Get in touch
Legal

Data Processing Addendum

Incorporated into every Nasrev agreement. Sets out roles, security measures, sub-processors, breach notification and international transfers.

Version 1.0Effective 1 September 2026 Nasrev LLC — 8 Holmes Ave, Apt 2, Jersey City, New Jersey, 07306, USA

Scope and roles

This Data Processing Addendum (“DPA”) forms part of the Master Services Agreement between Nasrev LLC and the Partner and applies to all processing of Personal Data under it.

The Parties acknowledge that in respect of data processed through the advertising exchange, each Party acts as an independent controller determining its own purposes and means. Where Nasrev processes Personal Data solely on the documented instructions of the Partner, Nasrev acts as a processor and sections 4 to 9 apply.

Definitions. “Personal Data”, “controller”, “processor”, “data subject” and “processing” have the meanings given in the GDPR. “Data Protection Laws” means the EU GDPR, the UK GDPR and Data Protection Act 2018, the CCPA as amended by the CPRA, and all other applicable privacy laws.

Subject matter and duration

ItemDetail
Subject matterProvision of real-time bidding advertising services
DurationThe term of the Master Services Agreement, plus any retention period in section 9
Nature and purposeTransmission and receipt of bid requests, auction execution, frequency capping, fraud detection, measurement and reporting
Categories of data subjectEnd users of the Properties on which advertising is served
Categories of Personal DataOnline identifiers, IP address, device and browser identifiers, mobile advertising IDs, approximate location, user agent, consent strings, interaction events
Special categoriesNone. Neither Party shall transmit special category data through the exchange

Independent controller obligations

Where the Parties act as independent controllers, each shall:

  1. Establish and maintain a lawful basis for its own processing, including obtaining valid consent where required;
  2. Provide clear and accurate information to data subjects about its processing;
  3. Transmit and honour consent and privacy signals accurately, including IAB TCF, Global Privacy Platform and Global Privacy Control;
  4. Respond to data subject requests it receives in respect of its own processing, and pass on requests properly directed at the other Party;
  5. Not transmit Personal Data of any individual known or reasonably suspected to be under 16;
  6. Notify the other Party without undue delay of any regulatory action or data subject complaint that materially affects the other.

Processor obligations

Where Nasrev acts as a processor, Nasrev shall:

  1. Process Personal Data only on the Partner’s documented instructions, unless required otherwise by law;
  2. Ensure personnel authorised to process the data are bound by confidentiality;
  3. Implement the technical and organisational measures set out in section 6;
  4. Not engage a sub-processor without prior general written authorisation, and give at least thirty (30) days’ notice of any intended change, during which the Partner may object on reasonable data protection grounds;
  5. Assist the Partner, taking account of the nature of processing, with data subject requests, impact assessments and consultations with supervisory authorities;
  6. Make available all information necessary to demonstrate compliance and allow for audits under section 8;
  7. At the Partner’s election, delete or return Personal Data at the end of the relationship, subject to legal retention obligations.

Sub-processors

Nasrev engages sub-processors for cloud hosting, data storage, analytics and fraud verification. A current list is available on request from [email protected]. Nasrev imposes data protection obligations on each sub-processor no less protective than those in this DPA and remains liable for their performance.

Security measures

Nasrev maintains technical and organisational measures including:

  • Encryption of Personal Data in transit using TLS 1.2 or above
  • Access control on a least-privilege basis with multi-factor authentication for administrative access
  • Network segregation between production and non-production environments
  • Logging and monitoring of access to systems containing Personal Data
  • Regular patching and vulnerability management
  • Background-checked personnel bound by written confidentiality obligations
  • A documented incident response procedure, tested periodically
  • Business continuity and backup procedures

Personal data breach

Each Party shall notify the other without undue delay, and in any event within forty-eight (48) hours, of becoming aware of a Personal Data breach affecting data processed under the Agreement. The notification shall describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. The Parties shall cooperate in good faith on remediation and on any required notification to authorities or data subjects.

Audit

The Partner may, on thirty (30) days’ written notice and no more than once in any twelve-month period, audit Nasrev’s compliance with this DPA, either by reviewing documentation Nasrev provides or, where reasonably necessary, by an independent auditor bound by confidentiality. Audits shall be conducted during business hours, shall not unreasonably disrupt operations, and shall be at the Partner’s cost unless a material non-compliance is found.

International transfers

Where this DPA involves transferring Personal Data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the Parties agree that the European Commission’s Standard Contractual Clauses (Decision 2021/914) are incorporated by reference and apply, with Module One (controller to controller) or Module Two (controller to processor) as applicable. For UK transfers, the ICO’s International Data Transfer Addendum applies. The Parties shall complete the annexes using the information in section 2 of this DPA.

Retention and deletion

Nasrev retains bid request and auction logs for no longer than thirteen (13) months, after which they are deleted or irreversibly aggregated. Aggregated reporting data containing no identifiers may be retained for up to twenty-four (24) months. Data required for fraud investigation, billing or legal defence may be retained for as long as necessary for that purpose.

US state privacy laws

For the purposes of the California Consumer Privacy Act as amended, and equivalent laws in Virginia, Colorado, Connecticut, Utah, Texas and other states, each Party is a “business” or “controller” in respect of its own processing. Nasrev does not sell Personal Information and does not share it for cross-context behavioural advertising other than as necessary to run the auction the user’s publisher has enabled. Where Nasrev acts as a “service provider” it shall not retain, use or disclose Personal Information for any purpose other than performing the services, and certifies that it understands and will comply with this restriction.

Order of precedence and contact

In the event of conflict, this DPA prevails over the Master Services Agreement in respect of data protection matters. Where the Standard Contractual Clauses apply, they prevail over this DPA.

Nasrev LLC, 8 Holmes Ave, Apt 2, Jersey City, New Jersey, 07306, USA. Email [email protected].