ChatAdsAI · Palmidos Ltd
Part F - Data Processing Agreement (DPA)
Version 2.0 · Effective 1 October 2026
Version 2.0 · English
ChatAdsAI is operated by Palmidos Ltd (Company No. 517210829), Ramat Gan, Israel
| Document | Effective Date |
|---|---|
| Terms of Service | 1 October 2026 |
| Schedule A - Plans, Deliverables and Payment | 1 October 2026 |
| Acceptable Use Policy | 1 October 2026 |
| Cancellation and Refund Policy | 1 October 2026 |
| Service Level and Support | 1 October 2026 |
| Privacy Policy | 1 October 2026 |
| Data Processing Agreement | 1 October 2026 |
| AI Transparency Notice | 1 October 2026 |
This English version is the binding version for Customers whose principal place of business is outside Israel. For Customers in Israel, the Hebrew version is binding (Section 31).
This Agreement forms an integral part of the Terms of Service and applies to every Customer on whose behalf the Company processes Personal Data.
F.1 Roles
The Customer - Controller. Palmidos Ltd - Processor. With respect to the Customer's own account data, the Company is a Controller and the Privacy Policy applies.
F.2 Annex 1 - Details of Processing
Subject matter: campaign management services and the ChatAdsAI platform. Duration: for the term of the engagement and until completion of deletion or return under Section F.10. Nature and purpose: setting up, running, optimizing and reporting on campaigns; intake, storage, display, classification and export of leads; content generation; operational communications. Categories of data: name; email; telephone; business name and position; content of the inquiry; the wording of the direct marketing consent presented to the data subject and the timestamp at which it was given; campaign identifiers; IP address and device identifiers; ad interaction data. Data subjects: leads and inquirers from campaigns; contact persons acting on behalf of the Customer. Sensitive data: the Customer undertakes not to transfer sensitive data as defined in the Privacy Protection Law and in Article 9 of the GDPR, other than data whose transfer is unavoidable by the very nature of the Services as described above. The Company classifies the database at the corresponding security level in the database definitions document.
F.3 Processor Obligations
The Company shall:
(a) process Personal Data solely on the documented instructions of the Customer - including the instructions embodied in this Agreement and in the Customer's use of the Services - including with regard to transfers to a third country, unless otherwise required by law, in which case it shall inform the Customer in advance unless the law prohibits this; (b) ensure that every person authorized to process is bound by confidentiality; (c) implement security measures in accordance with Annex 3; (d) not engage a Sub-processor except in accordance with Section F.5; (e) assist the Customer by appropriate technical and organizational measures in responding to data subject requests; (f) assist the Customer, taking into account the nature of the processing and the information available to it, in fulfilling its obligations under Articles 32–36 of the GDPR; (g) delete or return the data, at the Customer's choice, in accordance with Section F.10; (h) make available to the Customer the information necessary to demonstrate its compliance with its obligations and allow audits in accordance with Section F.9; (i) inform the Customer if, in its opinion, an instruction of the Customer infringes the law; (j) not process Personal Data for any purpose of its own - including development, training, benchmarking or the generation of insights - and not sell, rent or share Personal Data with any third party, except on the Customer's instructions or as required by law; (k) maintain a record of processing activities under Article 30(2) of the GDPR and make it available for inspection upon request; (l) comply with its obligations as a holder under the Privacy Protection Regulations (Data Security), 5777-2017, including Regulations 15 and 19.
F.4 Controller Obligations
The Customer undertakes: (a) that there is a valid lawful basis for the collection of the data and its transfer to the Company, including consents to direct marketing as required; (b) that it has provided data subjects with the required notices; (c) to provide or approve in writing the wording of the direct marketing consent appearing in the lead form, which wording shall be deemed its documented instruction; (d) that its instructions comply with the law; and (e) not to transfer sensitive data in breach of Section F.2.
F.4A Controller Rights
The Customer has the following rights: to instruct on the manner of processing and to change its instructions; to receive documentation and conduct audits under F.9; to object to a Sub-processor under F.5.3; to choose between deletion and return under F.10; to receive assistance under F.7 and F.8; and to receive notice of a security incident under F.7.
