Skip to content
Próximo Ads

Data Processing Addendum

Last updated: October 10, 2026

This Data Processing Addendum (including its Schedules, the "DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Proximo Ads LLC ("Próximo Ads" or the "Company") and the client identified in the Agreement ("Customer"). It applies when the Company processes Customer Personal Data subject to Data Protection Laws while providing the Services, and it lasts for the term of the Agreement.

1. Definitions

  • "Customer Personal Data" means the Personal Data described in Schedule 1 that the Company processes on behalf of Customer.
  • "Data Protection Laws" means all privacy and data protection laws that apply to the Company's processing of Customer Personal Data, including European Data Protection Law and U.S. federal and state privacy laws (such as the CCPA).
  • "European Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), Spain's Organic Law 3/2018 (LOPDGDD), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and laws implementing or supplementing them.
  • "Personal Data" means information relating to an identified or identifiable individual ("Data Subject").
  • "Processing" (and "Process") means any operation performed on Personal Data, such as collection, storage, use, disclosure or deletion.
  • "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  • "Standard Contractual Clauses" or "EU SCCs" means Module 2 (controller to processor) of the clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner, in force from 21 March 2022.

Other capitalized terms have the meaning given in the Agreement.

2. Roles and instructions

Customer is the controller (or "business") and the Company is the processor (or "service provider") of Customer Personal Data. The Company will process Customer Personal Data only on Customer's documented instructions, which include the Agreement, this DPA and Customer's use and configuration of the Services, and only as needed to provide the Services. The Company will tell Customer if it believes an instruction violates Data Protection Laws, or if the law prevents it from following an instruction, unless the law prohibits telling Customer.

Customer is responsible for having a lawful basis for the Processing, including providing notices and obtaining any consents required from Data Subjects (for example, for website forms, cookies and pixels on Customer's website, and text-message marketing).

3. International transfers

If Customer Personal Data subject to European Data Protection Law is transferred to the Company in a country without an adequacy decision, the EU SCCs are incorporated into this DPA with Customer as "data exporter" and the Company as "data importer," and:

  • Clause 7 (docking clause) does not apply;
  • Clause 9: Option 2 (general authorization) applies, with notice of new subprocessors as set out in Section 5;
  • Clause 11: the optional language does not apply;
  • Clauses 17 and 18: the laws and courts of Ireland apply, unless Customer is established in Spain and requests Spain, in which case Spanish law and courts apply;
  • Annex I.A: the parties and contact details are those in the Agreement; Customer is controller and the Company is processor; signing the Agreement counts as signing Annex I.A;
  • Annex I.B: is described in Schedule 1; transfers are continuous for the term of the Agreement;
  • Annex I.C: the competent supervisory authority is the one for Customer's establishment (for Spanish customers, the Agencia Española de Protección de Datos);
  • Annex II: is described in Schedule 2.

For transfers subject to UK law, the UK Addendum applies, completed with the information above; either party may end it as allowed by its Section 19. For Swiss transfers, the EU SCCs apply with references to the GDPR read as references to the Swiss FADP.

4. Confidentiality and security

The Company will ensure that anyone it authorizes to process Customer Personal Data is bound by confidentiality. The Company will implement and maintain the technical and organizational measures in Schedule 2, and will provide reasonable assistance, at Customer's cost where permitted, to help Customer meet its own security obligations.

5. Subprocessors

Customer authorizes the Company to use the subprocessors listed at proximoads.com/legal/subprocessors. The Company will notify Customer by email (to the account contact) at least 14 days before adding or replacing a subprocessor that processes Customer Personal Data. Customer may object on reasonable data protection grounds within that period, and the parties will work in good faith to resolve it. If they cannot, Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.

The Company will impose data protection terms on each subprocessor that are at least as protective as this DPA, and remains liable for its subprocessors' performance.

6. Data Subject requests

If the Company receives a request from a Data Subject about Customer Personal Data, it will forward it to Customer without undue delay and will not respond except to direct the person to Customer, unless the law requires otherwise. The Company will provide reasonable assistance so Customer can respond to requests.

