AdPropixAdPropix

    Data Processing Agreement

    Last updated: January 30, 2026

    1. Introduction

    This Data Processing Agreement ("DPA") forms part of the Terms of Service between AdPropix ("Processor," "we," "us") and you ("Controller," "you") and governs the processing of personal data on your behalf.

    This DPA is designed to ensure compliance with data protection laws, including the General Data Protection Regulation (GDPR) and other applicable privacy regulations.

    2. Definitions

    • "Personal Data" means any information relating to an identified or identifiable natural person
    • "Processing" means any operation performed on Personal Data
    • "Data Subject" means an individual whose Personal Data is processed
    • "Sub-processor" means any third party engaged by us to process Personal Data
    • "Supervisory Authority" means a data protection authority under applicable law

    3. Scope and Purpose

    3.1 Scope

    This DPA applies to the processing of Personal Data that you submit to AdPropix for the purpose of receiving our services, including but not limited to:

    • Contact information of your leads and clients
    • Property listing data
    • Campaign targeting and audience information
    • Performance and analytics data

    3.2 Purpose

    We process Personal Data solely for providing our advertising automation services as described in our Terms of Service.

    4. Obligations of the Processor

    We shall:

    • Process Personal Data only on your documented instructions
    • Ensure personnel are bound by confidentiality obligations
    • Implement appropriate technical and organizational security measures
    • Assist you in responding to Data Subject requests
    • Support you in ensuring compliance with data protection obligations
    • Delete or return Personal Data at the end of services, upon request
    • Make available information necessary to demonstrate compliance
    • Allow for and contribute to audits conducted by you or an auditor

    5. Obligations of the Controller

    You shall:

    • Ensure you have a lawful basis for processing Personal Data
    • Provide clear instructions regarding the processing
    • Inform Data Subjects about the processing and their rights
    • Ensure the accuracy of Personal Data provided to us
    • Comply with all applicable data protection laws

    6. Sub-processors

    You authorize us to engage Sub-processors for the provision of our services. We maintain a list of current Sub-processors which includes:

    • Meta Platforms, Inc. - Advertising platform services
    • Cloud hosting providers - Infrastructure and data storage
    • Stripe, Inc. - Payment processing
    • Analytics providers - Performance monitoring

    We will notify you of any changes to Sub-processors and give you the opportunity to object on legitimate grounds.

    7. Security Measures

    We implement appropriate security measures including:

    • Encryption of Personal Data in transit and at rest
    • Access controls and authentication mechanisms
    • Regular security testing and assessments
    • Incident response and breach notification procedures
    • Employee training on data protection
    • Physical security of data centers

    8. Data Subject Rights

    We will assist you in responding to Data Subject requests, including requests to:

    • Access their Personal Data
    • Rectify inaccurate data
    • Erase data ("right to be forgotten")
    • Restrict processing
    • Data portability
    • Object to processing

    9. Data Breach Notification

    We will notify you without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach affecting data processed on your behalf. We will provide sufficient information to enable you to meet your notification obligations to supervisory authorities and Data Subjects.

    10. International Transfers

    We ensure that any transfer of Personal Data outside the European Economic Area (EEA) is conducted in compliance with applicable data protection laws, using approved transfer mechanisms such as Standard Contractual Clauses (SCCs).

    11. Data Retention and Deletion

    Upon termination of our services or upon your request, we will delete or return all Personal Data within 30 days, except where retention is required by law. We will provide written confirmation of deletion upon request.

    12. Audit Rights

    Upon reasonable notice, you may audit our compliance with this DPA. We will cooperate with audits and provide necessary access and information. Alternatively, we may provide audit reports from independent third-party auditors.

    13. Term and Termination

    This DPA remains in effect for the duration of our services. Provisions relating to confidentiality and data deletion survive termination.

    14. Contact

    For questions about this DPA or to exercise your rights:

    AdPropix Pty Ltd — Data Protection Team

    ABN: 56 696 674 656 | ACN: 696 674 656

    Level 10, 14 Mason Street, Dandenong VIC 3175, Australia

    Email: dpo@adpropix.io

    General Support: support@adpropix.io

    Phone: +61 402 018 828