Data Processing Agreement (DPA) Smarketer GmbH --- WaveMetrics Platform
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms and Conditions of Smarketer GmbH for WaveMetrics (the "Agreement") between Smarketer GmbH ("Smarketer," "Processor") and the Customer ("Controller"). This DPA governs the processing of personal data by Smarketer on behalf of the Customer in connection with the WaveMetrics platform, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR"). In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails, per § 6.8 and § 9.5 of the Agreement.
1. Definitions
Terms such as "personal data," "processing," "controller," "processor," "data subject," "sub-processor," and "personal data breach" have the meanings given to them in the GDPR. "Customer Personal Data" means personal data processed by Smarketer on behalf of the Customer in the course of providing the WaveMetrics platform, as further described in Annex 1.
2. Subject Matter, Duration, and Scope
2.1. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex 1. 2.2. This DPA applies for the duration of the Agreement and continues to apply after termination for as long as Smarketer processes Customer Personal Data, in particular during the data export and deletion period under § 6.9 of the Agreement.
3. Instructions
3.1. Smarketer will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country, unless required to do so by EU or member state law to which Smarketer is subject. In such a case, Smarketer will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. 3.2. The Customer's instructions are given through the Customer's configuration and use of the Service (including its settings, feature selections, and API usage), through this DPA, through the Agreement, and through any additional written instructions agreed between the parties. 3.3. Smarketer will immediately inform the Customer if, in Smarketer's opinion, an instruction infringes the GDPR or other applicable data protection law.
4. Confidentiality
Smarketer ensures that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security of Processing
5.1. Smarketer implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex 2 ("Technical and Organizational Measures" or "TOMs"). 5.2. Smarketer may update the TOMs from time to time to reflect technical and organizational developments, provided the updated measures do not materially decrease the overall level of protection during the term of the Agreement.
6. Sub-Processors
6.1. The Customer grants Smarketer general authorization to engage sub-processors to assist in providing the Service. The current list of sub-processors is set out in Annex 3. 6.2. Smarketer will impose data protection obligations on each sub-processor that are substantially equivalent to those in this DPA, in particular through a written agreement, and remains liable to the Customer for the sub-processor's performance of its data protection obligations. 6.3. Smarketer will notify the Customer, via the platform, its website, or by email, of the addition or replacement of any sub-processor at least fifteen (15) days in advance, except where a shorter period is required for urgent security, legal, or operational reasons. The Customer may object to a new sub-processor within this period on reasonable data protection grounds, by notice under § 9.12 of the Agreement. If the parties are unable to resolve the objection, the Customer may, as its sole remedy, terminate the part of the Service that cannot be provided without the objected-to sub-processor, effective at the end of the then-current billing cycle. 6.4. This subprocessor-notification mechanism governs all changes to sub-processors and does not constitute an amendment of the Agreement under § 9.2, consistent with § 6.8a of the Agreement.
7. International Transfers
7.1. Where Customer Personal Data is transferred to a sub-processor located outside the European Economic Area (EEA) in a country that has not been recognized by the European Commission as providing an adequate level of data protection, Smarketer ensures that such transfer is subject to appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (SCCs), together with any additional supplementary measures required to ensure an essentially equivalent level of protection. 7.2. Annex 3 indicates, for each sub-processor, the location(s) where Customer Personal Data may be processed and the transfer mechanism relied upon.
8. Assistance with Data Subject Rights
Taking into account the nature of the processing, Smarketer will, insofar as this is possible, assist the Customer by appropriate technical and organizational measures for the fulfilment of the Customer's obligation to respond to requests for exercising data subjects' rights under Chapter III of the GDPR (e.g., access, rectification, erasure, restriction, data portability, objection). Where a data subject contacts Smarketer directly with such a request concerning Customer Personal Data, Smarketer will promptly forward the request to the Customer without responding to it substantively, unless otherwise required by law.
9. Assistance with Security, Breach Notification, and Impact Assessments
9.1. Smarketer will assist the Customer in ensuring compliance with the obligations set out in Articles 32 to 36 GDPR, taking into account the nature of processing and the information available to Smarketer, including in relation to security of processing, notification of personal data breaches, and data protection impact assessments. 9.2. Smarketer will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include, to the extent available at the time, the information required under Article 33(3) GDPR, and will be supplemented as further information becomes available.
10. Audits
10.1. Smarketer will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations in Article 28 GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. 10.2. In lieu of an on-site audit, Smarketer may satisfy this obligation by providing a current third-party audit report or certification covering the relevant controls (e.g., SOC 2, ISO 27001), where available. Any on-site audit will be conducted during normal business hours, with reasonable advance notice (at least 30 days, except where a shorter period is required by a supervisory authority), no more than once per calendar year absent a specific incident giving reasonable cause for an additional audit, and subject to reasonable confidentiality protections and cost allocation to be agreed between the parties.
11. Deletion and Return of Data
Upon termination of the Agreement, Smarketer will make Customer Personal Data available for export as described in § 6.9 of the Agreement, and will thereafter delete or irreversibly anonymize such data, except to the extent EU or member state law requires storage.
12. Liability
The liability of each party under this DPA is subject to the liability provisions of the Agreement (§ 7), including the liability cap in § 7.5 and the unlimited liability carve-outs in § 7.2, unless mandatory data protection law provides otherwise.