F.5 Sub-processors
F.5.1. The Customer grants general written authorization for the engagement of the Sub-processors listed in Annex 2.
F.5.2. The Company shall give notice of any addition or replacement 30 days in advance, by email and on the Sub-processors page, to which updates can be subscribed.
F.5.3. The Customer may object on reasonable and reasoned grounds relating to data protection, within 15 days. The parties shall act in good faith to find a solution. If no solution is found within 30 days - the Customer may terminate the engagement immediately, the Commitment Period shall lapse, and the Customer shall receive a pro-rata refund of Service Fees paid in advance. Nothing in the foregoing derogates from the Company's right to replace a Sub-processor for emergency or security reasons, with notice given without delay.
F.5.4. The Company shall contract with each Sub-processor on data protection terms no less protective than those in this Agreement, including in accordance with Regulation 3 of the Transfer of Data Abroad Regulations, and shall remain fully liable to the Customer for its performance.
F.6 International Transfers
F.6.1. The Company is located in Israel, in respect of which there is an adequacy decision of the European Commission (reaffirmed on 15.1.2024) and equivalent recognition in the United Kingdom. Transfers from the EEA and from the United Kingdom to the Company do not require any additional mechanism for so long as such recognition remains in force.
F.6.2. Fallback mechanism. If the adequacy decision is revoked, suspended or limited in a manner that does not cover the transfers under this Agreement - the Standard Contractual Clauses set out in Commission Decision (EU) 2021/914, Module 2, which are hereby incorporated by reference, shall apply automatically, subject to the following completions: (a) the Customer - data exporter; the Company - data importer; details of the parties as set out in the Customer's account and in Section 32 of the Terms of Service - Annex I.A; (b) Clause 7 - applies; (c) Clause 9 - Option 2, notice period of 30 days; (d) the optional Clause 11(a) - does not apply; (e) Clause 17 - Option 1, the law of Ireland; (f) Clause 18(b) - the courts of Ireland, without prejudice to Clause 18(c); (g) Annex I.B - Annex 1; Annex I.C - the supervisory authority in the Customer's country of establishment, and in its absence the Irish DPC; Annex II - Annex 3; Annex III - Annex 2; (h) in the event of any conflict, the Clauses shall prevail, and Sections 30 and F.12 shall not apply to them.
F.6.3. For transfers from the United Kingdom - the UK International Data Transfer Addendum; from Switzerland - the required adaptations.
F.6.4. Transfers from Israel. The transfer of Personal Data from Israel to a Sub-processor outside Israel shall be made in accordance with the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 5761-2001, including a written undertaking from the recipient under Regulation 3. For a transfer to a country without a European adequacy decision - SCCs in Module 3 pursuant to Clause 8.8, and a documented transfer impact assessment. At the Customer's request, the Company shall provide a description of the mechanism applicable to each Sub-processor.
F.6.5. Data originating from the EEA shall also be handled in accordance with the Privacy Protection Regulations (Provisions Regarding Data Transferred to Israel from the European Economic Area), 5783-2023, including notice to the data subject within 30 days where required.
F.7 Security Incident
F.7.1. The Company shall notify the Customer of any security incident affecting data it processes on the Customer's behalf without undue delay, and in any event no later than 24 hours after becoming aware of it, by email to the registered contact person and in the interface.
F.7.2. If the circumstances have not been ascertained by the end of 12 hours - an initial notice shall be given and supplemented subsequently. The notice shall include a description of the incident, the categories and scope of the data and data subjects concerned, the likely consequences, the measures taken, and a contact person.
F.7.3. Formal responsibility for reporting to the supervisory authority and to data subjects lies with the Customer as Controller. The Company shall assist the Customer, at no additional charge, by providing information and documentation, quantifying the scope and identifying affected data subjects. Nothing in the foregoing derogates from the Company's obligation to report a serious security incident in a database owned by it to the Privacy Protection Authority under Regulation 11(d). A notice does not constitute an admission of liability.
F.8 Data Subject Requests
F.8.1. If the Company receives a request directly from a data subject - it shall refer the data subject to the Customer and notify the Customer.
