Data Processing Agreement
This Data Processing Agreement ("DPA") applies whenever you (the "Customer", "Controller") use the AdPilot Service to process personal data on behalf of consumers or end-customers — for example, personal information in lead-form responses you collect via Meta, or in audiences you upload. It is entered into between Shuhai Marketing ("AdPilot", "Processor") and the Customer.
This DPA is automatically incorporated into your Terms when you sign up. Enterprise customers requiring a signed counterpart can request one at office@shuhaimarketing.ca.
1. Roles
Customer is the Controller of any personal data it causes AdPilot to process. AdPilot is the Processor acting on Customer's documented instructions, including the instructions implied by Customer's configuration and use of the Service.
2. Subject matter, nature, and purpose
| Subject matter | Management of Customer's advertising on Meta and related platforms. |
|---|---|
| Duration | The term of Customer's subscription plus 30 days for deletion. |
| Nature of processing | Reading insights and metadata from Customer's connected ad accounts; storing brand assets; generating creative drafts via AI; writing changes (campaign creation, pause/resume, budget edits, creative swaps) to Meta when Customer confirms them; optional routing of lead-form responses to Customer-designated CRMs. |
| Purpose | Providing the Service requested by Customer. |
| Categories of data subjects | (a) Customer's personnel who have AdPilot accounts; (b) end consumers who interact with Customer's ads or fill out Customer's lead forms. |
| Categories of personal data | Identifiers (name, email), professional contact data, lead form field values configured by Customer in Meta (e.g. name, email, phone, city, custom questions), aggregated advertising performance data. |
| Special categories | AdPilot does not solicit special-category data. Customer must not configure lead forms to collect such data through the Service unless Customer has an appropriate lawful basis and notifies AdPilot in writing in advance. |
3. Processor obligations
AdPilot will:
- process personal data only on documented instructions from Customer;
- ensure personnel authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational measures (see Section 6);
- help Customer respond to data-subject rights requests (access, correction, deletion, portability, restriction);
- assist Customer with security, breach notification, and impact-assessment obligations under applicable law;
- make available the information needed to demonstrate compliance with this DPA;
- on termination, delete or return all personal data unless legal obligations require otherwise (see Section 10).
4. Customer obligations
Customer warrants that it has:
- a valid legal basis to provide the personal data to AdPilot for processing,
- obtained any consents and given any notices required by applicable privacy laws (PIPEDA, CASL, GDPR, CCPA, etc.),
- the right to engage AdPilot and the sub-processors listed at /legal/subprocessors.
5. Sub-processors
Customer authorises AdPilot to engage the sub-processors listed at /legal/subprocessors. AdPilot remains liable for the acts and omissions of its sub-processors.
AdPilot will notify Customer (by email to the workspace owner and a notice on the sub-processors page) at least 30 days before adding or replacing a sub-processor. If Customer objects on reasonable grounds within that period and the parties cannot find a commercially reasonable workaround, Customer may terminate the affected subscription for the remainder of the prepaid term with a pro-rata refund.
6. Security measures
AdPilot will maintain at least the following safeguards:
- TLS 1.2+ for data in transit;
- encryption at rest for the production database and uploaded files (provider-managed keys);
- access to production restricted to named administrators, with multi-factor authentication and SSH key auth;
- least-privilege role separation for application-level access;
- audit logging of administrative actions and of write actions performed against Customer's Meta accounts;
- regular security patching of operating system and application dependencies;
- incident response procedure including 72-hour breach notification to Customer;
- annual review of sub-processors' security postures.
7. Data subject requests
If AdPilot receives a request directly from a Customer's end-user (e.g. access, deletion, opt-out), AdPilot will forward the request to Customer without responding to the substance, unless legally required to do otherwise.
8. Government and law enforcement requests
If a government body, law enforcement agency, or court asks AdPilot to disclose personal data that AdPilot processes on Customer's behalf, AdPilot will:
- assess each request against applicable law before responding, and refuse any request that is not legally valid and binding on AdPilot;
- challenge requests that are overbroad, vague, or unlawful — including by asking the issuing authority to narrow the request, or by contesting it before the courts — wherever a good-faith basis to do so exists;
- disclose only the minimum data actually compelled by the request. AdPilot does not grant bulk, direct, or standing access to Customer data, and does not hand over credentials or encryption keys beyond what is specifically compelled;
- record each such request, the assessment made, and AdPilot's response in an internal log retained for at least three years, and make that record available to Customer on request to the extent disclosure is permitted;
- notify Customer before disclosing — or as soon as permitted afterwards — unless legally prohibited from doing so, and where prohibited, seek to have the prohibition lifted or time-limited.
9. Personal data breach
AdPilot will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer's data. The notice will describe the nature of the breach, the categories and approximate volume of data subjects and records concerned, likely consequences, and measures taken or proposed.
10. Return and deletion
On termination of the subscription, AdPilot will, at Customer's choice and within 30 days, either delete or return all personal data, and delete existing copies, unless applicable law requires storage. Backup copies are overwritten within the rolling 30-day backup window.
11. International transfers
Where transfers from the EEA, UK, or Switzerland to the United States or another non-adequate country are required, the parties incorporate by reference the European Commission's Standard Contractual Clauses (2021/914) as updated from time to time, with the Module-relevant options necessary to cover the transfer. AdPilot acts as the "data importer".
12. Audit
Customer may, at most once every 12 months and at its own expense, review AdPilot's written security documentation. On-site audits will be arranged only where (a) Customer is acting on a regulator's instruction or (b) a personal-data breach materially affecting Customer's data has occurred. The parties will agree reasonable scope, schedule, and confidentiality terms.
13. Liability
Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service.
14. Order of precedence
In case of conflict between this DPA and the Terms, this DPA prevails with respect to processing of personal data. In case of conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
15. Contact
Shuhai Marketing · Calgary, Alberta, Canada · office@shuhaimarketing.ca