Data Processing Agreement
Polyads
Last updated: 8 July 2026
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Use (the "Agreement") between Npcat LLC ("Polyads," "we," or "us") and the business customer that has accepted the Agreement (the "Customer" or "you"). It governs the processing of Personal Data in connection with the Polyads service (the "Service").
This DPA reflects how Polyads actually operates. For most data, Polyads is an independent controller, not the Customer's processor (Section 3). Polyads acts as the Customer's processor only for the limited category of Personal Data the Customer provides to be processed on its documented instructions (Section 4). This DPA becomes effective when it is executed by the parties or, absent separate execution, when the Customer provides Customer Personal Data for processing on its instructions.
1. Definitions
Terms not defined here have the meaning given in the Agreement or in Data Protection Law.
- "Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws including the California Consumer Privacy Act as amended (the "CCPA").
- "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," and "processing" have the meanings given in the EU GDPR (and equivalent terms in other Data Protection Law, including "business," "service provider," and "sell"/"share" under the CCPA).
- "Customer Personal Data" means Personal Data that the Customer provides to Polyads, or authorizes Polyads to process, for the sole purpose of processing on the Customer's documented instructions under Section 4 – for example, a list of contacts or other personal data the Customer chooses to upload for processing on its behalf. It does not include the data described in Section 3.
- "Independent-Controller Data" means the Personal Data described in Section 3.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
- "Subprocessor" means a third party engaged by Polyads to process Customer Personal Data.
2. Scope and roles
2.1 This DPA applies to Polyads' processing of Personal Data in connection with the Service.
2.2 The parties acknowledge that Polyads processes Personal Data in two distinct capacities: as an independent Controller for Independent-Controller Data (Section 3), and as the Customer's Processor for Customer Personal Data (Section 4). Different obligations apply to each, as set out below.
3. Polyads as independent Controller
3.1 For the following Personal Data, Polyads determines the purposes and means of processing and acts as an independent Controller, not as the Customer's Processor:
(a) account and team-member data and authentication data (identifiers, email addresses, roles, and access credentials handled by our identity provider);
(b) usage, product-analytics, and diagnostic data relating to use of the Service;
(c) the publicly available advertising content that the Service ingests and analyzes, including any Personal Data of third parties that such content may contain ("advertising data subjects"); and
(d) the Creative Score and other scores, analytics, insights, and derived or aggregated data produced by the Service.
3.2 Polyads processes the Independent-Controller Data in accordance with its Privacy Policy and Data Protection Law, and is responsible, as Controller, for the lawful basis for that processing, for transparency (including the Article 14 notice to advertising data subjects), and for handling requests from those Data Subjects. Requests from advertising data subjects to object to or erase Personal Data contained in advertising content are handled as described in the Privacy Policy and may be sent to support@polyads.ai.
3.3 To the extent Polyads and the Customer are each independent Controllers of the same Personal Data, each party is independently responsible for its own compliance with Data Protection Law; neither is the other's Processor with respect to that data.
4. Polyads as Processor of Customer Personal Data
Where the Customer provides Customer Personal Data for processing on its instructions, the following apply. These provisions implement Article 28(3) of the EU/UK GDPR.
4.1 Instructions. Polyads will process Customer Personal Data only on the Customer's documented instructions, including as set out in the Agreement and this DPA and as necessary to provide the Service, unless required to do otherwise by law (in which case Polyads will, where legally permitted, inform the Customer). Polyads will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
4.2 Subject matter and details. The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I.
4.3 Confidentiality. Polyads will ensure that persons authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality.
4.4 Security. Polyads will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking account of Article 32 of the GDPR. A description of those measures is in Annex II.
4.5 Subprocessing. The Customer provides a general authorization for Polyads to engage Subprocessors, subject to Section 5.
4.6 Assistance with Data-Subject rights. Taking into account the nature of the processing, Polyads will assist the Customer, by appropriate technical and organizational measures and insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Law.
4.7 Assistance with security, breach, and impact assessments. Polyads will assist the Customer in ensuring compliance with the obligations in Articles 32 to 36 of the GDPR (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to Polyads.
4.8 Deletion or return. On termination of the provision of the relevant services, Polyads will, at the Customer's choice, delete or return the Customer Personal Data and delete existing copies, unless retention is required by law.
4.9 Records and audits. Polyads will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by the Customer or a mandated auditor, subject to reasonable confidentiality, security, and notice arrangements (at least 30 days' written notice, no more than once per year absent a Personal Data Breach or regulator requirement).
5. Subprocessors
5.1 The Customer authorizes Polyads to engage the Subprocessors listed in Annex III to process Customer Personal Data.
5.2 Polyads will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains liable to the Customer for a Subprocessor's performance of its obligations.
5.3 Polyads will give the Customer advance notice of any intended addition or replacement of a Subprocessor (at least 15 days where practicable), giving the Customer the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected part of the Service.
6. International transfers
6.1 Where Polyads processes Customer Personal Data originating in the EEA, the UK, or Switzerland and transfers it to a country that does not benefit from an adequacy decision, the transfer is subject to an appropriate safeguard under Data Protection Law.