13. Order of Precedence and Term
13.1. This DPA forms part of the Agreement. § 9.5 of the Agreement (Order of Precedence) applies. 13.2. This DPA terminates automatically upon termination of the Agreement, subject to Section 2.2 above.
Annex 1 --- Details of Processing
-
Subject matter: The provision of the WaveMetrics SaaS/CSS platform, including product feed optimization, AI-based feed enrichment, performance analytics, and related features described in the Agreement.
-
Duration: For the term of the Agreement, and thereafter for the data export and deletion period described in § 6.9 of the Agreement.
-
Nature and purpose of processing: Hosting, storage, transmission, and analysis of Customer product and account data for the purpose of providing the Service, including: ingestion of product catalog data; transmission of data to Google Ads and Google Merchant Center via API on the Customer's instruction; AI-based processing of product descriptions and related content via third-party LLM providers to generate enriched feed attributes; generation of performance analytics and reporting; and payment processing via Stripe.
-
Categories of data subjects: The Customer's own personnel and Authorized Users (name, work email, login/account data); individuals identifiable from product data, reviews, or landing page content the Customer submits to the Service; end customers of the Customer to the extent identifiable from connected Google Ads/Merchant Center data.
-
Categories of personal data: Account and contact data of the Customer's personnel and Authorized Users (name, business email address, role); billing contact and payment-related data processed via Stripe (see Annex 3); to the extent present in product data or content submitted by the Customer, any personal data incidentally contained therein (the Customer is contractually restricted under § 6.2a of the Agreement from submitting special category personal data through the Service's AI-based features).
-
Special categories of data: None are intended to be processed; see the restriction in § 6.2a of the Agreement. Smarketer does not knowingly process special category personal data (Article 9 GDPR) through the Service.
Annex 2 --- Technical and Organizational Measures (TOMs)
-
Access control: Role-based access is in place. The product/engineering team holds administrative access to all systems. The sales team has read-only access limited to signup/onboarding status. The finance team has read-only access to Stripe for billing purposes. No other team has broader access than described here.
-
Encryption in transit: All data is transmitted using TLS.
-
Encryption at rest: All data is encrypted at rest on AWS using KMS-managed keys.
-
Backups: Databases are backed up via daily snapshots, retained for two weeks. Restoration from snapshots is tested periodically.
-
Logs and retention: Application logs are stored via AWS CloudWatch with a 90-day retention period.
-
Data segregation: Customer data is logically segregated by account ID, Customer, and Workspace within the platform's data model.
-
Personnel security: Staff receive annual security and data protection training.
-
Infrastructure hosting: Primary application infrastructure is hosted on AWS in Frankfurt, Germany (eu-central-1), per § 6.8a of the Agreement.
-
Incident response: A documented incident detection and response process is in place to identify, mitigate, and report security incidents in accordance with applicable breach notification requirements.
Annex 3 --- Sub-Processors
Stripe
-
Purpose: Payment processing
-
Contracting entity / processing location: Stripe Payments Europe, Limited ("SPEL")
-
Transfer mechanism: SCCs, per Stripe's DPA
-
Sub-processor's own list: stripe.com/legal/service-providers (Stripe gives 30 days' notice of changes; objection window 30 days)
OpenAI
-
Purpose: AI-based feed content generation and enrichment
-
Contracting entity / processing location: OpenAI Ireland Ltd (for customers based in the EEA/Switzerland). API-submitted data is retained a maximum of 30 days, then deleted.
-
Transfer mechanism: SCCs, per OpenAI's DPA
-
Sub-processor's own list: platform.openai.com/subprocessors (15-day objection window for new sub-processors)
Anthropic
-
Purpose: AI-based feed content generation and enrichment
-
Contracting entity / processing location: Anthropic PBC
-
Transfer mechanism: SCCs (Module 2/3), per Anthropic's DPA
-
Sub-processor's own list: anthropic.com/subprocessors (15-day notice for new sub-processors; 48-hour breach notification commitment; data deleted/returned within 30 days of termination)
Google (Vertex AI / Gemini Enterprise)
-
Purpose: AI-based feed content generation and enrichment
-
Contracting entity / processing location: Google Ireland Limited (EU-region processing; customer data is not used for model training).
-
Transfer mechanism: SCCs, per Google Cloud's DPA
-
Sub-processor's own list: cloud.google.com/terms/subprocessors
Google (Google Ads / Google Merchant Center APIs)
-
Purpose: Transmission of feed and campaign data to the Customer's own connected Google accounts, per the Customer's instruction.
-
Contracting entity / processing location: The Customer's own direct agreement with Google for its Ads/Merchant Center accounts governs that relationship independently. Smarketer acts solely as a conduit transmitting data via API on the Customer's instruction.
-
Transfer mechanism: N/A
-
Sub-processor's own list: ---
Amazon Web Services (AWS)
-
Purpose: Application hosting and primary databases
-
Contracting entity / processing location: Frankfurt, Germany (eu-central-1)
-
Transfer mechanism: Not applicable (EU)
-
Sub-processor's own list: ---
Smarketer will maintain an up-to-date version of this list, consistent with Section 6 above.