F.8.2. The Company shall assist the Customer by appropriate technical and organizational measures, including the export, editing and deletion tools in the Services, at no additional charge and within a time frame that enables the Customer to meet statutory deadlines. Manual assistance that materially exceeds ordinary use - by arrangement and for a reasonable fee agreed in advance.
F.9 Audit
F.9.1. The Company shall make available to the Customer, at its request and not more than once every 12 months, reasonable documentation demonstrating its compliance with this Agreement, including responses to a security questionnaire and third-party audit reports where available.
F.9.2. If the documentation does not reasonably address the aspects the Customer has requested to examine - the Customer may conduct an on-site audit, itself or through an auditor appointed by it, upon 30 days' notice, during business hours, not more than once every 12 months (unless required following a security incident or a demand from an authority), at its own expense, subject to confidentiality and in a manner that does not disproportionately disrupt the Company's operations. The Company may object to a particular auditor on reasonable grounds in writing within 10 days, in which case the Customer shall propose an alternative auditor.
F.10 Deletion and Return
F.10.1. Within 30 days of the end of the engagement, the Customer shall notify whether it wishes the data to be deleted or returned. In the absence of notice - deletion at the end of 60 days.
F.10.2. If the Customer elects return - the Company shall deliver the data in CSV or JSON format free of charge, and shall delete it thereafter.
F.10.3. The right of export and deletion is not conditional upon payment, the absence of any debt, or any other condition.
F.10.4. The Company may retain data that it is required by law to retain, to the extent required only. Backups shall be deleted in the ordinary backup cycle and no later than 90 days. The obligations under this Agreement shall continue to apply to retained data.
F.10.5. At the Customer's request - written confirmation of deletion within 14 days.
F.11 Liability
F.11.1. The parties' liability under this Agreement is subject to Section 22 of the Terms of Service, except for: (a) the Company's liability to data subjects under Article 82 of the GDPR, which is not limited; (b) the Company's liability under Article 28(4) of the GDPR for the acts of Sub-processors; and (c) the Customer's right of recourse under Article 82(5) of the GDPR in respect of the Company's share of the incident - to which a separate aggregate cap shall apply in the amount of the greater of the Service Fees paid in the 24 months preceding the incident or €50,000.
F.11.2. Nothing in the foregoing limits any liability that the law does not permit to be limited.
F.12 Governing Law
Israeli law, except with respect to the Standard Contractual Clauses if and when they apply.
Annex 2 - Sub-processors
| Full Legal Name | Country of Incorporation | Role | Processing Location | Transfer Mechanism |
|---|---|---|---|---|
| Vercel Inc. | Delaware, USA | Hosting and running the platform | USA, global edge network | EU-U.S. DPF where certified; otherwise SCCs Module 3 + Regulation 3 undertaking |
| Neon Inc. | Delaware, USA | Storage of leads and account data | Frankfurt, Germany (AWS eu-central-1) | No transfer outside the EEA; Regulation 3 undertaking |
| Resend Inc. | Delaware, USA | System notifications | USA | EU-U.S. DPF where certified; otherwise SCCs Module 3 + Regulation 3 undertaking |
| OpenAI, L.L.C. | Delaware, USA | Content generation (language model), no training on customer data | USA | SCCs Module 3 + Regulation 3 undertaking |
Disclosure of an independent Controller (not a Sub-processor): the OpenAI Ad Platform receives campaign data as an independent Controller, under its own terms, in accordance with the authorization that the Customer itself granted to it in its Ad Account. The Customer is responsible for the lawful basis for this transfer.
Processor of account data only (Privacy Policy, not the DPA): the payment processor.
Annex 3 - Security Measures
Role-based access control and the principle of least privilege · two-factor authentication for administrative access · immediate removal of permissions upon termination of employment · TLS 1.2+ in transit, encryption at rest · environment segregation · logs of access and administrative actions · encrypted backups and restore testing · security updates and dependency scanning · confidentiality agreements and employee training · Sub-processor due diligence · incident response procedure · a database definitions document under Regulation 2 of the Data Security Regulations, reviewed and updated annually, specifying the database manager, the holder and the information security officer · quarterly assessment of whether the obligation to appoint a privacy protection officer applies, based on the cumulative scope of processing.