6.2 The parties agree that:
(a) the EU SCCs are incorporated into this DPA by reference and apply to transfers of Customer Personal Data from the EEA where Polyads acts as the Customer's Processor, using Module Two (Controller to Processor). For the SCCs: the Customer is the data exporter and Polyads is the data importer; the optional docking clause applies; the supervisory authority and governing law are as set out in the SCCs and Annex I; and Annexes I to III of this DPA populate the corresponding SCC annexes. Transfers of Independent-Controller Data (Section 3) are not governed by this Section; they are subject to Polyads' own transfer safeguards as described in the Privacy Policy;
(b) for transfers subject to the UK GDPR, the UK International Data Transfer Addendum (IDTA) to the EU SCCs issued by the UK Information Commissioner applies and is incorporated by reference; and
(c) for transfers subject to the Swiss FADP, the EU SCCs apply as adapted by the Swiss Federal Data Protection and Information Commissioner's guidance.
6.3 Where a recipient is certified under the EU-US Data Privacy Framework (and its UK Extension and Swiss counterpart), Polyads may rely on that framework as the transfer mechanism for transfers to that recipient.
7. Personal Data Breach
Polyads will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own breach-notification obligations.
8. CCPA / US state law
8.1 To the extent Polyads processes Personal Data that constitutes personal information under the CCPA as the Customer's service provider or contractor, Polyads will: (a) process it only for the business purposes specified in the Agreement and this DPA, and not for any other purpose; (b) not sell or share it, and not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the services; (c) not combine it with personal information from other sources except as permitted by the CCPA; and (d) comply with applicable obligations under the CCPA and provide the same level of privacy protection as required of a business. Polyads certifies that it understands and will comply with these restrictions.
8.2 The Customer's disclosure of personal information to Polyads, and Polyads' processing of it on the Customer's behalf, is not a "sale" or "share" and does not form part of any monetary or other valuable consideration.
9. Liability and precedence
9.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
9.2 In case of conflict between this DPA and the Agreement on the subject of data protection, this DPA prevails. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
9.3 This DPA remains in effect for as long as Polyads processes Customer Personal Data.
Annex I – Description of processing
A. Parties.
- Data exporter / Controller: the Customer (the business that accepted the Agreement), for its own purposes.
- Data importer / Processor: Npcat LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States. Contact: support@polyads.ai.
B. Subject matter and duration. Provision of the Polyads competitive advertising-analytics Service; for the duration of the Agreement and until deletion or return of Customer Personal Data.
C. Nature and purpose of the processing. Hosting, storage, processing, and analysis of Customer Personal Data as necessary to provide the Service on the Customer's documented instructions.
D. Types of Customer Personal Data. As determined by the Customer when it provides Customer Personal Data – for example, business-contact identifiers or other personal data the Customer chooses to submit for processing on its instructions. The Customer must not submit special-category data unless separately agreed.
E. Categories of Data Subjects. As determined by the Customer – for example, the Customer's own contacts, personnel, or other individuals whose data the Customer submits.
F. Frequency. Continuous, for the duration of the services.
G. Competent supervisory authority / governing law of the SCCs. As determined by the Customer's place of establishment in the EEA (or, for UK transfers, the UK ICO), consistent with the SCCs.
Note on Independent-Controller Data. The publicly available advertising content, account/team-member data, usage and product analytics, and the Creative Score are processed by Polyads as an independent Controller (Section 3) and are described in the Privacy Policy; they are not "Customer Personal Data" processed on the Customer's instructions.
Annex II – Technical and organizational security measures
Polyads maintains technical and organizational measures appropriate to the risk, including:
- Access control: authenticated access via an identity provider with verification of access tokens; role- and permission-based access controls (including workspace-permission checks); an administrator allow-list for administrative functions.
- Credential protection: server-side command-line and session tokens and device codes are stored in hashed form (a newly issued command-line token is held briefly in plain text until the client retrieves it, then removed); single-use, short-lived invitations and connection claims.
- Network and application security: restricted network access; request rate limiting; a cross-origin request allow-list.
- Data segregation and storage: infrastructure and data storage (databases and object storage) located in the European Union (Germany); separate storage for application logs; short-lived analysis caches (evicted after approximately seven days). These measures reflect the current state of the Service and may be updated as it evolves, provided the level of protection is not materially reduced. As provided in Section 4.3, personnel authorized to process Customer Personal Data are placed under appropriate confidentiality obligations. Further measures (for example, formal encryption-at-rest, backup, and independent security-testing programs) are being developed as the Service matures.
Annex III – Subprocessors
The following categories of third parties support the provision of the Service. Where and to the extent any of them processes Customer Personal Data on the Customer's documented instructions, it acts as a Subprocessor under Section 5; otherwise it supports Polyads' processing of Independent-Controller Data (Section 3) as Polyads' own service provider. Today, none of these parties is required to process Customer Personal Data. A list identifying the specific providers is available to the Customer on request.
| Category of provider | Purpose | Location |
|---|---|---|
| Cloud hosting and storage | Hosting the Service and storing data | European Union (Germany) |
| Authentication provider | Authentication and identity; product analytics | United States |
| Advertising-data provider | Sourcing publicly available advertising content | United States |
| AI / machine-learning provider | Extraction of attributes from advertising creatives | United States / global (EU-US Data Privacy Framework participant) |
| IP-geolocation provider | Coarse location lookup on agent connection | Global |
| Software-distribution (package registry) | Distribution of CLI software updates | United States / global |
To request a countersigned copy of this DPA, contact support@polyads.ai.