Marketing Operator
Features
Loading...

Data Processing Agreement

Last updated April 27, 2026

DRAFT — requires legal review before launch. This is template seed copy from a public SaaS source; it has not been reviewed by counsel. Do not rely on it as legal advice.

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", the "Controller") and Marketing Operator (pre-incorporation — not a registered entity) ("Provider", the "Processor") and applies to the extent we process personal data on your behalf in the course of providing Marketing Operator (the "Service").

This DPA is a template based on the European Commission's Standard Contractual Clauses (SCCs, Module Two — controller to processor, Decision (EU) 2021/914) and the UK International Data Transfer Addendum. It is intended for B2B customers who need a signed DPA before contracting with us. If you require a counter-signed copy, contact support@marketingoperator.ai.

A counter-signed PDF copy of this DPA is available on request — email support@marketingoperator.ai.

2. Definitions

  • "Personal Data" has the meaning given in GDPR Art. 4(1) and the UK Data Protection Act 2018.
  • "Processing" has the meaning given in GDPR Art. 4(2).
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates — typically a Customer's end user, employee, or contact.
  • "Controller" and "Processor" have the meanings given in GDPR Art. 4(7) and 4(8).
  • "Subprocessor" means any third party engaged by the Processor to Process Personal Data on the Controller's behalf.

3. Roles

For the purposes of this DPA:

  • The Customer is the Controller of Personal Data submitted to the Service ("Customer Personal Data").
  • Marketing Operator (pre-incorporation — not a registered entity) is the Processor of Customer Personal Data and processes it only on documented instructions from the Customer (which include, by default, the actions necessary to provide the Service in accordance with the Terms of Service).

For Personal Data we process about the Customer's own account holders (e.g. the email of the person who created the Customer's account), we are the Controller. That processing is governed by our Privacy Policy, not this DPA.

4. Categories of Data Subjects and Personal Data

| Category | Description | | --- | --- | | Data Subjects | The Customer's end users, employees, contractors, and any individuals whose data the Customer chooses to submit to the Service. | | Categories of Personal Data | Account information (email, display name); content the Customer submits (URLs, text prompts, uploaded media that may incidentally contain Personal Data); usage metadata (timestamps, IP addresses); audit records of Customer actions. | | Special categories | The Service is not designed to process special categories of data (GDPR Art. 9). The Customer agrees not to submit special-category data unless a written addendum is in place. | | Frequency | Continuous, for the duration of the Customer's subscription. | | Duration | For the term of the subscription, plus the thirty (30) day soft-deletion grace period and any retention required by law. |

5. Subprocessors

The Customer authorises Marketing Operator (pre-incorporation — not a registered entity) to engage subprocessors to deliver the Service. Our current subprocessors are listed in the Privacy Policy Section 4. We will notify Customers of new subprocessors with at least thirty (30) days' notice (by email and an in-app notice); the Customer may object on reasonable data-protection grounds, and if we cannot accommodate the objection the Customer may terminate the affected portion of the Service.

We require each subprocessor to enter into a written agreement that imposes data-protection obligations no less protective than those in this DPA.

6. Security measures

Marketing Operator (pre-incorporation — not a registered entity) implements appropriate technical and organisational measures to protect Customer Personal Data, including:

  • Encryption in transit — TLS 1.2 or higher for all connections between the Customer, the Service, and our subprocessors.
  • Encryption at rest — server-side encryption for Customer Content stored in object storage; database encryption at the storage layer.
  • Access controls — least-privilege access for our personnel; multi-factor authentication for production access; access logging and routine review.
  • Audit logging — immutable audit records of privileged actions and security-relevant events, retained per the Privacy Policy.
  • Vulnerability management — routine dependency scanning, penetration testing, and patching.
  • Incident response — documented incident-response procedures; commitment to notify Customers of qualifying personal-data breaches without undue delay (see Section 8).

A current list of measures is available on request to support@marketingoperator.ai.

7. Data subject rights

The Service provides Customer-facing tooling to help the Customer respond to Data Subject rights requests, including:

  • Access and portability — Settings → Export my data produces a structured JSON export of the Data Subject's account data.
  • Rectification — Data Subjects can edit profile data in Settings.
  • Erasure — Settings → Danger zone → Delete my account initiates a 30-day soft-deletion followed by permanent erasure.

To the extent the Customer requires assistance fulfilling a Data Subject rights request that the in-app tooling does not address, contact support@marketingoperator.ai. We will assist within statutory timelines.

8. Personal data breach notification

We will notify the Customer without undue delay (and in any event within seventy-two (72) hours of becoming aware) of a Personal Data breach affecting Customer Personal Data, providing the information required by GDPR Art. 33(3) to the extent then known. Subsequent updates are provided as the investigation progresses.

9. International transfers

Where Customer Personal Data is transferred outside the EU/EEA, the UK, or Switzerland to a country without an adequacy decision, the parties rely on the Standard Contractual Clauses (Module Two — controller to processor) and the UK International Data Transfer Addendum, which are incorporated by reference into this DPA. Annexes I, II, and III of the SCCs are populated by reference to: (I) the parties identified in this DPA, (II) the Personal Data described in Section 4, and (III) the security measures in Section 6.

10. Audit

The Customer may request a copy of our most recent third-party audit report (e.g. SOC 2 Type II, ISO 27001) under reasonable confidentiality terms by emailing support@marketingoperator.ai. On reasonable notice and at the Customer's expense, the Customer may conduct an audit of our compliance with this DPA, no more than once in any twelve-month period (subject to any further audit rights under applicable law).

11. Return or deletion of Personal Data

On termination of the Customer's subscription, Marketing Operator (pre-incorporation — not a registered entity) will, at the Customer's option, return all Customer Personal Data or delete it (subject to the soft-deletion grace and any retention required by law). If no instruction is provided, we delete Customer Personal Data per the retention rules in the Privacy Policy.

12. Term and changes

This DPA enters into effect on the Customer's acceptance of the Terms of Service and remains in effect for the duration of the subscription. Material changes will be communicated to the Customer with at least thirty (30) days' notice.

13. Contact

DPA-related questions, signed-counterpart requests, or subprocessor enquiries: email support@marketingoperator.ai.

A counter-signed PDF copy of this DPA is available on request — email support@marketingoperator.ai.

Back to top
Marketing Operator

Research Meta ads, import your site, ship AI-generated ads in minutes.

Product

  • Features
  • Pricing
  • FAQ
  • Contact
  • About

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use
  • Refund Policy
  • Data Processing Agreement
© 2026 Marketing Operator (pre-incorporation — not a registered entity). All rights reserved.