Data processing agreement

Effective August 2026 · Last updated August 2026

This DPA is an addendum to the Master Services Agreement between CurrentAds and a client. It applies automatically to every engagement; signing the MSA is what makes it binding. If your procurement process needs a countersigned copy on your own paper, email contact@currentads.net and we will sign yours rather than insisting on ours.

It is published instead of sent on request for the same reason our pricing is: you should be able to read the terms before you are in a sales conversation about them.

1. Who is who

For personal data belonging to your customers and prospects — the people who fill in your forms, call your tracked numbers, and appear in your CRM — you are the controller and CurrentAds is the processor. You decide why and how that data is used. We act on your documented instructions and nothing else.

Under US state privacy laws we are a service provider (California) or processor (Colorado, Connecticut, Texas, Virginia and the other comprehensive-law states) with respect to that data.

For personal data about your own staff that we hold to run the engagement — the names and work emails of the people we deal with, portal logins, billing contacts — we are the controller, and our privacy policy governs it.

2. What we process, and why

Only what the services you bought require. Depending on scope that can include: lead and enquiry records, CRM records and pipeline status, email and SMS subscriber lists with their consent and opt-out records, call metadata and, where you enable it and give the required notice, call recordings, website and campaign analytics, heatmaps and session recordings configured to exclude form-field contents, and customer lists you upload for audience matching.

The purpose is to deliver the engagement described in your order form. We do not use your data to build our own marketing lists, to enrich a database we sell, to benchmark you to another client in an identifiable way, or to train any AI model. The AI use policy covers that last one in detail.

3. Your instructions bind us

We process on your documented instructions, which are your order form, your written scope, and anything you tell us in writing afterwards. If we believe an instruction would break the law or an advertising platform’s policy, we will tell you and decline that instruction rather than quietly comply.

Everyone with access is under a written confidentiality obligation, contractors included, and access is limited to those who need it to do the work.

4. Security

Access to client systems is through delegated access to accounts registered in your name, never shared passwords. Portal accounts use per-user credentials with hashed passwords, server-side sessions, and rate-limited sign-in. Client API credentials are scoped to a single client, revocable, and stored only as a hash. Data in transit is encrypted, and the site enforces HSTS, a strict content security policy, and frame denial.

We will not ask you for a password to a system that supports delegated access, and you should not give one to any agency that does.

5. Subprocessors

The current list, what each one does, and what it touches is published on the AI use policy and subprocessor page and kept current there.

We will tell you before adding a subprocessor that would handle your data. If you reasonably object, we will either keep your data away from it or, if that is not possible, let you end the affected part of the engagement without penalty. Every subprocessor is under contract terms no weaker than these.

Tools inside your own accounts — your Google Ads, your GA4, your CRM, your email platform — are not our subprocessors. They are yours, governed by your agreements with those companies, which is a direct consequence of the ownership model: you hold the contract, so you hold the relationship.

6. When someone asks for their data

If one of your customers contacts us directly with an access, correction, deletion, opt-out or portability request, we will not action it ourselves. We will pass it to you promptly, because it is your relationship and your decision. We will then help you fulfil it, at no extra charge, including finding the records inside systems we operate for you.

We honour Global Privacy Control signals on our own site, and we will configure the same on yours where the service scope covers it.

7. If there is a breach

We will notify you without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting your data. The notice will say what happened, what data and roughly how many people are affected, what we have done, and what we recommend you do. We will not wait until we have a complete picture to tell you something has happened.

Notifying regulators and affected individuals is your call as controller. We will give you what you need to make it.

8. Deletion and return

When an engagement ends, data inside accounts registered to you simply stays with you — that is the whole point of the ownership model, and there is no export fee, offboarding fee, or hostage period.

For the copies we hold in our own systems: we delete or anonymise them within 90 days of the engagement ending, on request sooner, except where law requires us to keep something (invoices and tax records, kept 7 years). Backups age out on their normal cycle and are not restored to serve a deleted record.

9. Audit

On reasonable notice, once a year, we will answer a written security questionnaire and provide the documentation we have. For a regulated client whose own obligations require more, we will agree a proportionate on-site or live review at your cost. We are a small company and will not pretend to hold certifications we do not have; if you need SOC 2 today, we do not have it, and you should know that before you sign rather than after.

10. Where the data goes

Processing is primarily in the United States. One subprocessor, Brevo, is in the European Union. If an engagement involves personal data of people in the EU or UK, the Standard Contractual Clauses apply and we will execute them with you. Say so before kickoff so the scope is right from day one.

11. CCPA service provider terms

CurrentAds is a service provider under the CCPA as amended by the CPRA. We do not sell your personal information and we do not share it for cross-context behavioural advertising. We will not retain, use, or disclose it for any purpose other than performing the services in your order form, and specifically not for our own commercial purpose, outside our direct business relationship with you, or combined with personal information from another source except as the statute permits.

We certify that we understand these restrictions and will comply with them.

12. Conflicts and term

This DPA runs for as long as we process your data. Where it conflicts with the MSA on a data protection question, this DPA wins. Sections 7, 8, 11 and 12 survive termination.

Questions, or a copy on your own paper: contact@currentads.net · CurrentAds · Tennessee, United States