7. Security Incidents

The Company will notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will include, as available, the nature of the incident, the data and Data Subjects affected, likely consequences and the measures taken. The Company will take reasonable steps to contain and remedy the incident and will reasonably help Customer meet any notification obligations. Notifying Customer is not an admission of fault or liability.

8. Impact assessments

The Company will provide reasonable information and assistance, at Customer's cost where permitted, for data protection impact assessments and prior consultations with authorities that relate to the Services.

9. Return and deletion

Within 90 days after the Agreement ends, the Company will delete Customer Personal Data, or return it first if Customer asks in writing before the Agreement ends, unless the law requires keeping it. Any retained data stays protected by this DPA and is processed only as the law requires. The Company will certify deletion on Customer's written request.

10. Audits

The Company will make available the information reasonably needed to demonstrate compliance with this DPA, including written answers to reasonable security questionnaires, once per year. If that is not enough, or after a Security Incident, or when required by a supervisory authority, Customer may audit the Company's compliance, at Customer's cost, with at least 30 days' written notice to hello@proximoads.com, during normal business hours and in a way that does not unreasonably disrupt the Company's business or breach its confidentiality obligations to others. Auditors must be independent, qualified and bound by confidentiality, and may not be competitors of the Company. Audits under Clause 8.9 of the EU SCCs are carried out under this Section.

11. Aggregated data

The Company may create anonymized and aggregated data from its Processing (for example, average cost per lead by industry) that does not identify Customer or any Data Subject, and use it to improve its Services and for other lawful business purposes.

12. U.S. state privacy laws (including CCPA)

Where the CCPA or similar U.S. state laws apply, the Company is a "service provider" or "processor." The Company will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it for any purpose other than providing the Services, or as otherwise allowed by law; (c) retain, use or disclose it outside the direct business relationship with Customer; or (d) combine it with personal information from other sources, except as allowed by law. The Company will tell Customer if it can no longer meet these obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws do not allow limits. If this DPA conflicts with the Agreement, this DPA prevails. If it conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

Schedule 1: Details of Processing

Data Subjects: Customer's prospects and customers (including people who respond to Customer's ads, submit Customer's website forms, call, or message Customer's social media pages or Google Business Profile); visitors to Customer's website; Customer's followers on social media; and Customer's employees and contractors who use the Portal.

Categories of Personal Data: contact details (name, email, phone); messages, comments and reviews; lead and form submissions; online identifiers and website usage data (IP address, device, pages visited, collected with cookies or pixels on Customer's website according to Customer's settings); advertising audience and conversion data; Portal account data (name, email, credentials); and any Personal Data contained in content Customer provides.

Sensitive data: none intended. Customer will not ask the Company to process special-category data unless agreed in writing.

Nature and purpose: building and hosting Customer's website and email; managing Customer's Google Business Profile, social media and advertising campaigns; collecting and reporting analytics and leads in the Portal; and communicating with Customer.

Duration: the term of the Agreement plus the deletion period in Section 9.

Schedule 2: Security Measures

  • Access control: unique accounts, strong passwords and multi-factor authentication on all business systems that hold Customer Personal Data; access limited to people who need it; access removed promptly when no longer needed.
  • Client separation: the Portal uses role-based access and database row-level security so each client can only see its own data.
  • Encryption: HTTPS/TLS for data in transit; encryption at rest provided by our hosting, database and email providers; encrypted company devices.
  • Vendors: reputable providers with their own security programs (see the subprocessor list); data protection terms with each.
  • Network and hosting security: firewalls, DDoS protection and malware scanning provided by our hosting providers; software kept up to date.
  • Backups and recovery: regular backups by our hosting and database providers, and a plan to restore service after an outage.
  • Logging: authentication and access logs kept for a commercially reasonable period to detect and investigate misuse.
  • Incident response: a documented process to investigate, contain, notify and learn from Security Incidents.
  • Change management: changes to the Portal are reviewed and tested before release.
  • People: confidentiality commitments and security awareness for anyone with access.
  • Review: these measures are reviewed at least once a year and as the Services change.