Legal · Data Processing Addendum
AdWash Data Processing Addendum
Last updated: June 7, 2026 · Effective: June 7, 2026
About this Addendum
This Data Processing Addendum (the "Addendum" or "DPA") forms part of and is incorporated into the AdWash Terms of Service between Yelu Marketing, the operator of the AdWash platform at adwash.ai ("Yelu Marketing", "we", the "Processor"), and the customer entity that has accepted those Terms (the "Customer", the "Controller"). It applies to the extent we Process Customer Personal Data as a Processor on behalf of Customer.
In the event of a conflict between this DPA and the Terms with respect to the Processing of Customer Personal Data, this DPA controls.
Definitions
Capitalized terms used but not defined here have the meaning given in the Terms or in applicable Data Protection Laws.
- Data Protection Laws means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 (the "GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (the "CCPA"), and any other comparable laws.
- Customer Personal Data means Personal Data that we Process on behalf of Customer in providing the Service.
- Personal Data, Process, Processor, Controller, Data Subject, and Supervisory Authority have the meanings given in the GDPR.
- Sub-processor means a third party engaged by us to Process Customer Personal Data on our behalf.
Roles and scope of Processing
With respect to Customer Personal Data, Customer is the Controller (or processor acting on behalf of a third-party controller) and Yelu Marketing is the Processor. Each party will comply with its obligations under Data Protection Laws.
The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex A (Processing Particulars).
Customer instructions
We will Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country. Customer's instructions include the Terms, this DPA, and the configurations and operations Customer initiates through the Service (for example, connecting a Google Ads account, connecting a CRM, generating and launching campaigns, or pushing offline conversions).
We will notify Customer if, in our opinion, an instruction infringes Data Protection Laws, unless prohibited from doing so by law.
Confidentiality
We will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations and have received appropriate training on the protection of Personal Data.
Security
We will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to such data (the "Security Measures"). These include the measures described in Annex B (Security Measures). We may update the Security Measures from time to time, provided the updated measures do not materially diminish the level of protection.
Sub-processors
Customer provides general authorization for us to engage Sub-processors to Process Customer Personal Data. We will (a) enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those in this DPA, and (b) remain liable to Customer for the performance of each Sub-processor.
Our current Sub-processors are listed in our Privacy Policy. We will notify Customer of new Sub-processors (by email or in-product notice) at least 14 days before they begin Processing. Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected portion of the Service.
International transfers
Where we transfer Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we will rely on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), the UK International Data Transfer Addendum, or other lawful transfer mechanism, in each case as appropriate to the transfer.
Data subject requests
Taking into account the nature of the Processing, we will provide reasonable assistance, by appropriate technical and organizational measures, to enable Customer to respond to requests from Data Subjects exercising rights under Data Protection Laws. Most such requests can be handled through the Service's self-serve controls; for the rest, contact privacy@yelumarketing.com.
Security incidents
We will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will include, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it.
Data protection impact assessments
Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with Supervisory Authorities that Customer is required to carry out under Data Protection Laws.
Audits
We will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including our most recent third-party audit reports or security certifications where available. On no less than 30 days' written notice, and no more than once per 12-month period (unless required by a Supervisory Authority), Customer may conduct an audit limited to information strictly necessary to assess our compliance with this DPA, at Customer's expense, during normal business hours, and subject to reasonable confidentiality obligations.
Return or deletion of data
On termination or expiration of the Agreement, we will, at Customer's choice and unless retention is required by applicable law, return or delete Customer Personal Data within a reasonable time period. Backup copies will be deleted in the ordinary course of our backup retention schedule.
Limitation of liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws.
Term and survival
This DPA takes effect on the Effective Date and continues for as long as we Process Customer Personal Data under the Agreement. Sections that by their nature should survive termination (including obligations regarding confidentiality, data return or deletion, and liability) will survive.
Annex A – Processing Particulars
- Subject matter. Operation of the AdWash Service as described in the Terms.
- Nature and purpose. Hosting, generating, publishing, and optimizing Google Ads campaigns on behalf of Customer; ingesting CRM job and invoice events; pushing offline conversions to Google Ads; computing ROI dashboards; authenticating users; supporting Customer through the in-app Help bot and email.
- Duration. For as long as the Agreement is in effect, plus any post-termination return / deletion period.
- Types of Personal Data. Account identifiers (name, email, hashed password, Google account identifier); business profile data; Google Ads campaign and performance data; CRM job and customer data (which may include end customer names, phone numbers, addresses, job values, payment status, GCLIDs); billing identifiers from Stripe; technical and security logs (IP, user agent, request timestamps).
- Categories of Data Subjects. Customer's authorized users, employees, and end customers whose information enters the Service through a connected CRM or through Google Ads telemetry.
Annex B – Security Measures
Our Security Measures include the following. We may update these from time to time, provided the updated measures do not materially diminish the level of protection.
- Access control. Principle of least privilege for personnel; unique credentials; multi-factor authentication required for production access; audit logging of administrative actions.
- Authentication. Passwords stored as bcrypt hashes; OAuth tokens scoped and rotated; platform-admin actions tied to a separate allowlist and logged.
- Encryption. TLS in transit for all customer traffic; encryption at rest for secrets and credential material.
- Webhook integrity. HMAC-SHA256 signature verification on incoming CRM and Stripe webhooks using timing-safe comparison.
- Application security. Server-side capability checks on every tier-gated action; defense in depth on billing endpoints; input validation via typed schemas; rate limiting on auth and high-cost endpoints.
- Operational resilience. Nightly database backups with rotation; structured application logs retained for incident review; production deploys via reviewed pull requests.
- Vendor management. Sub-processors selected for an equivalent or stronger security posture; written data processing terms with each.
Signatures and acceptance
By executing the Terms of Service (including through online acceptance), or by clicking "I agree" where this DPA is presented, Customer accepts this DPA as a binding addendum to the Agreement. No separate signature is required.
Contact
For DPA-related questions, contact privacy@yelumarketing.com.
AdWash is a product of Yelu Marketing. © 2026 Yelu Marketing. All rights reserved.