructions, including any transfer to a third country. The agreement for the provision of services, this Data Processing Agreement, and instructions given by email or through project tools constitute documented instructions.
- If the processor believes that an instruction from the controller infringes the GDPR or other law, the processor will inform the controller without undue delay.
- Only the controller may extend the purpose of processing.
4. Security
The processor will implement and maintain technical and organizational measures appropriate to the risk in accordance with Article 32 GDPR, including:
- protecting access to devices and accounts with unique login credentials and multi-factor authentication where available;
- limiting access to personal data to people who need it to provide the services;
- using software and services that meet standard security requirements and standards applicable in the EU;
- using encryption or other appropriate protection for data in transit and at rest, depending on the nature of the data;
- not creating copies of the controller's databases without the controller's prior consent; and
- processing data only in the form and to the extent necessary for the agreed purpose and not combining data obtained for different purposes.
5. Confidentiality
- The processor will ensure that all people authorized to process personal data, including employees and contractors, have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- The processor will keep personal data and the security measures adopted confidential. This obligation continues after the cooperation ends.
6. Sub-processors
- The controller gives the processor general authorization to engage other processors, including cooperating specialists and online tools necessary to provide the services.
- The processor will inform the controller of intended changes concerning the addition or replacement of sub-processors and give the controller an opportunity to object to those changes.
- The processor will impose by contract on each sub-processor the same data protection obligations as those set out in this Data Processing Agreement and remains liable to the controller for each sub-processor's performance of its obligations as if the processor performed them itself.
7. Assistance to the controller
- The processor will assist the controller in fulfilling the controller's obligation to respond to requests by data subjects to exercise their rights under Articles 12–23 GDPR. A request received directly by the processor will be forwarded to the controller without undue delay.
- Taking into account the nature of the processing and the information available to it, the processor will assist the controller in ensuring compliance with Articles 32–36 GDPR, including security, breach notifications, and data protection impact assessments.
- The processor will notify the controller of a personal data breach without undue delay after becoming aware of it, including a description of the nature of the breach, its likely consequences, and the measures taken.
- The processor will make available to the controller all information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits or inspections conducted by the controller or an auditor mandated by the controller. An audit will be conducted on prior notice, during normal business hours, and in a manner that does not unreasonably disrupt the processor's operations.
8. Transfers to third countries
The processor transfers personal data outside the EU or EEA only when using tools for which the transfer is covered by an adequacy decision adopted by the European Commission or by Standard Contractual Clauses. This applies in particular to the Meta platforms themselves.
9. End of the cooperation
After the provision of services ends, the processor will, at the controller's choice, delete or return all personal data to the controller and delete existing copies, unless EU or Czech law requires the data to be retained. At the same time, the processor will provide the controller with all access credentials for the controller's accounts and remove the processor's own access.
10. Final provisions
- This Data Processing Agreement is governed by the laws of the Czech Republic and the GDPR.
- The parties' liability is governed by Article 82 GDPR and the agreement for the provision of services.
- This Data Processing Agreement is concluded electronically as part of the Terms and Conditions and remains in force for the duration of the agreement for the provision of services. The confidentiality obligations and the obligations under Article 9 survive its termination.
Prague, July 14, 2026